Change its own permission settings
grant.credential.self: which products grant it, what stands in the way, what narrows it, and who wants it.
Source: https://what-can-it-do.games.sgit.ai/map/capabilities/grant.credential.self/index.html↗ · site v0.8.0 · this file is generated from the same content
as the page, so the two cannot drift. Every page on this site has a .md twin; internal links
below point at them.
Play↗ / The map↗ / The capabilities↗ / Change its own permission settings
Change its own permission settings
grant.credential.self — grant × credential at self reach (the agent's own process, sandbox or turn). Family: identity. Effect: undone by the same actor with no loss.
Granted by 3 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — local · confirm off↗ | ◐ setting | derived | shell (Bash) |
| Claude Code — local · confirm on↗ | ◐ setting | derived | shell (Bash) |
| Claude Desktop — local tools↗ | ◐ setting | derived | local files and commands (when enabled) |
What narrows it
The setting: settings owned by a different user than the one the agent runs as, or set above the session by the platform
What it costs: minutes, if the platform supports it; otherwise the separate account
Tier after: boundary
In the mandates
- not wanted by A coding assistant on my machine↗
- not wanted by The desktop app, with local tools switched on↗
Edit the primitives ↗ · edit the reductions ↗