Another permission that is common to delegate is the ability to link existing GPOs. This does not grant the users access to create their own GPOs, but rather just to view existing GPOs and link them only to OUs for which they have linking access. You generally want to make sure that only trusted administrators are able to create new GPOs. This delegation allows you to retain control over the creation process, but allows the head of the Accounting department the ability to assign/link those GPOs to the groups of Accounting users or computers that they deem fit.
GPO permissions are generally set inside GPMC's Delegation tabs, but this linking permission really has more to do with OU security than it does with GPO security. ...