Q: Is there any ramifications if the builtin groups are removed?
A: Yes, it is not advisable to remove these groups as certain service may use them.
Q: Does Foglight cache credentials?
A: No, Foglight does not cache credentials.
Q: Group memberships: Does it replicate or query?
A: When LDAP authentication is used, group membership is queried at time of login. There is no replication.
Q: Group membership does not appear to update until the user logs in.
a: That is correct, Foglight is working as designed. LDAP is only queried in the context of a user logging in.
Q: Does Foglight store authorization data?
A: Only if the built-in authentication is used. When LDAP or other external authentication is used, Foglight does not store authorization data other than the username.