sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

AGENT BEHAVIOUR POLICY — Claude Code on the web, with one repository attached

For one agent in one deployment: everything it can do, what you authorised, the gap between the two, and what actually stands in the way. It describes and it does not judge, so it carries no score.

Vault claude-code-web · status template · shape anthropic/claude-code-remote/ccr-container · grant 2026-09-05.2 · mandate 2026-09-09 · vocabulary abp.sgit.ai v0.3.0 · as at 2026-09-15


Four objects, and the verb attached to each

ObjectWhat it isHow it is obtainedHere
The mandateWhat the agent is authorised and expected to doElicited — you already know itMANDATE.md — 6 wanted, 3 refused, 14 unstated
The grantEverything the agent can doMeasured — from the shape, the account, the credentialsGRANT.md — 15 capabilities, 13 measured
The deltaExcess and shortfallDerived — recomputed whenever either input moves, never editedDELTA.md — 9 excess, 7 unbounded, 0 shortfall
The barrierWhat stands between the agent and each capabilityRecorded per row, one of four kindsthe third column of every table

The deployment

Claude Code on the web (a remote session container), Anthropic. A managed cloud container, ephemeral, one git repository attached, an egress proxy above it, and a set of harness tools scoped by the platform. MEASURED, by the thing being profiled: the shell probed on 5 September with probes/run.py, the fetch tool's reach and the harness tools reported by the operator. HOST MEANS THE CONTAINER, not your machine; TENANT means the platform's scoped tokens, not your accounts. The same environment measured on 26 August is the Grant & Mandate library's first entry, and the two agree on every row they share.

The mandate, in one paragraph

I attached a repository and I want it worked on: read it, change it, run things, commit, and push to that repository — that is why I attached it. The container is disposable, so what it does to the container's own files is its business. I do not want it signing as me, and I do not want it creating sessions or routines that keep going after this one ends.

The whole grant, with the mandate beside it

Irreversible rows first. ✓ marks a measured row.

CapabilityWhat it isBarrierUndoEvidenceMandate
authenticate-as.credential.signingSign commits with the key it holds● nonenoobserved ✓refused by the mandate
delete.file.hostDelete files anywhere the account can reach● nonenoobserved ✓unstated by the mandate
read.credential.hostRead credentials stored where it runs● nonenoobserved ✓unstated by the mandate
read.file.hostRead any file the account can reach● nonenoobserved ✓unstated by the mandate
read.record.historyRead a retained record: shell history, past sessions● nonenoobserved ✓refused by the mandate
authenticate-as.credential.tenantAct in accounts with the credentials it holds○ boundarynoinferredunstated by the mandate
send.endpoint.allowedReach a permitted list of hosts○ boundarynoobserved ✓in the mandate
execute.process.hostRun programs as the account● nonewith-effortobserved ✓in the mandate
write.file.hostChange any file the account can reach● nonewith-effortobserved ✓unstated by the mandate
write.file.projectChange the project it is working on● nonewith-effortobserved ✓in the mandate
write.repository.projectCommit to the repository it was pointed at● nonewith-effortobserved ✓in the mandate
write.repository.tenantPush to a code host (any branch it can reach)◐ settingwith-effortobserved ✓in the mandate
read.file.projectRead the project it is working on● noneyesobserved ✓in the mandate
create.schedule.tenantCreate something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)◐ settingyesself-reportedrefused by the mandate
create.schedule.hostCreate something that outlives the turn where it runs (a cron, a service)○ boundaryyesobserved ✓unstated by the mandate

The delta

9 in the grant that the mandate did not ask for. 3 of those it refused; 6 it never mentioned. 7 have nothing but a setting, a sentence or nothing at all in the way. Nothing wanted is missing.

Unbounded excess:

Prohibitions, each with its barrier

Every line an agent is asked to observe, next to what enforces it. A prohibition shown without its barrier is a claim this document cannot support.

LineBarrierEnforced by
Do not authenticate-as.credential.signing — sign commits with the key it holds● nonenothing
Do not delete.file.host — delete files anywhere the account can reach● nonenothing
Do not read.credential.host — read credentials stored where it runs● nonenothing
Do not read.file.host — read any file the account can reach● nonenothing
Do not read.record.history — read a retained record: shell history, past sessions● nonenothing
Do not authenticate-as.credential.tenant — act in accounts with the credentials it holds○ boundarythe token's scope, set by the platform (in-scope repositories only)
Do not write.file.host — change any file the account can reach● nonenothing
Do not create.schedule.tenant — create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)◐ settingthe platform's routines are the operator's to list and delete
Do not create.schedule.host — create something that outlives the turn where it runs (a cron, a service)○ boundarythe container is ephemeral: whatever is scheduled here dies with it
Stop and report if a task needs anything above◉ expectationnothing — and this is the line that makes the rest useful

What is blocked, and who holds the block

Everything above is what the agent can do once every block is applied. These are the things something withholds — and the record says what, because a ceiling the credential itself enforces and a tool a vendor has not shipped are different objects with different lifespans.

Validity

This describes the deployment shape as at this date. If the risk changed, the deployment changed — not this document. As at 2026-09-15, against grant 2026-09-05.2, mandate 2026-09-09, vocabulary v0.3.0. Void when: the grant version changes — a product release, a setting, a connector enabled or removed; the mandate changes — the deployer authorises more or less; the vocabulary version changes — a primitive is added, split or renamed; a barrier moves — a setting becomes a boundary, or a boundary is removed.

Where a score would live, and why it is not here

The same behaviour policy is dangerous in one deployment and harmless in another, and nothing about the document changed. A score needs the assets and the consequences, and this document has neither. That is not a preference; it is where the information is.


This describes the deployment shape as at this date. If the risk changed, the deployment changed — not this document. No score, rating, level or traffic light appears in this vault or in its data, and none will. The behaviour policy describes; it does not judge. Generated by scripts/site/build-abp-vault.mjs from data/grant.json, data/mandate.json and the pinned vocabulary; data/mandate.json is the only file a person writes. Licence: the published template is CC BY 4.0; a paid copy carries a commercial licence to the buyer. See LICENCE.md.