Network-infrastructure permissions matter because changing a port, prefix, route, firewall rule, load balancer, management path, or automation credential can alter connectivity and exposure for many services at once. Read-only access can also reveal topology, configurations, traffic patterns, device identities, or packet contents.
The structure should separate architecture, physical access, device administration, address allocation, route control, security policy, observation, change execution, validation, emergency response, automation, vendor support, and entitlement review. Workflow authorizes a specific task; permission determines what the identity can technically do before, during, and after that task. This distinction also determines how firewall rule and entitlement review should be evidenced and reconciled.