Just checking this is expected:
Any policy I create that ONLY has a custom trigger DOES NOT display the "LDAP GROUP" on the Scope Limitations section.
In theory this means that anyone that knows a trigger name can invoke it and we can't limit it to, say, technicians. I assume this has something to do with SU required to invoke triggers (IIRC).
-edit-
However, if you set the LDAP GROUP limitation BEFORE you set it as customer trigger only, it appears to remain (although may not work).