We could manage the users in various LDAP groups (mainly sudo) through Ansible.
This would be convenient, since it reduces the number of places where the list of admins must be kept in sync.
This is safe, because admins do not need their in-LDAP credentials to login to ldap.hashbang.sh (this is done through a public key) and re-establish their access, should something go terribly wrong.