Record Locking Proposal

What about creating a semaphore objectclass?
All one would need is to record the dn and allow only that dn to change the dn value to blank. If it is blank then anyone can access it.

Hmm... More and more this is looking like it is just a schema issue... What we need is a stand-alone dn value that will allow itself to be changed. Then we just make it "by self write" in the ACLs. Anybody know how we can grant access to "all" if the value is blank or if it is set to a specific value?

Your thoughts?