Permission inheritance can hide excessive access

Access that arrives by inheritance is the access nobody reviews, because nobody granted it.

A group inside a group inside a folder with permissions set three levels up. Everything looks reasonable at every individual level and the effective result is that somebody in marketing can read the finance share. Nothing was misconfigured in an obvious way and no single decision was wrong. It is why the only reliable review is of effective permissions rather than of the settings that produced them.

More on Authorisation and privilege