Glossary
Delegated administration is the practice of letting designated users (such as a business customer’s own administrator) manage a defined subset of identities and access themselves, within limits set by the platform, without routing every change through central IT. It pushes routine identity administration out to the people closest to it.
For any business serving organizations, doing all identity administration centrally does not scale. Each business customer wants to add and remove their own employees, adjust their access, and reset their logins on their own schedule.
The platform grants a tenant or group its own administrator role, scoped so that admin can manage only their own users and only within permitted bounds. That admin can then provision users, assign roles, and handle routine tasks for their organization, while the platform enforces the boundaries so delegation never becomes a security hole. It is a controlled handoff of authority, not a blanket one.
Delegated administration is essential for B2B identity and multi-tenant platforms. It removes a bottleneck (central IT handling every customer’s user changes), gives business customers the self-service control they expect, and scales identity administration across many organizations. The care point is scoping: delegated admins must be tightly bounded and monitored, because an over-privileged or compromised delegated admin can affect everyone under them.
What is delegated administration?
Letting designated users manage a defined subset of identities and access themselves, within limits, without central IT.
Why is delegated administration useful?
It scales identity administration and gives business customers self-service control over their own users.
What’s the risk of delegated administration?
Poorly scoped delegated admins can over-reach, so their authority must be tightly bounded and monitored.
Related: B2B Identity Management · Multi-Tenancy in Identity · User Management · Principle of Least Privilege · Authorization