You will have to add the user to the Group Policy creator owners group for
the domain. That will allow them to create and edit Group Policy that they
create only. You will also need to delegate that user/group authority to
link the GPO's they create to the OU. The link below explains more. ---
Steve