Skip to main content

Least privilege good practice

Apply data governance by granting only the access needed, for as long as it is needed, and to the right people.

When to use this​

  • Use it when designing access rules.
  • Use it in periodic governance reviews.
  • Use it when torn between broad access and restricted access.

Before you start​

  • Have defined approval criteria.
  • Know how sensitive the data involved is.
  • Use well-named groups and roles.

Step by step​

  1. Start by understanding the business purpose.
  2. Choose the most restricted data set that meets that purpose.
  3. Prefer a Group whenever the access is shared by more than one person.
  4. Use expiry for temporary needs.
  5. Use masks and filters to reduce exposure.
  6. Review broad rules often.
  7. Remove access that has no use or no clear owner.

What happens next​

  • The organization reduces risk without blocking legitimate work.
  • Auditors can understand why a grant exists.
  • Managers keep rules easier to review.

Common errors​

  • Granting everything to settle a one-off urgency.
  • Keeping temporary access with no expiry.
  • Granting individual access when a controlled group would be right.
  • Duplicating per-user rules with the same catalog, schema, and table: the rule repeats itself.

Good practice​

  • Standardize group and rule names.
  • Document the purpose and deadline in your organization's approval processes.
  • Review exceptions before they become the norm.
  • Prefer a Group for any access shared by more than one person.
  • Keep access minimal: specific tables where possible; a whole catalog or schema only when the person needs to create new objects, such as building bronze, silver, and gold layers.

Next steps​