Principle of least privilege
The principle that every user, application and service should have only the permissions needed to do its job, and only for as long as needed.
- 01
Why it matters
A hijacked account can only do as much damage as its permissions allow. In a system where everyone is an administrator, a single phishing e-mail opens access to all data. Narrower permissions also limit the impact of mistakes, such as records deleted by accident.
- 02
Example
At an agency, interns have full access to clients' hosting panels. After a permissions review, interns get content-editing rights only; server settings stay with two people.
- 03
Common mistake
Granting permissions once and never tracking leavers and role changes. Unused accounts and accumulated permissions should be reviewed at regular intervals.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.