Skip to content

Least privilege

Least privilege is the security principle that every person, application or AI agent gets only the minimum access needed to do its job, and nothing more.

Least privilege limits the damage when something goes wrong, whether a stolen password, a misconfigured integration or an AI agent that misreads an instruction. It matters more with AI because an agent with broad access can act at machine speed across many records.

For example, an AI assistant that drafts replies to customers might have read access to order history but no ability to issue refunds or edit account details. The common mistake is giving an integration an administrator account because it is quicker to set up. That shortcut is convenient at launch and costly after an incident, so access should be scoped and reviewed from the start.

Bring us a workflow.

Tell us where the work slows down. We will help you see where to start.

Book a discovery call