Proportionate governance

Delegance privacy

Govern authority with the minimum identity, relationship and activity data needed for the control.

01

Purpose and minimisation

Define why delegation data is required, who can see it and how long evidence must be retained. Do not turn access governance into unrestricted workforce surveillance.

02

Explainability

People and owners should be able to understand the role, attributes, delegation and policy that affected a material access decision.

03

Shared responsibility

MAITS, identity providers, target platforms and customer organisations each hold responsibilities according to the implementation. Privacy, employment and recordkeeping obligations must be assessed per engagement.

04

Public website boundary

This site is static marketing and education content. It contains no access-management runtime, customer identity data, authentication or administrative console.

Apply the model

Make authority explicit.

Start with the business action, accountable owner, current entitlement and platform control surface.

Talk to MAITS →