Access Control Works. Until Privilege Accumulates Over Time

Access controls are designed to enforce defined permissions at a point in time. They do not prevent permissions from accumulating over time as users change roles, join projects, receive temporary access, and accumulate exceptions.

RCDr. Richard Chingombe · Founder, Verisq·9 min read·Practitioner perspective, not legal advice

The control enforces what has been granted. Governance determines what gets granted. When governance is stronger at provisioning than revocation, access accumulates beyond what controls should be enforcing.

Why This Matters Now

Privilege accumulation is the identity governance equivalent of technical debt. It builds slowly, invisibly, and without triggering any alert. Each individual access grant is justified at the time it is made. The cumulative effect of many justified grants, never revoked, is a user with access that no single reviewer would approve if asked to grant it all at once.

The problem compounds with tenure. Long-tenured employees in organizations with active role mobility frequently hold access from every role they have occupied, every project they have supported, and every emergency they have responded to. Their access profile is a forensic record of their career, not a reflection of their current function.

Privilege accumulation is not a policy failure. The policies are correct. It is an operational failure: the organizational discipline to revoke access as proactively as it is granted. Most organizations are significantly better at the first than the second.

The Governance Problem Beneath the Surface

The structural cause of privilege accumulation is the asymmetry between provisioning incentives and revocation incentives. Provisioning access creates immediate, visible organizational value: the user can do their job, the project can proceed, the emergency can be resolved. Revoking access creates no immediate, visible organizational value and creates immediate, visible risk: what if the user still needs this access? The organizational system rewards provisioning and imposes costs on revocation.

This incentive structure produces predictable outcomes in the absence of deliberate countervailing governance. Access accumulates because provisioning pressure is continuous and revocation pressure is periodic and weaker. The access control system enforces whatever permissions exist. It does not independently assess whether those permissions are still appropriate.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

Role Change Without Full Access Cleanup

When a user moves from role A to role B, provisioning for role B occurs through the IAM system. Revocation of role A access requires identifying all permissions associated with role A, determining which are not needed for role B, and revoking each one. This is significantly more complex than provisioning and is frequently done incompletely. The user operates in role B with role B permissions plus a residual collection of role A permissions that were never revoked.

Project Access That Becomes Permanent

Project assignments create temporary access grants. When projects end, access revocation requires identifying every access grant associated with the project and executing revocation. In organizations without automated project lifecycle integration with IAM, project end dates pass without triggering revocation. Project access becomes permanent by default.

Every project that ends without triggering access revocation leaves a population of former participants with access to project resources they no longer need. In organizations that run many projects simultaneously, this population can be substantial.

Emergency Access That Outlives the Emergency

Emergency access grants, including break-glass access and elevated permissions for incident response, are provisioned quickly with the expectation that they will be revoked when the emergency ends. The organizational urgency that created the grant evaporates with the emergency. The revocation, lacking urgency, is deferred. Emergency access accumulates as a population of elevated permissions with no ongoing justification.

Access Reviews That Confirm Rather Than Assess

Access reviews produce meaningful governance output only when reviewers have the context to assess whether each user's access remains appropriate for their current function. Reviews conducted by managers who do not have operational visibility into system usage, or by reviewers working through high volumes in limited time, tend toward confirmation rather than assessment. High completion rates are achieved. Meaningful access cleanup does not follow.

How Different Teams See This: Where They All Miss

IAMManaging provisioning workflows and access review scheduling. Not typically accountable for the cumulative state of access across the user population.
Business UnitsRequesting access for their users. Not typically accountable for the revocation of access when it is no longer needed.
HRTriggering onboarding and offboarding processes. Not typically involved in the intermediate access management events: project assignments, role changes, and temporary grants.
SecurityConcerned about high-risk privilege accumulation and insider threat risk. May not have operational tools to surface the cumulative access state of individual users.

Privilege accumulation happens in the space between ownership. Provisioning belongs to IAM. Revocation of specific temporary grants belongs to the requestor. Role change cleanup belongs to the manager. No single team is accountable for the cumulative state, and the cumulative state is the governance problem.

Framework Control Reference

The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.

NIST CSF 2.0 | PR.AA-05Access permissions are managed incorporating the principles of least privilege and separation of duties throughout the access lifecycle, not just at provisioning time.
ISO 27001 | Annex A 5.18Access rights must be removed or adjusted when employment or role changes occur, and reviewed at regular intervals.
CIS Controls v8 | Control 6.2Establish and maintain an inventory of service accounts and user accounts. Maintenance requires currency, which requires tracking accumulation.
Zero Trust / NIST SP 800-207 | Principle of Least PrivilegeZero trust requires that access be granted on a per-request basis with minimum necessary scope. Standing excess permissions from accumulated grants violate this principle.
SOC 2 | CC6.3Access to system components is removed when no longer needed. The challenge is detecting when access is no longer needed given that the access was not revoked at the expected revocation event.
PCI DSS v4.0 | Requirement 7.3.1All user accounts and access rights are reviewed at least once every six months to confirm that user access is appropriate. Review must be substantive, not confirmatory.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise privilege accumulation reality gap is the difference between the access users are entitled to based on their current function and the access they actually hold based on historical grants. This gap is proportional to employee tenure, role mobility, and the frequency of project and emergency access. In organizations with long-tenured employees and frequent role changes, the gap between entitled access and held access can be substantial even in organizations with mature IAM programs.

The access that creates risk in a credential compromise incident is not the access the user needed for their current function. It is the accumulated access from all the functions they have ever performed, all the projects they have ever supported, and all the emergencies in which they have ever participated.

Enterprise Scenario

The setupA technology company's identity governance program shows 98 percent access review completion, clean IAM audit results, and a mature provisioning workflow. A security team member is asked to assess the actual access held by a sample of ten long-tenured users.
What the assessment foundThe ten users, averaging six years of tenure, held access to an average of 47 systems each. Their current roles required access to an average of 12 systems. The difference, 35 systems per user, represented access from historical roles, completed projects, and resolved emergencies that was never revoked. All of this access had been confirmed as appropriate by their respective managers in the most recent quarterly review.

The access review confirmed the access as appropriate. The access had accumulated from six years of provisioning without proportionate revocation. The reviewers approved access they did not investigate because the review process did not provide the information needed to identify accumulation. The access review produced compliance documentation. It did not produce privilege management.

Industry Signal

Insider threat incident analysis consistently finds that the blast radius of insider incidents is significantly expanded by privilege accumulation. Compromised credentials or malicious insiders cause more damage when they have access to systems beyond their current function, and they almost invariably do. The access they use to cause harm is rarely access they were provisioned for a malicious purpose. It is access that accumulated through normal operational processes and was never revoked.

Privilege accumulation is the mechanism through which legitimate access becomes excessive risk. Every revocation that does not happen is a reduction in the blast radius protection that least privilege is designed to provide.

Enabling Capabilities

  • Access usage analytics: Tools that identify access that is granted but unused, enabling data-driven revocation of permissions users have but do not exercise.
  • Role-change access reconciliation: Automated workflows that identify the delta between old-role and new-role access requirements on role change and prompt revocation of access not needed in the new role.
  • Project lifecycle IAM integration: Automated access revocation triggered by project closure events, rather than relying on manual revocation after the project urgency has passed.
  • Tenure-based access review: Periodic review triggered by tenure milestones that specifically assesses whether cumulative access across a user's career remains appropriate for their current function.

A Practical Starting Point

Select five long-tenured users in roles with system access. For each, pull their full access list and compare it to the access explicitly required for their current role. The difference is the privilege accumulation gap for each user. Multiply by the number of users and you have the scale of the problem.

The privilege accumulation gap is measurable. Most organizations have never measured it. Measure it and you have the starting point for a meaningful governance conversation about revocation investment.

Questions Leaders Should Be Asking

  • For our long-tenured employees, what is the average difference between the access they hold and the access their current role requires?
  • When a user changes roles, what process ensures that access from the previous role is revoked, and what proportion of previous-role access is actually revoked in practice?
  • How does our access review process distinguish between access that is appropriate for a user's current function and access that has accumulated from historical functions?
  • What is our process for revoking project-specific access when projects end, and what is the proportion of project access that is actually revoked at project close versus persisting indefinitely?

What to Require From Vendors

Ask directly:

"What access intelligence capabilities does your IAM platform provide for detecting and surfacing privilege accumulation in the existing access population, specifically including unused access and access from historical roles that predates the current function?"

Expect as evidence:
  • Access usage analytics with unused permission identification
  • Role-change access reconciliation workflow documentation
  • Project lifecycle access revocation integration

A vendor who describes access management through provisioning workflows and access review scheduling without addressing privilege accumulation analytics has built provisioning governance. Ask specifically for accumulation detection capabilities.

Demonstrating Diligence

  • Documentation: Privilege accumulation assessment methodology; role-change access cleanup process records; project lifecycle revocation tracking.
  • Process: Usage-based access review alongside scheduled review; role-change access reconciliation; tenure-based accumulation review.
  • Technical evidence: Access usage analytics showing privilege accumulation metrics; revocation records linked to role-change and project-close events.

Access governance diligence requires demonstrating that revocation discipline is as strong as provisioning discipline. Measure both.

Closing Perspective

Access controls are effective at enforcing what has been granted. The governance challenge is ensuring that what has been granted reflects what is actually needed. Privilege accumulation is the systematic failure of that governance challenge.

Closing the gap requires treating revocation with the same organizational priority that provisioning receives.

Access controls enforce permissions. Governance determines what those permissions are. When governance provisions aggressively and revokes weakly, access controls enforce a permission set that no one would have approved if asked to grant it all at once.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.