# Least Privilege for Vault Access — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/team-least-privilege

> Choose view-only, edit or manage permissions per vault and separate production from development.

## Match access to need

Most people only need to **use** a secret, not edit or reshare it. Give the lowest permission that lets them do their job, keep the production vault small, and review who has access regularly.

## A sample access plan

Treat this as a table you maintain. Developers can read staging and CI reads only what it needs; production is limited to a small on-call group.

```text
Vault        Group       Permission
Dev          Backend     read + edit
Staging      Backend     read only
Production   SRE         read only
Production   Leads       manage
```

## Review quarterly

Access creeps over time. Every few months, list who can open each sensitive vault and remove anyone who no longer needs it.

**Quiz:** Which setup follows least privilege?

- [ ] Everyone can manage every vault
- [x] Developers get read-only on staging; production is limited to SRE
- [ ] One shared admin login
- [ ] Access is never reviewed

*Answer:* Developers get read-only on staging; production is limited to SRE. Each group has only the access its work requires.
