I am sorry, but for sure this IS possible. It depends what you really need to do on the switches. You can create "Zones", that Zones you have to assign to end-system-groups and with the webview you can handle that each local admin is only able to see and manage the MAC addresses he should be able. We have done this concept with my biggest customer. But we did not give them access to the switches, they don't need this. You only have to create a end-system-group / rule you can put on specific ports when they have to install new (unknown) clients/mac addresses. With this they are able to see the new mac addresses and so they can move it to there own managed zones/ end-system-groups.