That hell wouldn't exist without the guys who like to endlessly and "dutifully" set up and rearrange security groups, IAM, ldap hierarchies, just in order to feel important I guess. Every company bigger than a dozen of employees has this type of guys and they are nightmare to work with; they vision is very often detached from the reality how the company works, but somehow they have the illusion that the policy existi…
These guys are often hired to implement regulation or certification requirements and the organization, if its goal is to comply, has to change its behavior and processes. Not saying your point is not true, I met guys who did it just because too. But it's not always malice or incompetence on their part.
This meant that the janitors had the same security responsibilities as the CFO.
It was ... invigorating.
The consultants that recommended it made a lot of money, though, so I guess it's all good.