General principles
This diagram shows the permission flow. The blue line represents a basic set of permissions defined by the sandbox. The green line represents additional permissions added by the Invoke function.
The elevated permissions live only within the green box.