On the User Security Page you can allow or disable the following options by group:

AllowHTMLInFields
Should this user group be allowed to write 
HTML? HTML fields can change the appearance, color, style, font and layout of your data. 
AllowScriptInFields
Should this user group be allowed to write scripts, such as Javascript? Scripts should only be given to trusted users, as they can be used to alter your system.
Allow Edit CSS
Can this user group to edit Cascading Style Sheets? 
EnableUploads 
 Can this user group upload attachments to your Qrimp app? 
Show Export Options
Can this user group see 
export options to export data from your tables?
Show related data
Should the group see 
related data?
Default Start Page
The default start page is what a user sees when they first log in. If you do not change this setting, all users see the 
Dashboard. 
See 
Change the Default Start PageInput Black List
If the user group has permission to enter 
HTML, which characters can they not enter?