host (reach)
The reach host as a node: the 8 capability primitives it appears in, what they reach, and how it connects. Meaning from connectivity, not from a definition.
Source: https://abp.sgit.ai/model/lexicon/reaches/host/index.html↗ · site v0.11.0 · this file is generated from the same content
as the page, so the two cannot drift. Every page on this site has a .md twin; internal links
below point at them.
Home↗ / The model↗ / The lexicon↗ / host
host
the machine, container or account it runs as
A node carries no inherent meaning. What
hostmeans here emerges from the edges traceable from it, and confidence in that meaning is proportional to how richly it is connected. It is connected to 8 of 23 primitives here. That, and not the sentence above, is what it means. The discipline this follows ↗.
What the shapes say host means, and they do not agree
These definitions are not merged, and that is the design. Merging two vocabularies erases the disagreement, and the disagreement is the finding. Each row below is owned by the shape that said it. A reader deciding what
hostcosts them has to read the row for the shape they run, not an average of the rows. Why vocabularies are bridged rather than merged ↗.
| The shape | Variant | What host means there |
|---|---|---|
| Claude Code on the web (a remote session container)↗ | ccr-container | this container - ephemeral, the vendor's; not your machine |
| Claude Code (the CLI, on your own machine)↗ | local-confirmations-off | your machine, as your user account |
| Claude Code (the CLI, on your own machine)↗ | local-default | your machine, as your user account |
| Claude Desktop (a desktop app with local tools)↗ | default | your machine, as your user account |
| Claude (in the browser, with connectors switched on)↗ | connectors-on | what the drive connector is scoped to; not your machine |
| Claude, with the Gmail connector enabled↗ | default | the mailbox itself: every message and thread, labels, filters and saved drafts, and attachment metadata - never attachment content |
| Claude, with the Gmail connector enabled↗ | measured-2026-09-19 | the mailbox itself, whole: every message and thread including archived, sent and trashed mail, every label with its counts, every draft; attachment content on the way out, up to 25MB |
| Claude's Microsoft 365 connector (Outlook, SharePoint, OneDrive, Teams)↗ | default | SharePoint sites and OneDrive files the user can already open - searched tenant-wide |
| The official Dropbox MCP server↗ | default | the Dropbox account as a store - and for a team user, "the usage and quota for the entire team" |
| A browser extension with broad host permissions↗ | broad-host-permissions | your browser - every page, every logged-in site |
| A scheduled job running as a service account↗ | service-account | the server it runs on, as the service account |
| Actions runner (a hosted CI job)↗ | ci | the runner - destroyed after the job; not your machine |
| An assistant connected to a personal Google Drive with drive.readonly↗ | readonly-connector | the Drive as a store: every file owned by or shared to the user |
| An assistant connected to a personal Gmail mailbox with gmail.readonly↗ | readonly-connector | the mailbox itself, as a store: every message and the account's mail settings |
| The Google Workspace MCP servers (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat)↗ | default | the Google account's Drive and mailbox - every file owned by or shared to the user; not your machine |
| A self-hosted n8n instance, reached with an owner-scoped API key↗ | owner-api-key | the instance itself: its accounts, its credential store, its execution records |
| ChatGPT (in the browser, no connectors)↗ | default | the vendor's environment; not your machine |
That is the ABP's own argument in one column. The same word, the same grammar, and a materially different exposure depending on where the agent runs. It is why an ABP is about the deployment rather than the product.
The 8 primitives with this reach
| Primitive | Published gloss | Spelled out | Undo | In how many shapes |
|---|---|---|---|---|
create.schedule.host↗ | Create something that outlives the turn where it runs (a cron, a service) | create↗.schedule↗.host↗ | yes | 4 of 17 |
delete.file.host↗ | Delete files anywhere the account can reach | delete↗.file↗.host↗ | no | 5 of 17 |
execute.process.host↗ | Run programs as the account | execute↗.process↗.host↗ | with-effort | 7 of 17 |
read.credential.host↗ | Read credentials stored where it runs | read↗.credential↗.host↗ | no | 11 of 17 |
read.file.host↗ | Read any file the account can reach | read↗.file↗.host↗ | no | 11 of 17 |
read.record.browsing↗ | Read every page you visit | read↗.record↗.host↗ | no | 1 of 17 |
read.record.history↗ | Read a retained record: shell history, past sessions | read↗.record↗.host↗ | no | 8 of 17 |
write.file.host↗ | Change any file the account can reach | write↗.file↗.host↗ | with-effort | 8 of 17 |
How this node connects
| Edge | Reads as | To |
|---|---|---|
reachable_from | host is the reach of these 8 primitives | 8 capabilities |
reaches | the inverse, walked the other way, with different fan out | one capability at a time |
This node as JSON↗ · The lexicon↗ · The edge vocabulary↗