Sorry for not using the exact terms, of course it is user - group - otherDocumentRoot should never be able to be read by others. Drush is doing a good thing here. The DocumentRoot group should match that of the user id executing httpd. This would allow the httpd user to read the DocumentRoot directory with 750 permissions.Thanks Ernie. I will contact the hoster for the appropriate way to handle this. cheers