The MODX permissions are... complex. The simple use case here is having one User Group with access to one set of resources and another User Group with access to another set of resources.
So no problem: we create User Groups and Resource Groups for each, associate the 2 together with a rule for context access for the manager and another rule for resource group access and we're done...
Except that the default pages in the site are openly editable by either group. If they are not associated with one Resource Group or another, either User Group can see/edit them.
Is there a way have a User Group with permissions ONLY to view/edit stuff inside a given Resource Group and have it hide/ignore/protect resources that are not any explicit Resource Group?