The Problem Nobody Solves
You can patch every server, harden every policy, complete every module engagement — and still lose ground every quarter. Because nobody is taking objects away.
A departed contractor’s account lingers. A temporary ACL becomes permanent. A VM spun up for a migration is forgotten but still reachable. A service principal granted broad consent for a project nobody remembers still holds it. The estate accretes objects continuously.
The usual answer is “we’ll schedule a cleanup sprint.” The cleanup sprint never happens, because it is never urgent — until it is the breach.
Why a Team Beats an Activity — The Sign Flip
A housekeeping activity is throughput gated by attention. Attention is the most volatile and preemptible resource in any IT organisation: the moment there is an incident, an audit, or a project deadline, the housekeeping stream drops to zero.
A housekeeping team is throughput gated by headcount, which is stable. It cannot be quietly defunded by reprioritisation, because it is a line item and a contract, not a good intention.
That difference is categorical, not marginal. The estate accretes objects continuously. If cleanup drains slower than accretion, the attack surface grows even while the team is “doing housekeeping.” A dedicated team that drains faster than accretion crosses zero net-throughput and flips the sign: bounded and shrinking instead of unbounded growth.
The dedicated team is not a faster bailer. It is the difference between a bucket and a pump.
| Housekeeping as activity | Housekeeping as team | |
|---|---|---|
| Throughput gated by | Attention (volatile, preemptible) | Headcount (stable) |
| Behaviour under incident/deadline | Drops to zero | Holds a floor |
| Net effect on attack surface | Usually negative (accretion > drain) | Positive (drain > accretion) |
| Defunding | Silent, by reprioritisation | Explicit, requires cancelling a contract |
Why This Is the Security Function Built to Be Outsourced
Most security functions outsource badly because they need deep, current context. Housekeeping is the exception:
- Procedural throughput, not context. Disabling an account whose owner left fourteen months ago and which has not authenticated since does not require understanding your business. Procedure plus throughput is the definition of outsourceable work.
- Counter-cyclical to your own attention. It is the work nobody internal will ever prioritise because it is never urgent until the breach — which is exactly why it should be somebody else’s entire business.
- SLA-able on clean metrics. Backlog aging, items closed per cycle, time-from-uncovered-to-owned, and the attack-surface trend line are all measurable and contractible.
- ASTRAL-gated for trust. Every disposition is an owned, prioritised, client-approved backlog item gated through an ASTRAL pull request. You see every action. The backlog is the control surface — that is what makes handing the work to an outside team an easy yes.
The Two Modes
The same team, the same backlog, and the same tooling deliver two distinct services. They differ on one axis — who assigns priority — and everything else follows from it.
Mode 1 — Client-Directed (The Night-Shift Crew)
The night-shift cleaning crew works around your operations, to the rota you set, and the office is clean in the morning. You point; they clean. The client owns prioritisation — the team drains whatever the client puts in front of it, within change-management constraints, never forcing a window the client has not agreed.
Character: cheap, slow, safe, thorough, non-disruptive.
Payoff: linear and reliable. The attack surface stops growing and slowly recedes.
Ideal for: organisations that know they have accumulated debt, want it worked down continuously, and prize operational stability over speed.
Mode 2 — Kill-Chain (The Strike Team)
Priority is assigned by security analysis — the kill chain, not operational comfort. The team closes the chain from the outside, deliberately unconstrained by the normal change calendar, because the point is to remove existential paths faster than bureaucracy would ever allow.
Character: expensive, fast, disruptive, asymmetric payoff.
Payoff: asymmetric. A small number of targeted removals on the kill chain yields disproportionate risk reduction. The chain-length trend does not bend — it drops.
Ideal for: post-incident, pre-audit, pre/post-M&A, or any organisation that has accepted it is carrying existential exposure and wants it gone faster than its own processes permit.
Requires: executive air cover. Disruption is a feature here, not a bug.
Switchability Is the Product
A client can move between modes as conditions change. The default posture is Mode 1: cheap, continuous, safe. When a triggering event arrives — a breach, an audit deadline, a kill-chain assessment that surfaces an unacceptable shortest path — the same team escalates into Mode 2 for a defined window, closes the existential paths under executive air cover, then drops back to Mode 1 maintenance.
You are not buying two teams. You are buying one team with a throttle — cheap continuity plus the option to surge when the threat justifies it.
What the Team Drains
Stale user, contractor, and service accounts with no owner. Orphaned group memberships and permissions that outlasted their project. Old app registrations and service principals. Enrolled devices no longer in use. Conditional Access policies with no named owner. Legacy protocols (NTLM, basic auth, SMBv1). DNS records for decommissioned services. Temporary firewall rules gone permanent. Old GPOs, admin rights, and certificates.
The Authorisation Rail
A team that disables accounts and removes ACLs needs one bad disposition away from severing something load-bearing. The safety is not trust — it is structure:
- Every disposition is a backlog item gated by an ASTRAL pull request the client approves. Nothing is removed silently.
- Soft-disable with a reversal window before hard delete. Disable, wait, confirm nothing broke, then remove.
- Freeze / break-glass mode. During an active incident, the housekeeping loop is freezable so the team never reverts an incident-response action.
- Explicit scoping. The team’s authority is bounded to named object classes and named scopes, documented and approved.
Commercial Tiers
| Tier | What it is | Best for |
|---|---|---|
| Assessment & Backlog Standup | Kill-chain assessment + ASTRAL/PULSAR feeders, backlog populated and prioritised, scope and authorisation rail defined | Clients with accumulated debt and no queue yet |
| Mode 1 Retainer | Continuous, change-windowed backlog attrition at contracted throughput | Stable-state clients wanting the surface worked down without disruption |
| Mode 2 Engagement | Time-boxed, exec-sponsored campaign to collapse existential paths | Post-incident, pre-audit, M&A, or unacceptable kill-chain exposure |
| Switchable Retainer | Mode 1 baseline with pre-agreed Mode 2 escalation triggers and rates | Clients who want cheap continuity and the option to surge |
SLA metrics are the same across all tiers: items closed per cycle, P0/P1 aging, time-from-uncovered-to-owned, and the attack-surface / kill-chain-length trend.
The Antifragile Connection
Housekeeping as a Service is the human action layer beneath the CQRE tooling: ASTRAL and PULSAR surface and prioritise; the housekeeping team acts on it. The ASTRAL identity-ownership extension — death signals (owner account disabled), silence signals (no authentication in a year), and change signals (property mutations) — manufactures prioritised backlog items automatically. Detect → accrete → drain → report, in one loop.
Security is a contact sport. The tools find the work. The team finishes it.
Ready to flip the sign?
The Assessment & Backlog Standup is the right entry point — a kill-chain assessment that populates and prioritises the queue before the team picks it up.