Hi Doug,
Yes.
To do this, you simply give the user Adinistrative access to the Users and Workgroups you want them to manage (note, this could be *[All] or, in the case of Users, All members of specified workgroup(s)) and to the actual roles you want them to be able to assign. Since they don't have access to all roles, they can't add new ones. You can also, in this way, limit which roles thay can actually assign.
Remember, however, that they will still be able to edit the actual roles as well as delete them, if so required.
HTH