This solution works is not acceptable http://kb.odin.com/en/122286
Because the account also has access to system directories like "bin" and "var" below the "httpd" directory.
Can i duplicate the account and limit it to see only the subdomain directory?