You could create an Organization for each level and then can create a single Organization Role with the following permissions:
- User / Update
- Organization / Manage Users
- Organization / View
Once that is done you assign the level admins to this role on the corresponding organizations.