Routine~12min

The Phantom Admins

Security review flagged something odd — we've got users with admin role who've never shown up in the audit log, not once. Every real admin action gets logged, so zero entries means those permissions have just never been used. Could be an orphaned service account, could be a deprovisioning gap we missed. Need to know which, and why.

Tables you'll query

usersaudit_log

What you'll learn

JOINs
Investigate this case →