Least privilege
Least privilege grants only the access necessary for a task.
What it is
Least privilege grants only the access necessary for a task.
When to use it
Limit user roles, database credentials, file access, and operational accounts.
Syntax
// Application DB account: required DML only
// Migration account: separate schema permissions
// Auditor: read audit records, no transaction mutationExample
// Tenant boundary in every relevant query:
$accounts = Account::where("tenant_id", $user->tenant_id)->get();
// Then authorize the requested action through a policy.Common mistakes
A local SQLite file has filesystem permissions rather than database users; protect backups as well.