Hi,
Endpoint policy follows a first-match concept, with Entire Organization being the last one that is being matched.
In SmartEndpoint we have the shared action concept so you can re-use the same action and its settings on different rules.
You have indication of the name in bold when the action on that rule is different than the one for Entire Organization.
In the example above the setting that will enforced on group CAD are those that are defined in "Scan all files upon access CAD". If you make changes to "Scan all files upon access" you should do the same changes on "Scan all files upon access CAD" for them to apply, or change the action on that rule to "Scan all files upon access".
Hope it is clearer.
Oren.