With the current way ArcGIS Enterprise and ArcGIS Online handles the permissions, to manage a group, a user is granted permissions ("Create, update, and delete") that also allow the user to create new groups and delete groups that they manage.
It would be nice to have these three permissions be distinct, separate permissions to allow creator user types to update (manage) a group but not create or delete. A use case of the need for these permissions to be separate is in an enterprise environment where the creation of groups are done by administrators and the updating of member is done by creator users in the group manager role.