I think the easiest course of action here would be to create a few forms where you do verify this using a mix of concrete5 permissions and ACL. These are called access control lists in say Zend Framework.
I am not aware of anything in concrete5 that checks a user's group status before allowing them to add to another group, though to be honest I haven't looked all that hard.
I think that's the one area i haven't been through :)
You are allowed to delete your post for 5 minutes after it's posted.