It's probably just a typo, but OAuth(2) is exactly NOT an authentication protocol: https://oauth.net/articles/authentication/
80 karma · joined March 18, 2017
The hydra ( http://github.com/ory/hydra ) project for example has groups, which allow you to set e.g. an admin group and then assign people to it. I think this helps a lot with managing policies!
However, usually major programming languages have some sort of ACL/RBAC module around.
This is a good example for separation of concerns. LDAP is for authentication, ladon is for Authorization. Don't mix those.