account manager
An organizational role — a designated person or position formally assigned responsibility for the lifecycle governance of one or more access accounts. It is distinguished from a generic administrator or supervisor by its explicit, policy-mandated accountability: the account manager is the named party whom the organization must notify when accounts are no longer needed, when users are terminated or transferred, or when need-to-know changes, and who is responsible for ensuring accounts are created, modified, enabled, disabled, and removed in accordance with organizational policy. In practice, NIST SP 800-53 AC-2 requires organizations to assign account managers who manage accounts and roles, and automated account management mechanisms are expected to notify account managers when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. The role is not confined to system accounts: AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removi