← ClaudeAtlas

enterprise-access-governance-reviewlisted

Design or audit enterprise tenant and administrator governance across ownership, organization hierarchy, domains, roles, permissions, delegated administration, SSO/SCIM authority boundaries, joiner-mover-leaver lifecycle, temporary elevation, support access, break-glass, privileged-action gates, customer-visible audit evidence, access reviews, tenant split/merge, and access exceptions. Use when the primary artifact is an Enterprise Access Governance Contract. Do not use for authentication or SSO/SCIM implementation, end-user account recovery, a generic authorization library, security certification, or a customer security questionnaire alone.
SylphxAI/skills · ★ 1 · Code & Development · score 74
Install: claude install-skill SylphxAI/skills
# Enterprise Access Governance Review Produce one **Enterprise Access Governance Contract** that answers who may grant, inherit, exercise, review, recover, and revoke administrative authority inside and across customer tenants. Treat identity assertions as inputs to product authority, not as a substitute for explicit tenant and permission semantics. ## Atomic boundary Own tenant hierarchy and data boundary, ownership authorities, role/permission semantics, source mapping, delegation, privileged lifecycle, support and break-glass access, privileged-action gates, customer admin UX, access-specific exceptions, audit coverage, access review, split/merge/transfer behavior, and governance metrics. Consume authentication protocols, identity-provider connectors, authorization enforcement code, security controls, account recovery, privacy, contract, and incident facts from their canonical owners. ## When not to use - Do not use to implement authentication, sessions, tokens, SAML/OIDC/SCIM, an authorization library, or policy enforcement code; hand exact requirements to the current engineering and specification owners. - Do not use for a legitimate user's lost credentials or channels; use `account-recovery-review` and supply tenant/admin authority as an input. - Do not use for security questionnaires, compliance evidence, generic product abuse, or the whole support model; route those to their specialist owners. ## Resource routing - Read `references/access-authority-life