1)
can i prohibit a user from having access to documents BUT for one resource group? That would be a pity if permissions for resource groups are not overwriting those general ones. If it’s not that way i’m doing something wrong.
I have a created a role "Editor". This Editor is supposed to be the one accessing the "News" Resource group (allready created and assigned resource News(3) to it - he shouldn’t have access to another ressource in my test case "Home" and "Info" which are unprotected [i think this is the problem, but that would be a pity]). So i created a "BasicAdmin" policy granting minimal permissions for the admin interface ( - that works

). Then i went to the "resources access" tab of my Admin group (the "Editor"-role user is in there, as well as the great working context access restrictions) and added "News|Editor-500|Administrator|Web". Now the admin can access this group (thats clear and desired) while the "Editor" cannot.
Edit:
okay i think i got that. I missunderstood the resource group concept at first. I somehow thought it was for granting some people permissions but actually it’s for protected. I have to protect the other resources and leave the news alone. Then i just need to give anonumous users and members frontend access to the protected resources with the load policy.
2)
Can’t i reate my own permission from the manager interface?
I have some comonents installed i want restrict access for different users. So i go the the "actions" menu and add for example "manage_events" in permission. Now the according component menu is gone. So i want to assign that permission to some Policies, but i can’t. It seems not possible to create own permissions.
P.S:
Revo 2.0.4.