If /useradmin doesn't work, then there is another tool for more granular permissions -- /crx/de Create multiple groups and restrict the model paths for each group per your use case using this console. I would update this thread, if I get a better solution.