Defining authorisation rules as part of your application sounds fine to me. Aim for making compilation and deployment of your application trivial.
Sounds like you want a linear hierarchy of roles. Attaching a number to each role and making rules based on that number might be all you need. For example:
Superadmin : 100
Admin : 90
Manager : 80
if (a.number > b.number) a can delete b