# Govern Enterprise Access

> Govern who may grant, inherit, exercise, review, recover, and revoke administrative authority across customer tenants. Use when identity-provider assertions are inputs to product permission, not a substitute for it.

- Skill: `sylphxai/govern-enterprise-access` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add sylphxai/govern-enterprise-access`
- Raw SKILL.md: https://api.skillmd.com/api/skills/sylphxai/govern-enterprise-access/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: SylphxAI (https://skillmd.com/u/sylphxai)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/sylphxai/govern-enterprise-access

---


# Govern Enterprise Access

Identity-provider assertions are inputs. Tenant and permission semantics stay in the product. Join is not permission. Break-glass is a logged, time-bounded grant with a removal predicate, not a standing admin role. An IdP group name is not product authority.

Open [access authority lifecycle](references/access-authority-lifecycle.md) and [privileged evidence](references/privileged-evidence-operations.md) when the grant ledger or review evidence needs depth.

