I perceive the Groups UI to be the easiest (to "fix") only because my list of requirements for this one is the easiest. The requirements for the permissions sub-system is the "hardest".
Now I have a roll-out due early next year. I typically attack first the area I am most worried about, and I think of the permissions-objects-context_id area to be the one that I do not have my head completely around yet. So, of these, I am spending most of my time right now on this area, not to speak of search, webmail and some other areas needed for our project. And I did figure out another permissions problem the other day that I need to post in the Testing forum and in the SDM.
My eventual goal is that sometime in 2002, I will be able to migrate my client over to OACS 4.x semi-smoothly, with the functions I am improving (if not the screens) included in that release (maybe a production 4.3).
That said, it is interesting to me that this thread has a dearth of respondents. This fact supports my theory that this area is the most opaque. Regardless, I will append my proposals in all of these areas in the coming weeks.
Regards..