That is definitely IMHO the best way, the old default deny policy - we will only allow you access to the things you can show us you have a business need to access.

The problem with this is the...