sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · what-can-it-do.games.sgit.ai

On this page

Reading room / what-can-it-do.games.sgit.ai · raw text · live ↗

From what-can-it-do.games.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

Run programs as the account

execute.process.host: which products grant it, what stands in the way, what narrows it, and who wants it.

Source: https://what-can-it-do.games.sgit.ai/map/capabilities/execute.process.host/index.html↗ · site v0.8.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a .md twin; internal links below point at them.


Play↗ / The map↗ / The capabilities↗ / Run programs as the account

Run programs as the account

execute.process.host — execute × process at host reach (the machine, container or account it runs as). Family: process. Effect: recoverable from a backup, a history or a revert, at a cost.

Granted by 6 of 9

ProfileControl on the pathEvidenceVia
Claude Code — web container↗● noneobservedshell (Bash)
Claude Code — local · confirm off↗● nonederivedshell (Bash)
Claude Code — local · confirm on↗◐ settingderivedshell (Bash)
Claude Desktop — local tools↗◐ settingderivedlocal files and commands (when enabled)
Scheduled job — service account↗● nonederivedthe job
GitHub Actions — hosted runner↗● noneobservedthe job's shell

What narrows it

The setting: keep the confirmation prompt on for commands, and run in a container: execution survives inside it and stops being execution on your machine

What it costs: a click per command · an afternoon for the container

Tier after: setting (prompt) · boundary (container)

Questions that ask about it

In the mandates

Edit the primitives ↗ · edit the reductions ↗


Site index for agents↗ · HTML version↗