Minimum permissions for web service account

I need to restrict a domain account so that it can only do tasks through web service calls, and not allow console login. What are the rights / permissions I need to give the account in EEM so that it can only execute these web service calls against processes?