It can then do everything required with a few exceptions.
The exceptions are creating init/systemd files (associated startup/shutdown) and creating the necessary top-level directories for new apps.
Those can be allowed with a few careful sudo rules.
It can be a little convoluted but much more secure.
* "gpasswd -A <user>,,, <group>"
Note: to be a group admin doesn't necessarily mean you're in that group; it means that you can put yourself in and out of that group as required.