sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · abp.sgit.ai · llms-full

On this page

Reading room / abp.sgit.ai / llms-full.txt · section 9 of 357

The capability grammar

verb.object.reach. 23 primitives, 10 verbs, 9 object classes and 5 reach classes. This grammar is the action vocabulary for everything else on this site, and it was not invented here.

This site did not author this. The grammar, the 23 primitives and their published glosses come from the capability map↗. Promoting an ontology means giving it an address, not a new vocabulary, so nothing here is renamed. A new primitive is a new verb, object class or reach, and it needs a probe; a specific path, host or mailbox is an instance of a primitive, never a new one.

The reach classes

ReachWhat it means
selfthe agent's own process, sandbox or turn
projectthe working tree or workspace it was pointed at
hostthe machine, container or account it runs as
tenantthe organisation's accounts, repositories and services
worldanything on the internet

What host, tenant and world mean is the deployment's to say, not the grammar's. For an agent in a vendor's container, host is the container and tenant is a scoped token: not your machine and not your accounts. Every example page states its own reach names for this reason.

The 23 primitives

PrimitivePublished glossReachUndoIn how many shapes
read.file.project↗Read the project it is working onprojectyes7 of 17
write.file.project↗Change the project it is working onprojectwith-effort6 of 17
read.file.host↗Read any file the account can reachhostno11 of 17
write.file.host↗Change any file the account can reachhostwith-effort8 of 17
delete.file.host↗Delete files anywhere the account can reachhostno5 of 17
read.record.history↗Read a retained record: shell history, past sessionshostno8 of 17
execute.process.host↗Run programs as the accounthostwith-effort7 of 17
execute.process.self↗Run programs inside its own sandbox onlyselfyes0 of 17
send.endpoint.allowed↗Reach a permitted list of hoststenantno1 of 17
send.endpoint.world↗Reach any host on the internetworldno7 of 17
read.credential.host↗Read credentials stored where it runshostno11 of 17
authenticate-as.credential.tenant↗Act in accounts with the credentials it holdstenantno15 of 17
grant.credential.self↗Change its own permission settingsselfyes3 of 17
send.message.world↗Send a message to anyoneworldno4 of 17
read.message.tenant↗Read mail or chat it is connected totenantno6 of 17
write.repository.project↗Commit to the repository it was pointed atprojectwith-effort4 of 17
write.repository.tenant↗Push to a code host (any branch it can reach)tenantwith-effort4 of 17
authenticate-as.credential.signing↗Sign commits with the key it holdstenantno3 of 17
create.record.world↗Publish packages, images or pages under the name it holdsworldno3 of 17
write.budget.tenant↗Spend money or tokens against an account it holdstenantno2 of 17
create.schedule.host↗Create something that outlives the turn where it runs (a cron, a service)hostyes4 of 17
create.schedule.tenant↗Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)tenantyes3 of 17
read.record.browsing↗Read every page you visithostno1 of 17

The rules that come with the set

The capabilities as JSON↗ · The source bytes↗

Provenance. 21 of 99 capability rows from the published map were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Those rows trace to the published capability map↗, retrieved 2026-09-11T13:00:37Z, content hash sha256:d6d4ba40f1fb1f93f66. The source bytes↗. A further 42 rows across 8 shapes were contributed by riskmandate.ai, 16 of them at the contributor's measured tier and 26 read from vendor documentation on a date; this site did not observe any of them and keeps the tier as stated. Retrieved 2026-09-20T17:23:43Z, content hash sha256:cb76bf9147de9ec2e38. The contributed bytes↗.


Site index for agents↗ · HTML version↗