Field Notes
Tool Permissions Are the New Org Chart

An agent with broad write access is not a helper. It is a role with no job description.
Permissions decide what it can touch. That is structure, not IT trivia.
At Helio Analytics, a support agent gained CRM edit rights so it could update statuses. Someone later added delete on attachments to clear clutter. It removed a contract file a buyer still needed. No one had approved the scope change in writing.
The claim
Map agent permissions the way you map decision rights. Expand them only with a named approver and a recorded reason.
What to put on the permission sheet
- Systems the agent may read.
- Fields it may write.
- Actions it may never take.
- Who can widen scope, and how that request is logged.
Helio froze ad-hoc permission edits. Product and security co-owned a monthly review. Scope grew slower. Incidents dropped. That trade was worth it.
Leave-behind
- Print the agent's current read and write list.
- Mark anything that can move money or delete records.
- Name the approver for the next scope change.