Hi Eric,
If you don't see the object-groups configured in the CSM policy but you still see them in the running-config then it sounds like the CSM database is out-of-sync with what is in the device's running config.
If you are not using any ACL rule sections or shared policies, the easiest way to resolve this is to right-click on the device and select "Discover Polices on Device". This will remove the full config from the CSM database and re-populate it with what is in the device's running config.
Otherwise, you should manually create/delete rules in CSM so that they match what is currently configured on the device. Then, submit and deploy the changes. Finally, remove the object-groups after CSM and the device are back in sync.
-Mike