Are you talking of inside Rancher before going to a cluster? Identify the user group when they come in and assign specific groups to specific roles.
In the clusters, do much the same with Cluster and Project Members, assigning permissions per project.
We're using AD as an identifier, so the groups are set in that.