Control effectiveness

Security and governance

Having access and having authority to use it are related—but not always the same. This is governance of delegated authority specifically: who owns a delegation grant, who reviews it while active, and who can revoke it.

01

Ownership of delegation grants

Every delegation needs a named accountable owner—the person or role who authorised it, not just the person who technically provisioned it. Technical administration should not silently become business approval, and a delegation without a clear owner is a delegation nobody is positioned to review.

02

Review of active delegations

Standing authority and open-ended delegations need periodic review by someone who understands what the authority is for, applying least privilege so a delegation is scoped to what the task actually requires rather than to whatever was easiest to grant at the time. A review that simply re-approves a long list of unfamiliar entitlements is not a control—it is a formality that happens to produce a signature.

03

Revocation of delegated authority

Temporary authority should end by design, and delegated authority specifically needs a clear path to early revocation when a relationship changes, a project ends, risk increases or policy is updated—independent of whatever review cycle would otherwise apply.

04

Separation of duties

Policy should prevent one person from requesting, approving and exercising incompatible authority without independent oversight. Exceptions require an owner, reason and expiry.

05

Policy consistency across platforms

The same delegated-authority rule—an approval threshold, a scope boundary, a review cadence—should be applied consistently wherever it is enforced, rather than each target platform interpreting the underlying policy in its own way. Inconsistent enforcement across systems is a common source of entitlements that are technically correct in one platform and quietly wrong everywhere else.

06

Evidence and audit

Record the request, policy result, approver, scope, activation, use, review and closure needed to reconstruct why access existed. Avoid collecting unrelated personal data.

07

Privileged guardrails

High-risk administration can require stronger authentication, narrower scope, just-in-time activation, session controls, monitoring and human approval. Controls must match platform capability and risk.

Apply the model

Make authority explicit.

Start with the business action, accountable owner, current entitlement and platform control surface.

Talk to MAITS →