We grant our clients access to the Space we work in for their account. This is done by granting the Group/User permission in the Permissions. This is the global - you can access/see.
Then we have to restrict each page (or parent pages) that we do NOT want the client to view.
This is how I thought it worked. The only way to allow the external Group/User access then restrict what they can see.
My question though is, can I eliminate the step of adding the group/user to Permissions and only grant access to pages for that group in restrictions? So the group is not in Permissions, but grant permission to view at a page level?