Permissions are enforced at the system level not based on user behaviour
Enforcing permissions at the platform level, with no shared logins standing in for real access control, is what makes A.5.15's role-based rules hold in practice.
The Sekit technical control enforces permissions at the platform level with no shared logins, the concrete enforcement mechanism this ISO control requires rather than a policy alone.