Tell me, is there any point in using a "security Scheme", if everything can be set in the "Scheme of access rights"?
The safety circuit just limits the "visibility" of zacci. Access rights - the ability to do something with this application. For example, the role developer can only comment application, and the role of qa - transfer of status to the status. With schema security you can restrict whether savca in principle visible, for example, qa or developer.

To be honest, in 99% of cases this stuff doesn't apply. It for Business processes, with the staff of connected within, for example, or internal requests. When the application default will be the security scheme "Only Rukovoditel" and the rest "all the others".
in contrast to the schemes of access rights, the security scheme is more fine-tuning of access down to the level of individual tasks

