Can it be done? Use AD groups, One group read only another group read/write.

Top