Sessions
Access with an end time, not an open door.
An agent does not hold access. It holds a session: a window a person opened, with a list of tools and a clock. When the window closes, the access is gone — there is no standing connection left behind.
One session, start to finish
Watch a session open, work and expire
Five calls, one window, one clock.
session-2291 · Claude · support triageopen
search_records
get_ticket
create_ticket
search_records
delete_record
approved1 hour laterEvery call above happens inside this window — and only this window.
02 Three properties
What holds a session together
Each one is checkable, and each one is the reason the window can be trusted.
The clock is part of the approval
Duration is approved along with the tools. A session cannot extend itself, and nothing renews quietly in the background.
One team’s sessions are their own
A session means nothing outside the organization it was opened in.
It can lose access mid-way
If someone leaves the team or a rule changes, a live session shrinks. It never quietly gains anything.
Next step
Where to go next
Two readers, two different next steps.