SUMMARY: Permission residue is the access that remains after the reason for access has expired.
Every system accumulates old grants. A temporary role becomes permanent by neglect. A test account keeps a capability. A room permission survives a finished project. A moderation exception remains after the incident that created it has been forgotten.
Permission residue is dangerous because it looks normal from inside the system. Nothing breaks. Nobody sees an error. The access simply remains available, waiting for drift, confusion, or abuse.
Residue Signals
Orphaned purpose: the role still exists, but nobody can name the current reason for it.
Silent escalation: a low-risk account slowly gains more practical reach through accumulated exceptions.
Unreviewed membership: a room, list, group, or capability has not been checked since its creation.
Expired emergency: crisis permissions outlive the crisis.
Cleanup
Pair every exceptional permission with a review clock, owner, and trust receipt. This extends the review clock into access control and reduces the quiet risk of permission drift.
Operator Rule
If access was granted for a reason, the system should remember when that reason needs to be checked.
Field assessment: old access is still active power.