do you know what are the minimal paths to set the ACL rights (path + right type [read, modify, create etc.]) to allow a customised group creating a new groups ? This is controlled only by ACL rights or need also somewhere to put a group name to a bundle configuration to allow creating a new groups? I know that the user-administrator group have the rights but I suppose this group enables much more than only creating a new groups - which should not be granted.