Home / Articles / v0.9.0

v0.9.0: Two more cases: this site's own session as a ledger, and three surfaces of one product over a record that contains secrets

The cost walkthrough said no case had run its prompts. The first case here is that case, on the one shape whose grant was measured, with a ledger counted from the repository and the workflow log. The second is a deployer with one assistant on three surfaces and one rule: reading the past is on demand.

This is the article for release v0.9.0, published 22 September 2026. Every release of this site gets one, and it explains what that release changed and why rather than restating v0.9.0's own release record. It is release 13 of 14 on this site. Every screenshot below was captured from a checkout of the v0.9.0 tag, so it shows the site as it stood at that release and not as it stands today. Read on to v0.10.0, or back to v0.8.0.

The case the cost walkthrough said did not exist yet

The article for v0.8.0 ended on a list of what that release did not settle, and the fourth item was that no case ran the cost prompts. The obvious candidate was the session writing the sentence. It runs on the one shape this site holds whose grant was measured by the thing being profiled, its commits and pushes are in the repository and the code host's workflow log, and the deployer's instructions are nine messages anybody can count.

The cases index at v0.9.0 with three cards: the beta user, the site's own session as a ledger, and three surfaces over one record
Three cases. The second card is the site counting itself, and its foot says with a ledger where the others say no grant measured.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.

A ledger where every line says where its number came from

Seventeen lines. Commits, pushes, pipeline runs, files changed split into written by hand, copied in, captured and generated, fetches, subagents, questions asked of the deployer, things handed over, reviews requested, commands the harness blocked, tokens, and the deployer's own time. Each line carries one of five sources: repository, platform, self, estimate, or cannot see, and the gate refuses any other word. An estimate carries an asterisk. A cannot see line carries no number at all, and the gate refuses one that does.

The ledger table on the session case: what was spent, how many, counted from, and a note, with commits from the repository and tokens marked cannot see
The top of the ledger. Thirteen commits, ten pipeline runs, 523 files of which 20 were written by hand and 418 were generated, and the token line saying what it has to say.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.
Two lines are the ones to sit with. Tokens, which the agent cannot see and the platform can, so every other line is a proxy for the bill. And the five commands the harness blocked, each a decision handed to the deployer: the fifth cost line from the walkthrough, another person's hour, appearing in a real ledger for the first time and counted by the thing that spent it.

The clauses that were in force before anybody wrote a cost policy

The session had a cost policy. It was spread across the harness's standing rules and the deployer's messages, and nobody had called it one. Every clause in it is over a count, a place, a frequency or a delegation: commit only when asked, no subagents, scratch files in the scratchpad, do not poll. Not one is a row in the mandate table on the deployment page, which is the finding the cost walkthrough predicted a day earlier and this case confirms with the site's own numbers.

A table of six clauses that were in force during the session, where each came from, and whether it was kept
Six clauses, two sources, and an honest third column: one kept mostly, one broken once and caught by the gate, one not kept at all.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.

The kept column is the agent grading itself, and the case says so: no accountant has read this ledger, the status carries that sentence, and the gate refuses a case with a ledger whose status does not say one way or the other.

For once the grant is measured

Every other case on this site says its grant is not measured, and the gate insists on the words. This one runs on anthropic/claude-code-remote/ccr-container, 13 of 20 rows seen on the container itself, so the deployment is the published shape and the delta on the grant side is the shape's own. The gate allows the phrase the published shape only when the named shape has measured rows, and it then requires the delta not to be marked provisional.

The delta table on the session deployment page: the shape, 15 of 23 primitives, 13 of 20 rows measured, the mandate, the excess and the unbounded excess
The one delta on a case page that is not provisional. The mandate side is still a draft elicited from nine messages, and the page says which side is which.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.

The second case turns on one rule

A deployer who runs one assistant in the browser, as a coding agent and as a desktop work product, over one account. The account holds the record of every past conversation, and the record contains secrets, because things get pasted into a chat that would never be committed anywhere. So the record is a credential store, reading it is reading credentials, and the deployer's rule is that reading it should always be on demand.

One person, three surfaces, one account holding every past conversationthe record is a credential store, and the question is which surfaces can read it and whenOne persona deployer, elicited on 22 SeptemberIn the browserconnectors possibly onThe coding agenta container, a repository, measuredThe desktop work productno published shapeOne account with the vendorthe record of every past conversation, on every surface, plus the connectorsreads?reads its ownreads?The union runs in time as well as across surfaces. Everything ever pasted is in the record, and turning reading off todaydoes not take it out. A mandate over this estate says what to do about what is already there.
Three surfaces over one account. Two of the three arrows carry a question mark, because whether the browser and the desktop product read the whole record is not measured; the coding agent's container was measured to hold only its own session's outputs.

The first case found that four grants over one Google account union into the account's exposure. This one adds a dimension: the union runs in time as well as across surfaces. Everything ever pasted is in the record, and turning reading off today does not take it out. A mandate over this estate has to say what to do about what is already there, which is why the case carries a prompt that finds the secrets so they can be removed, and says on its face that the prompt is itself a read of the record.

The mandate table on the browser deployment page: one wanted line, two refused, each with how we know and the fragment it came from
The browser deployment's mandate. One line said, one said and one inferred, and twenty unstated, because which connectors are enabled is the first open question.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.

What matters, before what is forbidden

The deployer named the concept in the memo: what is being given to the agent is context on what is important and what is not. A mandate is that list before it is a list of prohibitions. So the case carries a what matters table beside the mandate, and every clause set on its three pages opens with it. It changed how the clauses read: they start with the record matters, the repository is the work, the container is disposable, and the prohibitions follow from those rather than standing alone.

A table headed what matters, and what does not, with four rows: matters most, matters unknown, does not matter, must never be reused
The importance list. It is the part of a mandate the grammar cannot hold and the part an agent most needs, and it is one table.abp.sgit.ai at v0.9.0, captured 22 September 2026 from a checkout of the v0.9.0 tag. Unretouched.

What this release did not settle

The session case · The three surfaces case · The cost walkthrough · v0.9.0's own release record

Read the sequence

DirectionThe release
Olderv0.8.0: The cost ABP: every ABP so far bounded what, and this one bounds how much
Newerv0.10.0: The desktop walkthrough: on your own machine, host means your machine, and the mandate is a map of what matters before it is a list of rules
All of themOne article per release