IT Glossary

Privilege Creep

Privilege creep is the slow build-up of access rights as employees change roles. Learn why internal movers are the blind spot and how to reverse it.

August 7, 2026

What is privilege creep?

Privilege creep is the gradual accumulation of access rights by an employee who changes roles, joins projects, or covers for colleagues, without the previous permissions ever being removed. Nothing is granted improperly at any single step. The problem is cumulative: after three internal moves, one person can hold the combined access of three different jobs.

How privilege creep builds up

  • An internal transfer adds the new team access while the previous role access stays in place.
  • Temporary cover for an absent colleague quietly becomes permanent.
  • Project-based access outlives the project that justified it.
  • Group memberships inherited from an old department are never re-examined.
  • Nobody owns the removal, because joiners and leavers have a process and movers usually do not.

Why the internal mover is the blind spot

Joiner, mover, leaver is the standard identity lifecycle, but most companies automate only the first and the last. Onboarding has a trigger from HR and offboarding has a hard deadline. An internal move has neither, so the additive half of the change runs and the subtractive half quietly does not. Separation of duties conflicts almost always start here.

Examples and use cases

A financial controller moves into an FP&A role. She keeps her ability to create suppliers in the accounting system and gains approval rights on payments. No individual grant was wrong, but the combination breaks separation of duties and would be flagged in any ISO 27001 or SOC 2 audit. Catching it means comparing current entitlements against the current role, which is what a periodic access review does. Corma runs those reviews across applications and routes each line to the manager able to judge it.

Related concepts

FAQ

What causes privilege creep?

Internal mobility, temporary cover for absent colleagues, and project access that was granted correctly but never removed once the reason disappeared.

How do you fix privilege creep?

Run recurring access reviews, trigger an entitlement check on every role change, and set an expiry date on project and temporary access from the moment it is granted.

What is the difference between privilege creep and privilege escalation?

Privilege creep is accumulation through normal operations. Privilege escalation is an attacker actively obtaining rights they were never given.

Why do access reviews catch privilege creep?

Because they compare what a person holds today against what their current role requires, which is the only check that surfaces permissions nobody thought to revoke.

Request a demo