Give users, services, and administrators only the permissions they need, and review those permissions over time.
- least privilege
- role based access control
- application security
- identity management
Start with roles and responsibilities
Map common tasks to a small set of roles and separate sensitive actions from routine access. Avoid broad administrator permissions as a shortcut for solving workflow friction.
Cloud, Data & Security
Thoughtful decisions compound over time.
Practical product work brings technical choices back to the people and workflows they are meant to serve.
Protect service credentials
Use distinct credentials for environments and integrations, store them in a managed secret mechanism, and rotate them when exposure is suspected. Never place secrets in source control.
Review access as people and systems change
Remove dormant accounts and check privileged access after role changes. A security assessment can help find permissions that have accumulated without a current business need.
Practical application
Create test accounts for each business role and verify both allowed and denied actions. Check that API endpoints enforce the same access rules as the interface; hiding a button is not authorization.