Home / Articles / v0.11.0

v0.11.0: The Gmail connector measured end to end by the agent that holds it, and the ratchet as a number

An agent read its own thirty tool schemas, sent mail with no prompt, hit a refusal it could not explain, and wrote the four objects into a vault in the connector's own words, naming the join to this grammar as a gap. This release is that join, and it puts the agent's inferred mandate beside the site's own so the gap between them is one row rather than a warning.

This is the article for release v0.11.0, published 22 September 2026. Every release of this site gets one, and it explains what that release changed and why rather than restating v0.11.0's own release record. It is release 15 of 15 on this site, and the most recent. Every screenshot below was captured from a checkout of the v0.11.0 tag, so it shows the site as it stood at that release and not as it stands today. Nothing follows it yet, or back to v0.10.0.

The walkthrough asked a question, and a vault answered it

Every page of the mailbox walkthrough is a prompt for the reader to run against their own assistant, and the honest line under all of them was that this site had never seen the answer. On 19 September an agent operating a Google Workspace mailbox through the Gmail connector ran the equivalent: it read its own thirty tool schemas, checked them against the live permission page, sent mail, trashed mail, relabelled sixteen messages, hit one refusal it could not explain, and wrote GRANT.md, MANDATE.md, DELTA.md and AGENTS.md into an sgit vault. It wrote them in the connector's own vocabulary and named the missing join to this grammar as a gap. This release is the join.

The measured deployment page at v0.11.0: the heading, the lead, and the provenance note naming the vault, its version and commit, and the read key
The page. The note under the lead names the vault, its version and commit, the six files copied unchanged, whose words are whose, and the read key, published on purpose because it opens a read-only clone and nothing else.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.

Thirty tools, and the one on the wrong side

The schemas name thirty tools, six read only and twenty four that write or delete, cross checked one to one against the settings page. On this account ten run with no prompt: every read tool, three label tools, and send_message. Trashing a message needs approval and sending one does not, which inverts the usual ordering, and the session confirmed the consequence by sending to an external address and finding that only the sender's copy could be trashed.

A two column table: the ten tools that run with no prompt on the left, the twenty that stop at an approval on the right
The split as the settings page showed it. send_message is in the left column. The vault's whole recommendation is to move it to the right and leave create_draft open.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.
The connector has no sender field. Every compose tool was inspected: no from, no sendAs, no alias. The From header is the account's default send-as entry, which the operator set to a disclosed agent alias on a second domain. So the agent sends as the business and cannot send as anything else, and the disclosure is carried by the address before any signature has to.

What the measurement changed, and what it did not replace

This site already held a profile for the shape, read from two vendors' pages and the directory listing on 16 September. The vault settles three of its open questions and one of its contradictions: which tool sends, what the two truncated tool names were, and whether filter tools exist. They do not, so the earlier profile's create.schedule.tenant row is absent from this one, and the grant got smaller by being measured. The earlier profile stays as a second variant of the same product, which is the pattern the site has used for a coding agent since v0.1.0.

A table comparing the profile read from the pages on 16 September with the one measured by the agent on 19 September, row by row
Read against measured. One barrier moved, from a setting to nothing, and the build derives the setting that distinguishes the two variants by diffing their grants.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.

The ratchet, as a number

MANDATE.md opens by saying it is not a mandate: the agent reconstructed it from ten things it was asked to do in one session and was not stopped from doing. DELTA.md then declines to compute a gap from it, with the clearest sentence in the vault: an agent subtracting its own inferred mandate from its own measured reach will always report a narrow gap, because the act of using a capability is what put it in the mandate column.

This site agreed and published the mechanism rather than the number alone. The measured grant is read against the site's own starting mandate and against the agent's inferred one, side by side, and the two deltas differ by exactly one primitive.

A table with two columns, the site's starting mandate and the agent's inferred mandate, showing excess 4 against 3 and the difference as send.message.world
Two mandates against one grant. The operator created an alias for the agent to send from and asked it to introduce itself to one person; the agent inferred that sending was authorised. The difference between the columns is that inference.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.
What the approval prompt asks, and what it leaves outit arrives at the moment you know least about the thing you are approvingWhat it tells youthe class of actionthat something is about to happena yes and a noWhat it does notwhich message or threadhow many itemswho the correspondent iswhether you can undo itwhether the label is one you built in 2019whether this is one step of fortySo the question it appears to ask is not the question it asks. It appears to ask whether this action, on this object, is acceptable.It asks whether you still want the thing you asked for thirty seconds ago, and that question has one answer.Every one of the six on the right is available to the software at the moment it asks. This is a design gap rather than a data gap.
Approving is a formality rather than a decision, and a formality that produces a record of your agreement. Turning the prompt off removes the formality and changes nothing about the grant.

HARD and SOFT are the four barriers under other names

AGENTS.md tags every rule the agent follows as HARD or SOFT, and its first section says what the file is: a soft barrier that shapes behaviour reliably under normal conditions, and not at all if it is absent from context, contradicted later, or overridden by content read from an untrusted source. The tags map onto this site's barriers without remainder, with one row the four have no home for: the operator reading each message as it is sent, which the vault says is the barrier doing the real work and which detects rather than prevents.

A table mapping the vault's HARD and SOFT tags onto the site's barriers, with a row for the operator reading each message that fits none of the four
The mapping. HARD by absence is a boundary; HARD by the settings page is a boundary for twenty tools; SOFT is an expectation; and a person reading along is not a barrier in the four, which is why nothing scheduled survives it.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.

What a measured row looks like beside a read one

Five primitives, five of five rows measured, two tiers: observed where the agent saw it on the thing itself in its own session, measured where the operator confirmed it from outside. The read.credential.host row is the one to notice: on the earlier profile it was inferred, because codes and resets arrive in mailboxes; here it is observed, because the sender based sweep that relabelled sixteen messages swept a one time code and two new device alerts along with the marketing it was aimed at.

The grant against mandate figure for the measured Gmail deployment: one line from the mandate to read.message.tenant, four marks on the grant side with no line
The grant against the site's mandate. Four marks with no line reaching them, three at a barrier that is not a control, and every row behind them seen on the thing itself.abp.sgit.ai at v0.11.0, captured 4 October 2026 from a checkout of the v0.11.0 tag. Unretouched.

What the gate learned

A vault is a contributor who wrote in their own vocabulary, so the manifest gained a vaults list beside shapes: the vault, its version and commit, the read key published on purpose, who wrote it, what was and was not copied, and the module that does the mapping. The gate accepts a vault entry's own retrieval time, counts vault shapes with the others, requires every named source to be among the hashed files, and requires any read key a vault entry carries to be in the published list, so a key on this site is published on purpose or not at all. One altered byte in the vault copy fails the build in two places, which was tested before the commit.

What this release did not settle

The measured deployment · The verbatim bytes · The walkthrough · v0.11.0's own release record

Read the sequence

DirectionThe release
Olderv0.10.0: The desktop walkthrough: on your own machine, host means your machine, and the mandate is a map of what matters before it is a list of rules
All of themOne article per release