Right now Access Control to features like the Directory are restrictive, and having
any
restricted affiliation makes you unable to access that feature. Entitlements based "Alumni
may
access X" is a more common way of handling this, and makes more sense. This is also how other parts of the product function (such as Spaces) - going to entitlement only would unify the permissions systems. Verified Groups provide an sensible way of doing this.
This has been previously discussed in:
I'm submitting this as a separate request because the feature request is different.
tl;dr:
Entitlements, not restrictions, and using the Verified Groups system.