Hi,
Grant read access to the root folders the group should see, and remove read from the folders they shouldn't.
There's also 'Restriction by folder' at the operator level, though group level is more manageable for ACL.
If you're aiming to provision multiple tenants in a single instance, be aware there's more to it than folders- e.g. data segregation, modifications to global reports.
Thanks,
-Jon