Yes. Use loglevel acl (or 128) and you will see extensive information about ACL interpretation.
Of course, if your user still has right access when the ACL you pasted doesn't give it to him, it is probably because this access is granted by a previous ACL. Remember that ACLs are a list, and the first rule to match a target will win.
Regards, Jonathan
Oh yeah SUCCESS!
Thanks a lot!
by set="user & ([cn=UserManagement,ou=roleRights,dc=myDomain]/member*)" write
did the job.