The most straightforward approach would be the one that closely follows your description. You can define an object ContactSet with attributes Companies and Employees to allow one or more employees to work on a list of selected companies. Create access level 'Manager' and allow users of that access level to create/modify ContactSet instances at run time to assign employees to companies. Create access level 'Employee' for employees (not allowed to change ContactSet). Add the following protection rule to object ContactSet:
If LoggedInSystemUser.AccessLevel = 'Employee' AND NOT (LoggedInSystemUser IN ContactSet.AssignedEmployees)
Then READ PROTECT ContactSet FROM Employee
Add a query to display all ContactSet instances and allow Employee users to run it. At run time the system will automatically filter out ContactSet instances from the displayed results based on the above rule. Note that the rule will not affect the ability of other access levels (such as Manager) to see all ContactSet instances if they run the same query.
If you find it more convenient, you can simplify this design by eliminating the object ContactSet and making the list of assigned employees an attribute of object Company (and only allow Manager to change the attribute). The protection rule would then look like this:
If LoggedInSystemUser.AccessLevel = 'Employee' AND NOT (LoggedInSystemUser IN Company.AssignedEmployees)
Then READ PROTECT Company FROM Employee
The query would then display all Company instances. By running this query the employee user would see only those companies to which the user is assigned.
Let me know if either of these solutions is acceptable or if you need more details.