When someone accesses the Database mapper via the browser, if their login doesn't exists on the user list, it automatically gets added using the "Default Permission".
That is, the Active Directory membership information.
There is something on the documentation wherein we can add the user information before hand (its like a prep it up).
BUT, if you have multiple users, that is a bit of tedious, so we would prefer an Active Directory group to manage this permission