I'm thinking that we're leaning more towards AD-based single sign on, and then managing groups inside of BOE. For my application alone, I have approximately 1500 users at 24 different facilities, with report coordinators at each facility- who will manage their own groups. Also, each facility has its own view to our oracle DSS, and access views are being set on a per-group basis, with filters allowing for views with their own data.
Also, regarding the web application server- we're actually using the websphere interface in an SOA/UCE cluster. Thankfully we've got some knowledgeable websphere people here!