and let sudo verify that the user belongs to the group of allowed sudoers.
No need for the password to the root account.
I strongly prefer doas wherever it's available.