The principle of least privilege states that every person, application or account should have only the permissions it needs to do its job, and nothing more. If an accounting account can only see financial data, an attacker who steals it cannot reach the servers or HR records.
Related term in this glossary: IAM (identity and access management)
least privilege, PoLP, minimal privilege, least-privilege access