I manage all folder access through dynamic employee groups based on a saved search isolating roles based on our Delegation of Authority Matrix. I am not positive of the implications of doing this to the script folder but a quick test will tell you. I would imagine it would work fine to run a script even when restricted.