Glossary · Security and access
Least privilege
The practice of granting only the access needed for a defined task, system, and period.
Also called: principle of least privilege
Definition
Least privilege limits an account, key, service, or person to the specific resources and actions required. Permissions should be reviewable, revocable, and reduced when the task or role changes.
Why it matters
Narrow access reduces the impact of mistakes, compromised credentials, and automation behaving outside its intended scope.
Common misunderstanding
Least privilege is not one initial setup step; permissions drift and need periodic review, especially for service accounts and integrations.
Related terms
Related system family: Secure Integrations & Custom Tools
Sources
- Computer Security Resource Center glossary (opens in a new tab) · NIST
- Authentication (opens in a new tab) · NIST Computer Security Resource Center
Last reviewed July 16, 2026
