least privilege
compound.compound. the rule that a person or computer should only have access to the specific information and tools they need for their job. This helps keep systems safe because if an account is hacked, the damage is limited.
compound. a security principle requiring that users and processes are granted only the minimum levels of access — or permissions — necessary to perform their specified tasks. Often used in cybersecurity to mitigate the risk of unauthorized access or accidental system damage.
The company follows the principle of least privilege to protect its data.
By applying least privilege, the IT department ensured that the marketing intern could not accidentally delete the entire customer database.
Implementing least privilege across a distributed network architecture significantly reduces the attack surface, as compromised credentials provide limited lateral movement for potential intruders.
Coined by Jerome Saltzer in 1974. The term emerged from the field of computer security to describe a design principle for limiting system access.
Etymology adapted from Wiktionary, available under CC BY-SA 4.0.
Typically used as a compound noun in the phrase 'principle of least privilege'.
Last updated July 22, 2026