In practice
It applies to more than staff accounts. API keys, background jobs, integrations and AI agents all run with some level of access, and they are routinely given administrator rights because it was quicker during development and nobody revisited it. Scoped credentials, short-lived tokens and a periodic review of what each key can do cost very little.
Where it fits in a build
Everywhere, and especially in any system where a model reads content from outside the organisation — because whatever the model is allowed to do becomes what an attacker can do the moment an injection succeeds.
Common mistakes
- One administrator API key shared across every integration.
- Permissions granted for a one-off task and never removed.
- Developers holding production access by default rather than by request.
Related terms
Working on something that involves this?
ASTACKRA designs and builds AI systems, automation and custom software for businesses that need technology shaped around their own workflow. If this term turned up in a proposal and you want a straight answer about whether it applies to your situation, ask us — no obligation, and we will tell you if the answer is no.
ذات صلة