Currently the roles are for all zones in the account, the only way to scope for a specific domain is with API tokens. If you have certain groups of domains you need to be managed by different people, it is worth talking to Sales or your Account Team if you aready have Enterprise as they may be able to offer some workarounds.
I think it makes a lot of sense to enhance the account authorization system to have a better granularity, from the dashboard, to manage roles also per zone or group of zones, surely for enterprise customers.