Recommended ACL for nagios monitoring


I would like to monitor connectivity to my OpenLDAP using nagios with its check_ldap script and was wondering which minimal ACL would you recommend for that purpose?

For that purpose I will be using a dedicated user such as cn=nagios,ou=users,dc=domain,dc=tld and would like it just to be able to bind to dc=domain,dc=tld and nothing else. Any recommendations?