Controlled authority · For people and organisations

Understand authority.
Keep control.

Understand and control the authority you give and receive. Organisations can turn that authority into scoped, time-bound and accountable access.

Choose your perspective

Authority should be understandable before it becomes technical.

FOR ORGANISATIONS

Govern how authority becomes access

Use policy, approval, expiry, review and evidence across existing identity and application platforms.

Explore organisation capabilities →

Use Delegance independently or connect trusted evidence from DiligenceID and continuous assurance from Vigilance around a broader authority journey.

The business problem

Access accumulates. Authority is rarely reviewed.

These are well-understood patterns across enterprise and government organisations, not edge cases.

01

Role explosion and privilege creep

Permissions accumulate as people change teams and projects, and are rarely removed once the original need has passed.

02

Temporary and acting access

Temporary staff, and people covering a role while its substantive holder is on leave or secondment, need authority that should end automatically but often doesn't.

03

Delegated financial authority

Spend thresholds, invoice approvals and other delegated financial authority are often enforced by trust and memory rather than by policy.

04

Supplier, project and cross-organisational access

Suppliers, project teams and people from partner organisations need scoped access into systems they do not own, distinct from simply representing their own employer.

05

Access reviews nobody can complete

Reviewers are asked to approve long lists of entitlements they do not understand, which turns a control into a formality.

06

Manual, ticket-driven provisioning

Central IT queues process access requests by pattern-matching rather than business judgement, slowing down the people waiting on access.

The leadership issue

Delegation is unavoidable.
Uncontrolled delegation is a risk.

UNCONTROLLED

Access becomes broad, permanent and opaque

  • Business authority is translated manually by IT
  • Privileged roles accumulate standing access
  • External parties inherit internal-style administration
  • Auditors can see access but not always the authority behind it
WITH DELEGANCE

Authority becomes explicit and governed

  • Scope, purpose, owner and duration are recorded
  • Roles and attributes constrain policy decisions
  • Reviews, expiry and revocation are designed in
  • Evidence connects approval to action

Policy model

From identity to an authorised action.

Delegance separates identity, access, authority, delegation and the final decision so every control has a clear job.

How authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcomeHow authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcome
Each stage has a distinct responsibility: context informs policy, authority defines the boundary, the platform enforces, and evidence supports accountability.
Explore the operating model →

Decision context

Resolve the questions behind the permission.

How governance questions become scoped authorityWho, what, where, when, why and authorised by inputs converge into a policy decision, then scoped access or authority and audit evidence.WHOActorWHATActionWHEREResourceWHENValidityWHYPurposeAUTHORISED BYOwnerGOVERNED EVALUATIONPolicy decisionROLE + ATTRIBUTESSCOPE + APPROVALTIME + PURPOSEOUTCOMEScoped authorityENFORCEABLE BOUNDARYAUDITEVIDENCEGovernance inputs to scoped authoritySix explicit governance questions feed policy, scoped authority and evidence in a vertical mobile sequence.WHOActorWHATActionWHEREResourceWHENValidityWHYPurposeAUTHORISED BYOwnerGOVERNED EVALUATIONPolicy decisionROLE · ATTRIBUTES · SCOPEAPPROVAL · TIME · PURPOSEOUTCOMEScoped authorityENFORCEABLE BOUNDARYAUDIT EVIDENCE
A decision is explainable when its actor, action, resource, validity, purpose and accountable authoriser are explicit.

Control outcomes

Give the business room to act—inside deliberate boundaries.

01 / SCOPE

Reduce standing privilege

Replace blanket administration with task, resource and time-bound authority where platforms support it.

02 / OWN

Clarify accountability

Keep business ownership, technical enforcement and approval responsibility visible.

03 / EXPLAIN

Make decisions reviewable

Show which role, attributes, policy and delegation produced a material entitlement.

04 / END

Close the lifecycle

Design expiry, certification, revocation and exception handling alongside activation.

05 / MOVE

Keep the business moving

Self-service, policy-governed delegation mobilises contractors and project teams faster and cuts the manual, ticket-driven access requests that slow everyone down.

How scoped authority is governed over timeA delegation moves from request and policy evaluation through accountable approval, activation, use, review, expiry or revocation, and audit.01REQUESTPurpose + scope02EVALUATEPolicy + attributes03APPROVEAccountable owner04ACTIVATETime-bound authority05USEPermitted action06REVIEWNeed + activity07EXPIRE / REVOKEAuthority ends08AUDITDecision + outcomeHow scoped authority is governed over timeA delegation moves from request and policy evaluation through accountable approval, activation, use, review, expiry or revocation, and audit.01REQUESTPurpose + scope02EVALUATEPolicy + attributes03APPROVEAccountable owner04ACTIVATETime-bound authority05USEPermitted action06REVIEWNeed + activity07EXPIRE / REVOKEAuthority ends08AUDITDecision + outcome
Scope, owner and duration travel with the delegation; authority ends deliberately rather than becoming standing access.

RBAC + ABAC + delegation

Three controls. Three different questions.

RBAC, ABAC and delegated authority working togetherRole-based access creates a baseline. Attribute-based access evaluates identity, resource and context. Delegated authority adds accountable purpose, scope and expiry before a decision is enforced.RBAC · REPEATABLE BASELINEIDENTITYKnown actorROLEResponsibilityBASELINEExpected accessDECISIONExplainable resultABAC · CONTEXTUAL CONSTRAINTIDENTITYATTRIBUTESRESOURCECONTEXTPOLICYEvaluate conditions+ delegationDELEGATED AUTHORITY · SCOPE · EXPIRYRBAC and ABAC comparisonRole-based and attribute-based controls are shown as separate paths that both contribute to a governed decision, with delegated authority adding accountable scope.RBAC · BASELINEIDENTITYROLEEXPECTED ACCESSABAC · CONTEXTIDENTITY + ATTRIBUTESRESOURCE + CONTEXTPOLICY CONDITIONSDELEGATED AUTHORITYGOVERNED DECISIONRole + context + accountable scope
Roles simplify repeatable access; attributes constrain context; delegation records accountable authority, scope and duration.
Understand the policy foundations →

Where it fits

Govern authority across different platforms.

How Delegance governs existing platformsA business owner defines authority. Delegance policy and scope translate that authority into controls supported by Microsoft Entra, SaaS, enterprise applications, custom applications or APIs.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVALDURATIONDELEGANCE CONTROLPolicy + authorityROLE + ATTRIBUTESSCOPE + CONSTRAINTSDELEGATION + EXPIRYDECISION EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPIDelegance platform integrationBusiness ownership, policy and authority, and target platforms are stacked vertically for mobile reading.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVAL · DURATIONDELEGANCE CONTROLPolicy + authorityROLE · ATTRIBUTESSCOPE · DELEGATIONEXPIRY · EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPI
Delegance translates accountable business authority into the controls available in each target platform.

MAITS maps the control surfaces available in each target and builds the integration needed to enforce scope, expiry and accountable authority.

MAITS managed service

Software controls need an operating model.

DESIGN

Map authority

Define roles, attributes, owners, approval chains and separation of duties, typically captured in a policy model document agreed with business and technical stakeholders.

IMPLEMENT

Integrate platforms

Translate governed decisions into the controls exposed by identity and application platforms, with an integration and runbook artefact describing how each control point is configured and operated.

OPERATE

Review and improve

Run expiry, certification, exceptions and evidence against a defined review cadence with named business and technical owners, refining the model as roles and platforms change.

MAITS product family

Evidence. Authority. Assurance.

Use each proposition independently or combine them around a broader trust journey.

DILIGENCEIDTrusted evidence

What evidence can this person or organisation prove? DiligenceID's verified evidence can support a Delegance approval decision where an entitlement depends on proving who someone is or what they represent.

Explore DiligenceID →
DELEGANCEControlled authority

Who is authorised to act, where and for how long?

VIGILANCEContinuous assurance

How do we know when trust or access is at risk? Vigilance can provide ongoing monitoring of active delegations for anomalous use, complementing the review and revocation controls in Delegance.

Explore Vigilance →

Frequently asked questions

Delegance, without the ambiguity.

How does Delegance relate to authentication?

Authentication establishes identity. Delegance governs the authority to act and the access needed for that action.

How does Delegance work with Microsoft Entra?

It uses and extends controls in Microsoft Entra and other platforms while keeping business authority and governance explicit.

How is Delegance delivered?

MAITS designs and implements access delegation and governance around the platforms and control surfaces in each customer environment.

What is the difference between access and authority?

Access is a technical capability. Authority explains why a person is permitted to use it, who approved it, for which purpose and for how long.

Next step

Start with one authority chain.

Bring the action, owner, current access path and risk. MAITS can map a delegation model that fits the platforms you already operate.

Discuss Delegance →