Skip to content

Privilege packs

A privilege pack is a curated bundle of entitlements that are commonly requested together, such as “new backend engineer onboarding.” An admin builds a pack once, and a requester or a new department member then requests the whole bundle in one step. Use a pack when a group of entitlements is granted together as a matter of routine.

Requesting a privilege pack creates one access request per entitlement in the pack. Each request routes through its own approval workflow, the same as if the requester had requested each entitlement on its own.

  • A pack has a Title, an optional Description, and one or more entitlement bindings. Each binding sets the connection, the entitlement, and the request duration.
  • A pack cannot have two bindings for the same entitlement.
  • A pack must have at least one binding to be requested.
  • A pack can optionally have a Department. Trustle assigns that pack to every user who joins the matching department, in addition to letting requesters pick it manually.
  • Because an admin curates a pack, submitting it skips the guards that would otherwise hide an individual entitlement or connection from a requester. A pack always submits every binding it contains.
  • You need an org admin role to create, edit, or delete a pack. Requesters cannot manage packs.
  • Add the connections and entitlements a pack needs before you build it. The pack editor picks entitlements from your existing connections.

Go to Privilege Packs in the admin area.

Click Create Pack.

Enter a Title, such as Onboarding Pack. Optionally enter a Description to describe what access the pack grants.

Optionally choose a Department. The help text explains the effect: “All users joining this department should be assigned this privilege pack.”

Click Add Entitlement. Pick a connection, an entitlement, and a duration for each binding. Repeat for every entitlement the pack should grant. The entitlements table lists each binding you have added, and you can edit or remove one at any time.

Click Save Pack.

To change a pack later, open it, edit its title, description, department, or entitlements, and click Save Pack again. To remove a pack, open it and click Delete Pack. Deleting a pack does not revoke access already granted from a past request.

A requester picks Select a pack from the privilege pack tab of the access request flow. Choosing a pack shows its Pack Contents, the list of entitlements it grants. The requester enters a Reason and clicks Request Access.

A user who joins a department with a matching pack receives the pack’s requests automatically, pending the user’s acceptance, instead of picking the pack manually.

Submitting a pack creates one access request per binding, sharing a single pack request ID. An approver who opens that pack request approves or denies only the requests they are an authorized approver for. An org admin can act on the remaining, unassigned requests in the same pack.

An approver can approve a pack request in full, or exclude specific entitlements from the approval. Excluding an entitlement requires a comment, and the excluded request is denied with that comment instead of approved. Requests outside the approver’s authority stay pending for their assigned approver.