01From authority to action
Identity establishes the known actor. Role supplies a baseline responsibility. Attributes add reliable context—department, location, assurance level, project or employment status. Policy evaluates that context against a decision boundary. Delegated authority records who approved the request, its scope and its expiry. The resource is the enforcement point the platform protects, and the action is the specific operation permitted. Evidence closes the chain, capturing the decision and its outcome for later review.
02A governed lifecycle
Request → evaluate → approve → activate → use → review → expire or revoke → audit. Every stage has an owner, a control point and evidence suitable for assurance: a request captures purpose and scope, evaluation applies policy to role and attributes, approval assigns accountable authority, activation makes the access usable, use is the period the authority is exercised, review confirms the need still exists, expiry or revocation ends the authority by design rather than by accident, and audit retains what happened for anyone who later has to explain it.
03Delegation in practice
Consider a manager going on leave who delegates approval authority for purchase requests to a peer for a fixed two-week period; the delegation is scoped to that approval type, carries an explicit expiry, and reverts automatically without anyone having to remember to remove it. Consider, separately, a procurement officer who holds standing delegated authority to approve supplier invoices up to a defined spend threshold—above that threshold the request routes to a more senior approver, so the limit is enforced by policy rather than by trust alone. Consider a third case: an external consultant engaged for a fixed-term project who receives access constrained to the systems and data the engagement requires, for the duration of the contract, with the access withdrawn as a normal part of the engagement closing rather than as a separate offboarding task.
04Fit existing platforms
Delegance can be integrated with Microsoft Entra, SaaS services, enterprise and custom applications, APIs, directories and privileged platforms. The implementation pattern depends on the controls each target exposes; no ready-made connector is assumed.
05Decision boundaries
Delegance does not replace authentication or the target platform. It coordinates authority, policy and governance so those platforms receive narrower, better-evidenced access decisions.