Operating model

How Delegance works

Turn business authority into explicit, enforceable and reviewable access decisions.

Decision path

Every step has a different responsibility.

How authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcomeHow authority becomes an access decisionIdentity, role and attributes enter policy. Explicit delegated authority constrains the target resource and action, while evidence records the decision and outcome.01IDENTITYKnown actor02ROLEBaseline responsibility03ATTRIBUTESReliable context04POLICYDecision boundary05DELEGATED AUTHORITYOwner · scope · expiry06RESOURCEEnforcement point07ACTIONPermitted operation08EVIDENCEDecision + outcome
Each stage has a distinct responsibility: context informs policy, authority defines the boundary, the platform enforces, and evidence supports accountability.

Delegation lifecycle

Authority should end by design.

How scoped authority is governed over timeA delegation moves from request and accountable approval through activation, use, review, expiry or revocation, and retained evidence.01REQUESTPurpose + scope02APPROVEAccountable owner03ACTIVATETime-bound authority04USEPermitted action05REVIEWNeed + activity06EXPIRE / REVOKEAuthority ends07EVIDENCEDecision + outcomeHow scoped authority is governed over timeA delegation moves from request and accountable approval through activation, use, review, expiry or revocation, and retained evidence.01REQUESTPurpose + scope02APPROVEAccountable owner03ACTIVATETime-bound authority04USEPermitted action05REVIEWNeed + activity06EXPIRE / REVOKEAuthority ends07EVIDENCEDecision + outcome
Scope, owner and duration travel with the delegation; authority ends deliberately rather than becoming standing access.
How Delegance governs existing platformsA business owner defines authority. Delegance policy and scope translate that authority into controls supported by Microsoft Entra, SaaS, enterprise applications, custom applications or APIs.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVALDURATIONDELEGANCE CONTROLPolicy + authorityROLE + ATTRIBUTESSCOPE + CONSTRAINTSDELEGATION + EXPIRYDECISION EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPIDelegance platform integrationBusiness ownership, policy and authority, and target platforms are stacked vertically for mobile reading.ACCOUNTABILITYBusiness ownerPURPOSE · APPROVAL · DURATIONDELEGANCE CONTROLPolicy + authorityROLE · ATTRIBUTESSCOPE · DELEGATIONEXPIRY · EVIDENCEMICROSOFT ENTRASaaSENTERPRISE APPCUSTOM APPAPI
Delegance uses the control surface each target actually exposes; the diagram does not imply a catalogue of ready-made connectors.
01

From authority to action

Identity establishes the person. Roles and attributes add context. Policy evaluates the request. Delegated authority records who approved what, for which scope and period. The target platform enforces the resulting action.

02

A governed lifecycle

Request → evaluate → approve → activate → use → monitor → review → expire or revoke. Every stage has an owner, a control point and evidence suitable for assurance.

03

Fit existing platforms

Delegance can be integrated with Microsoft Entra, SaaS services, enterprise and custom applications, APIs, directories and privileged platforms. The implementation pattern depends on the controls each target exposes; no ready-made connector is assumed.

04

Decision boundaries

Delegance does not replace authentication or the target platform. It coordinates authority, policy and governance so those platforms receive narrower, better-evidenced access decisions.

Apply the model

Make authority explicit.

Start with the business action, accountable owner, current entitlement and platform control surface.

Talk to MAITS →