I think this makes sense: if I can't edit users/epriestley/, I shouldn't be able to create users/epriestley/is_dumb/? Currently, as long as I can see the parent, I can create children.
Practically, this means I can't lock down changelog/, for example.
Maybe this rule doesn't make sense, but I think it's reasonable? The only case I can think of that's a little iffy is if / is fairly locked down you'd have to create more-open subsections to let anyone do any real editing, but that seems OK.