Home / Articles / v0.4.3

The home page has argued about one setting since v0.1.0, and now the build walks it

A product, a tool and a setting became node types with formulas, derived from data the site already held. The setting that distinguishes confirmations on from confirmations off was found by diffing two grants, and whose material a capability reaches was declared without being guessed.

v0.4.3, 20 September 2026. v0.4.3's own release record.

An argument that had been a sentence since the first release

The clearest demonstration this site has is a pair of example pages: the same coding agent, the same machine, the same account, with the confirmation prompt on in one and off in the other. The grant does not change. The mandate does not change. The delta does not change. One barrier moves.

For three releases that was a paragraph. A reader had to take it on trust that something in the data connected the two shapes, because nothing did: a shape carried its tools as strings and carried nothing at all about what distinguished one variant of a product from another.

The confirmations flag, as a path the build walksone product, two variants, and the difference between their grantsClaude Code (the CLI)has_variantlocal-defaultlocal-confirmations-offthe settingthat distinguishes the twoderived by diffingtheir grantsnarrowsexecute.process.hostmovessettingnoneconfirmations onconfirmations offThe grant did not change. The mandate did not change. The delta did not change. One barrier moved, and not one number on the label.The home page has said that in a sentence since v0.1.0. Since v0.4.3 it is a path: two nodes, two edges, walked on every build.
Neither node was typed in. The product comes from the shape id, and the setting comes from diffing the grants of its two variants: whatever moved between them is what the setting moves.

Three node types, and nothing typed in

This release adds a product, a tool and a setting as node types with formulas the build walks. All three are derived from data the site already held.

TypeWhere it comes fromMatched
Productthe two segments of a shape id that are not the variant, so two shapes with the same product are the same thing in a different setting8
Toolthe tools a profile already listed, in the vendor's own words, one node per shape because what shell (Bash) reaches depends on where it runs17
Settingtwenty from the reductions the capability map publishes per capability, and one from diffing the grants of two variants of one product21
The deployment shape universe page listing its node types, which exist and which are still needed
The universe page reports its own state: three types now walked on every build with their counts, and four the world still needs. A status of partial is a claim the gate checks rather than a hedge.abp.sgit.ai at v0.4.3, captured 20 September 2026 from a checkout of the v0.4.3 tag. Unretouched.

The setting nobody wrote

The interesting node of the three is the last one. The setting that distinguishes confirmations on from confirmations off was not authored. The build takes the two variants of one product, diffs their grants, and whatever barrier moved between them is what the setting moves.

For this pair exactly one capability moves: execute.process.host sits at a setting in one variant and at nothing in the other. So the node carries one narrows edge to that capability and two moves edges, one to each barrier. The home page's paragraph is now a path with two nodes and two edges in it, walked on every build, and it would fail the build if it stopped being true.

A capability page showing the published reduction that would move it to the fourth barrier, now also a node
The other twenty settings come from the capability map's published reductions: for each capability, the specific configuration that narrows it, what it costs, and the barrier it reaches afterwards. This is a published reduction, not a recommendation, because whether it is worth doing depends on assets this document does not hold.abp.sgit.ai at v0.4.3, captured 20 September 2026 from a checkout of the v0.4.3 tag. Unretouched.

Whose material, declared without being guessed

The other half of the release answers the first of three requests a consumer of this data published against this site. Reach answers how far a capability goes. It does not answer whose material it touches.

read.message.tenant says the agent can read a mailbox. It does not say the mailbox is full of other people's correspondence, and no setting any of the four vendors documents makes a mailbox anything else.

ValueWhat it means
ownthe deployer's own material
organisationthe deployer's organisation's material
third_partyother people's material
mixedother people's material mixed with the deployer's, and no setting the vendor documents makes it otherwise
A property on a granted row, never a fourth element of the grammar. A fourth element multiplies the primitives and the vocabulary has to stay readable by address. And the nine shapes promoted from the capability map do not state it, so their rows say nothing rather than guessing: the field is null and the gate refuses any value outside the four. The first rows to carry a value arrived in the next release, from somebody who had read the vendor pages and written it down.

A grant you hold over other people's material is not a grant you may pass on. That sentence is in the foundation document and it had nowhere to live in the data until this release.

The deployment shape universe · The capability grammar · v0.4.3's own release record