How it plays out on a deal
In a data room, least privilege means a tax adviser sees the tax folder, an IT reviewer sees the IT folder, and nobody keeps access after their part ends. It sounds obvious; in practice deal teams often grant broad access to save time and never narrow it.
Software helps or hurts here. Group-based permissions, expiry dates, hidden folders and a clear view of who can see what make least privilege cheap to apply. A room where every restriction takes effort will drift toward everyone seeing everything.
What to check in a review or demo
- 1Whether a report lists, for any folder, every user who can see it.
- 2Whether new users start with no access until a group is assigned.
- 3Whether access can expire automatically per user or group.
Read alongside
- Granular permissionsRights that the administrator can tune down to one document and one bidder group, instead of a single on or off switch for everybody in the room.
- Access expiryA preset end date or time after which a user, group or document is no longer accessible, without the administrator having to remove it manually.
- Role-based access control (RBAC)An access model in which rights come from a user's role, such as administrator, contributor or viewer, rather than being granted to each person one by one.
- Clean teamA small, ring-fenced group, often outside advisers, allowed to review competitively sensitive information that the buyer's business staff may not see before a deal closes.