To fulfill the ACL control, Alfresco(and other CMIS system) need to either build its own or connect to 3rd party user/group management system, such as LDAP. It is fine to use its own module to manage user/group. There will be synchronization problem when connecting to 3rd party user/group management system. Particularly, the data is difficult to be synchronized instantly.
It would be great that CMIS has the API which could manage user/group. So the client will have a common interface to manage both its user/group and its documents, without caring about what kind of system is being used to manage user/group.
Any idea?