LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What does the least-privilege principle demand, and which four design principles follow from it?

An authenticated identity receives only the access rights needed to fulfil a concrete task (need to know): as much access as necessary and as little as possible, for exactly the task, resource and moment that require it. It implies fine-grained resources, minimal context-dependent permissions, just-in-time and just-enough access, and traceability.

Least privilege in the centre with its four consequences: fine-grained resources, minimal context-dependent permissions, just-in-time and just-enough access, traceability

* Least privilege and the four design consequences it forces. *

Least privilege is the design principle behind good authorisation. The four consequences:

  1. Fine-grained resources: you cannot grant "only what is needed" if the smallest grantable unit is "the whole database". Resources must be cut small enough.
  2. Minimal, context-dependent permissions: restrict the actions, the scope, the time and the context in which a right applies.
  3. Just-in-time and just-enough access: rights are granted when the task starts and withdrawn when it ends, and only to the extent the task needs, instead of standing rights held forever.
  4. Traceability: every grant and every use must be logged, so that it can be reviewed.

The reason is damage limitation: a compromised or careless account can only do what its rights allow, so fewer standing rights mean a smaller blast radius.

Go deeper:

From Quiz: IAM / IAM Fundamentals: Terms, Identity and Actors | Updated: Sep 17, 2026