Sunday, September 13, 2026 · Independent crypto coverage

Crypto markets, explained without the noise

The Control That Decays: Access After People Leave

Configured controls degrade as people change roles. The review cadence that keeps the designed setup and the actual one together.

By Marcus Feld··2 min read

Organisations configure controls carefully at setup and then let them drift. The drift is where losses originate.

How it happens

People change roles and accumulate access without losing any.

Addresses are added for projects that end and never removed.

Approval rules name individuals who leave, so a rule either cannot be satisfied or is quietly relaxed.

Notification routing is tidied up by someone who does not know why it was configured that way.

None of these are incidents. All of them are the conditions in which one becomes expensive.

The departure procedure

Written before it is needed.

Revoke access first, before the conversation if the departure is not amicable. Rotate anything they knew, including shared credential store contents. Review destinations they added. Read the log for the previous ninety days. For the practical side of all of this, a regulated European crypto platform publishes the equivalent numbers rather than estimating them.

And where they held a key in a threshold arrangement, rotate the key set.

That last step is the most work and the most frequently skipped, and skipping it means a former employee retains a share of control indefinitely.

Why rotation gets deferred

It requires moving funds to a new arrangement, which costs fees and coordination.

That cost is known and the risk of deferral is not visible, which is why it is deferred. Budgeting for it as a routine consequence of a departure rather than as an exception is what makes it happen.

The periodic review

Quarterly. Who has access and should they. Which destinations are registered and whose are they. What does the log show, including failed attempts. Are the approval rules still configured as designed.

Twenty minutes, and in practice it finds something almost every time.

What organisations find

Destinations nobody can identify. People with approval rights they no longer need. Notification routing pointing somewhere unmonitored. Rules naming people who have left.

The value is not in any single finding. It is in preventing the accumulation that makes an eventual incident expensive.

The governance point

Controls are configured once and operated continuously. The configuration is the easy part.

An organisation that reviews quarterly has the setup it designed. One that does not has whatever it has drifted into, and nobody knows what that is until something forces them to look. Coverage decides more of this than features do, and the published coverage list is the fastest way to check yours.

Filed under: access, process, governance

Marcus Feld. Financial journalist covering crypto markets since 2019.Analysis published by CoinCryptorama. Nothing here is investment advice.

Related coverage