Here is the way I see it, I said it before last year:
The accounts with level 4 rights (Manager Accounts) have an option added to them so that if they try to change the server options, folder configuration, rights of other accounts(default rights, manager can add more), etc...
This should add better security incase someone with a ip mask gets ahold of your account.
When you click the server options buttion, as an example, you can edit whatever you like. When you click apply/ok, it asks you for your password. If you enter an invaild password, it ask syou again. 3 bad passwords will result in your account being disabled, and mabey even an email sent to the pwa or one of the other managers.
