by Serguey Shinder
When I moved between teams, nobody took anything away from me. My new permissions arrived within a day, because I needed them to work, and someone chased that request until it was done. My old permissions stayed exactly where they were, because nobody needed them to be gone, and nothing in the world was pushing anyone to notice. I kept full write access to a system I had not touched in over a year, and I only found out because I went looking.
I want to be precise about what unsettled me. It was not that a process had failed. It was that there had never been a process at the other end. Granting access has a requester, a reason, an urgency, and a person who is blocked until it happens. Removing access has none of those. It benefits nobody today, inconveniences at least one person, and produces no visible result when it works. So it does not happen, not through malice or incompetence, but because nothing in the ordinary shape of a working week ever asks for it.
The result is that permissions accumulate on a person the way possessions accumulate in a house. Every role I had held, every project I had helped with for two weeks, every emergency where someone granted me something to unblock a fix, all of it was still attached to my name. If my account had ever been compromised, the attacker would not have inherited my current job. They would have inherited my entire career.
That is the part I had never thought about properly. I had spent years reasoning about access in terms of what a person needs to do their work, which is the right question at the moment of granting and completely the wrong question afterwards. The real question is what an account is capable of doing, and the answer to that drifts upward, always upward, never down, unless somebody deliberately reaches in and reverses it.
What I changed was small and it was mostly about honesty. I started treating my own access as something I was responsible for auditing, not something the organisation would manage on my behalf. When I leave a project, I ask for the permission to be removed, and I follow it up, and I feel slightly ridiculous doing so every time, because I am asking someone to take something from me for no immediate reason.
The ridiculousness is the point. Security decays quietly in exactly the places where doing the right thing produces no visible benefit and no one is waiting on it. The dangerous access is not the powerful key someone fought to get. It is the ordinary one nobody ever thought to take back, sitting on an account for years, useful to no one except the person who eventually finds a way in.
– Serguey Asael Shinder
Leave a Reply