IT Glossary
Privilege creep is the slow build-up of access rights as employees change roles. Learn why internal movers are the blind spot and how to reverse it.
August 7, 2026
Privilege creep is the gradual accumulation of access rights by an employee who changes roles, joins projects, or covers for colleagues, without the previous permissions ever being removed. Nothing is granted improperly at any single step. The problem is cumulative: after three internal moves, one person can hold the combined access of three different jobs.
Joiner, mover, leaver is the standard identity lifecycle, but most companies automate only the first and the last. Onboarding has a trigger from HR and offboarding has a hard deadline. An internal move has neither, so the additive half of the change runs and the subtractive half quietly does not. Separation of duties conflicts almost always start here.
A financial controller moves into an FP&A role. She keeps her ability to create suppliers in the accounting system and gains approval rights on payments. No individual grant was wrong, but the combination breaks separation of duties and would be flagged in any ISO 27001 or SOC 2 audit. Catching it means comparing current entitlements against the current role, which is what a periodic access review does. Corma runs those reviews across applications and routes each line to the manager able to judge it.
Internal mobility, temporary cover for absent colleagues, and project access that was granted correctly but never removed once the reason disappeared.
Run recurring access reviews, trigger an entitlement check on every role change, and set an expiry date on project and temporary access from the moment it is granted.
Privilege creep is accumulation through normal operations. Privilege escalation is an attacker actively obtaining rights they were never given.
Because they compare what a person holds today against what their current role requires, which is the only check that surfaces permissions nobody thought to revoke.