SECURITY / A CONCEPT NOTE
Least Privilege
the default should be 'no'
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
The security principle that users, programs, and service roles should only be granted the minimum necessary permissions to perform their tasks, and nothing more.
02 / FOLLOW THE MECHANISM
How privilege is restricted
Baseline deny
new service account starts with zero permissions (default block).
Audit run
operator reviews requirements: this service only needs to write log files.
Scope grant
attaches a policy granting write-only access to log storage folder.
Audit loop
monitors permissions periodically, removing unused access codes.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
find unused permissions on an IAM role
aws iam generate-service-last-accessed-details --arn arn:aws:iam::...The ellipsis omits required code or values. This sketch is not runnable as written.
05 / CHECK YOURSELF
Could you explain Least Privilege to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identitySecrets Rotationkeys that expire on purpose