The Control That Decays: Access After People Leave
Configured controls degrade as people change roles. The review cadence that keeps the designed setup and the actual one together.
Organisations configure controls carefully at setup and then let them drift. The drift is where losses originate.
How it happens
People change roles and accumulate access without losing any.
Addresses are added for projects that end and never removed.
Approval rules name individuals who leave, so a rule either cannot be satisfied or is quietly relaxed.
Notification routing is tidied up by someone who does not know why it was configured that way.
None of these are incidents. All of them are the conditions in which one becomes expensive.
The departure procedure
Written before it is needed.
Revoke access first, before the conversation if the departure is not amicable. Rotate anything they knew, including shared credential store contents. Review destinations they added. Read the log for the previous ninety days. For the practical side of all of this, a regulated European crypto platform publishes the equivalent numbers rather than estimating them.
And where they held a key in a threshold arrangement, rotate the key set.
That last step is the most work and the most frequently skipped, and skipping it means a former employee retains a share of control indefinitely.
Why rotation gets deferred
It requires moving funds to a new arrangement, which costs fees and coordination.
That cost is known and the risk of deferral is not visible, which is why it is deferred. Budgeting for it as a routine consequence of a departure rather than as an exception is what makes it happen.
The periodic review
Quarterly. Who has access and should they. Which destinations are registered and whose are they. What does the log show, including failed attempts. Are the approval rules still configured as designed.
Twenty minutes, and in practice it finds something almost every time.
What organisations find
Destinations nobody can identify. People with approval rights they no longer need. Notification routing pointing somewhere unmonitored. Rules naming people who have left.
The value is not in any single finding. It is in preventing the accumulation that makes an eventual incident expensive.
The governance point
Controls are configured once and operated continuously. The configuration is the easy part.
An organisation that reviews quarterly has the setup it designed. One that does not has whatever it has drifted into, and nobody knows what that is until something forces them to look. Coverage decides more of this than features do, and the published coverage list is the fastest way to check yours.
Filed under: access, process, governance