The reason least privilege fails in small organisations is not disagreement, it is friction. If scoped access blocks someone in the middle of an incident, they will ask for admin and they will get it. Access control that slows people down gets routed around.
Start from what is actually used
Cloud providers all log the API calls that are made. Turn that logging on, leave it for a month, and you have an evidence-based list of what each identity genuinely needs. Guessing from documentation produces permissions that are both too broad and missing something.
A sequence that does not block work
- Give everyone a named account. Shared logins make every other step impossible.
- Enable MFA before you tighten anything else.
- Create a break-glass admin that is audited and rarely used.
- Scope the automated and service identities first — they are easier to reason about and carry the most risk.
- Then work through humans, starting with the ones whose jobs are most predictable.
Accept that it is iterative
A first pass that is 80 percent correct and in place beats a perfect model that never ships. Revisit as the audit log tells you more.