Administration
Permissions nobody needs
Access grows by itself and never shrinks. How to cut it back without breaking anyone's work.
Permissions are granted at a specific moment for a specific reason — a project, an absence, an emergency — and nobody removes them when that reason disappears. Two years on, half the staff can see things they do not need, and nobody remembers why.
Where surplus permissions come from
| Origin | When it was granted | Why it persists |
|---|---|---|
| A temporary cover | During an absence | Nobody removed it on return |
| A project that ended | While it lasted | The project ended, the access did not |
| A change of role | On arriving in the new one | It was added to the old rather than replacing it |
| "Just in case" | At onboarding | There was never a specific reason |
Important
The third row grows fastest and is hardest to see. Someone who has held three roles accumulates all three sets, and on paper they look like a normal user: nobody checks that the sum makes no sense.
How to review without slowing anyone
- 1
Once a year, with a list of who sees what
An hour catches 90%, and the month does not matter as long as it is always the same.
- 2
Start with whoever changed role or department
That is where the accumulation is.
- 3
And with outsiders' access
The previous accountants, the consultant from the closed project.
- 4
Remove and wait
If someone needed it, they will ask within a week. Faster than auditing case by case.
Watch out
The fourth looks blunt and is the most practical, but with one exception: do not apply it to permissions that automatic processes or integrations depend on. There, remove-and-wait means breaking something nobody is watching.
What to look at besides who sees what
The second point decides whether an annual review is sufficient or pointless: if three people can grant access without criteria, the list will grow back by itself within six months.
Worth knowing
Fewer permissions also means cleaner assistant answers and less noisy searches: each person sees their own, which is almost always what they were looking for.
›What if I remove something that was needed?
It is restored in a minute. The cost of a surplus permission lasts years.
›Should the review be announced?
Yes, and it cuts complaints to nearly zero.
›How often is reasonable?
Annually for everyone; every six months for external access.
A real case
The situation
A company finds an engineer who has held three roles can see almost everything.
What you do
- Reviews role-changers first
- Removes what no longer applies and waits
What you get
Nobody complains and permissions match what each person actually does again.
The situation
There are permissions nobody remembers granting.
What you do
- Reviews case by case with the owner
What you get
What remains has a reason.
The situation
Somebody changed role and kept the previous rights.
What you do
- Reviews permissions on role changes
What you get
Access follows the role.
The situation
Broad permissions were granted for a one-off case.
What you do
- Withdraws them when the case ends
What you get
The temporary stops being permanent.
The situation
Nobody has reviewed in years.
What you do
- Schedules the periodic review
What you get
Access reflects today's organisation.
The situation
The review happens and nothing is recorded.
What you do
- Records what was reviewed and what changed
What you get
The review is demonstrable.
This article answers
- reviewing user permissions
- removing access no longer needed
- least privilege in practice
- too many people see too much