I don't have full admin privileges, so I can't see what our Admin is able to see. I am told
you bring up the Edit Role wizard in vSphere Client GUI to enable or disable access
permissions.
But I am afraid you can't define access control at per customization spec level.