This level of user access control would require an integration with CA Embedded Entitlements Manager(eEM).
.
Currently you only have the ability to assign a user either to an "admin" role or "user" role, if you wish to get more granular than that, it would require eEM to be integrated.
Instructions for setting this up can be found
hereThe list of available access policies can be found
here