That's precisely why the cookie should just be an identifier, that you look up group info from the database. Because you can guarantee the cookie contents will be modified by someone at some point. Make it useful to you, useless to them.
Please stop.
> By default flask doesnt have a db.
Do not trust the data you send to a user, to remain secure.
Security through obscurity is allowing REST commands to the /totallysecretaddress/neverleaked/ URI.