An AuthN/Z system would probably end looking like counterexample #2, which immediately raised a red flag for me about the article.
If you have two separate systems that depend on the auth system, and something depends on both, you have violated the polytree property.
This article, in my interpretation, is about hard dependencies, not soft. Each of your services should have their own view of "the world". If they aren't able to auth/auth a request, it's rejected - as it should be, until they have the required information to accept the request (ie. broadcasted role information and/or an acceptable jwt).
Take the simplest case of a CRM system a service provides search/segmentation and CRUD on top of customer lists. I can think of a million ways other services could use that data.