As an administrator I want to add or delete a user (from used identity provider) to group that is allowed to use app.
- build REST interface for allowed user data
- build web interface to manage data
- enhance security config, that only admin users can access api/web interface