If you don't own the authorization backend, how can an application guarantee data safety and ownership?
Meaning, you don't have to physically be the guard at the door, to know your door is guarded. And you can use passports and well formed policies (ideally as code) to communicate to your guards who to let in, when, and how.
This doesn't translate well to a web app, to guard your data you have to physically have it somewhere where you and only you can access it.
An authorization proxy is quite the same, and I would argue that for some teams is much safer to use than building your own AuthZ. Broken access control is the top OWASP risk for a reason (i.e: implementation complexity)
source: https://owasp.org/Top10/A01_2021-Broken_Access_Control/