@jb acl/rbac/whatever is genuinely hard with sufficient complexity, i get that
but cmon, man, 90% of use cases are dead simple
AD used to be pretty good, LDAP but not brain-breaking, but i guess MS just couldn't leave well enough alone and had to fuck it up