Timeline Detective
Investigate employee access histories over time. Review role changes, permission grants, and certifications — then flag the moments where privilege creep, orphaned access, or missing reviews created governance risks.
Ready to play?
Put your awareness to the test. See if you can spot the threats before it's too late.
Launch GameWhy This Matters
Privilege creep is one of the most common and least visible access risks in any organization. Every role change, project assignment, and lateral move accumulates permissions — but revocations rarely keep pace. A 2025 Gartner survey found that 75% of organizations have no automated process for removing access when employees change roles.
The result is identity sprawl: employees carrying permissions from three departments ago, service accounts nobody owns, and admin rights granted 'temporarily' two years prior. Each orphaned permission is a potential lateral movement path for an attacker and a compliance violation waiting to surface in an audit.
Effective access governance requires reviewing not just what access someone has today, but how they got it. A timeline view reveals patterns — rapid privilege accumulation, missing periodic reviews, access grants with no business justification — that a snapshot view misses entirely.
What You'll Learn
Identify privilege creep by tracing access accumulation across role changes and project assignments
Recognize missing or overdue access certifications as governance failures
Spot orphaned access — permissions that persist after the business justification has ended
Understand why periodic access reviews and joiner/mover/leaver processes are critical controls