Back to Admin console

How do I grant, renew and revoke a worker's access with entitlements?

Entitlements are time-bound access grants for workers. Every grant expires unless renewed, and high-risk grants need a second person to approve.

~4 min read · For admin · Updated 7 Oct 2026

Quick answer

Entitlements (/admin/entitlements, HR admins only) is where you grant a worker access to a resource — an API, an MCP server, a tool, a browser, a model, a provider, a lane, a token or rupee budget, a data class or an approval limit. Every grant has an expiry date. Low-risk grants start straight away; high-risk grants wait until a different person approves them.

Workforce is in beta. It is listed on the Modules page with no price yet.

How do I request a grant?

  1. Pick the worker

    Choose the person, agent, service, vendor or team from the list.
  2. Pick the resource type and reference

    Choose a resource type and type the reference, for example the tool or model name.
  3. Add an amount where it applies

    For an approval limit or a rupee budget, enter the amount in INR.
  4. Select Request

    The grant is recorded with you as the grantor and the default term: 90 days for agents and services, 180 days for people.

Which grants count as high risk?

  • Access to the restricted or regulated data class.
  • An approval limit above 1 lakh rupees.
  • Anything that touches money, payments, billing, payouts, secrets, credentials, API keys, tokens, environment settings, production, the main branch, migrations or deployments. These are owner-only: only your designated owner can decide them.

A high-risk request shows as requested until a different, active person selects Approve or Reject. The person who requested it cannot decide it, and an agent or service never can.

How do renewal, expiry and revocation work?

  • Renew gives an active or expired grant a fresh default term. A high-risk grant cannot be renewed in place — request it again so it is approved again.
  • Expiry runs every hour: grants past their expiry date move to expired.
  • Revoke ends a grant at once and asks you for a reason.
  • A protected grant (owner access) can never be revoked or expired.

Every request, approval, rejection, renewal and revocation is recorded in the audit log.

What do I need before I can approve or revoke?

Your own sign-in must be linked to an active human worker. If the page says your account is not linked, see the Workers article.

How do I check that grants are still needed?

Run an access review: every active grant in scope becomes an item for someone to keep, renew or revoke.

Frequently asked questions

How long does a grant last?
90 days for agents and services and 180 days for people, counted from when the grant starts. After that it expires unless someone renews it.
Can I approve a grant I requested myself?
No. A different, active person must approve a high-risk request. Agents and services can never approve anything.
Does ASHR.work block access in my other tools?
ASHR.work keeps the record of who may access what and answers "is this allowed right now?" through the entitlement check API. Your other tools have to ask it; ASHR.work does not change their settings itself.