The ops group, which is ussally assigned to SREs enables a lot of privileges such as root access to all productions severs as such we have started to limit access to this group while new hires complete there onboarding and get more familure with the WMF infrastructure. However there are still a lot of services which new SRE's need to be able to access which may otherwise be restricted to only the ops group (i.e. wmf ldap group dose not have access) .e.g puppetboard. Or possibly additional access to various gerrit repos
To enable this additional layer of access control we should create a new ldap group. This should be a simple thing to do but suggestions for names for the new group most welcome :)