Delegation audit — every coverage delegation in the tenant, its scope and active window, with CSV export. Administrator only.
Last updated: July 30, 2026 by Steve
Delegation Audit
Next to the Audit ledger, Delegation audit is the access-governance record for coverage delegations. It sits there rather than in Reports because the useful artifact is the roster itself — every delegation in the tenant, its scope, and its active window — not a statistic about it.

Where to Find It
Open Settings from the app toolbar and choose Delegation audit in the System & compliance group.
What the Panel Shows
| Column | Shows |
|---|---|
| Delegator & delegate | Whose access was delegated, and to whom. |
| Scope | The specific areas covered — Requests, Assessments, Incidents, Complaints, Assignments, Reviews — or Everything. |
| Status | The delegation's current state. |
| Activated / ended | When coverage was actually activated and ended. |
| Requested window | The start and end dates originally requested when the delegation was created. |
| Reason | The stated reason recorded for the delegation. |
Why It Exists: Access Governance, Not Reassignment
An active coverage delegation grants the delegate the delegator's in-scope permissions — it's an access overlay, not a reassignment: nothing changes hands, but access is genuinely extended for as long as coverage is active. "Who could act as whom, over what, and when" is exactly the question an access review or a breach investigation will ask, and this panel answers it for the whole tenant, in one place.
Filtering, Searching, and CSV Export
- Filter the list by status.
- Search across both parties and the reason.
- Export CSV for your access-review file. The export honours the filters currently applied, so you can produce an artifact like "every delegation active last quarter" on its own, ready to hand to an auditor or investigator.
Administrator Only, Deliberately
This panel is Administrator-only, and deliberately so: the list names which colleagues can act for which others, and carries free text that in practice explains why — sensitive by nature. The restriction runs deeper than the screen, too: the delegation read endpoints behind this panel are themselves restricted, so an ordinary user querying delegation data sees only delegations they are a party to, either as the person who granted coverage or the person holding it. The tenant-wide roster is visible only here.
Related
- Delegations — how a user sets up and manages coverage for their own work.
- Audit ledger — the append-only, hash-chained record of significant actions that this panel sits beside.