I am working on a special Confluence server and in this case, for a long time, all spaces were available to all users, so it was fine to leave the confluence-users group in place with its default settings in the space permissions for all the spaces that were created.
Recently it became necessary to add a small but specific group in Confluence - users in this group should only have access to a single space and NOTHING else.
Given that there is no explicit deny, I had to create a new group, put everyone in Confluence-users minus the small group in there, go to all of the spaces that were previously created, and then remove confluence-users from the permissions, and add the new group.
So now every time someone makes a space, since the confluence-users group is added automatically, the space creator has to remember to take confluence-users out and add this other group. There has to be a better way.