How these notes are written
Structure
Most notes follow the same shape: what the thing is, why it is harder than it looks, the method, where the method misleads, and what to do about it.
The failure sections are not optional. A description of last-login data that omits API usage, long-lived mobile sessions and service accounts describes a method that removes the wrong accounts.
Methods over assertions
Where a note says something can be measured, it says how, using data the organisation already holds. Vendor figures are treated as claims to be tested.
Several notes are entirely procedures: measuring your discovery coverage, producing an unused-seat report, exporting OAuth grants, reconciling a hardware register against endpoint management.
The uncomfortable material
Access reviews as usually run produce nothing. A certification rate near a hundred percent with a removal rate near zero is a common outcome and it is usually presented as a success.
Consolidation frequently costs more than it saves, and the honest analysis sometimes concludes with leaving both tools in place.
Endpoint and browser telemetry is employee monitoring. It closes a real discovery gap and it is not free, and the cost is not financial.
These are stated because programmes built without them either waste effort or damage trust.
Legal material
Descriptions of data residency, retention, disposal obligations, monitoring and deductions for unreturned equipment are general and jurisdiction-dependent. They are not legal advice and the notes say so. Take advice for your jurisdictions.
Commercial position
No vendor material. No sponsored content. No affiliate links. No product rankings or recommendations.