How do you implement role-based or attribute-based access control in large organizations?

Implementing role-based access control (RBAC) or attribute-based access control (ABAC) in large organizations seems complex, especially when managing multiple user roles. How do you handle this, and what challenges do you face in terms of scaling and maintaining the system? I’d love to hear about any tools or strategies that have worked for you in making this process more manageable.