Deny rules can create hard guardrails

Most permission systems work by granting. A deny rule works the other way and cannot be overridden by somebody granting themselves more.

That makes it useful for the small number of things that must never happen regardless of who asks: deleting the audit logs, disabling the security tooling, moving data out of a region. It is a blunt instrument and that is the point. A guardrail that a sufficiently senior person can simply grant their way past is not a guardrail.

More on Authorisation and privilege