defect
If buttons with a command group other than READ are added directly to a dialog (i.e. not to a child component, but to the dialog itself), ...
... these commands are not found in the role profile view and do not appear:
As a result, these commands cannot be authorized for any roles and can therefore only be executed by root users.
The error is probably in the com.top_logic.tool.boundsec.gui.profile.CompoundSecurityLayoutConfigDescender class in the addCommandGroupsRecursive(LayoutConfigTreeNode, LayoutConfigTreeNode) method, as only the child components are checked there and not the dialog itself.