The "failing" search you showed earlier was:
Nov 2 11:15:07 pen slapd[18902]: conn=8 op=1 SRCH base="ou=people,dc=ncl,dc=ac,dc=uk" scope=2 deref=3 filter="(&(uid=groupersystem)(objectClass=eduPerson))" Nov 2 11:15:07 pen slapd[18902]: conn=8 op=1 SRCH attr=cn cn uid Nov 2 11:15:07 pen slapd[18902]: conn=8 op=1 SEARCH RESULT tag=101 err=0 nentries=0 text=
Your slapcat does not have any entries with
uid: groupersystem
and therefore zero results should be returned. As it turns out, zero results were returned. It looks like the most powerful directory software on the planet is serving you well.
Uhhhh...so perhaps you want to add this entry? I don't know. It's not an ACL thing, you've used the rootdn AND you used slapcat (neither of which was subject to ACLs). loglevel acl can't show anything relevant when you're using the rootdn. You just don't have the data in there, as proven by the slapcat. nentries=0, zero results found, absolutely correct.