Privilege boundaries matter more than job titles
What somebody can reach matters more than what their role is called.
Two people with the same title routinely have wildly different access, because access accumulated from projects rather than from a definition. Reviews built on titles confirm that a manager has manager permissions, and miss that this particular manager also has production database access from a migration in 2023. The question worth asking is what this account can do, not what this person is called.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Permission inheritance can hide excessive accessGranted upstairs, arrives downstairs
- Wildcard permissions widen blast radiusOne character, a much bigger circle
- Deny rules can create hard guardrailsOne no ends it
- Admin tools are part of the privileged access pathThe hand is not on the system
