The consent granted once, and never looked at again
Event dated 15 April 2026 · Published 2 September 2026 · 3 sources
The security industry has spent five years agreeing that implicit trust is the problem. Network location should not confer access. Being inside should mean nothing. Every request should be evaluated on its own merits, against the identity making it and the state of the device it comes from.
Meanwhile, in the same organisations, a mechanism runs that does precisely the opposite. An employee finds a tool that summarises their documents, connects it to the company's file store, and grants it read access to everything they can see. The grant is durable by design, because a tool that had to ask again every morning would be intolerable.
Why this is invisible to the usual controls
An application using its token is not signing in. There is no authentication event to apply conditional access to, no device to check, and often no interactive session at all. The requests arrive with valid authorisation from an application the organisation approved — once, by implication, when somebody clicked.
Reviews miss it for a related reason: access reviews enumerate users and groups. A grant held by an application is not a group membership, does not appear on the list a manager signs off, and belongs to no leaver process. It is exactly the shape of thing that outlives everyone who knew about it.
The scope problem underneath
Consent screens ask for what the application wants, not what it needs for the task in front of the user. A tool that will summarise one folder asks for the whole store, because that is simpler to build and because the request is granted anyway.
The person clicking is not equipped to evaluate the difference. They wanted a summary of a document. What the dialogue actually asked was whether a third party may read the organisation's files indefinitely, and no interface presents it that way.
Three things that close most of it
Turn off end-user consent for anything touching organisational data, so the grant becomes a request rather than a click. Enumerate the grants that already exist, which most platforms will export and most organisations have never looked at. And expire them: a grant that has not been used in ninety days is a grant that nothing will miss.
None of that is new advice, and all of it sits outside the frame most zero-trust programmes were built in — because those programmes were designed around people signing in, and this is a category of access where nobody signs in at all.