When a domain model gets to complex with multiple configurations and associations, we need to create a separate domain model just to simplify the view although the same security rules applies. It would be nice to have multiple views or folders for "subsets" of the bigger domain model. In such a way you don't have to maintain multiple module roles.