Thanks for your help,
it seems to be working fine now (I think the problem before is that I was not testing it right (apparently cd does not work without +x

) )
It is great that you are one of the few hosts with ACL set up by default and it has really saved me a lot of time
Sadly it looks like ACL rules are not applied in SFTP so I guess I will need to look at NFS again.