This objective ensures that even authorized users can only perform specific actions or access certain functions as defined by their role. It focuses on enforcing least privilege—users should only be able to do what they are explicitly authorized to do.