Hi
I think it would be better (safer, easier to administer, less prone to error, more conventional) if permissions were inherited from the normal role.
And then for individuals you could over-ride with access/deny on their page.
Very much like how Windows Server/Workstation works with group permissioning (i'm showing my age!)
It seems like the idea was there and works for users when imported. But why not just have that as the overall default? Thanks Ian