As default behaviour we'd like to see that a group member can only view categories that the group itself has access to, not any other categories regardless of access level. The desired behaviour should be much like a firewall: deny all and only allow access to specific bits (ports). The reason for this is that we'd like to give people access to our <brand>. helpjuice.com account, but only to specific categories without even being able to see other (public!) categories. Right now, when we add an account a new user who logs into <brand>. helpjuice.com can always view all languages and public categories, regardless of user role or group membership, which defeats the purpose of groups, or user account management for that matter.