How do you structure user access

Hi All

I am looking for some advice on how to structure access and permission at my company in Looker.

We are currently using one group for all users and they have access to everything.

I have implemented different roles - that is sorted. I am referring to folder access and how you cascade that.

I have created groups for each department (but haven't implemented this yet, as I am unsure how this will work). From here, my understanding is that if you give a group permission to a folder, all the child folders are accessible to that group. So do I start at the deepest folder level and grant access and go up? How do I ensure some groups have access to certain folders while not having access to other?

I’d love to  get some feedback of how people are implementing this?

1 1 209