by Serguey Shinder
A contractor three days into a six week job went looking for a document template, typed part of a filename into the search box on our shared drive, and got back a spreadsheet listing every salary in the company. He told us inside a minute and said at once that he had done nothing clever. He had not. The search showed him what he was permitted to see.
Every permission in that tree had been set correctly by somebody competent. I spent the first afternoon hunting for the mistake and there is not one.
Our drive has a departmental root created in 2016 with read access for everybody who works here, because what lived in it then was policies and the staff handbook. That grant was right and remains right. In 2019 the HR team built their own tree underneath it and permissioned it deliberately, read and write for the HR group and nobody else. Open the properties of the folder holding those documents and you see a tight, defensible list.
What that screen does not show is the grant flowing down from three levels above, which the system applied precisely as designed. Permissions inherit. The effective answer to who may read this document was the union of a 2019 decision by the people who owned the data and a 2016 decision by somebody who never saw it, and the interface shows one at a time.
Two thousand three hundred documents in the tree. Three hundred and forty of them things no employee should read about another: offer letters, two grievance summaries, a list of names from the 2022 restructure, and the spreadsheet.
It had also passed every review we run. We audit access to systems each quarter and we are good at it: payroll, finance, the support tool, the production databases, all properly scoped. The salaries were not in payroll. They were in a spreadsheet, in a folder, and nothing we did had ever asked about a folder.
The HR trees no longer sit underneath anything with a broad grant, and inheritance is severed at the top of each one. That takes five minutes and was never done because nobody knew it needed doing. What actually protects us is duller. Each of those trees holds a decoy file with a distinctive string in its name, and a weekly job searches for it using an account with the rights of our most junior employee. A hit means the tree is wrong.
A permission is not a fact about the folder you set it on. It is a standing instruction covering everything anybody will later create beneath it, most of which does not exist yet. Ours was written in 2016 for a shelf of policy documents, and seven years later it was still being carried out, faithfully and automatically, on a spreadsheet of salaries.
– Serguey Asael Shinder
Leave a Reply