Quick answer
Entitlements (/admin/entitlements, HR admins only) is where you grant a worker access to a resource — an API, an MCP server, a tool, a browser, a model, a provider, a lane, a token or rupee budget, a data class or an approval limit. Every grant has an expiry date. Low-risk grants start straight away; high-risk grants wait until a different person approves them.
Workforce is in beta. It is listed on the Modules page with no price yet.
How do I request a grant?
Pick the worker
Choose the person, agent, service, vendor or team from the list.Pick the resource type and reference
Choose a resource type and type the reference, for example the tool or model name.Add an amount where it applies
For an approval limit or a rupee budget, enter the amount in INR.Select Request
The grant is recorded with you as the grantor and the default term: 90 days for agents and services, 180 days for people.
Which grants count as high risk?
- Access to the restricted or regulated data class.
- An approval limit above 1 lakh rupees.
- Anything that touches money, payments, billing, payouts, secrets, credentials, API keys, tokens, environment settings, production, the main branch, migrations or deployments. These are owner-only: only your designated owner can decide them.
A high-risk request shows as requested until a different, active person selects Approve or Reject. The person who requested it cannot decide it, and an agent or service never can.
How do renewal, expiry and revocation work?
- Renew gives an active or expired grant a fresh default term. A high-risk grant cannot be renewed in place — request it again so it is approved again.
- Expiry runs every hour: grants past their expiry date move to expired.
- Revoke ends a grant at once and asks you for a reason.
- A protected grant (owner access) can never be revoked or expired.
Every request, approval, rejection, renewal and revocation is recorded in the audit log.
What do I need before I can approve or revoke?
Your own sign-in must be linked to an active human worker. If the page says your account is not linked, see the Workers article.
How do I check that grants are still needed?
Run an access review: every active grant in scope becomes an item for someone to keep, renew or revoke.
Frequently asked questions
- How long does a grant last?
- 90 days for agents and services and 180 days for people, counted from when the grant starts. After that it expires unless someone renews it.
- Can I approve a grant I requested myself?
- No. A different, active person must approve a high-risk request. Agents and services can never approve anything.
- Does ASHR.work block access in my other tools?
- ASHR.work keeps the record of who may access what and answers "is this allowed right now?" through the entitlement check API. Your other tools have to ask it; ASHR.work does not change their settings itself.
Related articles
How do I keep a register of workers — people, AI agents, services and vendors?
The Workers register lists every person, AI agent, service, vendor and team that does work for you, with an owner and supervisor for each.
How do I run an access review?
An HR admin opens an access review campaign, decides keep, renew or revoke for each grant, and closes it. Grants left undecided expire on close.
How do I register and govern AI workers (agents)?
Give each AI agent a profile with default-deny allowlists, approve its prompt versions with a second person, roll back, and pull a kill switch.