For each group, you define the default shell (co-administrator have no control over it) and special tasks. The administrators will be able to apply those tasks to user accounts, with full root privileges. Tasks like reseting desktop defaults may be created.
None.
Special groups may be configured from the virtual registry using the usersbygroup prefix.
Each special group defines two privileges. The first allow an ordinary user to perform task and maintenance on the special group. The second allow the co-administrator to add account (or not).
None.
None.