Most stale access is not a hacking story, it is a mover story: someone changed roles, gained the new role's groups, and kept the old ones. Group hygiene is the discipline of making lifecycle events, joining, moving, and leaving, actually change membership.
Why movers are the hard case#
Joiners get provisioned because they complain if access is missing. Leavers get disabled because security insists. Movers complain about nothing: their old access still works, their new access arrives, and the union of both persists indefinitely. Every mover is an accumulation event.
Nesting amplifies it: an old direct membership carries transitive membership in everything above it, so one forgotten group can represent dozens of effective grants, and, if the group itself is licensed, seats as well.
Detecting accumulated access#
The signal is divergence: users whose membership sets are supersets of their current role's expected pattern, or whose direct-to-transitive ratio is an outlier against peers. Manually that is per-user membership review, which is why it happens only during audits, if then.
VisualizerEngine
How VisualizerEngine helps
Structural search finds users by membership patterns, and saved searches make the mover review a repeatable weekly question instead of an audit-time archaeology. Snapshots diff a user's memberships across dates, showing exactly what a role change did and did not clean up, and license analytics flags the inherited seats that stale memberships still hold.