Most apps start with a wide-open role and carve exceptions later. That creates silent privilege creep.
Prefer default-deny: every action is blocked until a grant says otherwise. New features stay locked until you deliberately open them. Audits get easier because you can list who was granted what, instead of hunting for forgotten carve-outs.
If a new endpoint needs access tomorrow, add an explicit permission. Don’t widen an existing role “just for now.”
Top comments (0)