OpenLDAP support role-based access control via the ACL group mechanism.
I really like this answer. ;-)
Ciao, Michael.