DFIELDSOLUTIONS

Security

GlossaryLeast privilege

Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.

The principle answers the question nobody asks until it is too late: when this account is compromised — not if — what can it reach? An automation that only needs to read invoices should not be able to delete them; a support login should not see payroll. Every extra permission is free damage handed to the attacker.

It applies everywhere: IAM roles, database users, API keys, the tool permissions an AI agent gets. The audit question is always 'what is the smallest set that still works?' — and the answer is almost always smaller than what is currently granted.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain