Zero trust shipped, standing grants are reviewed quarterly and every owner approves everything - what do you tell the executive it buys?
answer
- the residual is grant breadth
- measure the review, not the estate
- near-100% approval is the finding
- attestation buys an artefact
- expire the tail, review the top
basics
~20 sSay plainly that the attestation buys an audit artefact and an owner of record, not narrower grants. Redirect the same review capacity to the grants that would most help an adversary, and let the long tail expire.
solid answer
~50 sStart by separating what zero trust removed - network position as a route - from what it did not: a real credential inside a real grant. That residual lives entirely in how broad standing grants are. The quarterly recertification is the paper control on it, and you can show it is not working using its own data: approval rate near 100%, seconds spent per item, no revocations in a year. Say that out loud, because the alternative is an organisation that believes in a control that does nothing. What it does buy is narrow but real - an audit artefact and a named owner, which a contract or a regulator may require. So do not propose deleting it. Propose spending human capacity where it changes the outcome: rank grants by what they would give an adversary, review only that slice with last-used evidence attached, and let everything else lapse unless renewed.
go deeper
Understand what access recertification is - periodically asking owners to confirm each person still needs each grant - and that approving without checking is extremely common.
Explain why an adversary holding a real credential inherits the full breadth of that identity's standing grants, which is what makes grant size the residual risk after a zero-trust rollout.
Be ready to instrument the review itself - approval rate, seconds per item, revocations produced - and to propose evidence such as last-used data so reviewers can act rather than guess.
Own the honest message to a sponsor who was sold an end to lateral movement, the split between controls that are compliance artefacts and controls that reduce risk, and the funding and breakage you are asking the business to accept.
## The conversation you are actually having The executive was sold a programme that ended lateral movement. It did not; it changed its shape. Under the old model an adversary's reach came from where a compromised host could route; under this one it comes from what a compromised identity is entitled to. So the residual after the rollout is the breadth of standing grants, and the organisation's only control on that breadth is a quarterly access recertification in which owners approve everything put in front of them. This is a principal-level question because the technical answer is easy and useless - 'grants should be narrower' - while the actual constraint is human capacity, an auditor, and a sponsor's belief. ## Step one: measure the review, not the estate The most useful thing you can bring is data about the control itself rather than about access: - approval rate (if it is 99%-plus, reviewers are not deciding) - median seconds per item (if it is under ten, they cannot be reading) - revocations produced per cycle, and how many of those were re-granted within a month - items per reviewer per cycle (a manager handed 400 lines has been given an impossible task, not a lax one) Those four numbers turn a vague complaint into a finding. They also protect the reviewers, which matters politically: the failure is a design failure, not laziness. Nobody can make a meaningful judgement about 400 grants with no evidence about whether each is used. ## Step two: say what attestation actually buys Be precise and unsentimental. A quarterly attestation buys: - **an artefact** that an auditor or a customer's contract can be shown - **an owner of record** for each grant, which is genuinely useful when something later goes wrong - occasionally, **a departure catch** - a name a manager notices should be gone It does not buy narrower grants, because approving is cheaper than investigating and the incentives all point at approving. Saying this is uncomfortable and it is the job: the person who has to state what the control does not stop is the same person who writes the residual-risk page. ## Step three: propose where the capacity should go The budget is human review hours and it is fixed. Spend it where it changes an outcome: **Rank by what a grant would give an adversary, not by who holds it.** Production write access, bulk customer or payroll data, cross-tenant or cross-directory reach, and anything that can grant further access. That top slice is usually a few percent of grants, which is what makes it staffable. **Attach evidence.** Reviewers need last-used data - this identity has not exercised this grant in 180 days - so the default answer can become removal rather than approval. Producing that evidence is engineering work someone must fund, and it is the highest-leverage spend in the whole proposal. **Expire the tail.** Everything outside the ranked slice should be time-boxed: it lapses unless renewed. Expiry does what review never will, because it does not require a human to say no - only to say nothing. **Stop the pool growing.** New grants default to time-bound or request-and-expire, so the standing set stops accumulating while you work the backlog. ## Step four: name the costs and who signs for them This is what makes it a principal answer rather than a plan. - **Breakage.** Auto-expiry will take out an overnight job and lock somebody out mid-shift. You buy that down with warning windows, a fast self-service renewal path, and by starting on the low-value tail. You do not promise it will not happen; you say some breakage is the point, since a grant nobody renews is a grant nobody needed. - **Engineering funding.** Last-used evidence and an expiry mechanism are real work with a real owner. - **The auditor.** If a contract or a regulator requires an attestation of all access, you keep it. Run it as cheaply as the commitment allows and stop describing it as a risk reduction, and fund the ranked review beside it. If you believe expiry plus evidence-backed review is stronger, propose the swap explicitly with your data - but you never quietly drop a committed control, and if the regulator refuses, that refusal is the answer and you carry both. - **The residual that remains.** Even after all of it, an adversary holding a real credential still gets what that identity legitimately needs. Write that on the one-page residual-risk note now, while it is a design statement, rather than after an incident when it reads as an excuse. ## What a strong answer avoids Do not propose more frequent reviews with the same reviewers and no evidence - that multiplies the cost of a control you just showed does nothing. Do not claim zero trust already solved over-broad access. And do not present a 100% approval rate as a clean estate; it is the finding, not the result.
- What does automatic expiry of unrenewed grants cost the business, and who absorbs it?Service owners and users, at bad times. A lapsed grant is an overnight job failing or somebody locked out mid-shift, and the first cycles will produce both. You buy it down with warning windows, a fast self-service renewal path, and by starting where a mistake is cheap. But you say up front that some breakage is the point: a grant nobody renews is a grant nobody needed, and expiry is the only mechanism that does not require an over-loaded human to say no.
- Your auditor's control requires a quarterly attestation of all access. Now what?You keep it, and you stop claiming it reduces risk. Run the full attestation as cheaply as the commitment allows, treat it as an artefact and an owner of record, and fund the risk-ranked review beside it as the control that actually narrows grants. If you think expiry plus evidence-backed review is the stronger control, propose the swap explicitly with your measurements - but never drop a committed control quietly, and accept that a refusal means carrying both.
- How do you rank grants by what they would give an adversary?By the resource, not the requester. Production write access, bulk customer or payroll data, cross-tenant or cross-directory reach, and anything that can grant further access. Count how many identities hold each, weight standing grants above requested ones, and publish the top slice. It usually comes out at a few percent of all grants, which is exactly what makes the review staffable with the people you already have.
saying these in an interview costs you the question
- Proposes reviewing every grant more often with the same reviewers
- Claims zero trust already solved over-broad access
- Drops a committed audit control without telling the auditor
- Reads a near-100% approval rate as evidence the estate is clean
- Promises automatic expiry will break nothing