IC2 - Admin Access based on Device Tags

Would it be possible to add a further level of gating on admin access based on device tags - I wish to be able to add a temporary admin to a group in IC2, but restrict what devices they can see / touch based on tags.

Use Case:
We have some trusted customers that we tend to grant admin access to the devices they have hired via IC2, mostly for monitoring purposes but to also log into the device to do some local config (DHCP reservations or the like).

Presently when I need to grant an external admin access to one specific device I have to move that into its own group, make sure all the settings / tags etc. are copied across cleanly - spoiler alert, they do not!

