Consent, Identity & Human Agency / Access and Decision Rights
SUB-T04-059Least-Privilege Access
Definition
Least-Privilege Access is the study and design of how people establish, exercise, verify, delegate, constrain, revoke and recover control within access and decision rights.
Why this matters
Failures in least-privilege access can expose people to identity fraud, unauthorised decisions, coerced data use, loss of access, unfair exclusion, surveillance and diminished human agency.
Research questions
How can least-privilege access be designed and governed so that identity, consent and authority remain accurate, understandable, revocable, contestable and aligned with the person’s actual intentions?
Hypotheses
A purpose-limited, evidence-backed and revocable approach to least-privilege access, with explicit authority boundaries and human-readable controls, will improve user agency, reduce misuse and increase decision legitimacy compared with opaque, bundled or non-revocable approaches.
Proposed methods
policy and standards analysis; consent-flow mapping; identity and access-control testing; user research; threat modelling; adversarial simulation; usability and comprehension testing; audit-log analysis; rights-impact assessment; methods adapted specifically to Least-Privilege Access
Stakeholders and beneficiaries
individuals; families; workers; consumers; platforms; governments; identity providers; regulators; legal practitioners; financial institutions; health and social services