Today the only built-in dynamic org.apache.jackrabbit.api.security.user.Group is the one associated with the everyone principal that automatically has every other group and user as member.
In order to allow for additional flexibility we should consider introducing a DynamicMembershipProvider interface. while by default a single implementation for the everyone group would be present as today, it would allow to provide additional implementations. e.g. for those groups configured with the automembership option defined with DefaultSyncConfig, when additionally dynamicmembership is enabled.