MAITS managed access governance

Delegate authority.
Keep control.

Enable teams, managers, administrators and trusted parties to act where needed—while maintaining policy, accountability and evidence of who authorised what.

The leadership issue

Delegation is unavoidable.
Uncontrolled delegation is a risk.

UNCONTROLLED

Access becomes broad, permanent and opaque

  • Business authority is translated manually by IT
  • Privileged roles accumulate standing access
  • External parties inherit internal-style administration
  • Auditors can see access but not always the authority behind it
WITH DELEGANCE

Authority becomes explicit and governed

  • Scope, purpose, owner and duration are recorded
  • Roles and attributes constrain policy decisions
  • Reviews, expiry and revocation are designed in
  • Evidence connects approval to action

Policy model

From identity to an authorised action.

Delegance separates identity, access, authority, delegation and the final decision so every control has a clear job.

How authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcomeHow authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcome
Each stage has a distinct responsibility: context informs policy, authority defines the boundary, the platform enforces, and evidence supports accountability.
Explore the operating model →

Decision context

Resolve the questions behind the permission.

How governance questions become scoped authorityWho, what, where, when, why and authorised by inputs converge into a policy decision, then scoped access or authority and audit evidence.WHOActorWHATActionWHEREResourceWHENValidityWHYPurposeAUTHORISED BYOwnerGOVERNED EVALUATIONPolicy decisionROLE + ATTRIBUTESSCOPE + APPROVALTIME + PURPOSEOUTCOMEScoped authorityENFORCEABLE BOUNDARYAUDITEVIDENCEGovernance inputs to scoped authoritySix explicit governance questions feed policy, scoped authority and evidence in a vertical mobile sequence.WHOActorWHATActionWHEREResourceWHENValidityWHYPurposeAUTHORISED BYOwnerGOVERNED EVALUATIONPolicy decisionROLE · ATTRIBUTES · SCOPEAPPROVAL · TIME · PURPOSEOUTCOMEScoped authorityENFORCEABLE BOUNDARYAUDIT EVIDENCE
A decision is explainable when its actor, action, resource, validity, purpose and accountable authoriser are explicit.

Control outcomes

Give the business room to act—inside deliberate boundaries.

01 / SCOPE

Reduce standing privilege

Replace blanket administration with task, resource and time-bound authority where platforms support it.

02 / OWN

Clarify accountability

Keep business ownership, technical enforcement and approval responsibility visible.

03 / EXPLAIN

Make decisions reviewable

Show which role, attributes, policy and delegation produced a material entitlement.

04 / END

Close the lifecycle

Design expiry, certification, revocation and exception handling alongside activation.

How scoped authority is governed over timeA delegation moves from request and accountable approval through activation, use, review, expiry or revocation, and retained evidence.01REQUESTPurpose + scope02APPROVEAccountable owner03ACTIVATETime-bound authority04USEPermitted action05REVIEWNeed + activity06EXPIRE / REVOKEAuthority ends07EVIDENCEDecision + outcomeHow scoped authority is governed over timeA delegation moves from request and accountable approval through activation, use, review, expiry or revocation, and retained evidence.01REQUESTPurpose + scope02APPROVEAccountable owner03ACTIVATETime-bound authority04USEPermitted action05REVIEWNeed + activity06EXPIRE / REVOKEAuthority ends07EVIDENCEDecision + outcome
Scope, owner and duration travel with the delegation; authority ends deliberately rather than becoming standing access.

RBAC + ABAC + delegation

Three controls. Three different questions.

RBAC, ABAC and delegated authority working togetherRole-based access creates a baseline. Attribute-based access evaluates identity, resource and context. Delegated authority adds accountable purpose, scope and expiry before a decision is enforced.RBAC · REPEATABLE BASELINEIDENTITYKnown actorROLEResponsibilityBASELINEExpected accessDECISIONExplainable resultABAC · CONTEXTUAL CONSTRAINTIDENTITYATTRIBUTESRESOURCECONTEXTPOLICYEvaluate conditions+ delegationDELEGATED AUTHORITY · SCOPE · EXPIRYRBAC and ABAC comparisonRole-based and attribute-based controls are shown as separate paths that both contribute to a governed decision, with delegated authority adding accountable scope.RBAC · BASELINEIDENTITYROLEEXPECTED ACCESSABAC · CONTEXTIDENTITY + ATTRIBUTESRESOURCE + CONTEXTPOLICY CONDITIONSDELEGATED AUTHORITYGOVERNED DECISIONRole + context + accountable scope
Roles simplify repeatable access; attributes constrain context; delegation records accountable authority, scope and duration.
Understand the policy foundations →

Where it fits

Govern across platforms without pretending they are identical.

How Delegance governs existing platformsA business owner defines authority. Delegance policy and scope translate that authority into controls supported by Microsoft Entra, SaaS, enterprise applications, custom applications or APIs.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVALDURATIONDELEGANCE CONTROLPolicy + authorityROLE + ATTRIBUTESSCOPE + CONSTRAINTSDELEGATION + EXPIRYDECISION EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPIDelegance platform integrationBusiness ownership, policy and authority, and target platforms are stacked vertically for mobile reading.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVAL · DURATIONDELEGANCE CONTROLPolicy + authorityROLE · ATTRIBUTESSCOPE · DELEGATIONEXPIRY · EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPI
Delegance uses the control surface each target actually exposes; the diagram does not imply a catalogue of ready-made connectors.

Delegance is service-led. MAITS confirms available control surfaces and builds the integration appropriate to each target; this site does not claim prebuilt connectors or a universal console.

MAITS managed service

Software controls need an operating model.

DESIGN

Map authority

Define roles, attributes, owners, approval chains, policy and separation of duties.

IMPLEMENT

Integrate platforms

Translate governed decisions into the controls exposed by identity and application platforms.

OPERATE

Review and improve

Run expiry, certification, exceptions and evidence as environments change.

MAITS product family

Evidence. Authority. Assurance.

DILIGENCEIDTrusted evidence

What evidence can this person or organisation prove?

DELEGANCEControlled authority

Who is authorised to act, where and for how long?

VIGILANCEContinuous assurance

How do we know when trust or access is at risk?

Frequently asked questions

Delegance, without the ambiguity.

Is Delegance an authentication product?

No. Authentication establishes identity. Delegance governs the authority to act and the access needed for that action.

Does Delegance replace Microsoft Entra?

No. It can use and extend controls in Microsoft Entra and other platforms while keeping business authority and governance explicit.

Is Delegance a SaaS console?

Delegance is currently presented as a MAITS managed access-delegation and governance proposition. The implementation surface depends on the customer environment.

What is the difference between access and authority?

Access is a technical capability. Authority explains why a person is permitted to use it, who approved it, for which purpose and for how long.

Next step

Start with one authority chain.

Bring the action, owner, current access path and risk. MAITS can map a delegation model that fits the platforms you already operate.

Discuss Delegance →