Control 01
Accountability attaches to the grant, not to the action
A named person authorised a class of action up to a ceiling, and that person answers for the exposure they created. Nobody answers for an individual action they never saw, and a control design that pretends otherwise collapses the first time it is used.
The unit of accountability is the grant, and a grant is a document rather than a screen. It names the action type in the vocabulary the audit record uses, the ceiling per action, the aggregate ceiling per period, the conditions under which the authority holds, the person who signed it, the date they signed, and the date it lapses if nobody renews it. That is the same instrument a delegation of authority has always been, and it is enforceable for the same reason: a person with something to lose put their name to a total.
What the grantor answers for is the total, the conditions, and the review. What they cannot answer for is the merit of one action among forty thousand, which is why the ceiling is the real control and the review cadence is the second one. Ceilings are set at the amount the organisation can absorb without recourse, not at the amount the business case assumed, and the two numbers are rarely the same. Where they differ, the business case is the thing that should move.
The common failure is authority acquired by default. A service account created for an integration, holding the right to post journals or release payments because that was convenient during implementation, is an unwritten grant with no ceiling, no conditions and no grantor. Enumerating what the systems already in place can do without asking anybody is usually the first governance task of a programme like this, and it is usually the one nobody wanted to run. The requirement behind all of this is bounded authority, stated there as a property a design either has or does not have.