Modify access rules
diff --git a/groups b/groups
index 7cb274b..23a8094 100644
--- a/groups
+++ b/groups
@@ -3,11 +3,8 @@
 2a10ec5934b3fecac3781fe7d5dedc172e21d459	GitHub Replication - OpenCord
 4f32b523380e68c8595bdf27a006c697ea17bade	Non-Interactive Users
 61317511a4a11254cbbf9612896412663548965a	Administrators
-63e77955f1e6a49cb3169e4d3ec0a9fd30380c11	Read-only Users
 7177c81018e69d9a1b1f6f940aad91fbbba574d1	CORD Committers
-7d4b24c44430f22ab2ec0def4a60ae90633e3293	ONF Internal
 8b721006a49a00b0ba867e60d08dd5b13f1739a6	GitHub Replication - XOS-Project
-9a1085ebc62ecb78f5b25e928a96a84655b4d565	ONF CLA Accepted
 ea0401fd666860cbc94b2132ff9d30a0e10d60e9	GitHub Replication - Open-Cloud
 global:Anonymous-Users                  	Anonymous Users
 global:Project-Owners                   	Project Owners
diff --git a/project.config b/project.config
index 3ea1c62..bb1cd74 100644
--- a/project.config
+++ b/project.config
@@ -18,69 +18,37 @@
 	read = group Anonymous Users
 	read = group Non-Interactive Users
 	read = group Registered Users
-	create = group Administrators
-	create = group Non-Interactive Users
-	create = block group Read-only Users
-	forgeAuthor = group Project Owners
-	forgeAuthor = block group Read-only Users
-	forgeCommitter = block group Read-only Users
-	forgeServerAsCommitter = block group Read-only Users
-	push = block group Read-only Users
-	pushMerge = block group Read-only Users
-	label-Code-Review = group Read-only Users
-	label-Verified = group Read-only Users
-	labelAs-Code-Review = group Read-only Users
-	labelAs-Verified = group Read-only Users
-	rebase = block group Read-only Users
-	removeReviewer = block group Read-only Users
-	submit = block group Read-only Users
-	submitAs = block group Read-only Users
 	viewDrafts = group user/Cloud Lab (cloudlab)
-	editTopicName = block group Read-only Users
-	editHashtags = block group Read-only Users
 	deleteDrafts = block group Read-only Users
 	publishDrafts = block group Read-only Users
-	createTag = block group Read-only Users
-	createSignedTag = block group Read-only Users
 	revert = group Registered Users
 [access "refs/heads/*"]
 	create = group Administrators
 	create = group Project Owners
 	forgeAuthor = group Administrators
-	forgeAuthor = group ONF Internal
 	forgeAuthor = group Project Owners
 	forgeCommitter = group Administrators
-	forgeCommitter = group ONF Internal
 	forgeCommitter = group Project Owners
-	push = deny group Administrators
 	label-Code-Review = -2..+2 group Administrators
-	label-Code-Review = -2..+2 group CORD Committers
 	label-Code-Review = -2..+2 group Project Owners
 	label-Code-Review = -1..+1 group Registered Users
 	submit = group Administrators
-	submit = group CORD Committers
 	submit = group Project Owners
-	pushMerge = deny group Administrators
 	label-Verified = -1..+1 group Administrators
-	label-Verified = -1..+1 group CORD Committers
 	label-Verified = -1..+1 group Non-Interactive Users
 	abandon = group CORD Committers
 [access "refs/meta/config"]
 	exclusiveGroupPermissions = read
 	read = group Administrators
 	read = group Anonymous Users
-	read = group Project Owners
 	read = group Registered Users
 	push = group Administrators
 	label-Code-Review = -2..+2 group Administrators
-	label-Code-Review = -2..+2 group CORD Committers
 	label-Code-Review = -2..+2 group Project Owners
 	submit = group Administrators
-	submit = group CORD Committers
 	submit = group Project Owners
 	pushMerge = group Administrators
 	create = group Administrators
-	create = group CORD Committers
 	create = group Project Owners
 [access "refs/tags/*"]
 	createTag = group Administrators
@@ -118,6 +86,7 @@
 [access "refs/for/refs/meta/config"]
 	push = group Administrators
 [capability]
+	accessDatabase = group Administrators
 	accessDatabase = group user/Brian O'Connor (bocon)
 	accessDatabase = group user/Hung-Wei Chiu (hwchiu)
 	administrateServer = group Administrators