if i have the following structure: o=myCompany | | ou=myDepartment, o=myCompany | | | | uid=empOne uid=empTwo is there a way i can set up the acl so that someone can log in as ou=myDepartment,o=myCompany to add, modify or delete entries underneath? thanks for any help. peter choe