Your workspace
The annual permission review
Half an hour that prevents the problem nobody sees coming.
Permissions do not break suddenly: they accumulate. Someone changes role and keeps the old access, someone gets "temporary" access to a project and nobody removes it, an external auditor comes in and is still there two years later. None of that announces itself.
The four questions
- 1
Is everyone on this list still here?
It is what comes up most, and the easiest to fix.
- 2
Did anyone change role and keep the old access?
A promotion leaves permissions that no longer match what they do.
- 3
How many administrators are there?
It should be two. If it is seven, nobody feels responsible for anything.
- 4
Any external access still open?
Accountants, auditors, one-off collaborators. They are the most forgotten because nobody misses them.
What usually turns up
| Finding | Frequency | What to do |
|---|---|---|
| Accounts of people who left | Nearly always | Close them that day |
| Permissions inherited from a previous role | Very common | Adjust to what they do now |
| Too many administrators | Common | Reduce to two |
| An external with months-old access | Common | Remove it; if needed again, grant it again |
Important
Removing a permission is not distrust, and it is worth saying so when you do it. Surplus access is a risk to that person too: if their account is compromised, what the intruder takes is everything they could see.
Watch out
Do not run the review on a Friday afternoon. If you remove something by mistake, someone cannot work and nobody can fix it until Monday.
Worth knowing
Half an hour a year. Against the cost of discovering during an audit that six accounts of departed staff are still open, it is the best effort-to-result ratio in the whole of administration.
›Should people be told?
If it affects what they do, yes, and one sentence suffices.
›Is the change recorded?
Yes, who made it and when.
›Can I see who has never signed in?
The log shows it, and it is usually the first place to look.
A real case
The situation
A company runs its first permission review after two years.
What you do
- Closes six accounts of people who left
- Reduces administrators from nine to two
- Removes access granted for an audit eighteen months ago
What you get
Half an hour closes nine open doors nobody knew were there.
The situation
Nobody has reviewed permissions in years.
What you do
- Schedules the annual review
What you get
Access reflects today's organisation.
The situation
People leave and their access stays active.
What you do
- Cross-checks the user list with joiners and leavers
What you get
The active accounts are the right ones.
The situation
There are permissions nobody remembers granting.
What you do
- Reviews case by case with the owner
What you get
What remains has a reason.
The situation
The review happens and nothing is recorded.
What you do
- Records what was reviewed and what changed
What you get
The review is demonstrable.
The situation
An auditor asks about access control.
What you do
- Shows the review with its date
What you get
The control moves from assertion to evidence.
This article answers
- review who has access to what
- internal permission audit
- clean up old accesses
- someone has more permissions than they need