Is it even possible here?
Is it Even Possible Here?
In the previous two posts John was sharing his experience developing an RBAC program at a commercial exchange. At the same time Nick had been brought in to help a large bank with a problem they had been failing to solve for the better part of a decade. In this post Nick tells us what the start of that effort looked like:
I knew the shape of it by the end of the first hour. Ten thousand people, ten thousand distinct entitlements. Hundreds of thousands of individual assignments connecting them, every one reviewed by hand, every quarter, by managers certifying spreadsheets they did not have time to read.
What I did not expect was how openly everyone admitted it. In one of my first meetings, the security lead put it plainly: the certifications were being rubberstamped, everybody knew it, and it was creating real breach risk. The auditors had been circling the same findings for years. His message to the identity team was blunt. Fix it, and fix it now.
The harder part of my job was the history. This was not the first attempt. CISOs had arrived with mandates, kicked off role initiatives, and moved on before anything shipped. A mining tool had generated thousands of candidate roles that no business owner could explain. Working groups had debated taxonomies until reorgs made their drafts obsolete. Meanwhile the waste compounded: thousands of hours of manager time per cycle spent producing reviews that reviewed nothing, every new hire provisioned by hand, request by request. Across those years it added up to millions of dollars spent maintaining a pile of risk.
So the real question I was hired to answer was not "how do we do RBAC?" It was "Is it even possible here?"










