You can allow users in a group to read or run applications in directories, and the subdirectories and files, that are controlled by an owner of the group. For example, a project manager might update status information for a project team to review.
Using the steps described for setting access control for a server instance (see Setting Access Control for a Server Instance), do the following:
Access the Server Manager for the server instance.
On the Preferences tab, click the Administer Access Control link.
Select the desired resource from the drop-down list and click Edit.
Create a rule with the default values that deny access to everyone from everywhere.
Create another rule allowing users in a specific group to have read and execute rights only.
Create a third rule to allow a specific user to have all rights.
Deselect Continue for the last two rules.
Click Submit to save your changes.