How to restrict access to project folders by default in PDM

I am trying to solve a problem that may not be possible in PDM, but it would be really useful to find a way.  Please share any ideas!

How can I restrict access to all project folders by default and only allow access to each individual project folder by a group permission?

The problem is that IF the parent folder (i.e., Projects) is not given at least read access, then the sub-folder (i.e., individual project folder) is not accessible, even if permission was given by a group.  Giving read access to the parent folder (i.e., Projects) gives read access to ALL project folders created below.  I don't want to have to add a restriction to every individual project, in every permission group (besides the one granting access), each time a new project is added, but the nature of top-down permissions is pretty limiting in PDM, so maybe that's the only option?

I would love to find a creative solution that's more practical to manage, and defaults to restricted access.  I think a solution is needed where a permission could be applied to a parent, but set not to cascade down, so the other project folders at the same level remain hidden/restricted.  Perhaps an enhancement request is warranted, or maybe this simply isn't possible with the Windows integration?

Any ideas?  How are you managing your restricted folder needs in PDM?

 

Example folders and permissions:

>Projects (parent level, read access needed only to allow access to permitted projects, but we don't want any access to other individual project folders by default - they should remain hidden)

>>Project A (access permission granted by group)

>>Project B (restricted/hidden by default)

>>Project C (restricted/hidden by default)

>>Any new project folder (restricted/hidden by default)

 

In this example, a permission group "Project A" gives access to Project A, but if the "Projects" folder is also given read access, this opens read access to Project B, Project C, and any new projects as well, without adding explicit restrictions for each and again every time a new project is added.  This is tedious, high-maintenance, and also risky as the default is that anyone with access to one project sees all new ones until the admin takes action.

PDM