New One-call approvals are live in the console
Permission sets

A permission set is not permission.

A permission set is a starting point: which login, which tools, how long. Nobody gets access from it. Every time it is used, a person approves that one session — and they can only take things off the list.

One request, many sessions

The same permission set, used three times

Watch what each use actually gets.

Permission setSupport triage
search_recordsget_ticketcreate_ticketclose_ticket
up to 8 hours · 2 logins grants nothing on its own
Ana · Monday
search_recordsget_ticketcreate_ticketclose_ticket
1 hour
Sam · Tuesday
search_recordsget_ticketcreate_ticketclose_ticket
15 minutes
Ana · Friday
search_recordsget_ticketcreate_ticketclose_ticket
2 hours
Each session is approved on its own — and always asks for less than the permission set.
02 Why it matters

The alternative is asking someone every time — or asking once, forever

Permission sets remove the paperwork without removing the decision.

Set it up once

Write the request for a real job — support triage, billing lookups — and your team stops assembling it by hand.

It can only shrink

At approval time, tools can be unticked and the clock shortened. Nothing can be added that was not proposed.

Checked again every time

A permission set written in March is re-checked against today’s rules and today’s team before anything is granted.

Next step

Where to go next

Two readers, two different next steps.

Security leader

See how the controls hold up in a review.

Platform engineer

Connect any client to the same address.