Generate group memberships dynamically
After dropping LDAP, we can simply use JOINs to infer the current groups of a user from his roles (and other properties). The queries will be a bit complex (we need to take MFA status and default roles into account), but this change would eliminate the possibility of inconsistencies.