The principle answers the question nobody asks until it is too late: when this account is compromised — not if — what can it reach? An automation that only needs to read invoices should not be able to delete them; a support login should not see payroll. Every extra permission is free damage handed to the attacker.
It applies everywhere: IAM roles, database users, API keys, the tool permissions an AI agent gets. The audit question is always 'what is the smallest set that still works?' — and the answer is almost always smaller than what is currently granted.
Related terms
Zero trust
A security model that trusts nothing by default — every request is verified by identity and context, even inside the network.
AI guardrails
The checks around a model that constrain what it can say and do — input filters, output validation, permissioned tools — so a bad response fails safely.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
