...
Although this question exposes gaps in the functions of the groups manager channel, it seems like it could be solved (at least in the short term) you could get the desired behavior with a custom permissions policy. The policy would evaluate permissions owned by the groups manager channel, i.e.,
...
actually point to a group and its descendants. This is a very brittle approach that uses a hard-coded syntax to resolve an exceptional case. But it does work, and perhaps someone could think through and generalize the approach, perhaps introducing configurable wildcard syntax and permission owners.
I'm attaching a sample policy uses this approach.