I’m struggling with this too, so take my advice with a large grain of salt.
I did get users who could log in to the Manager by putting them in a user group, then giving that user group:
1. Access to the Mgr context with a role of super-user and a policy of administrator (this will let them log in, but not see any resources)
2. Access to the Web context with a role of super-user and a policy of administrator (this will let them see resources in the tree)
Once that’s working, you can play with alternate roles and policies.
You can, for example, duplicate the Administrator policy and remove the things you don’t want those users to be able to do, then assign that policy to the user group instead or Administrator.
You can also create a lesser role.
Remember, too, that you can use Form Customization (on the Security menu) to hide tabs and fields that you don’t want members of certain user groups to see.
Hope this helps.