It would be helpful if the application can have a Roles & Permission builder, which can aid administrators determine the needed permissions/restrictions.
The feature would be a administrator can setup a sample reference incident in the builder which contains their category, subcategory and other incident details. Then the user can decide if they want this incident can be seen by the user or not. Then the application would create the suggested required permissions to either manage/read the created sample reference incident.