Before I blow my demo box away, I figured it'd be a good time to make a video to show how I carved out permissions in CM so that I didn't need to bring up another site for the server team for security reasons. This method lets everyone share the same central site. Of course, all this is made easier in the next version via RBAC, but for now, this is what we have.
For that inheritance script I mention, you can download it here.
By the way, I'm hoping to show the pre-beta built of v.Next in our next user group meeting!
Update: Not in the video: grant class read for site permissions to your user groups.