We have four user roles: Admin, Manager, Supervisor, and Agent.
Discussion posts and replies are publicly visible
Action level security should help you configure this. Add all the roles you want to give access to an action. E.g. Actions which should be accessible to Analysts, add Supervisor, Manager and Admin groups also in the 'Who can see this action' and for Admin actions just have Admin group in the field.
Refer this : docs.appian.com/.../record-action-security.html