skip to content

What must a periodic review of secret-store grants against the access record produce so that rights are actually removed?

level: principalimportance: should knowfreq 36%

answer

  1. confirming costs nothing
  2. silence must remove, not keep
  3. an owner who is not the holder
  4. state the window and the evidence
  5. expiry beats attestation

basics

~10 s

A decision per grant, a named accountable owner who is not the holder, the evidence it rested on, and a default that removes on silence. A review where doing nothing keeps everything removes nothing.

solid answer

~40 s

Three outputs, and the third decides whether anything is ever removed. First, per grant: used or unused inside a stated window, where the window is longer than the slowest cycle the estate runs. Second, an accountable owner who is not the holder — a grant nobody will own is already a finding, not a pending question. Third, a default action on silence, and it must be removal: if confirming costs nothing and declining risks an outage, every holder confirms and the review becomes a signature exercise. The structural version is to stop reviewing — make grants expire so that continuing requires a renewal and lapsing is free. Then budget for the breakage, and watch for teams asking for wider scopes to escape the churn.

go deeper

for a junior

Rights do not expire by themselves. Someone has to look at a list of grants and decide, and the usual decision is "leave it", which is how a store ends up holding far more access than anyone intended.

for a middle

Explain why the access record has to be part of the review. Asking holders whether they still need something produces confirmations; pairing each grant with whether it was exercised in a stated window produces evidence.

for a senior

Describe a review that actually removes things: the window and why it is that long, the owner attached to each grant, the alert when a removal bites, and the rollback you keep ready for the first month.

for a principal

Treat this as a design choice about defaults, not a process to run. Decide what happens on silence, how much breakage the estate funds, and how you stop teams asking for wider grants to escape the renewal churn.

## Why review theatre is the default outcome A review that asks holders "do you still need this?" has a predictable result, and it is not a smaller estate. Confirming costs the holder one click. Declining risks an outage they will own. Nobody is ever thanked for giving up access. Run that loop quarterly and you produce a documented, signed, growing set of standing grants — the paperwork improves and the blast radius does not. The fix is not exhortation, it is changing what the default does when nobody acts. ## The three outputs 1. **A usage verdict per grant, with the window stated.** Used or unused inside a window longer than the slowest scheduled work in the estate. "Unused in thirty days" is not a verdict; it is a sentence about thirty days, and every monthly, quarterly and annual job falls outside it. 2. **A named accountable owner who is not the holder.** The holder bears the whole cost of losing access and none of the cost of keeping it, so their attestation is close to free. The owner should be whoever answers for the blast radius if that grant is abused — usually the owner of the data behind the names. A grant nobody will own is a result, not an open question: it can never be attested at this review or any later one. 3. **A default action on silence, and it must remove.** This is the load-bearing output. When lapsing is the default, inaction stops protecting the holder and starts clearing the estate; the only grants that survive are the ones somebody spent effort on. ## What the review cannot settle - **Why** a grant exists, when its author has left — the record shows exercise, not intent. - **Anything outside the window.** A quarterly window says nothing about annual work, and an external audit asking who could have read a value will ask about the year, not the quarter. - **Whether the record is complete.** The review depends on that record being trustworthy; establishing that it is, is a different job and a different control. State these limits in the review's own output. A review that claims more than it established is worse than a smaller one that is honest, because it retires a risk on paper. ## Expiry instead of attestation | | review-driven | expiry-driven | |---|---|---| | what happens when nobody acts | the grant survives | the grant lapses | | effort per cycle | proportional to the whole estate | proportional to what people actually renew | | how it fails | quiet accumulation nobody notices | a lapse at a bad moment, loudly | | what it needs to work | discipline, repeatedly | lead-time notices and a fast re-grant path | The expiry-driven model is strictly better at removing things and strictly worse at availability, and that trade is the decision a lead actually owns. Stage it rather than flipping it: expiry for new grants from today, a review backlog for the legacy set, lifetimes tiered by criticality, and a re-grant route measured in minutes so the failure mode is annoyance rather than an incident. ## The trade-offs a lead owns - **A breakage budget.** Removing standing access will break something. Fund it explicitly, or teams will quietly learn that the programme is unfunded and route around it. - **Who gets paged when a default fires**, and whether production-critical identities are exempt from automatic lapse — an exemption list is defensible, and an unwritten one is not. - **The second-order effect.** If lapses hurt, teams request wider grants with longer lifetimes so they need renewing less often. That is drift, re-created by your own control, and it shows up as scopes getting broader while the grant count falls. - **What you measure.** Not reviews completed on time. Rights removed per cycle; the share of grants carrying a named owner; the number of wildcards outstanding; the age distribution of standing grants. If the standing-grant count only ever grows, the review is documentation, not control. The short version a lead should be able to say out loud: the review does not remove rights, the default does, and everything else is evidence that makes the default defensible.

  • Why is the holder the wrong person to attest a grant?
    Because the holder bears all the cost of losing it and none of the cost of keeping it, so their answer is predictable and cheap. The accountable owner should be whoever answers for the blast radius if that grant is abused — usually the owner of the data behind the names, not the team that reads them.
  • Expiry-driven grants solve the review problem — what do they create?
    Renewal churn and a new outage mode: a grant lapses because the person who would renew it is on leave. You buy that back with lead-time notices, lifetimes tiered by criticality and a fast re-grant path, and you accept some breakage as the price of grants that do not accumulate.
  • What would you measure to know the programme is working?
    Rights removed per cycle, the share of grants with a named owner, wildcards outstanding, and the age distribution of standing grants. Reviews completed on time measures effort, not effect: if the standing-grant count only grows, the programme is producing documentation.

saying these in an interview costs you the question

  • Ask every holder to confirm they still need their grants.
  • A review is complete when every grant has been signed off.
  • A grant unused for thirty days can be removed on that basis.
  • Expiring grants automatically is too risky to attempt anywhere.
  • The metric is the number of reviews completed on time.