Glossary · 28 Sep 2026

What is least-privilege access?

← Glossary

Least-privilege access means giving each person, system and AI tool only the access its job needs, and no more. A national standards body's security glossary defines it as "The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function".

Why it matters

Access that isn't needed is risk without benefit. A stolen password can only reach what its owner could reach. A mistaken bulk update can only change what its author was allowed to change.

AI tools change the picture

Businesses now connect AI assistants and agents to their systems. Postman, which sells API and agent tooling, found in its 2025 survey that "51% of developers now cite unauthorized agent access as a top security risk".

The key design question is whose access an assistant uses. Microsoft's Copilot Studio documentation offers "User authentication" for data "that only the user has access to", and "Agent author authentication" for cases where access "is implicit, or for low-risk use cases". An assistant running on the asking user's permissions can only reach what that user could. One running on a broad service account lets any user reach whatever the account can.

In a timber business

Worth checking: do office staff hold full ERP access because it was simpler to set up? Do former contractors still have logins? Do integrations run as administrator accounts?

How to apply it

Give each person, system and AI tool its own identity, so its actions can be traced. Start from no access and add what the role needs. Make AI tools read-only by default. Review access when people change roles or leave, on a schedule the business sets.

The trade-off

In a small office, strict limits can push people to share logins or export data "just in case". That is worse than broad access that is logged. The aim is access matched to real roles, with a record of what each account did.

Quarri's security page sets out how customer data is isolated, encrypted and audited.

Sources

  1. NIST Computer Security Resource Center, glossary, "least privilege": csrc.nist.gov
  2. Microsoft Learn, "Configure user authentication for tools", Copilot Studio, last updated 7 April 2026: learn.microsoft.com
  3. Postman, "2025 State of the API Report": postman.com

Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.

See it on your own data.

Live in two weeks, on the systems you already run.