InSpective

Tier 1 + Tier 2 · Access

Security & access

Access configuration drifts silently. A role is created for a project and never granted a permission, or never revoked; a create permission gets wired to a named individual who later changes teams; an administrator is flipped to local authentication and quietly drops out of single sign-on; a departed partner's privileged account stays live. Each anomaly is invisible day to day and obvious the moment an incident review, an insurer's questionnaire, or a regulator asks for the access picture. This audit extracts that picture read-only, as one reviewable dataset, and surfaces the anomalies with the evidence attached.

T1T2

1What we examine

roadmapRole-by-work-type permission matrixCFG-RS

The complete matrix of which role holds which permission on which work type, extracted read-only through the System for Cross-domain Identity Management (SCIM) provisioning interface. On one live tenant this ran to 7,157 rows, reviewed as a single dataset rather than screen by screen, which is the only way the edge cases become visible.

roadmapRoles granting zero permissionsCFG-RS

Roles that exist, and often carry members, but grant nothing at all. Empty roles are noise that hides the real gaps in the matrix, and a reliable sign the role model has drifted from the original security design.

roadmapIndividuals hardcoded as create subjectsCFG-RS · CFG-PT

Create permissions wired to named individuals instead of roles. When that person changes teams or leaves, matter intake either breaks or, worse, keeps working under an account nobody is watching.

roadmapParticipant-permission gaps by phaseCFG-PT

Permissions that silently narrow or widen as a matter moves through its phases, leaving users unable to act where they should, or able to act where they should not.

roadmapAdministrator authentication driftCFG-RS

Users flipped to a local 'Administrator' authentication type, which silently takes them out of single sign-on (SSO) federation, and with it out of your multi-factor and conditional-access controls. A common and dangerous drift, and easy to miss because the account keeps working.

roadmapDormant privileged accounts

Privileged accounts with no login for 90 or more days: the accounts most worth disabling before an incident, or an auditor, finds them first.

roadmapSecurity barriers versus information wallsCFG-RS

Sharedo has two distinct wall mechanisms: security barriers on work items and Operational Data Store (ODS) information walls on parties. They are configured differently and fail differently, so this audit inventories each separately rather than conflating them into a single 'ethical walls' line.

2How we examine it

The security layout is extracted read-only over the System for Cross-domain Identity Management (SCIM) provisioning interface; login recency comes from the administration and audit surface. Nothing is changed and no matter content is read: this is access configuration and sign-in metadata only, which is why it sits in the lightest authority tiers.

Extraction is read-only, and every anomaly class on this page is one we have extracted and reported on a live engagement. The counts shown are illustrative: the demonstration corpus does not yet include users and roles, so unlike the Configuration and Key Dates pages these tiles are not computed values. We surface configuration facts and access signals, never a determination that any access was misused.

3Example finding

Illustrative example from the synthetic demonstration corpus (underlying lens on our roadmap, not yet in the productised pipeline)

The matrix itself extracted cleanly. The risk sat in the edges: nine roles granting no permissions at all, three create permissions wired to named individuals rather than roles, four administrators on local authentication with single sign-on bypassed, and seven privileged accounts dormant for 90 days or more.

  • Roles granting zero permissions are noise that hides the real gaps in the matrix
  • Create permissions tied to named individuals fail silently when those people move on
  • Local-authentication administrators sit outside single sign-on, and outside its multi-factor and conditional-access controls
48security roles in the matrix
9roles granting zero permissions
3create permissions wired to named individuals
4administrators on local auth (single sign-on bypassed)
7privileged accounts dormant 90+ days
Full permission coverage31 rolesPartial coverage8 rolesZero permissions9 roles
Illustrative access anomalies of the classes a read-only extraction of the security layout and login recency surfaces, with zero-permission roles highlighted. Hover any bar for the exact count.

4The benefit

What you walk away with

A defensible access picture before anyone asks for one: a role model cleaned of empty and drifted roles, create permissions re-anchored from individuals to roles, single sign-on restored as the only door in, and a dormant-account list you can disable this week.

← All audit domains See it in a full report