As a workaround it might be feasible to script document creation per Active Directory group.
Alternatively, dynamic folders can help in your scenario. If you can use a script to process data based on the user credential, you may be able to use a dynamic folder script to only show connections and objects based on the user executing the script.
Preben Justesen
This could support a zero trust strategy instead of the current assumed trust where everyone have access to everything within a document.