Lesson 5 / 26
Policies & Least Privilege
JSON permission documents, and why smaller is safer.
Policies at a glance
A policy is a JSON document listing allowed or denied actions on resources. Attach it to a user, group, or role, and that identity gains exactly those permissions.
A minimal policy
This policy allows reading objects from one specific S3 bucket only — nothing else.
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-app-bucket/*"
}]
}
Output:
Grants read-only access to objects in my-app-bucket
Principle of least privilege
Grant only the permissions an identity needs, and nothing more. Start narrow and add access as required — a wide policy today is a bigger blast radius tomorrow.
Quick check: What does the principle of least privilege recommend?
- Give admin access so nothing is ever blocked
- Grant only the permissions actually needed for the task
- Never grant any permissions
Answer
Grant only the permissions actually needed for the task — Least privilege minimizes what could go wrong if credentials leak or a mistake happens.