An employee moves from support to sales, then into operations. Each move grants a new set of entitlements for the new role. Almost none of them removes the entitlements from the old one. Access accumulates with every step, and it only ever grows.
Nobody owns the cleanup. The move adds the new access on day one; removing the old access has no deadline, no ticket, and no obvious owner. So it lingers through every subsequent move, and the employee ends up with a footprint no single role would ever justify.
The Veteran With the Widest Blast Radius
Your longest-tenured, most trusted people often hold the broadest access in the company. If one of those accounts is compromised, the blast radius is everything they collected on the way up, not just what they need today.
Baseline Use Against Role
PeopleBase compares what an identity actually does against what its current role implies, so entitlements carried over from a role two moves ago, held but never exercised, surface as anomalies worth pruning. The access nobody remembers granting is exactly what an attacker would love to find.
Access follows people as they grow through an organization. Rarely does anyone decide when it should stop following, and that decision is worth making deliberately.
See the latest from Abnormal's product and engineering teams.

