Z4.07.3Over-broad permissionsdesignresearch

Over-coarse permissions give secondary members unexpected power

Aliases: permission creep · over-privileged users

What it is

Coarse permissions ("household member = full control of everything") overshoot: adding a flatmate for the lights also hands over arming the security system, viewing camera playback, and making purchases; granting a cleaner door access throws in whole-home control. Secondary members — children, tenants, helpers, a newly moved-in partner — receive permissions designed for the owner, not for their role.

Over-broad grants are silent: nobody itemizes the scope at grant time, nobody reviews it before use, and discovery happens only through misuse (the child disabling the fridge alarm; the flatmate arming the system and triggering it on family returning) — discovery in the form of an incident, not an audit.

Why it happens

Overshoot is not laziness but the resultant of three structural drifts.

Interface expressiveness limits. Consumer products cannot present households with a member × device × action permission matrix — that is enterprise-IT furniture. Vendors offer two or three role tiers at most; heterogeneous device inventories get folded into one homogeneous role, and overshoot is the fold's inevitable product.

The granting moment optimizes for speed. "Add family member" is a one-tap invite that prioritizes speed over scope review: no question of "control over what?", only "confirm?". The scope is unknown the instant it is granted, and it never resurfaces on its own.

The permission ratchet turns one way. Granting is a one-time event; reviewing is a non-event: a scope apt at joining time goes stale as children grow, relationships shift, or duties end, and no mechanism triggers retraction. The ratchet is unidirectional, so over-breadth accumulates monotonically — permissions fitting an eight-year-old are latent hazards at thirteen, unless someone remembers to change them, and "remembering" is precisely what the system never schedules.

Studying it

  • Preference-versus-actual comparisons: in access-control preference surveys, parental device restrictions are among the most commonly desired permission shapes; comparing each family's desired restriction list against the product's actual default grant yields the direct measure of overshoot.
  • The inventory-gap method: in homes, inventory each member's nominal effective permissions (what they can open, view, delete), then ask the administrator "what do you want them to be able to do", and compare item by item. The research question is the shape of the gap — which device classes and which roles it concentrates in.
  • Longitudinal drift measurement: repeat the inventory for the same household at multi-month intervals; the growth curve of the permission set (almost always grow-only) is the empirical form of the ratchet.

One methodological caution: when asked "what permissions does he have", administrators routinely cannot answer (not knowing is the norm) — that itself is data, not respondent failure. Collect the self-report first, then reveal the system list; the size of the gap measures how silent the overshoot is.

Where it stops holding

  • Coarse is fine on low-risk devices. Family-wide sharing of lights, sockets, and TV is unproblematic — the claim strengthens with consequence, concentrating on locks, cameras, payments, and garages, where physical and financial stakes live.
  • "Secondary" is defined by the household. A partner in one home is a day-to-day co-administrator and a guest-level presence in another — judgements of overshoot must anchor in that household's stated intent, not an external standard.
  • Culture and regulation differ. Defaults for minors' device control vary by jurisdiction (boundaries of guardianship differ); "what a child may control" has no universal answer, only household-negotiated ones.

Applying it

  • When adding a member, scope by device class at creation: "may control: lights and sockets ✓; locks, cameras, purchases: off by default, open per item" — making scope an explicit decision at the granting moment.
  • Offer role templates with review reminders: a "child (8–12)" template prompts an annual review — the ratchet needs a counter-mechanism, and a reminder is the cheapest one.
  • Make "what can they do right now" an inspectable list: administrators can see each member's effective permissions at any time, giving overshoot a channel to be discovered.
  • How to check: present the effective-permission list directly to administrators and measure the surprise rate — the share who learn only then what someone can do. Surprise rate measures how visible overshoot is, and predicts whether review will ever happen.

Related

  • Same group: Z4.07.1 Household members can hold unequal control over the same device · Z4.07.2 Over-fine permission granularity adds friction to daily life · Z4.07.4 Permission changes need to notify affected members
  • Nearby: Z4.08 Guests and temporary access · Z6.02 Permission layering
  • Search terms: over-privileged users · permission creep · role-based access control · smart home

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z4.07.3