We could use full allow/deny capabilities on every single object in Hudu. Don't worry about keeping it simple :D
Enabling and disabling different parts of groups is important - currently, groups have to be either 'allow list' or 'deny list' types. we should be able to disable that in a certain group, to use it for another purpose. Thats just one of many examples.
What I'm currently trying to do, is configure our tenant so that all techs can have access to all clients including our internal assets, but not everyone can access domain / global admin passwords or certain sensitive assets. I would like to have multiple levels of limited admin access, as we have some people who manage CIPP, others who manage ConnectwiseControl, etc.