enterprise-access-governance-reviewlisted
Install: claude install-skill SylphxAI/skills
# Enterprise Access Governance Review
Produce one **Enterprise Access Governance Contract** that answers who may grant,
inherit, exercise, review, recover, and revoke administrative authority inside and
across customer tenants. Treat identity assertions as inputs to product authority,
not as a substitute for explicit tenant and permission semantics.
## Atomic boundary
Own tenant hierarchy and data boundary, ownership authorities, role/permission
semantics, source mapping, delegation, privileged lifecycle, support and
break-glass access, privileged-action gates, customer admin UX, access-specific
exceptions, audit coverage, access review, split/merge/transfer behavior, and
governance metrics. Consume authentication protocols, identity-provider
connectors, authorization enforcement code, security controls, account recovery,
privacy, contract, and incident facts from their canonical owners.
## When not to use
- Do not use to implement authentication, sessions, tokens, SAML/OIDC/SCIM, an
authorization library, or policy enforcement code; hand exact requirements to
the current engineering and specification owners.
- Do not use for a legitimate user's lost credentials or channels; use
`account-recovery-review` and supply tenant/admin authority as an input.
- Do not use for security questionnaires, compliance evidence, generic product
abuse, or the whole support model; route those to their specialist owners.
## Resource routing
- Read `references/access-authority-life