Group accounts
Sites that run CMS jobs need to use group accounts so that at any time each grid credential is mapped to an independent local account. This is needed for security reasons because any file in use (or produced) by a process must be accessible only to its owner. This is particularly relevant for proxies). The only exception to this rule (and it is hardly accepted by WLCG security people) is for the software installation user that is a unique account for at least CMS and LHCb.