A reader got in touch recently with a question I suspect a lot of you are wrestling with:
“How do you effectively delegate processes that require high-level trust or security access without becoming the bottleneck yourself or micromanaging? That’s a huge one for us right now!”
Let’s start with a quick test. Imagine you’re completely unreachable for a week, starting tomorrow. No phone, no laptop, no “just checking in quickly.”
What stops?
I don’t mean what slows down. I mean what genuinely can’t happen without you. Things like:
- The payment runs.
- The admin access to client accounts.
- Approving anything that goes live.
- Resetting someone’s login.
- Signing off on anything with a pound (or dollar) sign attached.
If that list is longer than two or three items, you’ve got a problem.
Most managers frame this as a trust issue and tell themselves something along the lines of:
“I’d delegate it if I had someone I could trust with it.”
But in my experience, the person usually isn’t the problem. The problem is that the only safeguard in the process is you.
Today, I want to talk about why we hoard the high-stakes work, how to spot when it’s become a problem and how to hand it over without either holding your breath or looking over someone’s shoulder.
Why the sensitive stuff is so hard to let go of
We’ve talked before about delegating properly rather than dumping and about how managers become the bottleneck. But processes involving trust or security access have a few extra layers that make them harder to let go of.
The first is that the accountability doesn’t move
When you delegate writing a report and it’s not quite right, you fix it. When you delegate access to the finance system and something goes wrong, it’s still your name on it. You can hand over the task, but it feels like you can’t hand over the consequences. So it feels safer to just do it yourself – just in case.
The second is that we treat trust as all or nothing
In our heads, we either trust someone completely with the keys, or we don’t give them the keys at all. There’s no middle ground with these kinds of high level tasks. So the answer defaults to “not yet”. And “not yet” has a funny way of becoming “never”.
The third is that trust ends up living in your head instead of in the process
When you do something sensitive, the safeguards are all internal. You know which payments look off. You know which client settings you should never touch. You know when to pause and double-check something. None of that is written down, so from where you’re standing, the only way to make the process safe is for you to be in it.
And the truth is that being the only person who can do the important stuff feels good. It feels responsible. It feels like being a good leader. Sometimes it’s even a quiet source of job security – I’ve seen this happen up close and to be honest, I’ve felt it as well. We all want to feel like we have value and sometimes, that means not letting someone else deliver that same value.
The signs you’ve become the gatekeeper
You may have a vague feeling that there is a problem here but aren’t sure how big a problem it is. If the following signs resonate, then you almost certainly have become the gatekeeper for this kind of work.
The Holiday Freeze
Things stop when you’re away. Not slow down, stop. Your team saves up a list of things “waiting for you to get back”, or you find yourself approving things from a sunbed by a swimming pool or on the beach because nobody else can.
If your absence creates a queue, you’re the bottleneck, regardless of how much you’ve delegated everything else.
You can also spot the signal of this by how busy your return to work is. If you spend your first week back after a holiday doing all of the things that completely stopped the week before, then you have a problem.
The Password Relay
Someone needs to do something that requires access they don’t have, so you log in for them. Or worse, you share your login “just this once”. Or they message you a screenshot and you do it on their behalf.
This is the version that should worry you most, because it’s the worst of both worlds. You’re still the bottleneck and you’ve weakened your security. Shared credentials mean you can no longer tell who did what.
The Shadow Check
You have technically delegated it. But you quietly go back and check everything afterwards. Every invoice they processed. Every setting they changed. Every user they added.
They probably know you’re doing it, too. Which means they’ve learned that doing it right doesn’t earn more trust, so there’s little reason for them to take real ownership. And you haven’t saved any time either.
Five ways to delegate the high-trust stuff (without hovering)
Right, so let’s get into how you can fix these issues if any of the above sounds familiar to you.
1. Separate the access from the authority
Let’s start with something very practical and whilst it may sound obvious, I’ve seen too many examples of this not being the case – particularly in busy work environments.
Giving someone the ability to do something isn’t the same as giving them permission to do everything that access allows.
Start by giving people their own access, properly set up, rather than sharing yours. Most systems let you control what someone can see and do. Use it. Give the least access needed for the task, not “admin because it’s easier.”
Then be explicit about authority.
“You’ve got access to the ad account. You can adjust bids and pause campaigns. You don’t change billing or add users without speaking to me first.”
The access sets what they can do. The conversation sets what they *should* do. You need both.
2. Build trust in stages and name them directly
Instead of all or nothing, agree on a staged process of delegation. Something along the lines of:
- Stage one – watch me do it and ask questions.
- Stage two – you do it, I watch.
- Stage three – you do it, then tell me afterwards.
- Stage four – you do it, I’ll see it in the weekly review.
The true breakthrough here is making the stages visible and super clear. Tell them which stage they’re at and what it’ll take to move up. “Two more months of the payment run with no issues and we’ll move you to stage three.”
Of course, depending on the task, these stages could take days to move through – use your judgement here but don’t drag it out unnecessarily.
It turns trust from a vague feeling you hold into a path they can see. And it stops you hovering at stage four, because you’ve both agreed that’s not what stage four looks like.
3. Write down the guardrails, not the steps
Most process documents are step-by-step instructions. They’re useful, but they don’t capture the bit that actually lives in your head: the judgement.
So write down the boundaries instead. For example:
- “Any payment under £X, just process it. Over that, get a second pair of eyes.”
- “If a supplier’s bank details have changed, always call them to verify before paying. No exceptions.”
- “Never delete anything in a client account. Pause it instead.”
- “If a client asks to rearrange a call, that’s fine but always tell me if it’s a QBR that they rearrange.”
Guardrails let people act confidently within clear limits. And they give you something to point to when you feel the urge to check. If the guardrails are good and they’re being followed, you don’t need to be there.
One thing to call out here – this may feel a bit like micromanagement at first. Even though we’re not laying out a process step by step, it still feels like you’re controlling things to a high degree. This is okay – it’s not micromanagement, you’re just briefing someone on something and helping them avoid problems.
You’re not literally looking over their shoulder as they do it.
4. Replace watching with visibility
The reason micromanaging creeps in is that you want to know things are OK. That’s reasonable. The problem is how you find out.
Most systems keep a log of who did what and when. Set up notifications for the things that genuinely matter (a new user added, a payment above a threshold, a setting changed). Then review the trail on a regular schedule, say fifteen minutes on a Friday, rather than checking in on the person throughout the week.
For the highest-risk actions, put a two-person rule in place. But here’s the key point: the second person doesn’t have to be you. Train up two people so they can check each other. That way you’ve removed yourself from the process and made it more secure than when it was just you.
5. Agree the recovery plan before the mistake
Mistakes will happen. They happened when you were doing it too, you just caught them yourself.
So have the conversation up front: “If something looks wrong, stop and message me straight away. You will never be in trouble for flagging something early. You might be if you try to quietly fix it.”
Then make sure mistakes are recoverable. Backups exist. Changes can be rolled back. There’s a clear escalation route if you’re not available.
This matters because, as I wrote in Just Tell Me What You Need, the people you’re trusting with this stuff are often exactly the ones least likely to put their hand up when they’re stuck. If admitting a mistake feels risky, you won’t hear about it until it’s much bigger.
So, let’s put this into action.
Block out 20 minutes this week and write your “only me” list. Every process, system or approval that currently can’t happen without you.
Then pick one item on that list. Just one. Ask yourself three questions:
- Who could do this if they had the right access and the right guardrails?
- What stage of the trust ladder could they start at?
- What would I need to write down or set up so that I don’t need to watch them?
Then have the conversation. Not “can you take this off my plate?”, but “I want you to own this, here’s how we’ll get you there, and here’s how we’ll both know it’s going well.”
You’ll probably notice that the person you pick has been ready for longer than you realised.
And the next time you go on holiday, nothing will freeze.





