You need to create a new object role in the security tab and grant it computer assignment rights. Once you have done that go to the deployment group in question and add the user group and assign them the new role.
- Grant the user the "Viewer" role under Server Permissions. This allows the user to access the console.
- Create a new Object Security Role called "Computer Assignment" and grant the "Computer Assignment" permission to that role.
- Go into each Deployment Group (right-click and go to Security), add the User (under Permissions) and grant them the "Computer Assignment" role you created.
This will give the user the ability to Add computers, Delete computers, poll, install the deployment agent, and modify membership rules. That's a bit more than you're looking for, but seems to be the closest I can figure.
Thank you chaps. That was perfect. I managed to knock that scenario up in my lab and got it working. Now comes the excitement of trying to get it into Production past the change management team