When someone in your organisation holds permanent admin rights to your cloud environment, that access exists whether they are using it or not. It is there at two in the morning on a Sunday. It is there during a two-week holiday. It is there the day after someone hands in their notice.
The problem with standing privilege
Most cloud environments are set up the same way: an administrator is assigned a role, and that role stays assigned. It is convenient. Nobody has to request access every time they need to make a change, and IT teams value convenience because they are already busy.
The trouble is that convenience and risk sit on the same side of the ledger here. If an admin credential is compromised — whether through phishing, a leaked password, or a poorly secured personal device — the attacker inherits everything that account can reach. Not because the attacker is skilled. Simply because the access was standing there waiting, unattended, for anyone who found the key.
This is not a hypothetical. It is the default condition of a large proportion of business cloud environments today, and it rarely gets questioned because it has always been done this way.
What zero standing access actually means
Zero standing access means nobody holds permanent privileged access to your environment. When an administrator needs to do something that requires elevated rights, they request it. That request is time-bound, it is logged, and in higher-risk environments it requires a second person to approve it before the access is granted.
When the task is finished, or when the time window closes, the access disappears again. The administrator goes back to holding no more privilege than anyone else on the team.
The difference this makes is structural, not cosmetic. A compromised credential with standing admin rights gives an attacker the keys to the building. A compromised credential with zero standing access gives them a locked door and a request form that logs their name.
Where this sits inside the Sovereignty Index™
Identity is one of the five pillars we score as part of the Sovereignty Index™, and standing access is one of the clearest signals within it. It is a binary, observable fact about an environment. Either privileged access is time-bound and logged, or it is sitting there permanently, waiting.
We treat it this way because it is one of the few security questions with no grey area in the answer. A business either knows exactly who can reach what, and for how long, or it does not. E7OSIRA monitors this continuously after the baseline is established — surfacing dormant privileged accounts, unusual access patterns, and offboarding gaps before they accumulate.
What good practice looks like day to day
In an environment built around zero standing access, an administrator’s normal working day looks almost identical to anyone else’s. They sign in with the same level of privilege as a standard user. When a genuine need arises — a server needs patching, a permission needs granting, a configuration needs changing — they raise a request through the same system every time, and the elevation is granted for exactly as long as the task requires.
This is not friction for its own sake. A well-designed request process takes seconds, not hours, and the people doing the work barely notice it once it becomes routine. What it removes is the silent accumulation of permanent access that nobody remembers granting and nobody gets around to revoking.
The question worth asking this week
When did you last check how many accounts in your environment hold permanent admin rights? Not who is supposed to have them. Who actually does, today, whether they are using that access or not.
The answer tends to surprise people, and not in a reassuring way. Accounts belonging to people who left the business eighteen months ago. Service accounts nobody remembers creating. Admin roles assigned during a project that finished and were never revoked.
None of this happens through carelessness. It happens because standing access is the default, and removing it requires someone to actively design it out — which takes intent that most environments were never given.
Sovereignty means nothing if it is aspirational. The value of zero standing access is that it is checkable: you can look at an environment today and know, with certainty, whether privileged access is time-bound or permanent. Get in touch if you do not have that answer — we will tell you exactly what to check.