Viya gets users and groups from an external identity provider (either LDAP or SCIM). You can create custom groups within Viya, but for the most part group and user management is done outside of Viya.
Viya permissions on functionality by default are divided into actions for Administrators and non-Administrators (Authenticated Users). This can be customized by adding additional rules on capability endpoints (this would be similar to roles in SAS 9 - see the Access to Functionality link below). Permissions to folders can be assigned at the user or group (either custom groups or Identity Provider sourced groups) level. You can also control access to specific URI endpoints with rules, for example limiting access to /SASStudio to a Developers group.
General Authorization
https://go.documentation.sas.com/doc/en/sasadmincdc/v_047/calauthzgen/titlepage.htmAccess to Functionality
https://go.documentation.sas.com/doc/en/sasadmincdc/v_047/calatf/titlepage.htm
--
Greg Wootton | Principal Systems Technical Support Engineer