01Ownership of delegation grants
Every delegation needs a named accountable owner—the person or role who authorised it, not just the person who technically provisioned it. Technical administration should not silently become business approval, and a delegation without a clear owner is a delegation nobody is positioned to review.
02Review of active delegations
Standing authority and open-ended delegations need periodic review by someone who understands what the authority is for, applying least privilege so a delegation is scoped to what the task actually requires rather than to whatever was easiest to grant at the time. A review that simply re-approves a long list of unfamiliar entitlements is not a control—it is a formality that happens to produce a signature.
03Revocation of delegated authority
Temporary authority should end by design, and delegated authority specifically needs a clear path to early revocation when a relationship changes, a project ends, risk increases or policy is updated—independent of whatever review cycle would otherwise apply.
04Separation of duties
Policy should prevent one person from requesting, approving and exercising incompatible authority without independent oversight. Exceptions require an owner, reason and expiry.
05Policy consistency across platforms
The same delegated-authority rule—an approval threshold, a scope boundary, a review cadence—should be applied consistently wherever it is enforced, rather than each target platform interpreting the underlying policy in its own way. Inconsistent enforcement across systems is a common source of entitlements that are technically correct in one platform and quietly wrong everywhere else.
06Evidence and audit
Record the request, policy result, approver, scope, activation, use, review and closure needed to reconstruct why access existed. Avoid collecting unrelated personal data.
07Privileged guardrails
High-risk administration can require stronger authentication, narrower scope, just-in-time activation, session controls, monitoring and human approval. Controls must match platform capability and risk.