Least privilege good practice
Apply data governance by granting only the access needed, for as long as it is needed, and to the right people.
When to use this
- Use it when designing access rules.
- Use it in periodic governance reviews.
- Use it when torn between broad access and restricted access.
Before you start
- Have defined approval criteria.
- Know how sensitive the data involved is.
- Use well-named groups and roles.
Step by step
- Start by understanding the business purpose.
- Choose the most restricted data set that meets that purpose.
- Prefer a Group whenever the access is shared by more than one person.
- Use expiry for temporary needs.
- Use masks and filters to reduce exposure.
- Review broad rules often.
- Remove access that has no use or no clear owner.
What happens next
- The organization reduces risk without blocking legitimate work.
- Auditors can understand why a grant exists.
- Managers keep rules easier to review.
Common errors
- Granting everything to settle a one-off urgency.
- Keeping temporary access with no expiry.
- Granting individual access when a controlled group would be right.
- Duplicating per-user rules with the same catalog, schema, and table: the rule repeats itself.
Good practice
- Standardize group and rule names.
- Document the purpose and deadline in your organization's approval processes.
- Review exceptions before they become the norm.
- Prefer a Group for any access shared by more than one person.
- Keep access minimal: specific tables where possible; a whole catalog or schema only when the person needs to create new objects, such as building bronze, silver, and gold layers.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.