shared servers and internet path to be members of both VLANs...- those ports will configured as "trunk"
Other ports - VLAN1 VLAN2 according to their group.
I will never understand people using 192.168.x.x on production, it is ment to be use for home network.
It is more beneficiar to switch IP to 10.10.0.0/255.255.0.0 for example, use "logical " blocks , and separations with VLAN's.
10.10.0.1-10.10.0.255 - office
10.10.1.1-10.10.1.255 - guests
10.10.2.1-10.10.2.255 - contractors
10.10.3.1-10.10.3.255 - VPN users
10.10.4.1-10.10.4.255 - remote branch
and so on.........in this case you have 65K adresses available to you.
This way much more easy meanage securty, and will make live easier too.