No, you just make a user group that everyone is initially placed into (registered) without those permissions, then create a user group that does allow those permissions (whatever you want to name it) and create a user group promotion that has the necessary conditions that a user would have to meet in order to receive the promotion. No manual moderation should need to be required, that is completely separate