Currently you can set "Allow", "Block" or "Prompt" for "Startup settings" for the "Trusted" group.
I don't particularly want any application to be able to WRITE to the "Startup settings" without it asking me, but if I set this option to "prompt", I get asked for every application, because for some reason ALL applications need READ access to "startup settings".
There is however, NO option to allow all items in the "trusted" group to READ "startup settings" and not WRITE.
More fine-grained control over default groups is required.
