Managing Access Controls and Permissions

About this module

Access decisions are management decisions as much as technical ones. This module explains least privilege, access creep, role changes, onboarding, and offboarding through the manager's lens. Learners see why old permissions quietly create risk when employees move projects or leave the company. The lesson gives managers a simple rhythm: approve only what the role needs, review access on schedule, remove permissions when jobs change, and treat admin rights as a temporary exception rather than a permanent badge.

Key takeaways

  • Least privilege means access should match the job today
  • Access creep happens when old permissions are not removed
  • Managers should review access after role changes and projects end
  • Admin rights should be limited, tracked, and removed when no longer needed

Full Transcript

Every login, every folder, every admin panel is a door into your business. As a manager, you decide who holds the keys, and over time, that single decision shapes almost your entire security posture, for better or worse. Studies on access creep suggest well over half of employees end up holding permissions from roles they no longer have.

Nobody removes them on purpose, they just pile up quietly, month after month, expanding the attack surface. Take Jordan, who rotated off the finance project months ago, but still has full admin rights to its systems. Compare that to a least-privilege model, where access always matches your current role and gets reviewed on a regular schedule. One quietly grows into risk over time.

The other stays right-sized on purpose, review after review. Least privilege means every person gets exactly the access their job requires today, not the access that's convenient, and not the access left over from an old project or a promotion two years ago. Just what the current role actually needs. A healthy cycle looks like this. Day one, access is granted based on the role.

Every quarter, managers review who has what access. The moment a role changes, access is adjusted that same day. And when someone leaves, access is revoked before their very last day. An orphaned account, one nobody remembered to disable, is one of the easiest ways in.

No owner is watching it, no alerts are tied to it, and attackers actively search for exactly this kind of gap. Keep four things in mind as a manager. Approve only what the role truly needs, review your team's access every quarter without fail, revoke access the same day someone leaves the team, and always ask I.T. before granting any admin rights, even temporarily.

As one identity and access lead put it, access is never finished, it's a moving target, and you have to keep aiming at it. At the end of the day, you own these decisions. Every access grant, every review, every revocation starts with a choice only you can make. Three things to remember.

Grant least privilege by default, review access on a regular schedule, and offboard fast so nothing lingers behind. That's how permissions stay under control instead of slowly drifting out of alignment. In our next video, we look at vendor and third-party risk management, because your access boundary doesn't stop at your own employees, it extends to everyone you trust with a login.