Privilege boundaries become fragile. Users can inherit access across customer accounts, administrators may manage the wrong tenant, and application code starts carrying authorisation logic that should have lived in the identity layer. The result is inconsistent enforcement and a higher chance of accidental overexposure.