A dedicated tenant creates a useful ownership boundary only when access is deliberately provisioned and maintained. User invitations, role changes, service accounts, and offboarding should follow a documented operating model.

Define roles around process responsibility

Separate customer administrators, workflow owners, operators, approvers, reviewers, and technical support. Grant only the functions and data each role needs for its responsibility.

Manage the full access lifecycle

Customer administrators should invite approved employees, review access periodically, update roles when responsibilities change, and remove access promptly during offboarding.

  • Named user and accountable manager
  • Approved role and business purpose
  • Provisioning date and reviewer
  • Periodic recertification
  • Role-change and revocation record

Govern non-human access separately

Connector credentials and service identities need narrower scopes, technical owners, expiry or rotation procedures, and monitoring. They should not inherit the convenience permissions of a human administrator.

Use an approval-backed provisioning record

Each access grant should identify the person or service, accountable manager, approved role, business purpose, scope, granting administrator, and date. Sensitive or administrative roles may require a second approval. Invitations should expire, and acceptance should be bound to the intended identity rather than forwarded links or shared accounts.

Keep customer administration separate from platform support where practical. Support access should be time-bound, attributable, and limited to the task. Record role changes and revocations with the same care as initial provisioning because privilege accumulation often occurs through successive changes.

Plan recertification and emergency access

Review access at a cadence based on role sensitivity and business change. Managers and process owners should confirm that the user still has the responsibility, while system owners confirm the permission set remains appropriate. Dormant, duplicate, departed, or unexplained accounts should be investigated and removed promptly.

If emergency access is necessary, define who can authorize it, what scope is available, how long it lasts, what monitoring occurs, and who reviews activity afterward. Test revocation as well as activation. An emergency account that cannot be removed reliably is a standing privileged account.

Further reading

These primary references informed the operating principles in this guide.

Continue the evaluation

Review the access modelBook a process diagnostic →