I'm looking for a design guide covering the use case of user belonging to multiple AD groups, each assigned a unique SGT with associated SGACLs. Everything I've seen in the various resources seems to assume that a given user is only ever a member of ...