just found again:
which provides also a hint...
I can only suggest to conentrate first on the main t-codes (I mean for your core business applications). Saw also already, that the upgrade was taken as chance to redesign the auth-concept.
Or at least, create new roles for the main business tasks first and assign them. The decision, whether the old roles shall be 'upgraded' then later or if only 'new' roles should be used can be taken quickly, the realization can be spread then ito improtant and not so important tasks.
b.rgds, Bernhard