Authentication, authorization, and security in general are complex problems that are demonstrably difficult to get right. Any solution is going to have implementation complexity. The comment you responded to was actually describing a way to manage that complexity.
> Maybe the feature is worth the complexity
What feature? Security?