ACL question...

How do I do this...

I've an addressbook where I have users and their personal addressbook in the ldap tree. Let's say some user wants to give read access to one of his personal addressbook to a friend of his who is also on the tree. Basically I want the users of this addressbook to decide on access control for their part of the tree.

How do I do this kind of Access control?
Is dynaACL (ACI) the only way to do this?