Sure you can use the createdby field - I guess I had assumed that users wouldn’t be able to create their own resource. I don’t know if it would accept multiple values though, which would make using a TV useful if you wanted to allow more than one user to edit a particular resource. Depends on what you need, really.
The beauty of Bob’s solution is that you will only really need the plugin as a ’backup’ to prevent unauthorised access, as users will only be able to select their own documents from the tree.
But for those who might try to manipulate the url or somehow end up on someone else’s page, I found this example in the docs:
if (!$modx->hasPermission('edit_chunk')) die('Access Denied!');
Does
die() work for you? If not, you could have a look through the core files to do with manager access and see how ’access denied’ is handled there.