Least privilege means every user, service account, and job gets only the permissions required to do its job, nothing more.
BAD:
spark-etl-role = s3:* on all buckets + admin on warehouse
GOOD:
spark-etl-role:
read s3://lake/bronze/orders/*
write s3://lake/silver/orders/*
no delete on gold BI schemas
no IAM adminWhy it matters
Limits blast radius of a leaked key, a buggy job, or a compromised account. A transform job should not be able to drop production gold tables "by accident."
Apply least privilege to
- Cloud IAM roles for each pipeline identity
- Warehouse roles (raw reader ≠ mart owner ≠ analyst)
- Orchestrator connections and secrets scope
- Human access (prod write vs read-only)
Related ideas
Separation of duties (who deploys vs who approves), short-lived credentials, and periodic access reviews.
Interview tip: Define least privilege, give a pipeline role example with narrow S3/SQL paths, and mention blast-radius reduction. That is the security answer interviewers want.