A lot of application frameworks have some kind of a security policy engine, but all of these invariably are inadequate - because modern policy management is about interfacing outside of systems, and that they don't do.
Exactly in the same way that load balancing should not be a part of an application framework, neither should authorization.
A coherent, formalized, well manageable policy engine can go a great deal for practical organization security