Additionally,
@Luca_Lattarini , you may also want to exclude the permissions that are company-wide. Even though it is less convenient for the vendors since the ability to Manage Properties means they cannot create their own properties, they also won't be able to reconfigure/delete them.