[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-least-privilege::en":3,"gloss-cluster-least-privilege::en":23,"gloss-next-least-privilege::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"least-privilege","security","Principle of Least Privilege","The principle of least privilege (PoLP) says every user, service, and API key should hold the minimum permissions needed to do its job — and nothing more. It limits blast radius: if an account is phished or a key leaks, an attacker inherits only that narrow slice of access instead of the keys to the kingdom. In practice least privilege is less a feature than a discipline — it fights the natural drift toward over-granting because broad access is convenient and revoking it later feels risky. For SaaS builders it applies at every layer: scoped API tokens, per-service database roles, tightly bounded cloud IAM policies, and RBAC roles that match real job functions. Practical note: default new roles to deny and add permissions deliberately, prefer short-lived scoped tokens over long-lived master keys, review and prune access on a schedule (especially after people change teams or leave), and pair least privilege with an audit log so over-broad grants stay visible.","Least privilege gives every user, service, and key only the permissions it needs — so a leaked key hands an attacker a narrow slice, not everything.",null,[11,14,17,20],{"slug":12,"name":13},"audit-log","Audit Log (Audit Trail)",{"slug":15,"name":16},"rbac","Role-Based Access Control (RBAC)",{"slug":18,"name":19},"scim","SCIM (System for Cross-domain Identity Management)",{"slug":21,"name":22},"zero-trust","Zero-Trust Architecture",[24,26,30,34,37,40,43,46,49,52,55,58],{"slug":12,"category":5,"name":13,"updated_at":25},"2026-08-24T02:46:37+00:00",{"slug":27,"category":5,"name":28,"updated_at":29},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":31,"category":5,"name":32,"updated_at":33},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":35,"category":5,"name":36,"updated_at":33},"bridge-letter","Bridge Letter",{"slug":38,"category":5,"name":39,"updated_at":33},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":41,"category":5,"name":42,"updated_at":25},"byok","Bring Your Own Key (BYOK)",{"slug":44,"category":5,"name":45,"updated_at":33},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":47,"category":5,"name":48,"updated_at":29},"data-classification","Data Classification",{"slug":50,"category":5,"name":51,"updated_at":33},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":53,"category":5,"name":54,"updated_at":33},"data-minimization","Data Minimization",{"slug":56,"category":5,"name":57,"updated_at":33},"data-poisoning","Data Poisoning",{"slug":59,"category":5,"name":60,"updated_at":33},"data-processing-agreement","Data Processing Agreement (DPA)"]