sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

MANDATE — what the agent is authorised and expected to do

A starting point, not a survey. It is written to be argued with, and the correction is usually upward: read it and tell us where it is wrong.

Vault claude-code-web · status template · shape anthropic/claude-code-remote/ccr-container · grant 2026-09-05.2 · mandate 2026-09-09 · vocabulary abp.sgit.ai v0.3.0 · as at 2026-09-15


Mandate id coding-assistant-in-a-container · status starting-point · authored 2026-09-09 by the site, as a starting point — not measured, not surveyed; the first thing to argue with

In one paragraph

I attached a repository and I want it worked on: read it, change it, run things, commit, and push to that repository — that is why I attached it. The container is disposable, so what it does to the container's own files is its business. I do not want it signing as me, and I do not want it creating sessions or routines that keep going after this one ends.

What is wanted (6)

CapabilityWhat it isReach
read.file.projectRead the project it is working onproject
write.file.projectChange the project it is working onproject
execute.process.hostRun programs as the accounthost — this container — ephemeral, the vendor's; not your machine
write.repository.projectCommit to the repository it was pointed atproject
write.repository.tenantPush to a code host (any branch it can reach)tenant — the attached repository and the platform's scoped tokens; not your accounts
send.endpoint.allowedReach a permitted list of hoststenant — the attached repository and the platform's scoped tokens; not your accounts

What is explicitly not wanted (3)

CapabilityWhat it isReach
authenticate-as.credential.signingSign commits with the key it holdstenant — the attached repository and the platform's scoped tokens; not your accounts
create.schedule.tenantCreate something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)tenant — the attached repository and the platform's scoped tokens; not your accounts
read.record.historyRead a retained record: shell history, past sessionshost — this container — ephemeral, the vendor's; not your machine

Unstated (14)

Named neither way. For the ones that are in the grant, this is authority nobody scoped — see DELTA.md.

CapabilityWhat it isIn the grantNote
authenticate-as.credential.tenantAct in accounts with the credentials it holdsyesunstated: the scoped platform token is how it pushes at all — not a want, not a refusal, a mechanism
create.record.worldPublish packages, images or pages under the name it holdsno
create.schedule.hostCreate something that outlives the turn where it runs (a cron, a service)yes
delete.file.hostDelete files anywhere the account can reachyes
execute.process.selfRun programs inside its own sandbox onlyno
grant.credential.selfChange its own permission settingsno
read.credential.hostRead credentials stored where it runsyesunstated: the only keys in the image are the session's own
read.file.hostRead any file the account can reachyesunstated: host is the container, and the container is thrown away
read.message.tenantRead mail or chat it is connected tono
read.record.browsingRead every page you visitno
send.endpoint.worldReach any host on the internetno
send.message.worldSend a message to anyoneno
write.budget.tenantSpend money or tokens against an account it holdsno
write.file.hostChange any file the account can reachyes

Correct it

Move any capability between the three lists in data/mandate.json and rebuild. Three questions settle most rows:


This describes the deployment shape as at this date. If the risk changed, the deployment changed — not this document. No score, rating, level or traffic light appears in this vault or in its data, and none will. The behaviour policy describes; it does not judge. Generated by scripts/site/build-abp-vault.mjs from data/grant.json, data/mandate.json and the pinned vocabulary; data/mandate.json is the only file a person writes. Licence: the published template is CC BY 4.0; a paid copy carries a commercial licence to the buyer. See LICENCE.md.