Here is the solution I came up with:
AwareIM Objects:
IntAcct with Groups_add, Groups_del, Groups, and Groups_auto reference attributes to the groups object. Only the groups attribute is a matching attribute, all others are not (e.g just one way from the IntAcct to the Group).
ExtGroups that reads from an external mysql table that has groupname and acctid in it.
Rules on IntAcct like so:
Override to delete auto_generated groups:
If Groups was added to IntAcct.Groups_del then remove AddedGroups from IntAcct.Groups
else if Groups was removed from IntAcct.Groups_del then insert RemovedServices in IntAcct.Groups
Override to add in additional groups:
If Groups was added to IntAcct.Groups_add then insert AddedGroups in IntAcct.Groups
else if Groups was removed from IntAcct.Groups_add then remove RemovedServices from IntAcct.Groups
Autogenerated groups checking on overrides:
if Groups WAS ADDED TO IntAcct.Groups_auto AND Not (AddedGroups in IntAcct.Groups_del)
then INSERT AddedGroupss in IntAcct.Groups
else if Groups was removed from IntAcctg.Groups_auto and not (RemovedGroups in IntAcct.Groups_add)
then remove RemovedGroups from Staff.Groups
To stop wonderful users from breaking things🙂:
if Groups was added to IntAcct.Groups_add and AddedGroups in IntAcct.Groups_del then report error 'Cannot have same group in both add and delete override'
else if Groups was added to IntAcct.Groups_del and AddedGroups in IntAcct.Groups_add then report error 'Cannot have same group in both add and delete override'
This seems to work ok once I made the rule for IntAcct.Groups_auto a priority 60 so it runs first. The nice thing about this solution is that in the GUI presentation, I put the groups onto a different tab and all the user has to do is to add or remove the group they need to override. Also, because only the IntAcct.Groups attribute is matched with the Groups object, everything it is updated, the Groups object for that group is automagically updated so the groups are kept up-to-date. The downside is that you cannot add accts to a group from the group object, you have to add groups to an account via the overrides or else this will get all mucked up.
Any ideas and comments are welcome and appreciated.
ski