Okay, thanks for clearing that up. My reasoning was, if I su to someone, even if I belong to some totally different default group, when I try to access the directory belonging to group nsadmin, unix thinks, "I see this line nsadmin:x:502:jon in /etc/group, so I will let him in." I didn't know that doesn't apply to daemons.