openldap and service permissions

I'd like large grained control over my services like FTP & Samba. They're set up to use LDAP for user authentication. I'd like to be able to enable and disable services on a per user basis. Eventually I'd like to enable and disable on a per group basis as well.

As it stands though, I kind of just got everything working (the infamous ldap+kerberos solution) without really learning LDAP. I understand some of how LDAP works, but not enough to know how to attack this problem. Any help which could be offered would be great.