Each resource can have a global permission. Check the Manage User Accounts page for understanding users and user groups.
Open the window System → Resources :
Select a resource in the list. At the bottom of this panel we can see the permissions set for the selected resource. Use the buttons 'Add', 'Remove' and 'Edit' to manage the permissions for this resource.
In this example, the GLOBAL permission is set to 'viewable'. This means that everyone can view or access this resource, except those who have an explicit different permission.
We can see the usergroup 'users' with a permission 'editable'. This means that all users belonging to this group, and only those, have access to this resource and can edit its contents.
Finally, there is a single user called 'dieter' who has a strictly private permission set to 'hidden'. It is possible that the user 'dieter' belongs to the usergroup 'users' or not, but this will not influence its private permission: this is set to 'hidden', meaning he can not access and view the resource.
When assigning permissions, it is advised to keep a logical structure in mind :