Our disposition model, covered in an earlier piece, already protects one kind of access carefully: a privilege we genuinely cannot observe is never dropped for lack of evidence. But a client asked us a sharper, fair question about a narrower case: what about access we can see hasn't been used, but that happens to cost nothing extra because the person already needs that license tier for something else? Does that get removed too?
That's a real design decision, not a technicality, and different organizations reasonably want different answers. One client wants the leanest design the evidence supports, full stop. Another wants us to change nothing that isn't actually costing them money, whether or not we've seen it used, because every access change carries its own operational cost, retraining, support tickets, someone's workflow breaking on a Monday, that a license-cost model doesn't capture. Neither preference is wrong. So we built a dial instead of picking one answer for everyone.
What the three settings actually control
To be precise about scope first: none of this touches access that would cost more. A privilege nobody uses, that would bump someone to a pricier tier if kept, is removed or flagged the same way in every mode, that part of the model doesn't change. The dial only governs the narrower case: unused access that's already free because of a license the person needs anyway.
- Evidence-only. If we haven't seen it used, it goes, even when keeping it would cost nothing. The leanest possible design, and the easiest to defend line-by-line in an access review: everything present has a reason.
- Balanced, our default. Free access is kept only when we genuinely couldn't have seen whether it's used, the same audit-blind protection from our disposition guardrail. Anything we directly observed going unused, even if it's free, is removed.
- Continuity-first. Keep every piece of free access, observed-unused or not. Nothing changes for anyone unless it's actually driving cost. This is the right setting for an organization whose priority is minimizing operational disruption above minimizing the size of the access-review list.
Continuity-first genuinely costs nothing at the level of a single person: by definition, the access in question doesn't change what license tier that individual needs. For a while, we described it as cost-neutral across the board. That turned out to be incomplete, and finding out why is worth walking through, because it's a real trap in this kind of modeling.
The correction: free for one person isn't free for a shared role
The per-person math is correct on its own: keeping a privilege that costs a specific user nothing extra really doesn't change that person's bill. The gap appears once access is granted through a role that multiple people share. If enough people in a shared role individually qualify to keep a certain free privilege, that privilege can end up folded into the role itself, and everyone who holds that role receives it, including people for whom it wasn't free at all. One person's zero-cost keep became a shared grant that quietly priced up several other people's seats.
We initially told a client this setting was cost-neutral, based on correct per-person logic that didn't hold once we looked at what happens inside a shared role. We caught it by checking the model's output against that exact claim before final delivery, not after. The fix is straightforward once you see it: a shared role should only absorb a free privilege if it's genuinely free for everyone who'd end up holding that role, not just the majority. Where that's not true, the access stays available through a smaller, targeted grant instead of the shared role, more precise, same intent.
One more nuance worth stating plainly: the real cost of continuity-first isn't fixed, it depends on how tightly a role shares access in the first place. On a role built to share broadly, the effect above shows up clearly. On a role already built to share only what nearly everyone in it needs, we've measured the same setting costing close to nothing, and even producing a slightly tidier object count as a side benefit. Whether "keep everything free" costs real money is itself a property of the specific design it's layered onto, not a fixed price tag on the setting.
Why this is worth naming as its own setting
The instinct to treat this as a minor implementation detail undersells it. Whether unused-but-free access should stay or go is a genuine statement about what an organization is optimizing for, continuity and stakeholder trust in the process, versus the tightest defensible access footprint, and it deserves to be a decision the client actually makes, not a default buried in a script. Naming it, measuring its real cost precisely, and correcting our own early assumption about it in the open is what turns "we'll take care of it" into something a client can actually evaluate.
There's no universally correct answer to "should we remove access nobody's used, if it's free." It depends entirely on what an organization is protecting: the license bill, or the trust and continuity of the people who'll live with the new access model day to day. Both are legitimate priorities, they just produce different designs, and a client should get to choose deliberately rather than have the choice made silently on their behalf.
Questions we get asked
Isn't "continuity-first" just a way to avoid doing the hard work?
No, it still removes everything that's actually driving cost, and everything unobservable still goes to the same review process. What it changes is a narrower, genuinely optional category: unused access that happens to already be free. Choosing to leave that alone is a real design decision with a real (now correctly measured) cost, not a shortcut.
Does this setting affect the audit-blind guardrail at all?
No, that guardrail is unconditional in every mode: a privilege we structurally cannot observe is never dropped for lack of evidence, regardless of which of these three settings is active. This dial only ever governs access we directly observed going unused.
Can different departments in the same organization use different settings?
Yes, and it often makes sense to. A department running a stable, well-understood process might be comfortable with evidence-only. One mid-reorganization, or one where an access gap has an outsized operational cost, might reasonably prefer continuity-first. The setting is a per-scope input, not a one-time company-wide choice.
Glossary
| Term | Meaning |
|---|---|
| Unused-but-free access | A privilege with no observed usage that costs the holder nothing extra, because they already need that license tier for other access |
| Evidence-only policy | Removes unused access regardless of cost; the leanest design the evidence supports |
| Balanced policy (default) | Keeps unused-but-free access only when it was genuinely unobservable; removes it when directly observed unused |
| Continuity-first policy | Keeps all unused-but-free access, observed or not; nothing changes unless it's driving real cost |
| Shared-role inflation | The mechanism by which a privilege that's free for one member of a shared role can still price up other members if folded into the role itself |