Entitlement Risk
SL-05Permissions assessed against actual usage. An entitlement nobody exercises is pure exposure — it carries all the breach risk of access with none of the operational benefit.
3 leavers still hold entitlements
svc_ai_index_7, Uday Tiwari, Pallavi Gupta. Access for a departed person is the easiest finding a regulator or auditor will ever record, and it is entirely preventable.
Excessive permissions
468
Unused permissions
752
Privileged identities
9
Leavers with access
3
With children's data access
19
Permission exposure by department
Excessive permissions are those the identity holds but does not need; unused are those it has not exercised in the observation window. Both are candidates for revocation, but excessive is the one that expands blast radius.
68 identities
1–25 of 68
1 / 3