Hi,
you do NOT need SQL Logins for each user/group of the Orchestrator Web Console.
If you have
-Runbooks
|-Folder A
|--- Folder 1
|--- Folder 2
|- Folder B
and the Runbooks for Web Console are in "Folder 1" which is under "Folder A":
The user need Read Permissions for Runbooks, Folder A and Folder 1 and also "publish" for Folder 1.
The setting is perhaps not visible immediately: https://support.microsoft.com/de-de/help/2738490/orchestrator-runbooks-folders-and-or-statistics-are-not-displayed-or-u
Run this after the changes:
TRUNCATE TABLE [Microsoft.SystemCenter.Orchestrator.Internal].AuthorizationCache