Drift detection
Catch the permission that was only meant to be temporary
Access granted for one campaign rarely gets taken back. FlowSentinel compares live permissions to your approved baseline and shows every difference.
Example data, not a real portal
FlowSentinel
Dashboard
Portals
Users
Drift
Security
Hygiene
Audit
Drift
Permission drift
UserBaseline roleLive roleChange
user-01@example.comSales repSales managerEscalated
user-02@example.comMarketingMarketing + exportAdded
user-03@example.comService agentService agentMatched
user-04@example.comRead onlyRead onlyMatched
user-05@example.comNot in baselineSuper adminUnreviewed
Details
How the comparison works
Baseline import
Upload the approved permission set per portal as a spreadsheet. Deactivated accounts are marked so they stop appearing in live views.
Field-level differences
Role, team membership and permission set are compared individually, so you see what changed rather than just that something did.
Escalations first
Increases in access are ranked above reductions, so a rep who became a manager surfaces before a tidy-up removal.
Super admin exemptions
Where a super admin has no baseline role, the exemption is recorded as an informational note instead of a false drift finding.