SecurityScroll #021

Trust is not a security control.

Relationships and good intentions do not constrain what credentials or systems can do.

All scrolls

Interpretation

Trust can guide collaboration, but systems must enforce boundaries independently of character. Authenticate identities, authorize each action, validate inputs, and record sensitive operations. This protects the organization and the trusted person alike when credentials leak, software errs, or circumstances change.

Practice

  • Authorize server-side at every protected boundary.
  • Use short-lived, scoped credentials.
  • Audit sensitive actions with useful context.

Anti-pattern

Granting production admin because the recipient is “one of us.”