In addition to groups (with more multi-dimensional capabilities like customer and asset type), enable the inclusion of a confidentiality rating on any field (something simple like 1-100). Then you can have people with access to passwords, but some passwords might have a confidentiality rating that requires a higher security level assigned to the user. Would give very granular control with a fairly simple mechanism that lets us come up with the number scheme (grouped in 10's like old fashioned basic programming for example or MX record priorities).