At large scale, access roles multiply fast. Not by dozens. By tens of thousands. Every new service, every new team, every quick fix adds another layer. Soon your infrastructure access is a maze. No one built it that way on purpose. It just happened. Then one day, no one knows who can see what, who can deploy where, or who still has admin on a system they haven’t touched in two years.
This is the role explosion. It eats away at velocity. It erodes trust. It leaves you exposed. Audit reports turn into weeks of work. Incident resolution stalls in permissions hell. People start granting wildcard access just to get things done. Security debt piles up.
The cause is simple: infrastructure access is still built for static org charts and slow change. At scale, your org changes daily. Projects spin up and down. Teams form and dissolve. Vendors come and go. Each shift adds roles. Rarely do they get removed. The old model doesn’t scale.