I just saw
despite being logged into an admin account while reporting T388988.
This doesn't make sense. If the user is in one of the groups it says you need to be in, core should detect that and display a better error message. Even just badaccess-group0 ("You are not allowed to execute the action you have requested.") would be better.
