That sounds like are reasonable approach.
I haven’t tried it, but this might be a good way to do it:
$isAuthenticated = $modx->user->hasSessionContext('mgr');
That would be fairly secure and wouldn’t require a plugin (and would be a lot easier than working out the security details with resource groups and user groups).
Take a look at the code of the NpEditThisButton snippet that comes with the Revolution version of NewsPublisher:
https://github.com/BobRay/newspublisher/blob/dev/core/components/newspublisher/elements/snippets/npeditthisbutton.snippet.php.
With a little tweaking, I think it would do exactly what you want. It puts a button on the page that launches NewsPublisher for that page. It doesn’t it by forwarding the user to another page with the form action, but it could just as well use $modx->sentRedirect() or $modx->runSnippet(). The button is hidden from people without certain permissions but it could just as well use the code above. It returns an empty string if the user isn’t qualified so the button is invisible.
You might find the method it uses a little confusing. The Edit button caption is set to "Edit" at the top. If there’s any error, it’s set to an error message instead. At the end, the snippet checks the value against "Edit" and if they match, it returns the button. If they don’t match and debug is on, it still returns the button (which will contain the error message). If debug is off, it returns an empty string.