Zero Standing Privileges
An access model where no one holds permanent elevated rights; privileges are granted just in time and expire automatically. The strongest form of least privilege for admin access.
Zero standing privilege is the outcome that makes a privileged access program measurable: count the identities holding permanent elevated rights and drive it toward zero. It also changes what a compromised admin workstation means, since there is nothing to inherit at rest. The prerequisite is an elevation path fast enough that engineers use it during an incident rather than keeping a standing account "just in case".
See also: just-in-time access, least privilege, what is PAM, break-glass
Related on Start with Identity
- GlossaryPrivilege Escalation
Gaining higher access than originally granted, by exploiting misconfigurations, vulnerabilities, or over-permissioned identities. Tightly linked to privileged a
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryEntitlement
A specific permission or right an identity holds over a resource. Governance and CIEM exist to keep entitlements understood, justified, and minimal. Entitlement
- GuideRolling out zero standing privileges
[Zero standing privileges](/glossary/zero-standing-privileges/) (ZSP) is the strongest form of [least privilege](/glossary/least-privilege/): no human holds per
- ArticleZero Standing Privileges: Eliminating Persistent Access with JIT, JEA, and Ephemeral Credentials
A practical guide to implementing zero standing privileges through just-in-time access, just-enough access, ephemeral credentials, and workflow automation to dr
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a