We're delegating admin rights to our various IT departments, only giving them access over their stuff under their OUs.
They're missing the option to see the group membership changes of user accounts, specifically when new employee accounts are provisioned or to validate when exactly certain security groups had been added or removed.
They would not have access to the central logging area, where you could filter by target user and group membership operations.
I saw something about creating a script based report for that kind of thing.
Before I go that route, and probably put in a feature request for showing the group membership changes on user's management history, is there another approach that I'm not aware of?