Tier 1 + Tier 2 · Access
Access configuration drifts silently. A role is created for a project and never granted a permission, or never revoked; a create permission gets wired to a named individual who later changes teams; an administrator is flipped to local authentication and quietly drops out of single sign-on; a departed partner's privileged account stays live. Each anomaly is invisible day to day and obvious the moment an incident review, an insurer's questionnaire, or a regulator asks for the access picture. This audit extracts that picture read-only, as one reviewable dataset, and surfaces the anomalies with the evidence attached.
The complete matrix of which role holds which permission on which work type, extracted read-only through the System for Cross-domain Identity Management (SCIM) provisioning interface. On one live tenant this ran to 7,157 rows, reviewed as a single dataset rather than screen by screen, which is the only way the edge cases become visible.
Roles that exist, and often carry members, but grant nothing at all. Empty roles are noise that hides the real gaps in the matrix, and a reliable sign the role model has drifted from the original security design.
Create permissions wired to named individuals instead of roles. When that person changes teams or leaves, matter intake either breaks or, worse, keeps working under an account nobody is watching.
Permissions that silently narrow or widen as a matter moves through its phases, leaving users unable to act where they should, or able to act where they should not.
Users flipped to a local 'Administrator' authentication type, which silently takes them out of single sign-on (SSO) federation, and with it out of your multi-factor and conditional-access controls. A common and dangerous drift, and easy to miss because the account keeps working.
Privileged accounts with no login for 90 or more days: the accounts most worth disabling before an incident, or an auditor, finds them first.
Sharedo has two distinct wall mechanisms: security barriers on work items and Operational Data Store (ODS) information walls on parties. They are configured differently and fail differently, so this audit inventories each separately rather than conflating them into a single 'ethical walls' line.
The security layout is extracted read-only over the System for Cross-domain Identity Management (SCIM) provisioning interface; login recency comes from the administration and audit surface. Nothing is changed and no matter content is read: this is access configuration and sign-in metadata only, which is why it sits in the lightest authority tiers.
The matrix itself extracted cleanly. The risk sat in the edges: nine roles granting no permissions at all, three create permissions wired to named individuals rather than roles, four administrators on local authentication with single sign-on bypassed, and seven privileged accounts dormant for 90 days or more.
A defensible access picture before anyone asks for one: a role model cleaned of empty and drifted roles, create permissions re-anchored from individuals to roles, single sign-on restored as the only door in, and a dormant-account list you can disable this week.