Admin Rights Exorcist
We removed root. Why can it still do that?
They removed the root credential. The agent can still do everything. "Then what was that key for?" Nobody likes this question. Someone opens a permissions panel. Someone else opens a different permissions panel. Both say inherited. The Admin Rights Exorcist untangles root credentials, inherited roles, and the second key nobody remembered issuing.
Symptom
Removing a credential changes nothing. Access chains through service accounts, inherited roles, and cached grants that no single dashboard shows end to end.
Why It Matters
Permission removal is only real when access actually narrows. The Exorcist traces the whole chain, because the agent's effective authority is the union of everything that was ever granted.
What the Chapter Gives You
How to trace effective permissions across inheritance, the revocation test that proves removal worked, and why the second key is always found after the first one is revoked.
Want the full chapter? Grab the free cheat sheet, read an excerpt, or get the book.
Recognize this one in your codebase?
Free cheat sheet, excerpts, and interactive diagnostics.