Use roles to limit privilege, not to collect it
Distinguish useful role-based access from role sprawl that violates least privilege.
The move: keep roles job-shaped. Role-based access is useful when it turns repeated approvals into a governed pattern. It is dangerous when it hides privilege under friendly names. The test is simple: can the owner explain why each permission belongs in the role? Watch for three signals of role sprawl. First, the role has a vague name such as standard, power, or all-team. Second, the role contains permissions from different risk levels, such as read, export, and admin. Third, exceptions are added permanently because nobody wants to design a better path. Fix role sprawl by separating baseline access from elevated…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in