I have a situation where the sole PO Approval person is out of the office. I’m being asked to approve the PO, but according to NIST (and one day CMMC), as an IT administrator, I shouldn’t be approving these.
I know my refusal to do this will result in emails and meetings about how to handle this, so I’m wondering how this is handled in your respective companies. I have some thoughts, but would appreciate some ideas on the cleanest way to handle this without sharing passwords.
Thanks in advance.