I am using "share a unique session" because I want scheduled workflows to be able to run independently of a particular employee's AD account still being active. As a result the service account I am using for "Share a unique session" has full rights in vCenter.
However I don't want every vRO user to have the ability to create workflows with the permissions of that service account which can do anything. Apart from going to each workflow and assigning rights to all the users to indicate which workflows they can and can't run, is there an easier way to set up permissions in vRO and allow different levels of rights to run workflows based on different AD groups?