I'd strongly suggest you do not do this. It's just bypassing the whole system and we cannot remotely encourage that. The system is there to make admins aware of what they're giving users access to, you shouldn't assume that the user even has an Admin group - they could easily rename it to anything they like or decide to have a completely different structure. I know it is a bit inconvenient to have to edit the ACL, and we may look at simplifying it in the future, but it's for the best!