account manager
163502·updated Aug 30, 2026An organizational role — a designated person or position formally assigned responsibility for the lifecycle governance of one or more access accounts. It is distinguished from a generic administrator or supervisor by its explicit, policy-mandated accountability: the account manager is the named party whom the organization must notify when accounts are no longer needed, when users are terminated or transferred, or when need-to-know changes, and who is responsible for ensuring accounts are created, modified, enabled, disabled, and removed in accordance with organizational policy. In practice, NIST SP 800-53 AC-2 requires organizations to assign account managers who manage accounts and roles, and automated account management mechanisms are expected to notify account managers when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. The role is not confined to system accounts: AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removi
Source
Notify account managers and designated personnel or roles within:the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- NIST SP 800-53 Access Control (AC): 25 Controls Explained
- AC-2(1) - NIST 800-53 r5 Control Explorer - GRC Academy
- NIST AC-2 Account Management — HIPAA User Provisioning Guide
- 03.01.01: Account Management - CSF Tools
- Assign roles and responsibilities for administering user account management. | Control Result - Unified Compliance
- COMSEC account manager - Glossary | CSRC
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
An organizational role or designated individual responsible for overseeing the full lifecycle of user or system accounts — creation, modification, monitoring, disabling, and removal — on behalf of an organization's access-control program. Under NIST SP 800-53 (AC-2), organizations are required to assign account managers as a named element of the account management control, alongside specifying authorized users, defining account types, and requiring approvals for account creation. In practice, account managers are the parties who must be notified when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. NIST SP 800-171 likewise requires organizations to notify account managers within organization-defined time periods when accounts are no longer required, when users are terminated or transferred, or when system usage or need-to-know changes for an individual.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- account managers
- possessive
- account manager's
- pluralpossessive
- account managers'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An organizational role — a designated person or position formally assigned responsibility for the lifecycle governance of one or more access accounts. It is distinguished from a generic administrator or supervisor by its explicit, policy-mandated accountability: the account manager is the named party whom the organization must notify when accounts are no longer needed, when users are terminated or transferred, or when need-to-know changes, and who is responsible for ensuring accounts are created, modified, enabled, disabled, and removed in accordance with organizational policy. In practice, NIST SP 800-53 AC-2 requires organizations to assign account managers who manage accounts and roles, and automated account management mechanisms are expected to notify account managers when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. The role is not confined to system accounts: AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removiDR-088 backfill from the noun definition column