Permission inheritance can hide excessive access
Access that arrives by inheritance is the access nobody reviews, because nobody granted it.
A group inside a group inside a folder with permissions set three levels up. Everything looks reasonable at every individual level and the effective result is that somebody in marketing can read the finance share. Nothing was misconfigured in an obvious way and no single decision was wrong. It is why the only reliable review is of effective permissions rather than of the settings that produced them.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Privilege boundaries matter more than job titlesRead the account, not the business card
- Wildcard permissions widen blast radiusOne character, a much bigger circle
- Deny rules can create hard guardrailsOne no ends it
- Admin tools are part of the privileged access pathThe hand is not on the system
