Tips for managing privileged resource access?

As our footprint begins to grow and we grant more named accounts specific access to perform resource management functions or create new resources in a group, I can foresee the access sprawl becoming a problem area.

Any tips you’ve found super useful to continuously audit/manage access to these sorts of higher level privileges? Easy way to report on who has add/edit/delete to specific groups, resources, etc?

