CR | ๐ฃ๐ผ๐๐ #๐ฏ๐ฒ๐ฌ
A few years ago, an auditor asked a simple question during a review:
“๐ช๐ต๐ผ ๐ฎ๐ฝ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฑ ๐๐ต๐ถ๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐?”
Everyone in the room knew who had access.
Nobody knew why.
That distinction matters more than most organizations realize.
Over time, permissions accumulate.
Projects start.
Teams expand.
Vendors are onboarded.
Emergency access is granted.
New applications are deployed.
And little by little, access becomes part of the environment.
Rarely challenged.
Rarely questioned.
Simply inherited.
The problem is that access without purpose eventually becomes risk without visibility.
๐ช๐ฒ’๐๐ฒ ๐ฟ๐ฒ๐๐ถ๐ฒ๐๐ฒ๐ฑ ๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐๐ ๐๐ต๐ฒ๐ฟ๐ฒ:
- Users had administrator privileges for systems they hadn’t touched in years
- Third-party vendors retained access long after contracts ended
- Service accounts were running critical processes without an identified owner
- Shared mailboxes contained sensitive information but had dozens of authorized users
- Nobody could explain the original business justification behind key permissions
What struck me wasn’t the existence of the access.
It was the absence of accountability.
Because every permission should answer three simple questions:
๐ญ. ๐ช๐ต๐ผ ๐ต๐ฎ๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐?
๐ฎ. ๐ช๐ต๐ฎ๐ ๐ฐ๐ฎ๐ป ๐๐ต๐ฒ๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐?
๐ฏ. ๐ช๐ต๐ ๐ฑ๐ผ ๐๐ต๐ฒ๐ ๐๐๐ถ๐น๐น ๐ป๐ฒ๐ฒ๐ฑ ๐ถ๐?
Most organizations focus heavily on the first two.
The third is where governance often breaks down.
A useful exercise for any audit, security, or governance team:
๐ฃ๐ถ๐ฐ๐ธ ๐ฎ๐ฌ ๐ฟ๐ฎ๐ป๐ฑ๐ผ๐บ ๐ฝ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ๐ฑ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐.
Then ask stakeholders to explain the business justification for each one.
Not the technical reason.
The business reason.
The results are often eye-opening.
Good security isn’t just about restricting access.
It’s about ensuring every access decision remains intentional.
The moment access becomes “normal” instead of “justified,” risk begins to accumulate quietly in the background.
And eventually, someone will inherit privileges that nobody remembers granting.
That’s usually where the story starts.