The inheritance issue aside (I don’t complain but I sure would use in some case to give access to a document children without giving access to the parent document), I never used sirlancelot’s empty user group.
As far as I am concerned, I have systematically build a user group for editors, and made all manager document private. Some are into the admin document group and others into the editors document group (managing this has really been made easier by DocManager !). I confess I never tested if this made those documents unavailable to any other user with no permissions but assumed it did.
Anyway, the user perms are not perfect but should work for you 95% of the case if you juggle with document and user groups properly (which, to some, is not natural at all... support request is proof there).
Now what has been mentionned time and again is merging manager and web users. I always agreed with that but I wonder now if it won’t make the permission system even more complex... maybe syncrhonizing both user groups is the way (never managed to make Raymond’s plugin
Web2Manager by the way.. neither did people who posted on the support thread, it would seem. I’d love to see this plugin updated !)