You can translate to multiple IPs by using a NAT pool.
For a simple way of doing that, it's a 2 step process.
1. Configure a NAT pool.
2. Configure the rules in your user role ACLs to NAT to that pool.
For example....
ip NAT pool my-nat-pool 1.1.1.1 1.1.1.10
!
ip access-list session nat-to-my-nat-pool
user any any src-nat pool my-nat-pool
!
user-role natted-user
session-acl nat-to-my-nat-pool
!
Of course, if your user role has more rules, it might be more complex!