Skip to content
Standing Access

How these notes are written

Structure

Most notes follow the same shape: what the control is, why it is harder than it looks, the method, where the method misleads, and how to tell whether it worked.

The sections on what does not work are not optional. A description of vaulting that omits the five routes it leaves open describes a control that does not exist.

Measurement over assertion

A recurring theme: coverage measured against the deployment's own scope is measuring the project, not the estate.

Several notes are entirely procedures for measuring something usually asserted: the path count on a system, brokered sessions against target-side authentication logs, rotation time under drill conditions, the permission gap in cloud.

The uncomfortable material

Most deployments vault credentials and leave standing rights untouched, which improves attribution and changes exposure very little.

Most recordings are never reviewed, which converts a control into a storage bill.

The insider framing is overstated and it damages the cooperation of the administrators the programme depends on.

The administrator's workstation remains the largest gap in most mature deployments, and it defeats brokering, recording and just-in-time simultaneously.

These are stated because a programme that does not know them reports success while the exposure is unchanged.

What is not covered

Offensive technique of any kind.

Specific product configuration, which changes faster than anything written here would remain accurate.

Specific legal requirements, which differ by jurisdiction.

Commercial position

No vendor material. No sponsored content. No affiliate links. No product rankings.