Drift detection

Catch the permission that was only meant to be temporary

Access granted for one campaign rarely gets taken back. FlowSentinel compares live permissions to your approved baseline and shows every difference.

Example data, not a real portal

Drift

Permission drift

UserBaseline roleLive roleChange
user-01@example.comSales repSales managerEscalated
user-02@example.comMarketingMarketing + exportAdded
user-03@example.comService agentService agentMatched
user-04@example.comRead onlyRead onlyMatched
user-05@example.comNot in baselineSuper adminUnreviewed
Baseline against live permissions. All accounts shown are examples.

Details

How the comparison works

Baseline import

Upload the approved permission set per portal as a spreadsheet. Deactivated accounts are marked so they stop appearing in live views.

Field-level differences

Role, team membership and permission set are compared individually, so you see what changed rather than just that something did.

Escalations first

Increases in access are ranked above reductions, so a rep who became a manager surfaces before a tidy-up removal.

Super admin exemptions

Where a super admin has no baseline role, the exemption is recorded as an informational note instead of a false drift finding.