CClaude Cert Prep
P5Governance, Safety & Risk ManagementConcept

Least Privilege

Also: principle of least privilege · PoLP · minimal scope · need-to-know

Grant an agent, tool, or credential only the minimum access needed for its task — nothing more.

View .md

Why CCAR-P tests this

The exam tests whether you scope agent and tool permissions to the narrowest set that still does the job, limiting blast radius.

What it is

Least privilege means every identity — a user, an agent, a service account, a tool integration — holds only the permissions required for its specific function, and no broader. A summarization agent gets read access to the one collection it summarizes, not admin on the whole database.

For LLM systems this is the primary limiter of blast radius when a prompt injection or model error slips through. If an agent can only read a scoped resource, a compromised prompt cannot make it delete records or exfiltrate other tenants' data — the capability simply isn't granted. Scope tokens tightly, prefer read-only where writes aren't needed, separate credentials per tool, and expire/rotate them.

Least privilege pairs with fail-closed (default deny, grant explicitly) and with tool-call authorization (the runtime check that a specific action is within the granted scope). It is a standing property of how access is provisioned, complementing the per-request escalation and authorization checks.

Exam trap

Giving an agent a broad admin key "for convenience" or "so we don't have to change it later" is the trap — over-provisioning turns any single injection into a full compromise.

All CCAR-P concepts

Independent, unofficial study material from Claude Cert Prep. Not affiliated with Anthropic.