How Many Dormant Permissions Are You Carrying?
From "the list is long" to an actual number
Pull the unused-permissions report from AWS IAM Access Analyzer, Azure Access Reviews, or GCP Policy Analyzer and the list is usually long — but "long" isn't a number anyone can act on. Enter your environment's scale and that percentage, and this turns it into an actual count, including how many of those dormant permissions are the kind that matter most if something goes wrong.
Your environment
Rough counts are fine — this is an estimate, not an audit.
Assumptions (adjust if you have better numbers)
"High-risk" here means action types like delete, create-user, attach-policy, and other write/admin-tier actions — the ones where an unused grant is most worth prioritizing first.
Where the number comes from
| Category | Count |
|---|
What if you addressed some of this next review cycle?
See what removing a share of dormant permissions would leave for the next cycle.
This is the aggregate version of the usage-delta matrix from Phase 3 of the NHI rollout guide — pulling the per-identity list and finding it long is the starting point; this is roughly how long. The same guide's shadow-policy dry-run is the mechanism for safely removing what shows up here without breaking anything that turns out to still be needed.
Export this breakdown. Download this — including your inputs and the what-if comparison — as a PDF to share with your team. Requires a free subscription.