I use xcacls and cacls to restrict access to certain files at logon but once the files acl's have been changed so that the user logging on can't modify the acl's there is no problem with them changing the acl's unless the user owns the file.

I also use kix to create new users so being able to set the acl's without shelling out would be extremely useful.