Hey,
sorry for the late reply.
I think I was not clear enough. The Users don’t edit the resource in frontend and backend. They only edit the pages in the manager. The thing what I’m trying to do is following:
There are two contexts: web and sandbox (both in the manager)
I have two groups of User "Admins" and "Stuff"
Admin can edit any Context (web and sandbox) in the manager
The Stuff group should only be able to edit the sandbox context
and see/view the web context (not edit) (all in the manager)
What i did:
I created to more policies by duplicate the admin policy then I removed some core features like packages, system setting, flush_session etc in the policy i called "standard_mgr". In the second one I removed more permissions like save_document, save, edit_document, remove and so on. (All permissions that have something to do with the resources) and i called this one "read_context".
Now I went to Staff-Group -> Context ACL Tab and edit the ACLs:
1. mgr - lowest role in group - standard_mgr
2. web - lowest role in group - read_context
3. sandbox - lowest role in group - standard_mgr
Surely, I put the users in this group and they have the right role.
Result:
A stuff user can create,edit,remove any document in both context. I looks like that the mgr context policy just overwrites all other.
thank you for your help.