Saltar al contenido

Your workspace

The annual permission review

Half an hour that prevents the problem nobody sees coming.

Updated on 13/08/2026

Permissions do not break suddenly: they accumulate. Someone changes role and keeps the old access, someone gets "temporary" access to a project and nobody removes it, an external auditor comes in and is still there two years later. None of that announces itself.

The four questions

  1. 1

    Is everyone on this list still here?

    It is what comes up most, and the easiest to fix.

  2. 2

    Did anyone change role and keep the old access?

    A promotion leaves permissions that no longer match what they do.

  3. 3

    How many administrators are there?

    It should be two. If it is seven, nobody feels responsible for anything.

  4. 4

    Any external access still open?

    Accountants, auditors, one-off collaborators. They are the most forgotten because nobody misses them.

What usually turns up

FindingFrequencyWhat to do
Accounts of people who leftNearly alwaysClose them that day
Permissions inherited from a previous roleVery commonAdjust to what they do now
Too many administratorsCommonReduce to two
An external with months-old accessCommonRemove it; if needed again, grant it again

Important

Removing a permission is not distrust, and it is worth saying so when you do it. Surplus access is a risk to that person too: if their account is compromised, what the intruder takes is everything they could see.

Watch out

Do not run the review on a Friday afternoon. If you remove something by mistake, someone cannot work and nobody can fix it until Monday.

Worth knowing

Half an hour a year. Against the cost of discovering during an audit that six accounts of departed staff are still open, it is the best effort-to-result ratio in the whole of administration.

Should people be told?

If it affects what they do, yes, and one sentence suffices.

Is the change recorded?

Yes, who made it and when.

Can I see who has never signed in?

The log shows it, and it is usually the first place to look.

A real case

The situation

A company runs its first permission review after two years.

What you do

  1. Closes six accounts of people who left
  2. Reduces administrators from nine to two
  3. Removes access granted for an audit eighteen months ago

What you get

Half an hour closes nine open doors nobody knew were there.

The situation

Nobody has reviewed permissions in years.

What you do

  1. Schedules the annual review

What you get

Access reflects today's organisation.

The situation

People leave and their access stays active.

What you do

  1. Cross-checks the user list with joiners and leavers

What you get

The active accounts are the right ones.

The situation

There are permissions nobody remembers granting.

What you do

  1. Reviews case by case with the owner

What you get

What remains has a reason.

The situation

The review happens and nothing is recorded.

What you do

  1. Records what was reviewed and what changed

What you get

The review is demonstrable.

The situation

An auditor asks about access control.

What you do

  1. Shows the review with its date

What you get

The control moves from assertion to evidence.

This article answers

  • review who has access to what
  • internal permission audit
  • clean up old accesses
  • someone has more permissions than they need