What Is the Principle of Least Privilege?
The principle of least privilege says every actor should hold only the permissions its task requires, for only as long as it needs them. Stated by Saltzer and Schroeder in 1975, it bounds the damage of any mistake, compromise, or manipulation: what an actor cannot do, it cannot be tricked into doing. For an autonomous agent with tools and credentials, least privilege is the single most effective containment against prompt injection and error.
The cheapest strong defence
Most security effort goes into stopping bad things from happening. Least privilege accepts that some will, and makes them survivable: an agent scoped to read one inbox cannot drain a wallet no matter what a prompt injection tells it, because the authority simply was not granted.
It is why the estate pairs capable agents with narrow authority and human consent on consequential actions — the model can fail, and the limits are what keep a failure from becoming an incident.
Related standards
Questions
Is least privilege the same as zero trust?
Related: zero trust removes implicit trust in the network; least privilege minimises granted authority. They are used together.
Does it slow things down?
A little scoping cost up front, in exchange for bounding every future failure — usually the best trade an agent system can make.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.