The reference desk / In practice

Privilege creep

The slow accumulation of standing access after the original job that justified it has ended.

What it means

Privilege creep happens when permissions accumulate while the need for them changes. A person moves teams, covers an absent colleague, or completes a project, yet old access remains. Direct permissions, nested groups, cloud roles, and local application accounts can all contribute. The result may be difficult to see from a job title alone. Managing it combines sound joiner, mover, and leaver processes with access that expires when practical and periodic reviews tied to real tasks. Service accounts can accumulate unnecessary privileges too.

AN ILLUSTRATIVE SCENARIO

A nurse changes departments

A hospital moves a nurse from outpatient scheduling to a specialist unit. The new role grants appropriate unit access, but a review finds that the nurse still has an old scheduling-administrator role from temporary holiday cover. The manager confirms the temporary duty ended and the application owner removes that role. They verify that the nurse can still perform current clinical tasks. The team also fixes the temporary-access process so future cover assignments have a documented end date instead of relying on someone's memory.

Put it to work

  1. For role changes, compare existing access with the new duties rather than only adding permissions. Include application-local accounts, group inheritance, privileged roles, and temporary assignments.
  2. Use explicit owners, justifications, and expiry for elevated or temporary access. Where practical, provide privilege only for the approved task and duration instead of permanent administrative membership.
  3. Run focused access reviews with managers and resource owners who can judge business need. Track removals to completion and verify effective access, including nested permissions and sessions that may retain older rights.

How to check your work

Select a test role change or completed project and compare required tasks with effective permissions. Demonstrate that obsolete privileged actions are denied, current duties still work, and the review record identifies who confirmed and implemented the change.

Connect the ideas

  • IGA

    Processes and tools for reviewing who should have which access and removing what is no longer justified.

  • Least privilege

    Granting each identity only the actions, objects, and time window required for the current job.

  • PAM

    Controls that broker, record, and constrain powerful administrative identities and sessions.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.