Hello,
After a upgrade to 9.3.1 I ran into some unexpected behaviour regarding permissions. We use a similar configuration as described in your manual.
But the Deny setting on de default group All, is not overridden by the sub-groups I add below it.
A temporary solution was to uncheck all options at the All group, add a filter group All users, and override those deny settings with the subgroup.
But if I'm correct (and according to the manual), the All group permissions should be overridden by the subgroups. Thats why I think this is a bug.
Greetings Harald