The problem is that if you implement security that is too strict, then employees will find ways around it that are even worse than the more permissive method. I don’t disagree that people should have the minimum access required to do their job, but if it isn’t proprietary then the controls should be relaxed, and if someone requests access to something it needs to be responded to immediately so they are not delayed in whatever they were trying to do.
The problem is that if you implement security that is too strict, then employees will find ways around it that are even worse than the more permissive method. I don’t disagree that people should have the minimum access required to do their job, but if it isn’t proprietary then the controls should be relaxed, and if someone requests access to something it needs to be responded to immediately so they are not delayed in whatever they were trying to do.