skip to content

You must withdraw broker grants nobody uses, but the audit trail records only refusals. How do you establish use?

level: principalimportance: should knowfreq 33%

answer

  1. silence is not evidence
  2. prune by connections before judging grants
  3. measure positively for a stated window
  4. the removed grant makes refusals speak
  5. expiry moves the burden of proof

basics

~20 s

A refusal-only trail is negative evidence and cannot show use. Prune by connection records first, measure positively for a time-boxed window on the streams under review, then withdraw in stages — and make grants expire so the burden shifts to justifying renewal.

solid answer

~50 s

The problem is that a refusal-only trail proves who was turned away and never who succeeded, so silence cannot distinguish a grant used constantly from one belonging to a service retired a year ago. Work in three moves. **Prune from connection records**: principals that have not connected at all need no grants, and that usually removes a large part of the roster before you touch the grant table. **Measure positively, briefly**: switch on allowed-decision recording for the streams under review for a stated window, which converts absence into a real observation. **Withdraw in stages and let refusals speak**: once a grant is removed, the refusal-only trail becomes the right instrument, because a refusal now means the access was genuinely needed — so do it in a declared window, smallest blast radius first, with restoration a minute away. The structural fix is to give grants an expiry, which turns "prove this is unused" into "justify keeping it".

go deeper

for a junior

The key idea is that a trail of refusals cannot show use: no refusal for a principal is equally consistent with constant access and with no access at all.

for a middle

Be able to name the cheap sources of positive evidence — connection records first, then a temporary period of allowed-decision recording on the streams under review.

for a senior

Show the staged withdrawal done safely: ordered by blast radius, inside a declared window, restoration in about a minute, and a watch period long enough to catch periodic workloads.

for a principal

Argue the burden of proof. Expiring grants make the review routine and put the knowledge with the owner, and the design work is the expiry interval and a renewal path that does not cause outages.

## Why this is hard, stated precisely A grant review is the act of reading the grant table against who is actually reading and writing, and withdrawing what nobody uses. Its evidential requirement is positive: to withdraw safely you must establish **use**, and a refusal-only trail records only failure. The absence of a refusal for a principal is equally consistent with two opposite worlds — the grant is exercised thousands of times a minute, or the principal was decommissioned last year — and no amount of care in reading the trail separates them. Everything below is a way to manufacture the positive evidence the trail does not hold, or to restructure the problem so you do not need it. ## Four sources of positive evidence, cheapest first - **Connection records.** Almost every cluster that records anything records connections. A principal that has not opened a connection in a year needs no grants, whatever the grant table says. This is coarse — it tells you a principal is alive, not which streams it touched — but it is free and it typically removes a large fraction of the roster before you make a single risky judgement. - **Per-principal activity accounting.** Clusters commonly attribute bytes and operations to a principal for fairness purposes, without writing an audit record per request. That attribution tells you which identities are genuinely busy. It usually does not resolve to a stream, so use it to sort the roster into active and dormant rather than to justify a specific withdrawal. - **A time-boxed measurement window.** Switch on allowed-decision recording for the streams under review, for a stated period, then switch it back. This produces exactly the evidence you lack. Its weakness is the window: a monthly batch, a quarterly close or an annual process will not appear in two weeks, so the window must be chosen against the rhythm of the workloads involved, and anything periodic must be listed in advance rather than discovered by its absence. - **Who is attached as a reader.** The operator can generally see that a stream has readers. Be careful how far you push this: the reader identity visible on the operating surface is not always the principal the grant is written against, so treat it as a hint that leads to a conversation, not as an attribution. ## Inverting the instrument The refusal-only trail is useless as evidence of use and is precisely the right instrument once you start removing grants. After a withdrawal, a refusal appearing for that principal on that stream is a direct, unambiguous statement that the access was needed. The whole review can be run this way, and on estates with no positive recording at all it is the only method that works. It is also a deliberate production break, so it is run like one: 1. **Order by blast radius.** Begin with principals that have not connected at all, then dormant ones, then active principals holding grants they appear not to use. Never begin with the most central service because it is the most cluttered. 2. **Declare a window.** A withdrawal outside a declared window produces an incident with a confusing symptom, because the failure surfaces in a client as a refusal rather than as an outage of anything obvious. 3. **Make restoration cheap and fast.** The grant must be restorable in about a minute by whoever is watching, without an approval step. If restoring takes an hour, the method is not safe to use. 4. **Watch for a stated period, then close.** Periodic workloads are the trap: a grant withdrawn on Tuesday may not be missed until the month-end run. ## The structural repair, which is the actual answer at this level Every technique above is a way of paying for evidence you did not collect. The lasting fix is to change the burden of proof: | Approach | Burden of proof | What it demands of you | |---|---|---| | Review against a refusal-only trail | On the reviewer, to prove a grant is unused | Evidence the cluster never produced | | Review against positive access records | On the reviewer, but the evidence exists | Standing cost of recording, chosen per stream | | Grants that expire | On the owner, to justify renewal | Discipline at grant time, and a renewal path that works | A grant with an end date is reviewed by construction. Nobody has to prove a negative: the grant lapses, and whoever still needs it says so. It converts an archaeological exercise into a routine one, and it is the difference between an estate whose grant table has only ever grown and one that reflects current reality. The cost is real — a renewal path that is slow or manual causes outages at expiry and gets defeated by long expiry dates — so the expiry interval and the renewal mechanism are the design, not the idea itself. ## The honest limit Even with all of this, some access leaves no attributable trace, and evidence is always about the window you observed. A grant review is therefore a risk decision, not a proof. State it that way: **these grants showed no use under this evidence over this period, and were withdrawn with restoration available** — which is defensible, unlike a claim that they were unused.

  • Why does giving grants an expiry date change the problem rather than just automating it?
    It reverses the burden of proof. Reviewing a permanent grant means proving a negative with evidence the cluster never produced. An expiring grant lapses on its own and whoever still needs it asks for renewal, so the knowledge lives with the owner instead of with a reviewer reading a trail. The renewal path has to actually work, or long expiry dates quietly return.
  • What is the main way a time-boxed measurement window misleads you?
    Periodicity. A window of two weeks sees nothing of a monthly batch, a quarterly close or an annual process, and the grant those jobs need looks unused. List known periodic workloads before the window opens and treat any grant tied to one as in use regardless of what the window shows.
  • How do you report the outcome of a grant review honestly?
    As a risk decision with its evidence and period named: these grants showed no use under this evidence over this window and were withdrawn, with restoration available. Claiming they were unused overstates what any trail can support, because some access leaves no attributable trace and evidence only ever covers the window observed.

Withdrawing grants to see who complains is like closing a valve in a plant with no flow meters: you learn what it fed by hearing which line runs dry. It works, which is why it is done — and it is why you do it on a planned day, with someone standing at the valve able to reopen it.

saying these in an interview costs you the question

  • Treating the absence of a refusal as proof a grant is unused
  • Withdrawing grants without a declared window or fast restoration
  • Starting the review with the largest, most central service
  • Choosing a measurement window shorter than a monthly workload
  • Reporting a review as proof rather than as a risk decision
  • Setting long grant expiry dates to avoid fixing renewal