Tomcat permissions



Curious as to the best practices when setting up a tomcat server.
Should there be a tomcat user? if so, what should that user have
permission to (bin and webapps, anyting else?)

.