IT Glossary

Delegated Administration

Delegated administration gives limited admin rights to teams closest to a tool. Learn how to scope it and why unscoped delegation spreads risk.

August 7, 2026

What is delegated administration?

Delegated administration is the practice of granting limited administrative rights to people outside the central IT team, so the manager, application owner, or regional lead closest to a system can handle routine tasks. The delegation is bounded by design: the delegate performs specific actions on a specific scope, not everything a full administrator could do.

How delegated administration works

  • A scope is defined: an organizational unit, a department, a single application, or a group of users.
  • A limited set of actions is attached to that scope, for example resetting passwords or approving access to one tool.
  • The delegate receives only that combination, never a broad built-in administrator role.
  • Delegation is granted to a role rather than a named person, so it survives staff changes.
  • Actions performed by delegates are logged separately, which is what makes the arrangement auditable.

Where delegation goes wrong

The failure is almost never the principle, it is the scoping. A company decides each application owner should manage their own tool, then grants each of them the full admin role because carving out a narrower one is fiddly. Twenty applications later, twenty people hold unbounded rights on systems the security team no longer watches closely. Delegation without scope is not delegation, it is distribution of the highest privilege in the company.

Examples and use cases

A company with three country offices delegates user management to a local IT lead in each one, scoped to that country organizational unit. Local hires get access the same day and central IT stops being the bottleneck. The control that keeps it honest is a recurring review of who holds delegated rights and on which scope, since delegations reliably outlive the reason they were created. Corma surfaces those administrative rights across applications so one review covers all of them.

Related concepts

FAQ

What is the difference between delegated administration and RBAC?

RBAC assigns permissions to use a system. Delegated administration assigns permissions to manage it, on a defined scope, on behalf of central IT.

Does delegation reduce or increase risk?

Properly scoped it reduces risk, by removing bottlenecks and shrinking the number of people who need global rights. Unscoped, it simply multiplies the number of full administrators.

Who should receive delegated rights?

The person accountable for the system or the population concerned, typically an application owner, a team manager, or a regional IT lead.

How often should delegations be reviewed?

At least as often as privileged accounts, so quarterly for sensitive systems. Delegations are rarely removed on their own once the reason for them disappears.

Request a demo