This has probably been answered many times but just in case.
I wonder if anyone has a sample policy kicking around to fix the
groupmembership backlink after an ldap add.
create a user with group membership via ldap.
watch for the add event and generate a loopback to fixup the member of