User segregation

Hi! I need to create a role in order to enable a user to be a kind of “admin” but just for one ore more HostGroup.
To do this I create a new role and i apply A FILTER ON “director/filter/hostgroups” field.
In this way the usr see and manage only that hostgroup, but unfortunately cannot see the service associated to the template.
The role created t in this way do not see any services.
It can view service template \ commands or host template, BUT NOT the service definition itself.
Ad of course cannot see the service inside a template.
Is there a way to enable the view ot the service also ?
P.