sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · abp.sgit.ai · llms-full

On this page

Reading room / abp.sgit.ai / llms-full.txt · section 31 of 357

authenticate-as.credential.tenant

Act in accounts with the credentials it holds. Its effect is no: cannot be undone.

What this id is made of

This is not a string. It is authenticate-as↗.credential↗.tenant↗, three nodes joined by three edges, and each of them has an address, a page and a JSON file. Follow any of them and you get the query for that word rather than a definition of it.

NodeEdgeReads as
authenticate-as↗has_verbthis capability has the verb authenticate-as
credential↗acts_onthis capability acts on credential
tenant↗reachesthis capability reaches tenant
identity↗in_familythis capability is in the identity family
no↗has_undo_classthis capability has the undo class no

The gloss above is a convenience, not the definition. A node carries no inherent meaning: what authenticate-as.credential.tenant is emerges from the edges traceable from it. The strongest case is tenant↗, where the deployment shapes that use it do not agree about what it means, and the page keeps the disagreement rather than averaging it.

In 15 of 17 published shapes

Deployment shapeBarrier thereKnown byWhose materialNote
○Claude Code on the web (a remote session container)boundaryinferrednot statedfive key-shaped variables and a code-host token - the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you
●Claude Code (the CLI, on your own machine)none (not a control)derivednot statedinferred from the credentials the account holds
●Claude Code (the CLI, on your own machine)none (not a control)derivednot statedinferred from the credentials the account holds
●Claude Desktop (a desktop app with local tools)none (not a control)derivednot stated
○Claude (in the browser, with connectors switched on)boundaryderivednot stateda cloud connector acts as you
○Claude, with the Gmail connector enabled (contributed by riskmandate.ai)boundarymeasuredownacts as the account holder over the Gmail data of the connected account. "Claude mirrors your existing permissions - you cannot access information you don't already have access to in Google Workspace." The OAuth application is named "Claude for Gmail" on Google's screens. Measured 2026-09-16: the three Google screens - choose an account; "Sign in to Claude for Gmail"; "Claude for Gmail wants access to your Google Account" with the three scope lines pre-ticked - are transcribed in evidence/.
○Claude, with the Gmail connector enabled (contributed by riskmandate.ai)boundarymeasuredorganisationacts as the account holder over one mailbox, and sends as whatever the account's default send-as entry is. The operator set that default to a disclosed agent alias on a second domain, DKIM signed and confirmed aligned by a live round trip. So the agent sends as the business and cannot send as anything else, including the account's primary address.
○Claude's Microsoft 365 connector (Outlook, SharePoint, OneDrive, Teams) (contributed by riskmandate.ai)boundarydocumentedown"Users can only access Microsoft 365 data they already have permission for." Anthropic hosts the connector and holds the token.
○The official Dropbox MCP server (contributed by riskmandate.ai)boundarydocumentedown"Get the authenticated Dropbox user's identity, team/account context"; the server acts as the account, and for team users GetUsageAndQuota "will retrieve the usage and quota for the entire team".
◐A browser extension with broad host permissionssetting (not a control)documentednot statedacts inside sites where you have a session, as you
●A scheduled job running as a service accountnone (not a control)derivednot stateda service-account credential, rarely rotated
○An assistant connected to a personal Google Drive with drive.readonly (contributed by riskmandate.ai)boundarydocumentedownthe connector acts as the account holder
○An assistant connected to a personal Gmail mailbox with gmail.readonly (contributed by riskmandate.ai)boundarydocumentedownthe connector acts as the account holder, over everything the scope names
○The Google Workspace MCP servers (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat) (contributed by riskmandate.ai)boundarydocumentedownevery server acts as the user who consented - "inherit the same permissions and data governance controls as the user"
●A self-hosted n8n instance, reached with an owner-scoped API key (contributed by riskmandate.ai)none (not a control)measuredorganisationowner level on the account's personal project; the key was held for the session only and never persisted. Everything below it follows from it.
BarrierWhat stands in the wayIs it a control
●nonenothing in the wayno
◉expectationa rule in prose, enforced by nobodyno
◐settinga switch the agent's own account can flipno
○boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisedA scheduled job under a service account
refusedA coding assistant on my machine, The desktop app, with local tools switched on, Chat in the browser, nothing connected, A browser extension I installed
unstatedA coding assistant in a container on the web, Chat, with connectors switched on, A CI job on a hosted runner, A reader on my mailbox, Find things in the inbox, draft replies, never send, A reader on my drive, Search our tenant, read-only, Find and read my files, An assistant over my Workspace, reading, A sandbox: build and run one AI-agent workflow, What the agent inferred it was authorised to do, from one session

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
scoped, short-lived tokens issued to the agent rather than your own; read-only where read is all it needsan hour per service, and rotationboundary

This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. Since v0.4.3 it is also a node, setting/authenticate-as.credential.tenant, in the deployment shape universe↗: it narrows this capability and moves it to the barrier named in the third column, which is the path the prohibitions table's last column is a projection of.

The capability grammar↗ · This primitive as JSON↗


Site index for agents↗ · HTML version↗