I don't have a perfect answer, but let me approach this way.
a) If action effort of end user side could be scoped, give them USM access to let them manage maintenance rules by themselves.
If maintenance mode related permission is granted, they are also able to manage maintenance rules by themselves.
b) if action effort of end user side could not be scoped, you may want to use some event driven logic to automate it.
I have one example, but I won't say this is a good example.
capture net_connect probe based PING fail alert, then attach the target device into active maintenance in an automated manner.
capture net_connect probe based PING success alert, then detach the target device from active maintenance in automated manner as well.