Authorization

Least Privilege

Least privilege is the principle of granting only the minimum level of access necessary to perform a legitimate task.

Acronym
PoLP
Synonym
Principle of Least PrivilegePoLP

Definition

Least privilege is an authorization design principle according to which a subject should receive only the permissions required to perform its legitimate duties, and no more. This principle applies to end users, administrators, service accounts, workloads, APIs, and machine identities. In modern environments, least privilege also has temporal and contextual dimensions: access should be limited not only in scope, but also in duration, target, sensitivity, and business need. Effective least privilege depends on good role design, permission hygiene, usage visibility, access reviews, and controlled exception handling.

Why it matters

Least privilege reduces blast radius, fraud potential, accidental misuse, and the impact of account compromise.

The Ariovis perspective

Least privilege is an operating model, not a one-off cleanup. Access must be justified, limited in scope and duration, traceable and removable when the context changes.

Common pitfalls

  • Organizations often declare least privilege as a principle while maintaining broad shared roles, persistent admin rights, and uncontrolled exceptions.

Standards and protocols

Reference standards
  • NIST SP 800-53
  • ISO/IEC 27001

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.