TL;DR: As B2B SaaS platforms add self-service identity administration, they are shifting more access, role, and tenant control out of engineering workflows and into tenant-aware portals, according to Descope. That changes governance from custom build-and-maintain work to strict scoping, role enforcement, and delegated admin oversight.
Editorial analysis by NHI Mgmt Group, based on content published by Descope: “Introducing the Descope Admin Portal”.
Key questions
Q: How should security teams govern delegated administration in multi-tenant SaaS?
A: Security teams should scope delegated administration by tenant first, then by role and action.
Q: Why do custom tenant admin dashboards create governance risk?
A: Custom dashboards often duplicate authorization logic across front end and backend workflows, which makes permissions drift over time.
Q: What breaks when portal widgets are not tightly role-scoped?
A: Users can see administrative actions they should not be able to perform, which turns a self-service portal into an overexposed control surface.
Practitioner guidance
- Define tenant-scoped admin boundaries List every administrative action that a tenant user, manager, or partner admin can perform, then bind each action to explicit tenant membership and role rules.
- Standardise delegated admin workflows Replace duplicated custom dashboards with one governed portal experience so user management, role management, access-key handling, and application access all follow the same authorization path.
- Test widget-level authorization Validate that enabled widgets only reveal actions a user is actually allowed to perform, including cases where a tenant admin, viewer, or partner role shares the same portal.
Bottom line: Tenant-aware admin portals shift identity administration into a governed self-service model that must preserve tenant boundaries and role limits.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Delegated administration is becoming an identity governance boundary, not a feature request. Once customers and partners can manage users, roles, and access keys themselves, the platform inherits an internal governance obligation that used to sit with engineering. The question is no longer whether the portal exists, but whether the delegated actions are tightly scoped to tenant membership and role authority. Practitioners should treat the admin experience as part of the identity control plane, not a separate support workflow.
A few things that frame the scale:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should security teams review before rolling out delegated admin access?
A: Review tenant membership rules, admin role definitions, audit logging, and the offboarding path for customer and partner admins. Delegated access should be removable when a tenant relationship changes, and it should never depend on manual cleanup in engineering workflows.
👉 Read our full editorial: Tenant-aware admin portals are reshaping delegated identity governance