Authority in practice

Delegance use cases

Enterprise access rarely fails because a permission is missing—it fails because permissions accumulate, temporary needs become permanent, and nobody can explain why an entitlement still exists. These are the recurring patterns Delegance is built to address.

01

Delegated application administration

An application owner needs a specific function performed—resetting a user’s password, adjusting a configuration flag, supporting an account issue—without handing over full platform administration. The owner delegates that narrow function to a nominated operator, and the scope, duration and accountable owner remain visible throughout rather than disappearing into a standing admin group.

02

Business-managed access

A finance manager or HR lead understands which entitlements their team genuinely needs far better than a central IT queue processing tickets by pattern-matching. Delegance lets that business owner approve the access decision directly, while guardrails translate the decision into whatever the target platform can technically enforce and IT retains oversight of the technical control.

03

Temporary elevated access

A support engineer needs administrative rights on a system to resolve an incident, or an analyst needs a broader data view to close out a project task. Authority is activated for that task or period, monitored while active, and removed automatically or through an explicit lifecycle event—so the elevated access does not quietly become the engineer’s everyday permission set.

04

Project access

A project team is assembled from people who do not normally work together—internal staff from different business units, sometimes a contractor or two—and needs shared access to a workspace, repository or dataset for the life of the project. Access is granted for that team and that project, time-boxed to the project schedule, and withdrawn as the project closes rather than left in place because nobody owns the task of removing it.

05

Emergency and break-glass access

An operator needs rapid access to a system during an outage or security incident, and the normal approval chain is too slow for the moment. Delegance allows a narrowly scoped emergency grant to be activated quickly, with the exceptional circumstance recorded at the time and a mandatory post-hoc review confirming what was accessed, why, and whether the access should be extended, adjusted or closed out.

06

Acting-position delegation

A team lead goes on parental leave, secondment or extended sick leave, and a peer or direct report needs to exercise the substantive holder’s approval authority for the duration. The delegation is scoped to the acting period and the specific decisions the acting position requires, and it lapses automatically when the substantive holder returns rather than lingering as an unreviewed permission.

07

External-party delegation

Partners, contractors and service providers need to do real work inside the organisation’s systems without being treated as unrestricted internal administrators. Their authority is bounded by organisation, purpose and expiry, so a supplier engagement or contract renewal is the moment access is reconsidered, not the moment it is discovered still active.

08

Cross-organisational access

A person employed by one organisation—a shared-services provider, a partner agency, a subsidiary—needs scoped access into a different organisation’s systems or resources, distinct from simply representing their own employer in a transaction. This is common in shared-services arrangements, joint ventures and inter-agency programmes, and it requires the receiving organisation to authorise, scope and review access held by someone outside its own workforce.

09

Organisational representation

Some actions require more than proving who a person is—they require evidence that the person is authorised to represent an organisation and perform a specific action on its behalf, such as submitting a regulatory return or approving a payment as a company officer. Delegance connects the person’s access to that evidence rather than assuming employment alone implies authority to represent.

10

High-risk administration

Identity recovery, credential issuance, privilege assignment, user administration and access changes are the actions most likely to be abused if something goes wrong. These can require stronger approvals, separation of duties and evidence beyond what a routine access request needs.

Apply the model

Make authority explicit.

Start with the business action, accountable owner, current entitlement and platform control surface.

Talk to MAITS →