Below acl's will help you to achieve the same.
aci: (targetattr = "*") (target = "
ldap:///ou=ouone,dc=example,dc=com") (versi
on 3.0;acl "user_one";allow (all,proxy)(userdn = "
ldap:///uid=userone,ou=Peo
ple,dc=example,dc=com");)
aci: (targetattr = "*") (target = "
ldap:///ou=outwo,dc=example,dc=com") (versi
on 3.0;acl "user_four";allow (all)(userdn = "
ldap:///uid=userfour,ou=People,
dc=example,dc=com");)
aci: (targetattr = "*") (target = "
ldap:///ou=outhree,dc=example,dc=com") (ver
sion 3.0;acl "user_six";allow (all)(userdn = "
ldap:///uid=usersix,ou=People,
dc=example,dc=com");)
It says uid=userone,ou=People,dc=example,dc=com can write in ou=ouone,dc=example,dc=com
& uid=userfour,ou=People,dc=example,dc=com can write in ou=outwo,dc=example,dc=com
& uid=usersix,ou=People,dc=example,dc=com can write in ou=outhree,dc=example,dc=com
Example
# entry-id: 19
dn: uid=utest,ou=ouone,dc=example,dc=com
uid: utest
givenName: user
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetorgperson
sn: test
cn: user test
userPassword: {MD5}4nmK8Sp6D09wtNae+8JfTQ==
creatorsName: uid=userone,ou=people,dc=example,dc=com <---------- created as per ACI
modifiersName: uid=userone,ou=people,dc=example,dc=com
createTimestamp: 20120227201512Z
modifyTimestamp: 20120227201512Z
nsUniqueId: ad0ee181-617f11e1-bd04f4a7-338b5e96
Regards
Arpit Tolani