Clean · Access model

Do not migrate an access model nobody understands.

A migration faithfully reproduces whatever permission mess you hand it, and then it is a new platform’s problem.

We document who currently has access to what, identify the access nobody intended, and design a model the destination can actually express.

  • Exported as data
  • Nested groups resolved
  • Owners confirm access
  • Reconciled after applying

Price cue, ex GST

From $2,500

Scope a cleanup Or call 1300 652 280
The profile comes first

Before anything changes you get a profile: what is actually wrong, how much of it there is, and which rule found each case. Nothing is altered on the strength of an estimate.

  • Australian managed
  • Delivered remotely
  • Source data never deleted
  • Verification report at sign-off

How the access model is documented

Export it as data. Everything else follows from having it in a form you can query.

The full 17-gate method
  1. 01Export every permission entry from the source as data, not as screenshots of a dialog
  2. 02Resolve group membership recursively, so effective access is visible rather than nominal
  3. 03Identify direct user grants where a group should be — the main cause of unmaintainable access
  4. 04Locate every point where inheritance is broken, and establish whether anyone knows why
  5. 05Flag access held by disabled or deleted accounts
  6. 06Put effective access in front of content owners for confirmation
  7. 07Design the destination model from the confirmed source model, and reconcile after applying it

What the deliverable includes

The point is a document someone can act on, and act on again in two years.

  • A full effective-access register: who can reach what, resolved through nested groups.
  • An exceptions list: unintended access, orphaned grants, and inheritance breaks nobody can explain.
  • A proposed destination group model, expressed in what the destination can actually enforce.
  • A record of what each content owner confirmed, and what they declined to review.
  • A reconciliation after application, entry by entry against the source.
  • The register in a form you can re-run later, so this does not become a once-a-decade exercise.

The proof you keep

Effective access, resolved and counted.

Nominal permissions are easy to list. Effective access — what a person can actually reach once nested groups resolve — is the number that matters. Example format below.

Access Review Report

Pre-migration access review · Example format

Verified
Example reconciliation: source totals compared with destination totals
Access findingBeforeAfterStatus
Permission entries24,1189,442Verified
Direct user grants6,884206Verified
Inheritance breaks41238Verified
Grants to disabled accounts1,2060Verified
Groups with no owner840Verified
Access carried as-is, unreviewed1,8841,884Recorded by agreement

Access carried across unreviewed is recorded deliberately. It means a content owner declined the review, and the record of that is what answers the question later.

Free · About three minutes · No sales call required

Tell us about the data. We will tell you the likely range.

Volumes, custom structures and whether history has to survive are what drive the price. Four steps, and an engineer reviews every answer before a proposal is issued.

  1. 1. Route
  2. 2. Volume
  3. 3. Project
  4. 4. Contact

Loading the Fit Check. If nothing appears, JavaScript is disabled — call 1300 652 280 or email info@output.com.au and we will scope it with you directly.

Step 1 of 4

Questions about access cleanup

Why is a migration the right moment for this?

Because it is the only time the destination structure is genuinely open, and because the alternative is paying to reproduce the current model and then paying again to fix it. It is also the one moment when asking a department head to confirm who should have access to their files is a reasonable request rather than an imposition.

What do you actually find?

Direct user grants where a group should be, inheritance broken at a dozen points for reasons nobody remembers, groups whose membership contradicts their name, access held by staff who left, and at least one folder where a permission was granted as a temporary favour in 2014. This is the normal state of any estate over about eight years old.

Is this a security audit?

It is adjacent to one and it is not a substitute. We document the access model factually and identify access that appears unintended. Deciding what the access model should be is a business decision that needs the business in the room, and we will not make it on your behalf.

How is a new model designed without disrupting people?

By designing from the source model rather than from scratch, and by having the people who own the content confirm it before it is applied. The model that works is the current one minus the accidents, not an idealised structure nobody recognises.

What if a department will not engage with the review?

Then their access carries across as-is and that is recorded in writing. It is a legitimate outcome and considerably better than guessing on their behalf. The record matters later, when someone asks why a folder is open to forty people.

Find out what is actually in there.

Profile first, change second.

Scope a cleanup
Permissions cleanup Free Fit Check · about three minutes