We need to surface permissions for groups and remotes here: https://github.com/ansible/galaxy_ng/blob/master/galaxy_ng/app/api/ui/serializers/user.py#L111
Surfacing add, change, view and delete for groups, remotes and distributions should do the trick.