Privilege packs
A privilege pack is a curated bundle of entitlements that are commonly requested together, such as “new backend engineer onboarding.” An admin builds a pack once, and a requester or a new department member then requests the whole bundle in one step. Use a pack when a group of entitlements is granted together as a matter of routine.
How it works
Section titled “How it works”Requesting a privilege pack creates one access request per entitlement in the pack. Each request routes through its own approval workflow, the same as if the requester had requested each entitlement on its own.
- A pack has a Title, an optional Description, and one or more entitlement bindings. Each binding sets the connection, the entitlement, and the request duration.
- A pack cannot have two bindings for the same entitlement.
- A pack must have at least one binding to be requested.
- A pack can optionally have a Department. Trustle assigns that pack to every user who joins the matching department, in addition to letting requesters pick it manually.
- Because an admin curates a pack, submitting it skips the guards that would otherwise hide an individual entitlement or connection from a requester. A pack always submits every binding it contains.
Before you start
Section titled “Before you start”- You need an org admin role to create, edit, or delete a pack. Requesters cannot manage packs.
- Add the connections and entitlements a pack needs before you build it. The pack editor picks entitlements from your existing connections.
Configure a privilege pack
Section titled “Configure a privilege pack”Step 1: Open Privilege Packs
Section titled “Step 1: Open Privilege Packs”Go to Privilege Packs in the admin area.
Step 2: Start a pack
Section titled “Step 2: Start a pack”Click Create Pack.
Step 3: Name and describe the pack
Section titled “Step 3: Name and describe the pack”Enter a Title, such as Onboarding Pack. Optionally enter a
Description to describe what access the pack grants.
Optionally choose a Department. The help text explains the effect: “All users joining this department should be assigned this privilege pack.”
Step 4: Add entitlements
Section titled “Step 4: Add entitlements”Click Add Entitlement. Pick a connection, an entitlement, and a duration for each binding. Repeat for every entitlement the pack should grant. The entitlements table lists each binding you have added, and you can edit or remove one at any time.
Step 5: Save the pack
Section titled “Step 5: Save the pack”Click Save Pack.
To change a pack later, open it, edit its title, description, department, or entitlements, and click Save Pack again. To remove a pack, open it and click Delete Pack. Deleting a pack does not revoke access already granted from a past request.
What users see
Section titled “What users see”A requester picks Select a pack from the privilege pack tab of the access request flow. Choosing a pack shows its Pack Contents, the list of entitlements it grants. The requester enters a Reason and clicks Request Access.
A user who joins a department with a matching pack receives the pack’s requests automatically, pending the user’s acceptance, instead of picking the pack manually.
How approvals work for a pack request
Section titled “How approvals work for a pack request”Submitting a pack creates one access request per binding, sharing a single pack request ID. An approver who opens that pack request approves or denies only the requests they are an authorized approver for. An org admin can act on the remaining, unassigned requests in the same pack.
An approver can approve a pack request in full, or exclude specific entitlements from the approval. Excluding an entitlement requires a comment, and the excluded request is denied with that comment instead of approved. Requests outside the approver’s authority stay pending for their assigned approver.