Saltar al contenido

Administration

Permissions nobody needs

Access grows by itself and never shrinks. How to cut it back without breaking anyone's work.

Updated on 13/08/2026

Permissions are granted at a specific moment for a specific reason — a project, an absence, an emergency — and nobody removes them when that reason disappears. Two years on, half the staff can see things they do not need, and nobody remembers why.

Where surplus permissions come from

OriginWhen it was grantedWhy it persists
A temporary coverDuring an absenceNobody removed it on return
A project that endedWhile it lastedThe project ended, the access did not
A change of roleOn arriving in the new oneIt was added to the old rather than replacing it
"Just in case"At onboardingThere was never a specific reason

Important

The third row grows fastest and is hardest to see. Someone who has held three roles accumulates all three sets, and on paper they look like a normal user: nobody checks that the sum makes no sense.

How to review without slowing anyone

  1. 1

    Once a year, with a list of who sees what

    An hour catches 90%, and the month does not matter as long as it is always the same.

  2. 2

    Start with whoever changed role or department

    That is where the accumulation is.

  3. 3

    And with outsiders' access

    The previous accountants, the consultant from the closed project.

  4. 4

    Remove and wait

    If someone needed it, they will ask within a week. Faster than auditing case by case.

Watch out

The fourth looks blunt and is the most practical, but with one exception: do not apply it to permissions that automatic processes or integrations depend on. There, remove-and-wait means breaking something nobody is watching.

What to look at besides who sees what

The second point decides whether an annual review is sufficient or pointless: if three people can grant access without criteria, the list will grow back by itself within six months.

Worth knowing

Fewer permissions also means cleaner assistant answers and less noisy searches: each person sees their own, which is almost always what they were looking for.

What if I remove something that was needed?

It is restored in a minute. The cost of a surplus permission lasts years.

Should the review be announced?

Yes, and it cuts complaints to nearly zero.

How often is reasonable?

Annually for everyone; every six months for external access.

A real case

The situation

A company finds an engineer who has held three roles can see almost everything.

What you do

  1. Reviews role-changers first
  2. Removes what no longer applies and waits

What you get

Nobody complains and permissions match what each person actually does again.

The situation

There are permissions nobody remembers granting.

What you do

  1. Reviews case by case with the owner

What you get

What remains has a reason.

The situation

Somebody changed role and kept the previous rights.

What you do

  1. Reviews permissions on role changes

What you get

Access follows the role.

The situation

Broad permissions were granted for a one-off case.

What you do

  1. Withdraws them when the case ends

What you get

The temporary stops being permanent.

The situation

Nobody has reviewed in years.

What you do

  1. Schedules the periodic review

What you get

Access reflects today's organisation.

The situation

The review happens and nothing is recorded.

What you do

  1. Records what was reviewed and what changed

What you get

The review is demonstrable.

This article answers

  • reviewing user permissions
  • removing access no longer needed
  • least privilege in practice
  • too many people see too much