Lesson 11 / 24
Least Privilege for Vault Access
Choose view-only, edit or manage permissions per vault and separate production from development.
Match access to need
Most people only need to use a secret, not edit or reshare it. Give the lowest permission that lets them do their job, keep the production vault small, and review who has access regularly.
A sample access plan
Treat this as a table you maintain. Developers can read staging and CI reads only what it needs; production is limited to a small on-call group.
Vault Group Permission
Dev Backend read + edit
Staging Backend read only
Production SRE read only
Production Leads manageReview quarterly
Access creeps over time. Every few months, list who can open each sensitive vault and remove anyone who no longer needs it.
Quick check: Which setup follows least privilege?
- Everyone can manage every vault
- Developers get read-only on staging; production is limited to SRE
- One shared admin login
- Access is never reviewed
Answer
Developers get read-only on staging; production is limited to SRE — Each group has only the access its work requires.