Here's the short version - off the top of my head:
Put all the resources on the site in a Resource Group called AllDocs and create a Resource Group Access ACL entry connecting that Resource Group to the Administrator User Group (which the users in question are not members of but you are). Use a Policy of Resource and a Context of 'mgr'. You can use a utility snippet to put the resources in the Resource Group (create the Resource Group first!):
$count = 0;
$docs = $modx->getCollection('modResource');
foreach($docs as $doc) {
$resource->joinGroup('AllDocs');
$resource->save(); // probably not necessary, but can't hurt
$count++;
}
return "Added ' . $count . 'Resources to AllDocs Group';
Install the DefaultResourceGroup extra to put all future resources in the AllDocs group.
That will "protect" all resources from anyone outside the Administrator group.
Once that's done,
Put the users in a User Group Called AllowedDocs
Put the parent resource and it's children in a Resource Group called AllowedDocs
Connect that Resource Group to the AllowedDocs User Group with a Resource Group Access ACL entry with a context of 'mgr' and whatever Policy you want them to have (the Resource policy if you want them to have full rights).
Flush permissions and Sessions before testing any changes.
More info here:
https://bobsguides.com/revolution-permissions.html.
If you want to understand why you're doing it, watch
this 50-minute video.