You could keep the waterfall permission structure and introduce a feature, to restrict users/groups from files/folders, that would have precedence.
There are already classifications that can override the main permissions, so it should not be so complicated to add a function - restrict, that would be used exactly the same as the share function.
You could keep the waterfall permission structure and introduce a feature, to restrict users/groups from files/folders, that would have precedence.
There are already classifications that can override the main permissions, so it should not be so complicated to add a function - restrict, that would be used exactly the same as the share function.