Geeks logo

The Quiet Way Companies Outgrow Their Own Permissions

Nobody plans for permission drift. It's the slow accumulation of access that nobody owns and nobody reviews. Here's why it's the most expensive thing you're not measuring.

By ChainDocPublished 4 months ago 4 min read
The Quiet Way Companies Outgrow Their Own Permissions
Photo by ThisisEngineering on Unsplash

A founder I know ran a small SaaS company that grew from eight people to forty-five over two years. Solid trajectory, healthy revenue. The kind of growth that makes investors happy.

When their first SOC 2 audit started, the auditor pulled an access list. They had 312 active accounts in their document workspace. They had 45 employees. The other 267 accounts were old contractors, former employees who never got offboarded, vendor staff from a project two years ago, and a handful of accounts that nobody could explain at all.

Cleaning that up cost them three weeks of work and a delayed audit. Nothing was breached. Nothing was stolen. They just hadn't been managing access, and the audit revealed how much had accumulated.

This pattern is everywhere. Permission drift is the slow-motion equivalent of a security breach. It builds quietly, it costs real money to fix, and almost nobody measures it until something forces them to.

The math of unmanaged access

IDC studied this in 2024 and found that companies without scheduled permission reviews accumulate roughly 47 stale access grants per 100 employees over twelve months. That number scales linearly with team size and time. A team of fifty, two years in, looks at something like 470 dormant grants quietly hanging around.

Most of those grants are inactive in any practical sense. The contractor isn't logging in. The former employee deleted the bookmark. The risk isn't usage, it's that the access exists at all. If any of those accounts gets phished, sold on a credentials marketplace, or accessed by someone the original owner shouldn't have shared a password with, your audit log shows perfectly legitimate access from a perfectly legitimate account.

The Ponemon Institute puts the average cost of an insider-access incident at $4.5 million. That number includes investigation, remediation, customer notification, and the reputational tail. Most of those incidents trace back to access that was technically legitimate at one point but should have been revoked years before the incident.

Why invite tracking matters more than you think

An invite that's been sent but never accepted is a small thing. The new contractor is busy. They'll get to it. Two weeks pass. The invite is still pending. Three weeks. Then they finish the project, ghost the email, and the invite stays in the system as a perpetual unaccepted access path.

In a mature company, this would never fly. In a fast-moving small team, nobody has the cycles to chase it down. So invites pile up. Some get accepted by someone other than the intended recipient because the email got forwarded. Some get accepted by the intended recipient and then forgotten about for months.

The fix is real-time invite tracking with expiry windows. Every invite has a finite shelf life. Pending invites show up in a dashboard the manager can see. Anything older than seven days gets reviewed or revoked. The expiration is the default, not the manual action. This sounds like bureaucratic friction; it's actually the only thing that prevents the access list from drifting in the first place.

The contractor offboarding gap

Contractor offboarding is the single largest source of permission drift in small companies. The contract ends. The contractor moves on. There's no formal HR process to revoke their access because they were never officially in HR.

The fix that works is automatic offboarding tied to the contract itself. The contract has an end date. When that date passes, access expires automatically. If the work extends, the contract gets extended and access continues. If the work doesn't extend, access ends without anyone having to remember.

The same logic applies to roles internally. A junior employee gets promoted to senior. The system updates their permission tier automatically based on the role change in the HR system, not on someone remembering to file a permissions ticket. The principle of least privilege only works at scale if the defaults enforce it without manual intervention.

Permission audits, on a calendar

Even with good defaults, drift accumulates. The fix is recurring permission audits on a fixed schedule. Monthly for fast-growing teams, quarterly for stable ones. The trick is putting them on the calendar before you need them, because once you need them, the cleanup is a real project.

The audit itself is short if your tooling is good. Pull the active access list. Compare it to current employees plus active contractors plus active clients. Anyone outside that set gets reviewed and either confirmed or revoked. Most platforms with reasonable RBAC make this a 20-minute exercise. Without that tooling, it's a multi-day spreadsheet hellscape.

Document the audit. Keep a record of what got revoked and when. Compliance frameworks like SOC 2, ISO 27001, and HIPAA all want evidence that access reviews are happening on a real cadence, not just configured at onboarding. The audit log is the evidence.

What changes for teams that build this in

When this works, the day-to-day looks unremarkable. New people get the right access on their first day. People leaving lose access on their last day. Quarterly the manager glances at an audit report and signs off in fifteen minutes. None of it is dramatic.

The drama shows up at audit time, when other companies discover their access list looks like a horror story and yours is clean enough that the auditor blinks at it and moves on. The cost of building this in early is significantly less than the cost of cleaning it up later, even though the early cost feels heavier because the problem isn't visible yet.

If you want to see the practical patterns for scalable team collaboration that don't fall apart at twenty-five or fifty people, the playbook walks through how role-based defaults, invite expiry, and audit cadence fit together.

The thing nobody mentions about access management is that doing it right is mostly invisible. The benefit is the absence of a problem you would otherwise be paying to fix in three years. That's a hard sell to people who are watching the cost go in. It's a much easier conclusion if you've ever been on the other side of that audit.

how to

About the Creator

ChainDoc

Chaindoc is a secure platform that combines eSignatures, blockchain verification, and instant payments in one place. It helps freelancers, teams, and businesses sign and pay contracts faster, transparently, and with full legal protection.

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by ChainDoc