Hello,
This happens because you excluded security principal Self from the activity scope of the Blind User role. The security principal Self also includes all groups a user is a member of.
To fix your problem you can do the following:
-
Create a new Security Role.
-
Add Deny Read Groups permission to this role.
data:image/s3,"s3://crabby-images/376aa/376aa6c4707d73f8a214587eaca1bfff4e402fe3" alt=""
-
Assign this role to Everyone over the groups that you what to hide.
data:image/s3,"s3://crabby-images/1fda4/1fda40ec0dcb434437272aa7562276f3a3e7e073" alt=""
-
Exclude the users that you want to allow to view these groups from the activity scope.
data:image/s3,"s3://crabby-images/e48e2/e48e229b109b49597d5f0046c824f2d01127e8f2" alt=""
We are considering changing this behaviour, and probably in the next version, the security principal Self will be treated as the self user account only.