The idea
Authentication establishes an identity; authorization evaluates its allowed actions. People and workloads can have different identity mechanisms. Avoid shared accounts that obscure accountability, and use appropriate multifactor protection for people. An authenticated identity is not automatically entitled to every resource.
Worked example
A fictional analyst signs in successfully but can only read the reporting bucket. A background import service uses its own workload identity. Sharing an administrator account between both would grant excessive authority and make their actions harder to distinguish.
Try it
List two people and one fictional service with their tasks. Assign separate identities and define what successful sign-in does and does not permit. Identify an administrative action none of these daily tasks needs.
