What BobRay is suggesting is always step one. When I configure my deeply nested ACLs (we have about 10-15 of them with 10-20 roles and 10 resource groups, not to mention element permissions), you'd always have to work like a surgeon. Get your MODX manager SUDO login going in like Chrome, and do your testing in an Incognito tab (again, from Chrome) or rather Firefox or Opera.
When you do updates to the permission sets, always and ALWAYS either flush permissions or logout. I'd make it best practice to simply delete your cookies with the Webdeveloper Toolbar, both for Firefox and Chrome.
Alright, let's get into the thick of it.
If you've got a set of resources protected by a Resource Group, MODX needs to 'see' those resources before either granting or revoking your access to those resources. So, if you are an anonymous user, always make sure you got the 'load' permission set up on that Resource Group. The same goes for the fact when you're logged in and the logged in user belongs to a different user group. Match the role and permissions to that of the ACL and link it to the resource group.
Simply put, this'd be the following:
Anonymous - Member 9999 - Resource Group Name - load
Revoked User Name in User Group Name - User Revoked 5000 - Resource Group Name - load
Granted User Name in User Group Name - User Granted 4000 - Resource Group Name - load, list & view
I hope this helps!