Half of your workforce has too many privileges. Do you know who they are?
Studies show that many employees retain access rights they no longer need. With every vacation cover, every project, and every role change, the gap between authorized and actual access rights widens. Anyone who tries to reconcile this using Excel spreadsheets wastes days and still misses something. We’ll show you how reconciliation and recertification automate the comparison between authorized and actual access, so you can always demonstrate who has access to what.
Very few organizations could say off the top of their heads who in the company is actually authorized to access what. This question usually doesn’t come up until things get awkward: during an audit, after an incident, or when someone resigns and it suddenly becomes apparent just how extensive their access rights were.
The numbers behind this are troubling. In a survey by Ponemon and Varonis, 62 percent of employees reported having access to company data they weren’t supposed to see. The Varonis Data Risk Report paints the same picture from the other side: On average, about one-fifth of all folders are accessible to every employee. Without an audit, it’s impossible to say whether that figure is exactly half in your organization. And that’s precisely the real problem.

How Regular Employees Become Rights Holders
Hardly anyone is granted too many permissions all at once. It happens gradually. A project might require temporary access to an additional drive. When someone covers for a colleague on vacation, they take over that colleague’s tasks and are granted the corresponding permissions. When someone changes departments, new permissions are added, but the old ones carry over.
Every single assignment of privileges is justified and appropriate. The problem is that almost no one ever revokes privileges that are no longer needed. Over the years, this results in an individual whose access rights are the sum of all their previous roles. Experts call this “privileges creep.” As a result, in many companies, employees hold onto permissions they no longer even know they have—and the organization is just as unaware.
The gap between “approved” and “actually awarded”
A well-designed access control policy specifies who is authorized to access what based on their role. That is the target state. The actual state is what is actually configured in Active Directory, on the file servers, in SharePoint, and in the line-of-business applications. Over time, the two states drift apart.
This discrepancy is dangerous because no one notices it as long as nothing goes wrong. An active account belonging to someone who left long ago, an access permission granted in direct violation of the role-based model, project access that remains active after the project has ended: all of these are invisible in day-to-day operations, yet all become critical as soon as an audit is conducted. For an attacker, an account with excessive permissions is a jackpot, because it opens more doors at once than intended.
Why Excel Spreadsheets Don’t Solve the Problem
The usual way to get things in order is through a manual reconciliation. The IT department exports access permissions, distributes the lists to the business units, and asks for feedback on what’s still correct. Anyone who’s done this before knows the result: It takes days, the lists are already out of date by the time they’re sent out, and no one can in good conscience verify whether line 2,480 is really still correct.
Such a comparison is always just a snapshot. The day after the big cleanup, the authorization drift starts all over again, while the Excel document shows a state that no longer exists. A dynamic process simply cannot be monitored using a snapshot—certainly not manually.
Quick Check: Are you accumulating too many rights? If you check more than two items, you should review your current situation.
Reconciliation and Recertification: The Target-Actual Comparison That Takes Care of Itself
To prevent the gap from widening in the first place, two mechanisms need to work together.
Reconciliation is the continuous process of comparing target and actual states. The system continuously checks whether the actual state in the target systems still corresponds to the defined role model and reports discrepancies as soon as they arise. Instead of once a year, a directly set authorization or an orphaned account is noticed immediately. The BAYOOSOFT Access Manager can also directly rectify detected discrepancies according to clear rules—for example, by resetting an authorization granted without authorization or deactivating an account without an owner.
Recertification is the periodic confirmation by the responsible parties. At fixed intervals, department or directory administrators check whether the permissions in their area are still needed and either grant or revoke them. It is not the IT department that makes the recommendation; rather, the decision is made by the person who is qualified to assess the situation. Our article on recertification of access rights.
Together, the two form a closed loop: Reconciliation continuously keeps the current state up to date, while recertification confirms the target state at a later time. The need for a major manual effort is eliminated because the work is broken down into many small, automated steps.

Be able to verify at any time who has access to what
DThe real benefit becomes apparent during the next audit. Because verification and correction take place during normal operations, the supporting documentation is generated automatically and remains up to date. When asked who is authorized to access a specific directory and on what basis, a reliable answer is available in minutes rather than days.
This not only reduces the scope of potential issues but also eases the stress leading up to audit dates. When you know that the actual status is continuously compared with the target status, you no longer have to gather lists of documents before a recertification or audit. The evidence is already there.
Conclusion
Having too many permissions is rarely the result of a single wrong decision. It is the result of many correct decisions that were never reversed. That is why the problem cannot be solved with a one-time cleanup, but only through ongoing reconciliation.
Reconciliation and recertification transform what would otherwise be a rare, Herculean task into a calm, ongoing process. The question “Who actually has access to what?” thus loses its intimidating edge, because you can provide the answer at any time.

