this plugin seems to have an excellent feature set in its simplicity! many thanks.

what is not fully clear out of the text: what permission does a user get? edit? view? in our case we would like to have most tickets public, except security critical. editing should be done with group virtual permissions, ie give it to a person of a group.

You can use PrivateTicketsPlugin to restrict VIEW (use TICKET_VIEW_OWNER_GROUP or TICKET_VIEW_CC_GROUP, and assign/cc the ticket to a virtual user who is _only_ a member of the security group) and VirtualTicketPermissionsPlugin to restrict what actions can take place. I do not know of any way (I have not checked Trac logic in 6 months), on how to restrict EDIT.

