If everyone needs to have access to a central storage location, there is always access to all files or access needs to be set granularly at the network level.
[Answered by @antirotor | Discord]
There are so many ways how to set permissions of filesystem level that AYON is not trying to step in in any way. Ideally, you can have something like LDAP/AD/… linked to AYON User accounts and manage combination of filesystem/pipeline permission, you can write some pre-launch hooks, ftrack actions, publishing plugins to do something with permissions, you can create your own AYON Service that will do something with file permissions, it really depends on you studio setup