The principle of least privilege (PoLP) is a foundational information security concept that dictates users, applications, systems, or devices should be granted only the minimum access rights or permissions necessary to perform their required tasks—nothing more. This means that every entity in an IT environment, whether human or non-human, operates with the least amount of privilege needed to function, reducing the risk of accidental or intentional misuse of sensitive resources.