Delegated Administration of Metadata

The term delegated administration refers to the ability of a site administrator to delegate responsibility for administering metadata to another administrator called a delegated administrator.

Features

Limitations

Security Considerations

For delegated administrators, the Federation Manager recognizes federated credentials only (no local credentials are issued to delegated admins). Currently there are no explicit assurance requirements associated with these credentials, however. Since a trusted site administrator must approve any metadata update request submitted by a delegated administrator, it is thought that this approval process mitigates against any weakness in the delegated administrator's login credentials.