What do other large (non-google scale) to medium companies use for authorization? Can anyone recommend open source (preferably) or close source products?
Website: https://www.keycloak.org/
[1] You do so by implementing this interface: https://github.com/ory/ladon/blob/master/warden.go
In practice, we use Kerberos to obtain/distribute authorization tokens, which live for less than 24 hours. The authorization-value of these tokens is determined by the LDAP affinities of the bearer. If everything is configured correctly (which it always is, until you need new permissions / switch teams), all you have to do is auth with kerberos at the beginning of each day. We have ~200 engineers.