crispexi,
That may be okay for you. However, I only have 2-4 people who need su for root to my boxes. For me that is just one more file to manage which I don't have time to manage.
I can imagine one bad scenario. In an environment that allows users to have a regular password, that type of setup can be jeopardized to gain access to root, if someone gains access to another user's password. Also, I believe that granting group permissions are considered by some to be another possible security breach.
My situation is very restrictive, such that we use one-time password at the user level and less than 5 people have root su privileges, so I don't need to manage another file for only 5 users. Also, we have standards that don't allow us to change permissions on executables that can be considered a security hole.
How many people have root that you would need to create such a file? And why do so many people have root access?
root is privileged for a reason. I hope you trust all of those people implicitly.
The bottom line is if this works for you, great. Just remember, in most cases your scenario is not feasible.