sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · what-can-it-do.games.sgit.ai

On this page

Reading room / what-can-it-do.games.sgit.ai · raw text · live ↗

From what-can-it-do.games.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

ChatGPT — no connectors

ChatGPT (in the browser, no connectors): what it can reach, tool by tool, with the control on the path and the evidence behind each row.

Source: https://what-can-it-do.games.sgit.ai/map/grants/openai/chatgpt-web/default/index.html↗ · site v0.8.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a .md twin; internal links below point at them.


Play↗ / The map↗ / The products↗ / ChatGPT — no connectors

ChatGPT (in the browser, no connectors)

An assistant in the vendor's environment. It reaches what you paste or upload and nothing on your machine: the vendor's environment is a boundary you did not build. DERIVED from the assess library's web tree. Browsing, if on, is the vendor's egress, not yours.

OpenAI · surface web · variant default · profile version 2026-09-05 · reaches 1** of 23 capabilities, **0 of which cannot be undone. Edit this profile ↗ · the file ↗.

CapabilityUndoChatGPT (no connectors)
filesystem — files and directories
Read the project it is working on read.file.projectyes●
Change the project it is working on write.file.projectwith-effort·
Read any file the account can reach read.file.hostno·
Change any file the account can reach write.file.hostwith-effort·
Delete files anywhere the account can reach delete.file.hostno·
Read a retained record: shell history, past sessions read.record.historyno·
process — programs and their execution
Run programs as the account execute.process.hostwith-effort·
Run programs inside its own sandbox only execute.process.selfyes·
network — endpoints and hosts
Reach a permitted list of hosts send.endpoint.allowedno·
Reach any host on the internet send.endpoint.worldno·
identity — credentials and who the agent can act as
Read credentials stored where it runs read.credential.hostno·
Act in accounts with the credentials it holds authenticate-as.credential.tenantno·
Change its own permission settings grant.credential.selfyes·
communication — messages to people
Send a message to anyone send.message.worldno·
Read mail or chat it is connected to read.message.tenantno·
code — repositories and what lands in them
Commit to the repository it was pointed at write.repository.projectwith-effort·
Push to a code host (any branch it can reach) write.repository.tenantwith-effort·
Sign commits with the key it holds authenticate-as.credential.signingno·
Publish packages, images or pages under the name it holds create.record.worldno·
money — budgets and spend
Spend money or tokens against an account it holds write.budget.tenantno·
schedule — things that outlive the turn
Create something that outlives the turn where it runs (a cron, a service) create.schedule.hostyes·
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) create.schedule.tenantyes·
browser — what a browser extension or automation can see and do in your browser
Read every page you visit read.record.browsingno·

What host, tenant and world mean here

ReachHere, it means
hostthe vendor's environment; not your machine
tenantnothing of yours
worldthe vendor's egress, if browsing is on

What it cannot reach, and why

WhatWhySource
your machine's filesthe vendor's environment is a boundary you did not buildassess/library.json (web: home)
your accountsno connectors are onassess/library.json (web: connect)

The grant, tool by tool

Two tools in one session reach different things, which is why the unit of mapping is the tool and not the product. Each row carries the control on the path and the tier of evidence behind it.

conversation and uploads

CapabilityControlEvidenceWhat is on the path
Read the project it is working on↗ read.file.project● nonederived— · what you paste or upload — and a record once read is exposure that cannot be unread, on the vendor's side

What narrows it

For each capability in the grant: the specific setting or arrangement that narrows it, what it costs, and the tier the control reaches afterwards. Guidance is free and stays free.

CapabilityThe settingWhat it costsTier after
Read the project it is working on↗none: this is what it is fornothingnone

Against the mandates

What a reasonable person wanted from this setup, and the gap: ▲ excess is what it can do that they did not want; ▼ shortfall is what they wanted that it cannot do.

MandateExcessShortfall
Chat in the browser, nothing connected↗▲ 0▼ 0

Sources

A derived row is an inference from what this kind of program architecturally is. It is a claim, and the most useful pull request on this page is one that replaces a claim with a probe run — how↗.


Site index for agents↗ · HTML version↗