• A DDL trigger at the server scope could do this. I think you'd want to look at these events:

    • ALTER_AUTHORIZATION_SERVER
    • ADD_SERVER_ROLE_MEMBER
    • ADD_SERVER_ROLE_MEMBER - you'd want this one so you can see if there is someone adding then quickly dropping the permissions
    • .

    • GRANT_SERVER