sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · what-can-it-do.games.sgit.ai

On this page

Reading room / what-can-it-do.games.sgit.ai · raw text · live ↗

From what-can-it-do.games.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

Sign commits with the key it holds

authenticate-as.credential.signing: which products grant it, what stands in the way, what narrows it, and who wants it.

Source: https://what-can-it-do.games.sgit.ai/map/capabilities/authenticate-as.credential.signing/index.html↗ · site v0.8.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a .md twin; internal links below point at them.


Play↗ / The map↗ / The capabilities↗ / Sign commits with the key it holds

Sign commits with the key it holds

authenticate-as.credential.signing — authenticate-as × credential at tenant reach (the organisation's accounts, repositories and services). Family: code. Effect: cannot be undone.

Granted by 3 of 9

ProfileControl on the pathEvidenceVia
Claude Code — web container↗● noneobservedshell (Bash)
Claude Code — local · confirm off↗● nonedocumentedshell (Bash)
Claude Code — local · confirm on↗● nonedocumentedshell (Bash)

What narrows it

The setting: a signing key of the agent's own, so its commits are signed as it and not as you (the registry's identity records exist for this)

What it costs: an hour, and a second key to manage

Tier after: boundary

In the mandates

Edit the primitives ↗ · edit the reductions ↗


Site index for agents↗ · HTML version↗