{
  "type": "abp/delta/v1",
  "profile": "anthropic/claude-code-remote/ccr-container",
  "mandate": "session-001/claude-code-web",
  "grant_version": "2026-09-05.2",
  "mandate_version": "2026-09-22",
  "pack_version": "v0.8.0",
  "computed_at": "2026-09-22T00:00:00Z",
  "computed_by": "abp.delta/v1",
  "excess": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "boundary",
      "evidence": "inferred",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "the token's scope, set by the platform (in-scope repositories only)",
      "note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": "the container is ephemeral: whatever is scheduled here dies with it",
      "note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
      "material": null,
      "undo": "yes",
      "is_bounded": true
    }
  ],
  "excess_refused": [
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "excess_unstated": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "boundary",
      "evidence": "inferred",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "the token's scope, set by the platform (in-scope repositories only)",
      "note": "five key-shaped variables and a code-host token — the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.host",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": "the container is ephemeral: whatever is scheduled here dies with it",
      "note": "systemctl and /etc/cron.d exist, so a cron can be written — and dies with the container; the real scheduler is the platform's routines, on the harness row",
      "material": null,
      "undo": "yes",
      "is_bounded": true
    }
  ],
  "unbounded_excess": [
    {
      "capability": "authenticate-as.credential.signing",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) — not with yours",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "delete.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "anything in the container, including the clone; irreversible for the container, and the container is disposable",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "read.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "any file in the container — the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary')",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "write.file.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a zero-byte file was created and removed in /etc: system configuration of the container is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "create.schedule.tenant",
      "barrier": "setting",
      "evidence": "self-reported",
      "via": [
        "harness (MCP and built-in tools)"
      ],
      "control": "the platform's routines are the operator's to list and delete",
      "note": "a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "shortfall": [],
  "aligned": [
    {
      "capability": "read.record.history",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here",
      "material": null,
      "undo": "no",
      "is_bounded": false
    },
    {
      "capability": "send.endpoint.allowed",
      "barrier": "boundary",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "fetch (WebFetch)",
        "harness (MCP and built-in tools)"
      ],
      "control": "a mandatory egress proxy configured above this process — hosts it refuses are refused with a 403 on the CONNECT; the six hosts probed on 5 September all answered",
      "note": "six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies",
      "material": null,
      "undo": "no",
      "is_bounded": true
    },
    {
      "capability": "execute.process.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.file.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "the attached working tree is writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)"
      ],
      "control": null,
      "note": "a repository is attached and writable",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "write.repository.tenant",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": "pre-commit and pre-push hooks in the clone (the mandate hook and the insurance policy) — refuse by exit code, --no-verify passes; no branch rule at the host",
      "note": "the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host",
      "material": null,
      "undo": "with-effort",
      "is_bounded": false
    },
    {
      "capability": "read.file.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "shell (Bash)",
        "harness (MCP and built-in tools)"
      ],
      "control": null,
      "note": "the attached working tree is readable",
      "material": null,
      "undo": "yes",
      "is_bounded": false
    }
  ],
  "derived_never_authored": "No field in this record is writable by a person. The way to change a delta is to change a grant or a mandate, and then recompute.",
  "provisional": false,
  "provisional_note": "Computed against the published shape this deployment is, whose rows were measured by the thing being profiled. The mandate side is still an elicited draft."
}
