Reconstruct effective access
Ana-user receives prepare on payments-prod through a direct grant and payment-makers. She reaches that group through operations and alternate. Counting memberships or examining only direct grants does not answer what she can do. The recursive SQLite query visits distinct type-and-identifier pairs, using UNION to terminate even when groups contain a cycle. The result aggregates the same operation on the same resource and shows g-direct and g-group as grant sources. It neither enumerates every possible path nor proves external inventory completeness. Transitive inheritance is a teaching choice, not a reproduction of particular Active Directory or Entra rules. In an actual system, confirm which group, role and application types really propagate access.
Assess combinations by person and context
Ana-admin can approve on payments-prod. Each account has one function, but both belong to Ana: the model identifies the prepare/approve combination for the same person and resource. Separate account names do not create two independent people. Bruno has prepare on payments-prod and approve on payments-test; this does not violate the local rule because the resources differ. Define incompatibilities with purpose and scope, avoiding omissions and false positives. The exercise detects the combination only; it does not block actual transactions. A rule preventing someone from approving a payment they created also needs operation context and creator identity. Separation reduces opportunities for individual abuse but does not eliminate collusion or replace observation and investigation.
Give the reviewer sufficient context
A reviewer receives a request to remove g-direct from Ana-user. They should understand the associated person, role, resource, relevant activity, reason for retention and other access sources. A context-free click can confirm unnecessary privilege or remove a legitimate dependency. In the model, policy permits only reviewer as decision maker and prevents review by the account holder or owner; these fictional identifiers do not perform actual authentication. The decision is bound to a data snapshot. If a new grant appears before application, the transition is refused until reassessment. This comparison detects changed content but neither validates signatures nor guarantees distributed concurrency. Organizations should define review controls and periods; no universal frequency is invented from the exam.
Separate decision, application and effect
Recording revoke does not delete g-direct. Applying the decision actually removes that row from the synthetic database, but prepare remains available through g-group. The report returns effectiveAccessStillPresent=true. Technical execution matched the bounded action yet did not remove the ultimate capability. After deleting operations membership, the alternate path still grants access. Only removal of the remaining path closes that permission in the model. Reapplying the same review is a no-op returning its historical result, not fresh proof of current state. In production, track connector execution, errors, residual paths and subsequent validation. A retain or defer decision does not authorize the removal transition implemented in this exercise.
Use evidence to accept the service
Prepare a matrix containing person, account, resource, operation, grant sources, decision, application and outcome. Include legitimate permissions that should survive: the exercise confirms batch-service still reads reports after Ana’s correction. A change removing everything does not automatically meet required continuity. Record unevaluated cases, stale sources and exceptions with authority and validity. The 43 checks executed twice cover SQL and local policy without an IdP, HR, LDAP, SCIM, MFA or session propagation. The result is not a compliance certification. Use the exercise to prepare project criteria and representative tests, with explicit responsibility for conflict analysis, review and application. The material deepens CISSP 5.4 and 5.5 with links to personnel risk and operations.
# Inspect observations in the generated evidence
# initialRights -> two grant sources, one effective permission
# appliedDirectRemoval.result.effectiveAccessStillPresent -> true
# conflicts -> one person, two accounts, same resourceThe review removes g-direct, but g-group retains prepare. Successful removal of one grant does not establish removal of the capability.
Common pitfalls
Two accounts as two people; direct removal as absence of inheritance; cycles as endless traversal; snapshot as authentication.
Related topics: Identity lifecycle · Effective privileges and review · Separation of duties
Review effective capability and its context, following each decision through to the outcome required.
Reference: Security and Privacy Controls for Information Systems and Organizations · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29