Writing
What Posture Actually Means

Posture as a Continuous Process, Not a Quarterly Audit

The quarterly audit is a photograph of a moving river. Identity drifts daily; here's what it takes to operate posture as a loop instead of an event.

Michael AbramovichJune 13, 20263 min read

The quarterly audit is a photograph of a river. It's accurate for the instant the shutter opens and wrong by the time you've printed it, because the thing it measured is moving. Identity posture drifts daily — new tenants, new apps, new joiners and leavers, new vendor defaults — and a process that inspects it four times a year is, by construction, wrong most of the year. If you take one idea from this series, take this: posture is a loop you run, not an event you schedule.

Why identity drifts faster than other things

Some things stay configured. Identity doesn't, because it's coupled to everything that changes in a business. Every hire and departure moves it. Every new SaaS tool adds an integration and a set of grants. Every product you use ships new defaults. Every client (if you're an MSSP) does all of this on their own schedule, without telling you. The result is continuous entropy aimed straight at your controls. MFA coverage that was 100% on Monday is 99% on Friday because someone spun up a tenant. The drift isn't a failure; it's the normal weather, and the audit is umbrella-shopping once a season.

What a loop looks like

Operating posture as a process means closing four steps continuously, not annually:

  1. See. Maintain live coverage of the estate — accounts, apps, integrations, recovery flows — and know what fraction you can't see. Drift mostly enters through the parts you're not watching.
  2. Detect. Notice when a gap opens: a new account without MFA, a new high-permission OAuth grant, a privileged factor reset. The detection has to be continuous because the gaps are.
  3. Decide. Triage. Not every gap is urgent; weight by exposure so the privileged, sensitive-data risks move first.
  4. Close — and confirm it stayed closed. Fix it, then verify it didn't quietly reopen. Recurrence is its own failure mode.

The metric that matters for this loop isn't a static score; it's mean time to close — how long between a gap opening and you shutting it. A quarterly audit makes that number, at worst, three months. A loop makes it hours or days. That delta is the actual security difference.

The economics force the cadence

There's a reason the quarterly audit persists despite being obviously stale: continuous is expensive if you do it by hand. Re-checking every control across every tenant, every day, is not a thing a human team does manually at any scale. So organizations default to the cadence they can afford — quarterly — and accept the drift in between as invisible risk. That's a budget decision masquerading as a methodology.

Which is exactly why this is a problem worth automating the detection of, while keeping the ownership human. You can automate "see, detect, and flag" so the loop runs continuously without a person re-checking by hand. What you can't automate is the deciding and the accountability — someone still owns whether a given exposure is acceptable for a given client. The loop is continuous; the judgment in it is human.

What changes when you operate it this way

  • You stop trusting snapshots. A clean audit becomes "clean as of a moment," not "clean," and you plan around the drift you know is coming.
  • You measure your operation, not just the estate. Time-to-close, drift rate, and recurrence tell you whether your process works — which is what posture is.
  • You make coverage a first-class goal. The loop's blind spots are where breaches enter, so expanding what you can see beats polishing the score on what you already do.
  • You match cadence to change. Daily change demands daily verification. Anything slower is a known, quantifiable gap, not a methodology.

The takeaway

A posture program that runs on a quarterly cadence is measuring a daily-changing system four times a year and calling the photographs "the river." Operate it as a loop instead — see, detect, decide, close, confirm — and judge it by how fast you close gaps, not by the score on the last snapshot. The audit can stay; it's a fine checkpoint. It just isn't the posture. The posture is what you do in the three months between audits, every day, while the river keeps moving.


Running this loop continuously across many clients — without a human re-checking every control by hand, but with a human owning every decision — is what we build Aurelion for. If quarterly snapshots have stopped feeling like enough, I'd be glad to talk.

#posture #process #mssp #operations