Restricting Logon permission

We are working on trying unifying our password database via openldap, and I am 
looking for a way to restrict logon rights, so only certain people can log 
onto some servers.  For example I do not want everyone to be able to log onto 
a machine we use for testing applications before we make them public, but it 
would be nice if we could use ldap for authentication.

thanks for any help,