It would be good to have a 4th privilege option added to make the limiting of process creation easier to manage. Currently to have a view only user type you need to switch on the "limit process creation to PM, BA and PC" option in config which then means that you need to add users to the PC role in each process group manually.
It would be much easier to have a privilege available where view only access can be set at the user level rather than managing process creation user by user in each process group.