Hello again
I've taken a look at it, but i'm having the following issue, and i might be imagining things, so bear with me and feel free to tell me if i'm doing it wrong

:
Groups:
- a user can be only a member of one group.
- a source can only be assigned to one group.
- admins overarch groups so:
I can have a bunch of admins, say team members and myself - we maintain things so we should see everything (we double as the Unix admins). But then it gets hairy: what if i want the Microsoft Admins to be able to access the server net, the database net, the exchange farm and their test networks, and the Database Admins to access the server net, the database net, but not exchange etc. I've just tried to do something like that and i didn't realize my interpretation of Admin is wrong... if i'm not a member of a group it vanishes.
But uses can be in multiple groups... So if i assign a unique group to every log, i can grant individual users access to logs in a sufficiently restrictive way...
That will work, it's not very straight forward ... I'd probably prefer multiple groups per source, but it is workable...
We were discussing the ACL by IP here, and we concluded it probably wouldn't be very sensible to implement... but then we aren't php coders

Cheers. chakkerz