One compromised user should not be enough
A rogue or compromised user can only do what their role and your policies allow.One leaked key should not be enough
Service account credentials live on servers, in CI systems, and in secret managers. They leak more often than passkeys, so scope them for containment.Policies that don’t protect you
A policy can exist and still not protect you.Blind spots
You can’t react to what you don’t see.Lockout risks
Hardening cuts both ways: check that you can’t lock yourself out.Next steps
Security best practices
The reasoning and configurations behind each checklist item
Create policies
Step-by-step policy creation in the dashboard