I like this one. Generally, I'll have a Windows Group such as SharePoint [Farm Designator] Administrators and add users to the group. Then, manually:
- Add group to Local Administrators on all farm servers
- Add group to CA -> Security -> Farm Administrators
- Add group to CA -> Site Collection Admins
- Grant group permissions on Service Applications where needed
- Grant permissions in SQL Server