Would be great to have a feature, to automate permissions definition over LLD group prototypes in the root top level, which is not already a subgroup of another existing parent group involving some permissions.
When a new group is being created via the LLD PROTOTYPE, there could be an option to predefine own permissions to that LLD PROTOTYPE GROUP in advance, so that it would not need any manual permissions intervention later on and would start working right away for any on it depending feature, e.g. custom API features, etc..
Option can allow to
1) select an already existing USER GROUP to be assigned to the GROUP PROTOTYPE.
2) new USER GROUP and it's USER account would be allowed to be created in the GROUP PROTOTYPE fields, the same way like you can create e.g. new Application or other object