{
  "type": "abp/delta/v1",
  "profile": "anthropic/claude-code-remote/ccr-container",
  "mandate": "estate-002/claude-code",
  "grant_version": "2026-09-05.2",
  "mandate_version": "2026-09-22",
  "pack_version": "v0.8.0",
  "computed_at": "2026-09-22T00:00:00Z",
  "computed_by": "abp.delta/v1",
  "excess": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.record.history",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "boundary",
      "evidence": "inferred",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "the token's scope, set by the platform (in-scope repositories only)",
      "note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "send.endpoint.allowed",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "fetch (WebFetch)",
        "harness (MCP and built-in tools)"
      ],
      "control": "a mandatory egress proxy configured above this process — hosts it refuses are refused with a 403 on the CONNECT; the six hosts probed on 5 September all answered",
      "note": "six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.tenant",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "pre-commit and pre-push hooks in the clone (the mandate hook and the insurance policy) — refuse by exit code, --no-verify passes; no branch rule at the host",
      "note": "the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": "the container is ephemeral: whatever is scheduled here dies with it",
      "note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
      "material": null,
      "undo": "yes",
      "is_bounded": true
    }
  ],
  "excess_refused": [
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.record.history",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here",
      "material": null,
      "undo": "no",
      "is_bounded": false
    }
  ],
  "excess_unstated": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "boundary",
      "evidence": "inferred",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "the token's scope, set by the platform (in-scope repositories only)",
      "note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "send.endpoint.allowed",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "fetch (WebFetch)",
        "harness (MCP and built-in tools)"
      ],
      "control": "a mandatory egress proxy configured above this process — hosts it refuses are refused with a 403 on the CONNECT; the six hosts probed on 5 September all answered",
      "note": "six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.tenant",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "pre-commit and pre-push hooks in the clone (the mandate hook and the insurance policy) — refuse by exit code, --no-verify passes; no branch rule at the host",
      "note": "the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": "the container is ephemeral: whatever is scheduled here dies with it",
      "note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
      "material": null,
      "undo": "yes",
      "is_bounded": true
    }
  ],
  "unbounded_excess": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.record.history",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.tenant",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "pre-commit and pre-push hooks in the clone (the mandate hook and the insurance policy) — refuse by exit code, --no-verify passes; no branch rule at the host",
      "note": "the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "shortfall": [],
  "aligned": [
    {
      "capability": "write.file.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the attached working tree is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a repository is attached and writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "read.file.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": null,
      "note": "the attached working tree is readable",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "derived_never_authored": "No field in this record is writable by a person. The way to change a delta is to change a grant or a mandate, and then recompute.",
  "provisional": true,
  "provisional_note": "Computed against the nearest published shape, which is not this deployment. It shows what the delta would look like if the deployment's grant matched that shape, and nothing more. The deployment's own grant has not been measured."
}
