Based on advice from yourselves we have a "read only" group that we add to all user roles. It holds all the custom lookup designs along with some out of the box designs that users as a minimum need read only access to. As you can imagine, there are a few thousand of these permissions, so it is a headache to set up. Also if we forget to add a new design to the group permissions, we won't know until someone complains that they are getting an error message, which can cause significant disruption, especially if working in the field. It would be good if designs flagged as lookups automatically got added to a group along with essential out the box designs that require read only access. Alternatively if it was possible when editing group permissions to be able to bring up lookups that don't have access set for that group, that would also be a way of easily staying on top of it. Open to a 3rd option if you have one, but it needs something to help us manage permissions better