📝 ESSAY

Every mature platform carries more privileged access than anyone can explain. The security team run a review, the numbers fall for a quarter, and within a year the count has climbed back to where it started. I have watched that cycle in most customers i’ve worked with over the years.
📍 IN BRIEF
Access sprawl is not a failure of discipline. It is the predictable output of your incentives. On most platforms, granting broad access is cheap for everyone who touches it and granting narrow access is expensive, so people choose broad, and they will keep choosing broad however many awareness campaigns you run. Change the incentives and the sprawl stops renewing itself.
The organisations with the worst access sprawl are frequently the most disciplined ones in every other respect. They run delegated financial authorities that nobody dares breach, they document change with genuine rigour, and their access estate is still a thicket of privileges that no-one can justify. Every individual in the granting chain behaved reasonably, and the estate ended up over permissioned anyway. A theory built on carelessness cannot account for careful people producing the same failure everywhere.
Every access grant is a purchase, and breadth is on discount
The person granting access pays nothing for breadth and pays repeatedly for precision.
Follow one access request through the queue and the economics become easy to understand. The analyst working it has two options in front of them. The broad role closes the ticket in one move and will never bounce back, because broad access satisfies every future need the requester might later discover. The narrow role demands work first, because someone has to establish which of the scoped alternatives actually covers this job, and it carries the risk of a repeat ticket tomorrow when the scope turns out to be an inch too tight. The requester prefers breadth for the same reason, one request instead of three. The approving manager, who can rarely tell the two options apart on the form in front of them, signs whatever the form contains.
Now look at where the costs land. The cost of granting narrow access is paid immediately, by named individuals, in minutes of analysis and repeat tickets. The cost of granting broad access is paid years later, by the whole organisation, in audit findings, breach surface and clean-up programmes that nobody connects back to the original decision. When the benefits of a choice are private and immediate and the costs are shared and deferred, the outcome is not in doubt. Economists call that an externality, the cost is real but the person who created it never pays it, and externalities do not self-correct.
The convenience gradient decides, not the policy
Access flows downhill, toward whichever access grant closes the ticket fastest.
Call this the convenience gradient. Your access policy states the principle, almost always some phrasing of least privilege, but your role catalogue sets the costs, and the costs decide. If the broadest role is the easiest one to find, the easiest one to name in a request and the easiest one to approve, then it sits at the bottom of the hill and every ambiguous case rolls down to it. Least privilege fails in most organisations not because anyone disagrees with it but because it is published as a value when it needed to be priced as a default.
The record of major incidents reads like a study of this gradient. In 2019, Capital One lost on the order of a hundred million credit applications through a cloud role attached to a firewall, a role that carried permissions reaching far beyond anything the firewall's job required. One exploited misconfiguration turned that excess reach into one of the largest financial data breaches on record, and the regulatory penalties and settlements that followed ran well into the hundreds of millions of dollars. Nobody had decided the role should reach that far. Breadth was simply the cheapest way to make the thing work on the day it was set up. Six years earlier, Edward Snowden walked out of the National Security Agency with an archive of classified material that his contractor role should never have put within reach, because systems administration there came bundled with standing access to nearly everything. The agency's response afterwards was telling, because it did not announce a discipline campaign, it announced that it would cut the number of people holding that kind of access by around ninety per cent. It repriced.
The pattern is measured as well as anecdotal. Gartner predicted, years before it became fashionable to say so, that around three quarters of cloud security failures would trace back to poorly managed identities and privileges. Whatever the precise figure turns out to be in any given year, the direction is the point. Estates keep failing in the same place, the place where breadth was cheap.
✅ PRINCIPLE
A policy states what people should choose. The cost decides what they actually choose. If your least-privilege policy is losing, it is losing to your cost structure.
Repricing beats reviewing
A review discovers sprawl after you have already bought it. A price changes what you buy next.
The standard institutional response to sprawl is a bigger review. Certification campaigns arrive on a calendar, managers are handed hundreds of entitlements they cannot evaluate, and they certify the lot because the alternative is a week of investigation nobody has budgeted. Reviews have their place, and your compliance obligations will demand them regardless, but a review is a clean-up crew standing at the end of a production line that nobody has slowed down. The sprawl it removes this quarter is being manufactured again while the report is still being written.
Repricing means two moves made together. The first move is to make granting narrow access cheap. Design a catalogue of role bundles around the real shapes of jobs in your organisation, keep it small enough to hold in your head, and make each bundle requestable by name and approvable without analysis, because the analysis was done once at design time by people who are named and accountable for it. The second move is to make granting broad access expensive. A request for one of the handful of genuinely powerful roles should require a named senior owner to sign it, a recorded justification, and a date on which the grant is re-decided rather than quietly kept, and any dispute about whether breadth is warranted should escalate to the tier of your governance structure that actually owns platform risk. The platform delivery world has long carried a working benchmark of roughly one administrator for every thousand users. Publish your own ceiling, whatever you decide it is, so that every request that would breach it has to buy its way through a real decision instead of a queue.
Notice what this framing does to emergency access, which is where the objection usually arrives. Break-glass mechanisms are already priced correctly, being loud, logged, time-boxed and reviewed, which is exactly why nobody abuses them for convenience. The task is not to invent that pricing, it is to stop reserving it for emergencies while everyday breadth stays free.

The price list decides what people request. Field pattern across platform delivery programmes.
Where this doesn't apply
A small estate run by a single team who all know each other does not need a role catalogue, because the overhead of designing one would cost more than the sprawl it prevents, although even there the ceiling on the most powerful roles is worth writing down. Repricing is also peacetime work rather than something to attempt under fire. If you are in the middle of an incident, take the broad grants you need to recover, loudly and with dates attached, and rebuild the price list once the fire is out.
The bottom line
Stop funding larger and larger access reviews and start repricing the grants those reviews keep finding. Commission two artefacts this quarter, a role catalogue built around real job shapes and a broad-grant rule that attaches a named owner, a written justification and a re-decision date to every powerful role on the platform. Then track one ratio, requests met from the catalogue against requests escalated for breadth. When the catalogue wins most weeks, the gradient has reversed, and your reviews will start finding less every cycle, which is the only access metric that genuinely signals improvement.
Nobody chooses broad access because they are careless. They choose it because it is the cheapest thing on the menu. Change the menu.
P.S. Watch the last fortnight before any major go-live. Deadline pressure is when the convenience gradient is steepest. Temporary broad grants get issued to keep the programme moving, priced at zero because everyone intends to remove them later, and years afterwards they are still there, still working, and still on nobody's list.
📍 QUICK REFERENCE. Repricing grant of access
Access sprawl is an equilibrium, not an accident. Broad grants are cheap for the requester, the fulfiller and the approver, so broad is what gets bought.
The convenience gradient beats the policy. Whatever least privilege says, access flows toward whichever grant closes the ticket fastest.
Make narrow cheap. A small catalogue of role bundles, designed once around real job shapes, requestable by name and approvable without analysis.
Make broad expensive. Named senior owner, recorded justification, a re-decision date, and escalation when breadth is disputed.
Publish a ceiling for your most powerful roles and make every breach of it buy its way through a real decision.
Reviews are the clean-up crew, not the fix. Track catalogue wins against breadth escalations instead, and watch the reviews start finding less.