Theory is great, but everywhere I've worked managing permissions becomes a nightmare that either ends up with everybody having too much access or not having the access they need.
Have you ever worked anywhere that implements the system described here?
Why do you think this is? The wrong people empowered to create new acls? Limitations in the system itself? Lack of auditing?
Not parent but in my experience it's the third thing.
People who gravitate to being in charge of permissions are anal retentive micromanaging types. They get a kick out of making others come to them to beg permission to access whatever it is, and making them get permission from their manager and his director. They are insufferable so people develop workarounds, shadow systems, or try to accumulate as much permission as they can so they can avoid future dealings with the permissions bureaucracy.
I hear you! Ended up building such a system so many times, so much we've built an open-source, self-hosted system to do it out of the box! https://cerbos.dev