It seems to me like a rogue relay owner in a NIP-29 group is just as disastrous as a rogue group admin NIP-87?
And this isn't in NIP-87 but I don't see any reason you couldn't use FROSTR threshold signatures to publish events from the admin key. In this way a few admins could hold shards or you could even distribute a shard to every group member and have clients collaborate to approve membership changes or other policy changes?
