Thanks nd, I think your idea for giving access to "others" is best, then individual access can be controlled with SELinux policy, or at least that's the idea, haven't tried it yet in practice.