If you have not heard of this before, the NCSC explains it thus:
“Access to your network and the assets within it should be controlled. The principle of ‘least privilege’ should be followed and means users and systems have access only to the resources needed to do their job.” https://www.ncsc.gov.uk/guidance/network-security-fundamentals.
How are you implementing this, and especially in relation to shared systems such as a CRM or fundraising database, and systems containing special category data?