Skip to main content

Aug 24, 2026

Day One Access Nobody Ever Takes Back

Offboarding gets the attention, but the access a new hire is over-granted on day one is the entitlement that never gets revisited

Offboarding gets the scrutiny. There are checklists for the leaver, tickets to revoke accounts, a scramble to claw back access the day someone walks out. The opposite end of the lifecycle gets almost none of it.

New hires are provisioned by template. Copy the access of someone already on the team, add the standard groups, err toward too much so they aren't blocked in week one. It is efficient, and it quietly over-grants from the first morning. That excess rarely gets a second look, because nothing prompts a review of an account that isn't causing problems.

Over-Provisioned and Forgotten

Standing access that no one exercises is standing risk that no one sees. A new engineer cloned from a senior teammate inherits entitlements they will never use, and those entitlements sit dormant, a broad attack surface waiting for a compromise that turns them live. The same dynamic compounds with every role change—access accumulates, and no one owns the cleanup.

Baseline What They Actually Use

Access reviews look backward at what people accumulated. The more useful question is what arrived on day one — before any behavior existed to compare it against — and how much of it has never been touched since. Identity Threat Protection surfaces overprivileged accounts ranked by actual usage and attack susceptibility, not just what a policy says they're allowed to hold.

You take access back when people leave. It is worth asking why so much gets handed over on the day they arrive.

See the latest from Abnormal's product and engineering teams.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.