From abp.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.
{
"type": "abp/delta/v1",
"profile": "anthropic/claude-code-remote/ccr-container",
"mandate": "session-001/claude-code-web",
"grant_version": "2026-09-05.2",
"mandate_version": "2026-09-22",
"pack_version": "v0.8.0",
"computed_at": "2026-09-22T00:00:00Z",
"computed_by": "abp.delta/v1",
"excess": [
{
"capability": "authenticate-as.credential.signing",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "delete.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.credential.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "authenticate-as.credential.tenant",
"barrier": "boundary",
"evidence": "inferred",
"via": [
"shell (Bash)",
"harness (MCP and built-in tools)"
],
"control": "the token's scope, set by the platform (in-scope repositories only)",
"note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
"material": null,
"undo": "no",
"is_bounded": true
},
{
"capability": "write.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "create.schedule.tenant",
"barrier": "setting",
"evidence": "self-reported",
"via": [
"harness (MCP and built-in tools)"
],
"control": "the platform's routines are the operator's to list and delete",
"note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
"material": null,
"undo": "yes",
"is_bounded": false
},
{
"capability": "create.schedule.host",
"barrier": "boundary",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": "the container is ephemeral: whatever is scheduled here dies with it",
"note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
"material": null,
"undo": "yes",
"is_bounded": true
}
],
"excess_refused": [
{
"capability": "create.schedule.tenant",
"barrier": "setting",
"evidence": "self-reported",
"via": [
"harness (MCP and built-in tools)"
],
"control": "the platform's routines are the operator's to list and delete",
"note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
"material": null,
"undo": "yes",
"is_bounded": false
}
],
"excess_unstated": [
{
"capability": "authenticate-as.credential.signing",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "delete.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.credential.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "authenticate-as.credential.tenant",
"barrier": "boundary",
"evidence": "inferred",
"via": [
"shell (Bash)",
"harness (MCP and built-in tools)"
],
"control": "the token's scope, set by the platform (in-scope repositories only)",
"note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
"material": null,
"undo": "no",
"is_bounded": true
},
{
"capability": "write.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "create.schedule.host",
"barrier": "boundary",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": "the container is ephemeral: whatever is scheduled here dies with it",
"note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
"material": null,
"undo": "yes",
"is_bounded": true
}
],
"unbounded_excess": [
{
"capability": "authenticate-as.credential.signing",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "delete.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.credential.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "read.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "write.file.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "create.schedule.tenant",
"barrier": "setting",
"evidence": "self-reported",
"via": [
"harness (MCP and built-in tools)"
],
"control": "the platform's routines are the operator's to list and delete",
"note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
"material": null,
"undo": "yes",
"is_bounded": false
}
],
"shortfall": [],
"aligned": [
{
"capability": "read.record.history",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here",
"material": null,
"undo": "no",
"is_bounded": false
},
{
"capability": "send.endpoint.allowed",
"barrier": "boundary",
"evidence": "observed",
"via": [
"shell (Bash)",
"fetch (WebFetch)",
"harness (MCP and built-in tools)"
],
"control": "a mandatory egress proxy configured above this process — hosts it refuses are refused with a 403 on the CONNECT; the six hosts probed on 5 September all answered",
"note": "six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies",
"material": null,
"undo": "no",
"is_bounded": true
},
{
"capability": "execute.process.host",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "write.file.project",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "the attached working tree is writable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "write.repository.project",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)"
],
"control": null,
"note": "a repository is attached and writable",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "write.repository.tenant",
"barrier": "setting",
"evidence": "observed",
"via": [
"shell (Bash)",
"harness (MCP and built-in tools)"
],
"control": "pre-commit and pre-push hooks in the clone (the mandate hook and the insurance policy) — refuse by exit code, --no-verify passes; no branch rule at the host",
"note": "the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host",
"material": null,
"undo": "with-effort",
"is_bounded": false
},
{
"capability": "read.file.project",
"barrier": "none",
"evidence": "observed",
"via": [
"shell (Bash)",
"harness (MCP and built-in tools)"
],
"control": null,
"note": "the attached working tree is readable",
"material": null,
"undo": "yes",
"is_bounded": false
}
],
"derived_never_authored": "No field in this record is writable by a person. The way to change a delta is to change a grant or a mandate, and then recompute.",
"provisional": false,
"provisional_note": "Computed against the published shape this deployment is, whose rows were measured by the thing being profiled. The mandate side is still an elicited draft."
}