What, you don't like buying spec's for a little bedtime reading?
Yeah, me neither. The following opinion is worth 2 cents, but provided free of charge...
My interpretation is your 1st option: free to create your own since the rest of the dn gives you global uniqueness. I'm kind of surprised it wasn't "aa-oid:id" given the general fascination with oid's in most IHE standards.
From a directory client UI perspective, I don't see much value in showing this field to users since it may or may not be meaningful: one system might do usernames (eg: SomeHospital:gcarver); another might assign guids (eg: SomeOtherHospital:5a362051-6c9e-4002-9277-1db2058317eb). I wouldn't risk showing the latter to a user on the chance the former format is used by some. For purposes of group memberships, either is clearly acceptable.
Greg