skills/skills.volces.com/least-privilege-access-design

least-privilege-access-design

Installation
SKILL.md

When to Use

Use this skill when you need to systematically reduce the damage any one user, automation, or compromised credential can cause — by granting only the access needed and no more.

Invoke it for:

  • Any service where an engineer with a production role could accidentally or maliciously cause an outage or data breach
  • Systems where admin tooling uses broad, interactive APIs (SSH to hosts, root shells, POSIX-level access) rather than narrow functional APIs
  • Designing new administrative APIs for a service where the access model hasn't been explicitly defined
  • Hardening automation credentials: automation roles often accumulate unnecessary permissions over time
  • Evaluating whether an emergency override (breakglass) policy is necessary and properly governed

Do not invoke it for selecting the cryptographic authentication mechanism, designing network segmentation, or full threat modeling — those are separate concerns.


Context and Input Gathering

Before designing least-privilege controls, gather the following:

Installs
2
First Seen
Apr 24, 2026
least-privilege-access-design from skills.volces.com