Field Notes · 3 March 2026

Writing Password Exceptions That Expire On Purpose

Exception lists grow quietly. Here is a simple structure that keeps temporary permissions temporary.

Handwritten exception log beside a closed laptop

Exception lists grow because saying yes is easier than redesigning a process. Six months later, nobody remembers why the guest Wi-Fi password still sits on the reception desk.

Write every exception with four fields: who requested it, which system, the business reason in one sentence, and a review date. Put the review date in a shared calendar, not only in the policy appendix.

When the date arrives, renew deliberately or close the exception. Silence should never equal permanence. Managers need a short script for saying “this temporary access ends Friday” without sounding punitive.

During password policy gap reviews, we often find expired exceptions still active. Cleaning that list before a full rollout removes half the arguments launch week would otherwise create.

Talk through your rollout questions