Operating model

How Delegance works

Turn business authority into explicit, enforceable and reviewable access decisions.

Decision path

Every step has a different responsibility.

How authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcomeHow authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcome
Each stage has a distinct responsibility: context informs policy, authority defines the boundary, the platform enforces, and evidence supports accountability.

Delegation lifecycle

Authority should end by design.

How scoped authority is governed over timeA delegation moves from request and policy evaluation through accountable approval, activation, use, review, expiry or revocation, and audit.01REQUESTPurpose + scope02EVALUATEPolicy + attributes03APPROVEAccountable owner04ACTIVATETime-bound authority05USEPermitted action06REVIEWNeed + activity07EXPIRE / REVOKEAuthority ends08AUDITDecision + outcomeHow scoped authority is governed over timeA delegation moves from request and policy evaluation through accountable approval, activation, use, review, expiry or revocation, and audit.01REQUESTPurpose + scope02EVALUATEPolicy + attributes03APPROVEAccountable owner04ACTIVATETime-bound authority05USEPermitted action06REVIEWNeed + activity07EXPIRE / REVOKEAuthority ends08AUDITDecision + outcome
Scope, owner and duration travel with the delegation; authority ends deliberately rather than becoming standing access.
How Delegance governs existing platformsA business owner defines authority. Delegance policy and scope translate that authority into controls supported by Microsoft Entra, SaaS, enterprise applications, custom applications or APIs.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVALDURATIONDELEGANCE CONTROLPolicy + authorityROLE + ATTRIBUTESSCOPE + CONSTRAINTSDELEGATION + EXPIRYDECISION EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPIDelegance platform integrationBusiness ownership, policy and authority, and target platforms are stacked vertically for mobile reading.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVAL · DURATIONDELEGANCE CONTROLPolicy + authorityROLE · ATTRIBUTESSCOPE · DELEGATIONEXPIRY · EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPI
Delegance uses the control surface each target actually exposes; the diagram does not imply a catalogue of ready-made connectors.
01

From authority to action

Identity establishes the known actor. Role supplies a baseline responsibility. Attributes add reliable context—department, location, assurance level, project or employment status. Policy evaluates that context against a decision boundary. Delegated authority records who approved the request, its scope and its expiry. The resource is the enforcement point the platform protects, and the action is the specific operation permitted. Evidence closes the chain, capturing the decision and its outcome for later review.

02

A governed lifecycle

Request → evaluate → approve → activate → use → review → expire or revoke → audit. Every stage has an owner, a control point and evidence suitable for assurance: a request captures purpose and scope, evaluation applies policy to role and attributes, approval assigns accountable authority, activation makes the access usable, use is the period the authority is exercised, review confirms the need still exists, expiry or revocation ends the authority by design rather than by accident, and audit retains what happened for anyone who later has to explain it.

03

Delegation in practice

Consider a manager going on leave who delegates approval authority for purchase requests to a peer for a fixed two-week period; the delegation is scoped to that approval type, carries an explicit expiry, and reverts automatically without anyone having to remember to remove it. Consider, separately, a procurement officer who holds standing delegated authority to approve supplier invoices up to a defined spend threshold—above that threshold the request routes to a more senior approver, so the limit is enforced by policy rather than by trust alone. Consider a third case: an external consultant engaged for a fixed-term project who receives access constrained to the systems and data the engagement requires, for the duration of the contract, with the access withdrawn as a normal part of the engagement closing rather than as a separate offboarding task.

04

Fit existing platforms

Delegance can be integrated with Microsoft Entra, SaaS services, enterprise and custom applications, APIs, directories and privileged platforms. The implementation pattern depends on the controls each target exposes; no ready-made connector is assumed.

05

Decision boundaries

Delegance does not replace authentication or the target platform. It coordinates authority, policy and governance so those platforms receive narrower, better-evidenced access decisions.

Apply the model

Make authority explicit.

Start with the business action, accountable owner, current entitlement and platform control surface.

Talk to MAITS →