sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · abp.sgit.ai

On this page

Reading room / abp.sgit.ai · raw text · live ↗

From abp.sgit.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

authenticate-as.credential.signing

Sign commits with the key it holds. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say.

Source: https://abp.sgit.ai/model/capabilities/authenticate-as.credential.signing/index.html↗ · site v0.11.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a .md twin; internal links below point at them.


Home↗ / The model↗ / The capabilities↗ / authenticate-as.credential.signing

authenticate-as.credential.signing

Sign commits with the key it holds. Its effect is no: cannot be undone.

What this id is made of

This is not a string. It is authenticate-as↗.credential↗.tenant↗, three nodes joined by three edges, and each of them has an address, a page and a JSON file. Follow any of them and you get the query for that word rather than a definition of it.

NodeEdgeReads as
authenticate-as↗has_verbthis capability has the verb authenticate-as
credential↗acts_onthis capability acts on credential
tenant↗reachesthis capability reaches tenant
code↗in_familythis capability is in the code family
no↗has_undo_classthis capability has the undo class no

The gloss above is a convenience, not the definition. A node carries no inherent meaning: what authenticate-as.credential.signing is emerges from the edges traceable from it. The strongest case is tenant↗, where the deployment shapes that use it do not agree about what it means, and the page keeps the disagreement rather than averaging it.

In 3 of 17 published shapes

Deployment shapeBarrier thereKnown byWhose materialNote
●Claude Code on the web (a remote session container)none (not a control)observednot statedcommits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) - not with yours
●Claude Code (the CLI, on your own machine)none (not a control)documentednot statedif commit signing is configured for the account, the agent signs as you
●Claude Code (the CLI, on your own machine)none (not a control)documentednot statedif commit signing is configured for the account, the agent signs as you
BarrierWhat stands in the wayIs it a control
●nonenothing in the wayno
◉expectationa rule in prose, enforced by nobodyno
◐settinga switch the agent's own account can flipno
○boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisednone
refusedA coding assistant on my machine, A coding assistant in a container on the web
unstatedThe desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account, A reader on my mailbox, Find things in the inbox, draft replies, never send, A reader on my drive, Search our tenant, read-only, Find and read my files, An assistant over my Workspace, reading, A sandbox: build and run one AI-agent workflow, What the agent inferred it was authorised to do, from one session

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
a signing key of the agent's own, so its commits are signed as it and not as you (the registry's identity records exist for this)an hour, and a second key to manageboundary

This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. Since v0.4.3 it is also a node, setting/authenticate-as.credential.signing, in the deployment shape universe↗: it narrows this capability and moves it to the barrier named in the third column, which is the path the prohibitions table's last column is a projection of.

The capability grammar↗ · This primitive as JSON↗


Site index for agents↗ · HTML version↗