Currently, there's only is_admin in the userprefs, defining whether or not a user is an administrator.
It would probably be best to assign this permission (and roles in case of #28), on groups, so that revoking someone's permission in the auth backend (IPA for example).
This issue ticket was originally removed from the tracker as it clashed with the pull request. See upstream ticket for migration details.
Metadata Update from @t0xic0der: - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)