I have had multiple interaction with support where the master account owner was required even when I have full right on everything else.
Most often it was to disable the MFA on a specific user that it was required to reach out to the master account owner. I have the right to create and edit users except for that specific MFA part. I have ask our TAM if more could be delegated and only one user can be the master account right now.
It should simply be a group in the IAM with that role, so more that one person could be delegated that role especially in large enterprise with a worldwide footprint.
Do not place IBM confidential, company confidential, or personal information into any field.