Groups should be able to explicitly grant access to devices without assigning them to customers, while their customer access remains restricted by customer lists or customer rules. This should not require either global customer access or an artificial assignment of devices to customers.