Access control

I've been reading the docs on access control, but I'm having a hard time
figuring out how to do a few things.

I would like to grant full access to people with a certain gidNumber, so
that I can grant them admin status just by setting their gidNumber to the
'admin' group. Can anyone give me some pointers on how to do this?

Also, how would I configure LDAP so that users are able to modify their
own entry and entries below them in the tree, but nothing else?

