Least privilege from real usage.
Paste entitlements against observed usage. ACCESS LENS flags standing privilege, drift, and over-permissioned grants — and refuses a least-privilege claim without usage evidence.
Deterministic gate onlineLeast privilege from real usage
Deterministic — the same packet returns the same verdict and hash, every run. Your result appears on the right →
Blocked. The runner found release-breaking evidence gaps or unsafe behavior.
Standing vs. just-in-time
Granted-but-unused entitlements
Time-bound + periodic review
Admin / root / wildcard / prod-write entitlements are held on a standing basis.
Privileged-grant signal detected.Convert standing privilege to time-bound, just-in-time elevation.
Entitlements are granted but show little or no matching usage.
Unused-entitlement signal detected.Revoke unused entitlements; enforce least privilege from observed usage.
Access lacks a recertification cadence or expiry (standing / permanent grant).
Standing-grant / no-expiry signal detected.Add time-bound grants and a recurring access review.
Engineering suite deterministic rule corpus
Input packet hash
ACCESS LENS right-size gate
3 finding(s), score 55