Assuming you’re using AD at your work, can you not create ldap roles in AD and use the information to automate adding removing users/groups. Your group manager can then be the owner of the LDAP role and adding/removing users to the role is automatically synced to datahub.