Access and continuity
Giving each person the narrowest access that lets them do their job, so that a compromised or departing account costs the least it can.
Access tends to accumulate: granted for one project, never withdrawn, inherited by whoever takes the role next. After two years the average small company has several people holding administrative rights nobody would grant them today, and no record of when or why.
The practical form is boring and works. Roles rather than individuals; the narrowest role that completes the task; a quarterly review that lists who holds administrative access to each system and requires a named person to justify each one; and a fixed expiry on anything granted for a specific piece of work. A contractor's access should end on the date the contract does, set at the moment it is granted rather than remembered afterwards.
Granting full rights to avoid a permissions conversation is the origin of nearly every access problem that surfaces later. It also removes the audit trail that would have shown what happened, because when everyone can do everything, nothing is attributable.
The definitions are the easy part. Whether the figure on your dashboard was computed this way is a different question, and usually the more expensive one.