A payment gateway's permission structure determines who can see transactions, issue refunds, change checkout settings, and connect other systems. These are different responsibilities. A support agent who needs to find a customer's payment should not automatically receive the same access as the person who manages the merchant account.
Good permissions let people finish routine work while limiting the damage from a mistake or a compromised login. The useful question is specific: can this person perform the required action on the right transactions without gaining unrelated financial or administrative powers?