non-privileged access
A category of system access in which the account, role, or session carries only standard user permissions and is explicitly excluded from administrative, security-function, or other elevated capabilities reserved for privileged users. It is distinguished from privileged access by the absence of authorizations to execute security-relevant operations such as modifying system configurations, managing accounts, or administering cryptographic functions. In practice, frameworks use it both as a classification of access type and as an operational requirement — mandating that even users who hold privileged accounts switch to non-privileged accounts or roles whenever they perform ordinary, non-security functions, thereby limiting the attack surface exposed during routine work.