Makios One Portal has been an amazing addition to our portfolio and something we're very proud of, but increasingly complex business systems bring increased challenges. This article describes some of those challenges in detail, to help you understand, take note and get engaged with things that matter and can really affect you and your team.
One of the harder parts of managing your technology today has nothing to do with computers, cybersecurity, software, or the internet. It is figuring out who is actually authorized to make a decision.
- Who can approve a major technology change?
- Who can authorize access to sensitive company information?
- Who can add or remove employees?
- Who can approve a contract, purchase, security exception, or service cancellation?
- Who should Makios call when there is a serious issue and a decision needs to be made?
For many businesses, the answer seems obvious, until it is not.
Employees change positions. Owners step away from daily operations. Companies grow. Departments are added. Responsibilities are reassigned. Someone who handled technology several years ago may still be listed as the primary contact, even though they are no longer involved. Sometimes the person submitting a request is a trusted employee who has worked with Makios for years, however that does not necessarily mean they are authorized to make every type of decision.
Familiarity is not the same as authority.
That is why we recently added a new feature to Makios One Portal called the Primary Authorized Representative, and it may sound formal, because it is. But the idea behind it is simple, Makios should not be guessing who has authority inside a client’s business. Clients should tell us.
What Is the Primary Authorized Representative?
The Primary Authorized Representative, or as we refer to internally as PAR, is the person the client identifies as having the highest level of authority for the company’s relationship with Makios. The PAR becomes the starting point for confirming the company’s account structure. They can help define who should have access, who is responsible for different areas of the business, and who is authorized to make certain decisions.
This does not mean the PAR must personally manage every technology request. They do not have to approve every new computer, respond to every ticket, review every invoice, or become the company’s unofficial IT coordinator. That would probably make the feature less useful, not more.
Instead, the PAR confirms the structure. They identify who Makios can rely on, what those people are responsible for, and what level of authority they should have. For a small business, the PAR may be the owner who handles most decisions directly. For a larger organization, the PAR may be the owner, CEO, president, executive director, or another senior leader who delegates responsibilities to other executives and managers.
The structure can be simple or detailed. What matters is that the client defines it.
Why Existing Contact Lists Are No Longer Enough
Most technology providers maintain some type of client contact list. Makios does too but the problem is that a traditional contact list usually tells you who someone is, but not necessarily what they are authorized to do or what you want them to be able to do. You as an owner or operator-in-charge may not know what you don't know.
A person may be listed as a billing contact because they receive invoices where another person may be listed as a technical contact because they coordinate service requests. Someone else may be labeled as the primary contact because they were the first person entered into the system ten years ago.
Those labels can be helpful, but they do not create a reliable authority structure. They also tend to become outdated when a contact leaves the company, changes roles, retires, or stops being involved. Unless someone remembers to notify Makios, the information may remain in place. Then, several years later, someone looks at the account and assumes the contact list still reflects reality.
That is where problems begin.
An old technical contact may still appear to have broad authority. A former executive may still be included in important communications. An employee may request access to information they no longer need. A manager may approve something outside the scope of their actual responsibilities. These are not always malicious situations. Most of the time, they are the result of outdated information, unclear processes, or people trying to get work done.
But that does not make the risk less real.
I believe that technology providers should not make sensitive decisions based on assumptions, old notes, email history, or whoever sounds the most confident on the phone. We need something more dependable than that.
This is the Foundation, Not the Entire Structure
The Primary Authorized Representative is an important feature, but it is only one part of the larger contact and authority system we built inside of Makios One Portal. The PAR establishes the top level of authority. From there, the client can help define Contact Functions, roles, access, and permissions for other people in the organization.
These concepts are related, but they are not interchangeable.
A Contact Function describes what someone is responsible for. A role describes their position within the portal’s account structure. Permissions determine what they can see, approve, or change. Authority determines which decisions Makios can rely on them to make.
That may sound like a lot of definitions, but unfortunately, vague definitions are how companies end up with the accounting department approving firewall changes, no can do.
What Are Contact Functions?
Contact functions help identify why a person is connected to the account and what areas of responsibility they handle. At the time of me publishing this article those functions include:
- Legal
- Financial
- Accounting
- Security
- Emergency
- Technical
- Operational
And of course, a person can have more than one Contact Function. For example, a company’s CFO may be responsible for both financial and accounting matters. And a chief operating officer may be responsible for operational decisions, emergency coordination, and certain contractual approvals. An internal technology manager may handle technical and security matters but have no authority over billing or contracts. The purpose of Contact Functions is to make those responsibilities visible and understandable.
When Makios needs to communicate about an invoice, we should know who handles accounting. When a cybersecurity issue occurs, we should know who must be included. When a contract requires review, we should know who represents the company’s legal or executive authority. When an urgent operational decision is required, we should not be searching through years of ticket history trying to figure out who might answer. Contact Functions give us a structured way to route communication and decisions to the correct people.
Contact Functions Are Not Permissions
This distinction is important.
Being responsible for a function does not automatically mean someone should have unlimited access inside Makios One Portal. Someone may be the accounting contact and need access to invoices, payments, and financial records. That does not mean they should automatically be able to review cybersecurity incidents, approve user access, or cancel services. A technical contact may need access to devices, tickets, projects, and licensing, but that does not necessarily mean they should see contracts, account balances, or confidential executive information.
An emergency contact may need to be reachable during a critical event. That does not mean they should have permanent administrative control over the account. This is where rights and permissions become important and the portal must understand not only what someone does, but also what they are allowed to see and what they are authorized to approve.
Those decisions should be made deliberately. They should not be inherited accidentally because someone was added to an email chain seven years ago.
The Client Should Decide
I personally feel strongly that people should have more autonomy and the central idea behind the Primary Authorized Representative is client control. Makios should not have to decide the internal authority structure of another company or guess. We may understand the client well, we may have worked with the same people for many years, we may have a very good idea of who handles certain responsibilities, but we are still outside the organization and dynamic.
We do not always know when things like ownership changes, responsibilities shift, internal disagreements occur, or someone’s authority is reduced. We also do not know every detail of the client’s governance structure. A company may allow a chief financial officer to approve contracts but require the owner to approve service cancellations - this happens all the time. An executive director may have broad operational authority but needs board approval for certain financial commitments. A department manager may be authorized to approve equipment purchases up to a specific amount but not sign a long-term agreement.
These decisions belong to the client.
The role of Makios is to provide the system where those decisions can be recorded, verified, maintained, and followed. That is a much better approach than pretending we know more about your internal structure than you do.
Delegation Without Losing Control
A good authority structure should allow delegation, and the owner or senior executive should not become a bottleneck for every routine request. At the same time, delegation should not mean giving everyone access to everything. That is why the Primary Authorized Representative can designate other people to handle specific functions and decisions.
That may include executives with broad authority, managers with operational responsibilities, accounting contacts, security contacts, technical contacts, and other trusted representatives, and the goal is not to centralize every action around one person. The goal is to establish a clear chain of authority.
The PAR identifies who can act on behalf of the company and where the boundaries are. This allows Makios to move faster on legitimate requests while being more careful with sensitive ones. That may sound contradictory, but it is not.
Clear authority reduces unnecessary delays because we do not have to stop and investigate every routine request. It also gives us a reason to pause when a request falls outside someone’s assigned authority.
Speed is useful but speed with no controls is how you end up spending Friday afternoon undoing something that should never have happened in the first place.
Protecting the Client from Unauthorized Changes
The PAR and permissions structure also improve security because many cybersecurity incidents begin with someone convincing a vendor, employee, or service provider to make a change.
The request may appear routine on paper like:
- Reset this password
- Add this user
- Forward this email
- Grant access to this system
- Change the billing information
- Transfer control of this domain
- Remove this security requirement
- Cancel this service
The person making the request may sound informed and urgent and they may know names, account details, or internal terminology but that does not prove they have authority.
We have seen first-hand how people with too much authority put the entire company at risk because things like MFA are too complicated and they don't have time for that. Owners are not aware and certainly legal and compliance was not informed or approved of such a potentially dangerous change.
So a documented authority structure gives Makios a better way to evaluate the request. Is this person recognized by the client?
- What function do they serve?
- Do they have permission to make this change?
- Does the request require approval from the PAR, an executive, or another designated contact?
- Should the action require additional verification?
The system will not eliminate every possible risk, nothing does. But it creates a much stronger foundation than relying on email familiarity and institutional memory.
Protecting Employees from Being Put in the Middle
This structure also protects the client’s employees and our team. Without clear authority, employees may be placed in difficult situations. A staff member may be asked to approve something they do not fully understand. A manager may feel pressured to authorize a change because nobody else is available. An accounting employee may receive a request that appears to come from an executive and assume it is legitimate. A technical employee may be asked to make a decision that has legal or financial consequences.
Clear functions and permissions reduce that ambiguity.
Employees can operate within the authority the company has assigned to them and Makios can direct requests to the correct people. And when someone asks us to do something outside their authority, we can escalate it without making the situation personal. It is not about whether we trust the person, it is about whether the company has authorized the action.
That is a much cleaner conversation.
Authority Should Be Reviewed and Audited
Authority should not become permanent by accident because people leave, companies reorganize, executives retire, responsibilities change, businesses are sold, new partners join, old partners move on.
That is why the authority structure inside Makios One Portal is intended to be reviewed and reconfirmed periodically.
That gives the client an opportunity to verify that the information remains accurate like:
- Are the right people still listed?
- Do they still have the same responsibilities?
- Should their access be expanded, reduced, or removed?
- Is the Primary Authorized Representative still correct?
- Has the company’s ownership or leadership changed?
Periodic reconfirmation is not exciting, neither is updating insurance information, reviewing bank permissions, or checking who has keys to the building, but when it comes to technology it is still worth auditing more than once a decade. Because important permissions should not remain active forever simply because nobody remembered to revisit them.
Building an Authoritative Source
The larger goal for Makios One Portal is to create one dependable source for the client’s relationship with Makios. That includes contacts, services, contracts, invoices, licensing, tickets, projects, approvals, users, devices, and account authority.
Today, that information is often spread across multiple systems, old emails, support tickets, documents, and the memories of people who have worked together for years. That can work when everything is routine, but it becomes much less reliable when there is a dispute, ownership change, urgent security event, employee departure, or important financial decision.
Makios One Portal is intended to bring that information together, and the Primary Authorized Representative is a critical part of that effort because authority sits underneath almost every other function.
- Before we can decide who should approve a quote, we need to know who has purchasing authority and for how much
- Before we can provide access to contracts, we need to know who should see them.
- Before we can accept a cancellation, we need to know who can legally and financially bind the company.
- Before we can allow someone to delegate permissions, we need to know they have the authority to delegate them.
Without that foundation, the rest of the system is just a collection of features but with it, the portal becomes a reliable operating framework for the relationship between Makios and you, our client.
This Is About Clarity, Not Bureaucracy
Any time you add verification, permissions, or formal authority, there is a risk that it feels like unnecessary bureaucracy.
That is not the objective, our objective is clarity.
- We want routine work to move quickly.
- We want people to have the access they need.
- We want clients to have control over their own structure.
- We want owners to be pulled if and when their business may potentially be harmed.
- We also want important actions to be handled by people who are actually authorized to make them.
A good system should make the normal path easier and the dangerous path harder. That is what the Primary Authorized Representative helps us accomplish. The client defines the structure, and Makios follows it.
And everyone has a clearer understanding of who is responsible for what.
The Bottom Line
The Primary Authorized Representative may look like one more feature inside Makios One Portal, but it is an important piece of a much larger puzzle. It connects Contact Functions, roles, permissions, approvals, and account authority. More importantly, it shifts an important decision back where it belongs.
With you, the client.
Makios should not assume that the person who submitted the last ticket is authorized to approve a contract. We should not assume that the person receiving invoices can approve a security change. We should not assume that a contact entered years ago still represents the company today. And we should not be deciding the internal authority structure of someone else’s business.
The client should identify who has authority, who is responsible for each function, and what each person is allowed to access or approve. Our responsibility is to provide the framework, verify the information, maintain the record, and follow the structure the client has established.
Because when it comes to access, authority, contracts, security, and important business decisions, we should not be guessing.







