Least Privilege as a Default

Least privilege means every person, job and service gets exactly the access its task needs, which limits the damage of a stolen password or a buggy job. BookNest's sales report should read orders and nothing else. Given customers and orders tables (created by demos/ch01/privacy/setup.sql):

A read-only role for one job, in PostgreSQL 18
CREATE ROLE sales_report NOLOGIN;
GRANT SELECT ON orders TO sales_report;
SET ROLE sales_report;                      -- act as the job's role
SELECT count(*) AS orders, sum(total) AS revenue FROM orders;
SELECT email FROM customers;
UPDATE orders SET total = 0;
Output
 orders | revenue
--------+---------
      2 |  174.00
(1 row)
ERROR:  permission denied for table customers
ERROR:  permission denied for table orders

The report got its numbers; the attempt to read emails and the accidental update were both refused. Apply the same pattern everywhere: one service account per pipeline, short-lived credentials, and regular reviews, because access only grows unless someone removes it. Securing the Warehouse, Securing a Kafka Cluster and Security and Lakehouse Costs apply least privilege to warehouses, Kafka 129 and object storage.