Least privilege means every person, job and service gets exactly the access its task needs, which limits the damage of a stolen password or a buggy job. BookNest's sales report should read orders and nothing else. Given customers and orders tables (created by demos/ch01/privacy/setup.sql):
CREATE ROLE sales_report NOLOGIN;
GRANT SELECT ON orders TO sales_report;
SET ROLE sales_report; -- act as the job's role
SELECT count(*) AS orders, sum(total) AS revenue FROM orders;
SELECT email FROM customers;
UPDATE orders SET total = 0;Output
orders | revenue
--------+---------
2 | 174.00
(1 row)
ERROR: permission denied for table customers
ERROR: permission denied for table ordersThe report got its numbers; the attempt to read emails and the accidental update were both refused. Apply the same pattern everywhere: one service account per pipeline, short-lived credentials, and regular reviews, because access only grows unless someone removes it. Securing the Warehouse, Securing a Kafka Cluster and Security and Lakehouse Costs apply least privilege to warehouses, Kafka 129 and object storage.