When loading users, the ParentString attribute is used to reference the parent container for the user. This attribute uses a semicolon to separate each entity and consists of a prefix for the type of entity using “=” and the user ID (UID) of the entity. Refer to the following example where the user is a part of the iManage organization and the Records ManagerTeam organizational unit. 

<Person Define=”yes” UID="auser" ParentString="o=iManage;ou=Records ManagerTeam;"/>
The same format applies when allowing access to specific users or groups in a membership policy or security policy. For example:
<MembershipPolicy Name="AddDenyValidSecurityPolicyA" Description="This is the security policy." DefaultLevel="FULL_CONTROL" Define="yes">
<Allow Id="ou=Tester;g=records manager" AccessCode="FULL_CONTROL"/>
<Deny Id="dpilsen" AccessCode="MODIFY"/>
</MembershipPolicy>