Hi,as per [1], you should use deny sparingly. Usually I would give read rights to a group[2], groupA, groupB for:/content/site/A/content/site/BThere is no need to deny groupB, as it has no access rights on site A by default. In this way if you have a user that requires access to both sites, you simp...