Reach a permitted list of hosts
send.endpoint.allowed: which products grant it, what stands in the way, what narrows it, and who wants it.
Source: https://what-can-it-do.games.sgit.ai/map/capabilities/send.endpoint.allowed/index.html↗ · site v0.8.0 · this file is generated from the same content
as the page, so the two cannot drift. Every page on this site has a .md twin; internal links
below point at them.
Play↗ / The map↗ / The capabilities↗ / Reach a permitted list of hosts
Reach a permitted list of hosts
send.endpoint.allowed — send × network-endpoint at tenant reach (the organisation's accounts, repositories and services). Family: network. Effect: cannot be undone.
Granted by 1 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container↗ | ○ boundary | observed | shell (Bash), fetch (WebFetch), harness (MCP and built-in tools) |
What narrows it
The setting: shorten the list; a host it does not need is a host it can reach
What it costs: minutes per host, and a failure the first time it needs one you removed
Tier after: boundary
Questions that ask about it
- Does its outbound traffic go through a proxy or allow-list you did not set up? — eliciting, reliability 0.3
In the mandates
- wanted by A coding assistant on my machine↗
- wanted by A coding assistant in a container on the web↗
- wanted by The desktop app, with local tools switched on↗
- wanted by A scheduled job under a service account↗
Edit the primitives ↗ · edit the reductions ↗