Least privilege means giving a principal only the access needed for its current task. A read-only service with delete access creates a larger blast radius if its credentials are stolen.
The demo lets a reader role perform READ while blocking WRITE and DELETE. Authorization should also account for the target resource and context, and unused grants should be removed.
When to use
Apply it when defining user roles, API tokens, service accounts, and database credentials.