Hi!
There is a problem with the process of denying and then granting permission and that's because deny is stronger than grant!
I donät think you can deny on a folder level and then grant on the underlying object due to this.
I like to use permissions on folders and have folders for specific areas, one for each.
On the folder level I deny sasusers r/rm and grant r/rm to the user group(s) that should have access.
When new reports are created the only important thing to remeber is to put them in the correct folder 🙂
If you must (!) set permission on each report, I would go for scripting the permission. You can for example use the data step metadata-funtions or XML to achieve this.
//Fredrik
... View more