Hi,
you probabyl hit the limit of values desribed in SAP note 410993 ->3.. So when gererating the profile, 'sub'-authroizations are created automatically ->see last paragraph in that note.
You always should seperate between role data (agr*-tables) and authroization/profile data (usr*-tables) . Differences in the change docs may appear when you compare changed ocs for roles and changeodcs for profiles, auths, etc.
b.rgds, Bernhard