How it works
Least privilege gives a person, account or programme only the access required for its intended task. Scope and duration both matter: a permission needed once for installation need not remain enabled for everyday work. This reduces the possible impact of mistakes and misuse without assuming they can never happen.
A practical example
Someone updating website articles may need editorial access but no permission to install plugins or change payments. A camera viewer may need live video but no ability to add administrators. These examples distinguish the actual work from a convenient all-powerful account shared across unrelated tasks.
What to check
List the tasks each account must perform and compare them with available roles. Use a separate privileged account where administration is necessary, and review access after staff, devices or responsibilities change. Test ordinary workflows after reducing rights so that needed functions remain available. Document who authorizes exceptions and when they end.
Limits and safe use
Least privilege is not the same as denying every request or removing access blindly. Some systems offer only coarse roles and require a practical risk decision. It also does not authenticate the person using an account or replace backups. Shared credentials make individual accountability harder even if the account has a limited role.