Hello Guido,
if you deny all access rights of a user on a folder foo1 and grant again all rights at a direct descendant foo2 of foo1, the user should be able to create, delete or modify descendants of foo2, but he will not be able to delete or rename foo2, because this contains an update of foo1, which is not allowed for the user. If the modification of descendants of foo2 is not possible, it sounds like a bug and we will have a look at it.
regards Eckehard
#API-Management#Tamino#webMethods