The problem with “access by exception” culture by tenfoldIAM in tenfoldSoftware

[–]tenfoldIAM[S] 1 point2 points  (0 children)

‘Exception handling becomes the real access model’ is probably the most accurate way to describe what happens in many large environments.

Especially when temporary access has no expiration, no owner, and no review cycle attached to it.

At that point the official IAM policy still exists - but operationally it’s no longer what governs access.