- Proper change management procedures are required to govern both role design and role maintenance activities.
- Emergency procedure for role changes must be established and followed.
- There should be a strong naming convention which is followed for all roles.
- If role design is clean, maintenance is easy.
- Access should be segregated between users who can develop roles and users who can assign roles to users.
- Because of the technical complexity of role design, this function can be outsourced. However, it should still be controlled by the business.