A permission audit can be a report, a recurring review, or a system that explains and remediates access. Cost depends on role complexity, account boundaries, inherited grants, audit history, and the action required after a finding.
Define the audit scope
List users, roles, groups, tenants, resources, actions, environments, service accounts, sessions, tokens, and exports. Decide whether the audit is point-in-time or continuous.
Budget for effective access
Include inheritance, overrides, denies, temporary delegation, expired invitations, and provider permissions. The permission inheritance checklist helps explain why access exists.
Include evidence and review
Plan actor, source, time, role, resource, action, approval, change, and last-use data. Add reviewer assignment, exception, due date, and remediation state.
Protect the audit
Limit access to permission reports, mask resource or customer detail, secure exports, and retain only what policy needs. Avoid making the audit itself a broad data dump.
Test remediation
Test removing role, group, token, session, delegation, integration, and support access. Verify cached permissions, API, exports, and queued actions do not continue unexpectedly.
Compare ongoing cost
Ask about new roles, policy changes, access reviews, incidents, dashboards, reports, notifications, training, and support. Compare the quote by its ability to close findings safely.
Permission audits finding issues that nobody owns? Ask Vertinus to scope review through remediation.