There's already a record rule for the access group “Sales / User: Own Documents Only” that limits them to their own sales invoice and credit notes:

[('move_id.move_type', 'in', ('out_invoice', 'out_refund')), '|', ('move_id.invoice_user_id', '=', user.id ), ('move_id.invoice_user_id', '=', False)]
Do you want to apply that to the “ Sales / User: All Documents ” group and only allow the sales administrator group to have access to all invoices (along with accounting users)?
That can be done by editing the Record Rule:

Change this to the Sales All documents

Then change the other Record Rule in the pair to the Sales Admin:


Or maybe you need to remove sales users access to the accounting app?
More about Record Rules