Evaluation & safety · Glossary term
What is Least Privilege?
Giving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
Why does Least Privilege matter?
Models can make mistakes or follow malicious instructions. Narrow permissions reduce the damage any one failure can cause.
Least Privilege in practice
Give a documentation agent read access to source files and write access to one branch, but no production credentials or merge permission.
What is the common confusion about Least Privilege?
Authentication proves identity. Least privilege limits what that identity can do.
Learn Least Privilege in the course
No lesson links to this term yet. Search the course catalog for it.
Related terms
- SandboxAn isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host…
- Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
- Prompt InjectionAn attack or failure mode in which untrusted content influences a model to disregard intended instructions, expose data, misuse tools, or…
- Tool ContractThe complete agreement for a tool boundary: purpose, typed inputs, outputs, validation, permissions, side effects, errors, timeouts,…
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
- Data ExfiltrationUnauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted…
- Data MinimizationFor personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose.
- Defense in DepthUsing independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the…
- GuardrailsSystem controls that constrain inputs, tool use, outputs, permissions, and escalation.
- Instruction HierarchyA rule set for resolving conflicts among instructions from sources with different authority, such as application policy, users, and…
- MCP (Model Context Protocol)An open JSON-RPC protocol for a host to connect to servers that expose tools, resources, prompts, and extensions through defined request,…
- Separation of DutiesDividing conflicting responsibilities or authority across independent roles so one principal cannot complete a high-risk action without…
- Threat ModelA documented account of protected assets, trust boundaries, potential adversaries, assumed capabilities, attack paths, impacts, and…
- Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…
- Zero TrustA security model that grants no implicit trust from network location or asset ownership and instead evaluates each access request against…
More terms in Evaluation & safety
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.