# Permissions and identities under control: roles, multi-factor, leavers and review

> Who may do what and why: build an access concept, use roles instead of individual rights, introduce multi-factor authentication, automate joiners and leavers and review permissions regularly.

URL: https://techport.ai/en/it-beratung/sicherheit-und-resilienz/identitaeten-und-zugriffe

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)/
3.  Ordering identities and access

[Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

# Ordering identities and access

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

Permissions grow in one direction. Whoever changes department gains the new rights while the old ones remain. Whoever once needed access as a stand-in keeps it. Whoever leaves usually loses their account, but not every access, particularly not in services outside central management.

After a few years part of the workforce has access to areas nobody deliberately granted. That is invisible in daily work and becomes visible during an attack, during an audit, or when an assistant system suddenly finds everything a person is allowed to read.

## How you notice it

*   Accounts of departed employees are still active.
*   New employees get rights by being copied from a colleague.
*   There are shared accounts whose password several people know.
*   For a folder or a system nobody can say who may access it and why.

## Why this happens

Permissions are granted at the moment of the request, under time pressure, with the legitimate aim of letting someone work. They are never withdrawn at the moment of a request, because nobody asks. There is no trigger for withdrawal apart from departure, and even there the list of accesses to remove is rarely complete. As long as nobody reviews regularly, the stock grows automatically.

## How we go about it

1.  **Make the current state visible.** We analyse which people can access which systems and data areas, including services outside central sign-in. That analysis is usually the most persuasive part of the project.
2.  **Roles instead of individual rights.** We build roles along activities and assign rights to them, so that joiners, leavers and movers run through the role. Individual rights remain the justified exception with an expiry date.
3.  **Secure the sign-in.** We introduce multi-factor authentication, starting with everything reachable from outside and with administrator accounts, and separate administrative from normal accounts. Shared accounts get replaced or made traceable.
4.  **Anchor processes and review.** We tie joiners and leavers to a procedure with a checklist and evidence, and set up a recurring review in which the responsible areas confirm or remove their permissions.

## What you gain

*   A markedly smaller attack surface, because stolen credentials open less.
*   Evidence of who may access what, for audits and customers.
*   Faster onboarding, because rights come with the role rather than by request.

## From our projects

Analysing actual access to file storage almost always produces surprises, frequently around HR, costing or contract folders readable by large parts of the workforce. The cause is usually inherited rights from a folder structure created years ago. The second recurring finding concerns administrator rights: in many companies technical staff work permanently with elevated rights, including when reading email. Separating a normal from an administrative account is one of the most effective single measures and can be done within days.

## Good to know

For personal data, Article 32 GDPR requires measures ensuring a level of security appropriate to the risk, explicitly including access control. Granting permissions on a need to know basis is therefore not a recommendation but an obligation, and its implementation has to be demonstrable. For companies within the scope of the German BSI Act, access control and securing authentication are part of the risk management measures under Section 30 BSIG. Where permissions are analysed in order to assess employee behaviour, codetermination has to be observed as well.

## Häufige Fragen

Is multi-factor authentication not too cumbersome for daily work?

It is barely noticeable in the right places if it is configured sensibly: longer intervals for trusted devices on the internal network, consistent enforcement for external access and for administrator accounts. Measured against the effort it is the most effective single measure against stolen credentials, and stolen credentials are one of the most common entry routes.

How often should permissions be reviewed?

Every six months for critical systems and administrator rights, annually for the rest. What matters is that the review is confirmed by the responsible business people and not by IT alone, because only the department can judge who needs which access for their work.

## Let us talk about Ordering identities and access

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Operations and SupportWorkplaces and devicesHow workplaces become maintainable: set device standards, introduce central management, secure mobile devices, plan procurement and replacement, reduce effort per workplace.](/en/it-beratung/betrieb-und-support/arbeitsplatz-und-endgeraete)[Security and ResilienceTraining and awarenessHow awareness works instead of annoying: show real attack patterns, train short and often, build a reporting culture, involve managers and make the effect measurable.](/en/it-beratung/sicherheit-und-resilienz/awareness-und-schulung)[IT Governance and ComplianceImplementing data protection technicallyGDPR put into practice: technical and organisational measures, processor agreements, records, deletion concept, log data, third country transfers and handling data breaches.](/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

## Sources

*   [Article 32 GDPR, security of processing](https://gdpr-info.eu/art-32-gdpr/)
*   [Section 30 BSIG, risk management measures (in German)](https://www.gesetze-im-internet.de/bsig_2025/__30.html)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
