OpenAM has a capability of delegating administrator privileges to certain group of users. This feature is useful in more complex deployments, where more users needs to have permissions to modify OpenAM configuration. For example, let’s imagine scenario, where you have two different realms configured, one for customers and second for internal staff. You want to delegate permissions to modify configuration of this realms to specific users/group of users.
Read more at following blog OpenAM privileges delegation