Decrease administration, increase user experience
Allow users to specify the capacities they play or mandates they have and allow them to use those different personas with different rights and privileges. Let them use one profile for these different personas and apply Single Sign-on to switch from one persona to another. Use refined policies to exactly define what level of authorization is needed, based on the context and on the sensitivity of applications. Avoid role explosion and simplify life for the administrators. Increase security by eliminating role abuse.
Check out what industries benefit from multi-persona authentication