I thought I was beginning to get this -- maybe not.
I tried to set up permissions for a user who could only see and edit his own page in the Manager.
The user is JoeBlow.
I set up role called JoeBlow with an authority level of 9998.
I set up a resource group called JoeBlow and added his page to it.
I set up a user group and added him to it with a role of JoeBlow.
Under Context Access, I gave the user group Mgr context access with a mininmum role of 9998 and assigned the standard Resource policy.
Under Resource Group Access, I added the resource group with a context of Mgr, a minimun role of 9998, an Access Policy of Resource, and a Context of Mgr.
The result is that JoeBlow gets a permission denied error on logging in and, when logged in as the superadmin, I can no longer see his page.
Any clues appreciated.
[Update] by changing the Resource Group Access to have an Access Policy of Administrator (rather than Resource) I can log in as Joe Blow and see the Manager, but with no resources showing in the tree. I tried adding the docs in the path to Joe Blow’s page to the Resource Group, but it had no effect.