good grief, groups are complicated. got them working, though. created ambassador, representative, member, visitor in certs/statesman.xml. an ambassador can create new groups, and anyone can join them. this is done by creating an alias, which immediately went and destroyed one of my test users: i joined to a group it was already in, it overwrote the profile with the alias. *muur*.
