I need to make certain opportunities owned by Group A, not visible to users in Group B. Current setup: I established a public group with all users in Group A. I created a sharing rule for Opportunities, that only users in Group A, can view opps owned by Group A. I then changed the OWD on the Opportunity to be private. That didn't work. So then I did the same process with the Account, assuming that maybe it needed a top-down restriction. But the test opportunity is still visible by my QA user in Group B. I changed the profile permissions to make it so they don't have access to ALL. Still visible. I went to the role and changed it there, made it so they could only see opps they own. Still visible. I'm out of ideas.
What does the Sharing Hierarchy show for one of these Opportunity records that a User from Group B should not see, but can?