Not really, since an OU cannot be added to the DACL in any way. The best way to set these permissions in Group Policy would be by giving a domain local group (e.g.. ModifySalesData group) the relevant access rights to the files or folders, then adding groups containing users (e.g. SalesManagers) to these 'access' groups. When you get a new starter you would add them to a relevant group or groups to give them the access you require.
This was first published in September 2006