jargon

Platform & DevOps·Secrets, identity and the supply chain

the role was widened during an incident three years ago and nothing has ever narrowed it again.

Privilege creep

Also calledpermission creep, over-permissive role, accumulated access

The one-way accumulation of permissions over time, because granting is urgent and revoking never is. It is why the average production role bears no resemblance to what the workload uses, and why access reviews find identities with permissions for systems that no longer exist. The practical counter is data rather than diligence: most clouds report which permissions an identity has actually used, and the unused ones are the list.

Commonly confused with