Delegation creates chains of trust
When one system acts on behalf of another, which acts on behalf of a user, the question of whose authority is being used gets murky quickly.
Each link is reasonable. The chain as a whole often grants more than anybody intended, and when something goes wrong the logs record the last system in the sequence rather than the person who started it. The useful discipline is being able to answer, at the far end, whose authority this ultimately was.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Privilege boundaries matter more than job titlesRead the account, not the business card
- Permission inheritance can hide excessive accessGranted upstairs, arrives downstairs
- Wildcard permissions widen blast radiusOne character, a much bigger circle
- Deny rules can create hard guardrailsOne no ends it
