On our project we currently have admins, developers and users that are tied to AD groups. These groups have minimum read access to all stories in the project. What we would like to do is add groups that have more restricted read access.
For example, if the project has 5 stories 1-5, we would like to add a group that could only read stories 4 & 5 so we need a mechanism to group stories 4 & 5 and associate those stories as a collection with a specific AD group. Also, when creating a new story we need a way to associate the story with the collection.
I've been told I can do this with issue security levels and schemes, but I don't quite understand how to do that to achieve that described above.
Anyone who might have done this type of thing before?