Because ownership, workflow state, and tenant rules can matter beyond a coarse role.
A token claim like `role=CUSTOMER` does not prove that the customer owns a specific order or may perform a specific action. Strong authorization uses current business facts, not just login metadata.