• A trusted finance colleague who's nosey can be a good testing buddy in SB. If they can already see most (if not all data) for the sub/s the role can see, they can just click around, try and do things. But this will be limited to what they do know about the system, but if viewing/finding financially restricted data is a problem, then I find it's a good one to start with.
• Ultimately trail and error with some specific role testing (can they raise this transaction as needed etc).
• If it's particular for colleagues, get a testing buddy to try and do all their normal day to day in SB - then you can try and view the blocked/restricted things.
• If the role/s have anything they really aren't allowed to do/see, then I would start trying to view/navigate to those things first. Just to make sure they can/cannot.
Hope this helps