hardening-user-privileges
Installation
SKILL.md
Hardening User Privileges
Audits and tightens CockroachDB role-based access control (RBAC) by identifying over-privileged users, reducing admin grants, restricting PUBLIC role permissions, creating purpose-specific roles, and applying least-privilege principles.
When to Use This Skill
- Reducing the number of users with admin role
- Removing excessive PUBLIC role privileges (SELECT, INSERT, UPDATE, DELETE)
- Creating purpose-specific roles to replace broad admin grants
- Responding to a security audit finding about excessive privileges
- Implementing RBAC best practices for a production cluster
- Onboarding a cluster to a least-privilege access model
Prerequisites
- SQL access with admin role (required to modify grants and role membership)
- User inventory: Understanding of which users/applications need which level of access
- Application testing plan: Revoking grants can break applications that depend on them