I think I am getting it now, but I would like to hear some recommendations
Currently:
The short list of domain admins are Adaxes admins.
Help Desk has been added to the built-in Group Managers and Account Managers roles with access to certain OUs
So I suppose I would either create a new role to allow group membership changes and allow all domain users. Then a business rule that would cancel the task if the initiator is not the manager of the group or not in the built-in Group Manager or Account Manager roles. Or instead of roles, if not in a member of the Help Desk group.
We are just getting started with Adaxes and this seems it may lead to some tricky details in the future.
My apologies to all. It seems that I have hijacked this thread. I had thought that the post by Eugene was indicating that there was a new option for what I needed.
Help is very much appreciated. Thank you