Broad platform privileges increase blast radius and abuse potential.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Theoretical construct: explains a term, principle, or mental model.
Concrete cog in the system that works inside larger relationships.
Excessive platform privileges occur when users, services, or automations have more access to a platform than their task requires.
The approach builds on the long-standing information-security requirement for minimal rights. OWASP continues this principle across applications, service accounts, and platform administration.
A caretaker receives a master key for every room even though the job needs one corridor. If the key is misused or lost, the possible damage is much larger than with a key limited to the required room.
The concept captures a concrete system property that affects engineering decisions.
This concept reduces attack surface and blast radius through narrowly scoped roles, temporary elevation, and regular permission review.
This concept reduces attack surface and blast radius through narrowly scoped roles, temporary elevation, and regular permission review.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.