Deny rules can create hard guardrails
Most permission systems work by granting. A deny rule works the other way and cannot be overridden by somebody granting themselves more.
That makes it useful for the small number of things that must never happen regardless of who asks: deleting the audit logs, disabling the security tooling, moving data out of a region. It is a blunt instrument and that is the point. A guardrail that a sufficiently senior person can simply grant their way past is not a guardrail.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Privilege boundaries matter more than job titlesRead the account, not the business card
- Permission inheritance can hide excessive accessGranted upstairs, arrives downstairs
- Wildcard permissions widen blast radiusOne character, a much bigger circle
- Admin tools are part of the privileged access pathThe hand is not on the system
