{
  "type": "abp/delta/v1",
  "profile": "generic/scheduled-job/service-account",
  "mandate": "beta-001/chatgpt-inbox-scout",
  "grant_version": "2026-09-05",
  "mandate_version": "2026-09-21",
  "pack_version": "v0.8.0",
  "computed_at": "2026-09-21T00:00:00Z",
  "computed_by": "abp.delta/v1",
  "excess": [
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "a service-account credential, rarely rotated",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "send.endpoint.world",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "write.budget.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "if the credential is billed",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "as the service account, on a schedule",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "it is one",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "excess_refused": [
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "as the service account, on a schedule",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    }
  ],
  "excess_unstated": [
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "a service-account credential, rarely rotated",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "send.endpoint.world",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "write.budget.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "if the credential is billed",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "it is one",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "unbounded_excess": [
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "a service-account credential, rarely rotated",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "send.endpoint.world",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "write.budget.tenant",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "if the credential is billed",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "as the service account, on a schedule",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": null,
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "none",
      "evidence": "derived",
      "via": [
        "the job"
      ],
      "control": null,
      "note": "it is one",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "shortfall": [
    "read.message.tenant"
  ],
  "aligned": [],
  "derived_never_authored": "No field in this record is writable by a person. The way to change a delta is to change a grant or a mandate, and then recompute.",
  "provisional": true,
  "provisional_note": "Computed against the nearest published shape, which is not this deployment. It shows what the delta would look like if the deployment's grant matched that shape, and nothing more. The deployment's own grant has not been measured."
}
