Skip to main content
Cybersecurity

Least Privilege

A security principle that grants users only the minimum level of access needed to perform their job functions, limiting potential damage from compromised accounts.

The principle of least privilege (PoLP) dictates that users, applications, and systems should be granted only the minimum access rights necessary to perform their intended functions. No more, no less.

Least privilege reduces the blast radius of a compromise: if an account with minimal permissions is breached, the attacker’s access is limited. It also reduces the risk of accidental damage: users can’t accidentally delete resources they don’t have access to.

For teams, least privilege applies directly to credential management: not every team member needs access to every password. A team password manager with group-based access controls lets administrators assign credentials by role, ensuring developers access development tools while marketing accesses marketing platforms.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide