I imagined that OpenLDAP maintained a cache for dynamic groups (that's
how I understood "this exploits slapd group caching capabilities" in the
FAQ) in order to do a search on (member=member'sDN).
Such a cache would only need updating in only two cases:
1. when there's a change in an object's DN if the object has an
attribute used in any memberURL
2. when there's a change in any object in any attribute that's used
in a filter in any memberURL in the directory (sorry for
convoluted sentence, but it's a convoluted subject...).