Restrict Support team to only access the process instance and not the Process model object itself

Certified Associate Developer

What security settings should be given to restrict support users to access only the process instance but should not have any access to the main object itself ?

  Discussion posts and replies are publicly visible