Is there a way to limit/restrict the usernames that are allowed to use our postfix dovecot-sasl authenticated smtp relay?

should be what you search for.

We would like only *specific* usernames to be able to use the authenticated relay. And currently everybody with dovecot imap access can also use the relay. Is there a way to restrict that?

A simple list of usernames would work, or more advanced: dynamically using an ldap lookup to check group membership.

I believe you could use ldap tables here.
