Philippines staffing research ·
Philippines Employee Access Inventory Coverage: Measuring the Unknowns
Research how to compare expected and observed access while preserving unknown, inherited, and provider-managed permissions.
Published September 1, 2026. Research question: how can an organization estimate access-inventory coverage for Philippines-based employment operations without treating unobserved permissions as absent?
Coverage compares a declared expected population with observable identity-entitlement-system records. It does not prove that permissions are appropriate, secure, used, or removed.
Methodology: create thirty synthetic worker profiles across direct accounts, groups, shared resources, application roles, tokens, physical access, provider platforms, and systems without reliable exports.
The unit is one identity-entitlement-system tuple. Record identity match, entitlement, access path, owner, purpose, approval, observed state, last review, evidence type, and verification limitation.
Classify expected and observed, unexpected, expected but unobserved, unable to observe, identity conflict, and out of scope. Keep unknowns in the declared denominator and label provider attestations.
Limitations include incomplete expected populations and uneven platform evidence. Conclusion: an honest coverage report gives unknown and unobservable paths the same prominence as confirmed records.
Sources consulted: NIST Cybersecurity Framework 2.0 (https://www.nist.gov/cyberframework); CISA Identity and Access Management (https://www.cisa.gov/topics/cyber-threats-and-advisories/identity-and-access-management); GAO Standards for Internal Control in the Federal Government (https://www.gao.gov/products/gao-14-704g); International Labour Organization, Decent Work (https://www.ilo.org/topics-and-sectors/decent-work). These sources provide general research and control context; they do not certify an employer, provider, employment outcome, or legal conclusion.