hope u following active directory architech , this will solve your department problem.
regarding software applications which r installed on local machine , if u want to control by user account all users can have different access and they can control using user rights. each individual machine go to control panel ..>users ...>and define the users access rights for the applications there ..those users can only able to access that applications...when they login as users x , y , z etc...as per user rights for x , y , z ...good luck