Home / Examples

Five worked examples

Five ABPs, from the smallest grant in the set to a service account that outlives the turn. They are derived rather than authored: the rows come from a published data pack, and the delta on each page is computed when the page is built.

Before you read any of them, write down a number. For a deployment you actually run, how many of the 23 capability primitives do you think it has? Most people who have deployed an agent know what they asked it to do, and almost nobody knows what it can do. The gap between your number and the table below is the reason this document type exists.

The five, side by side

Deployment shapeWhy this oneGrantMandateExcessUnbounded excessIrreversibleWidest reachMeasured
Chat in the browser, nothing connectedThe smallest grant in the set11000project0 of 1
A coding agent on your own machine, confirmations onThe confirmation is a barrier, and you can see which row it sits on16512128world0 of 22
The same coding agent, confirmations offThe same agent, one setting different16512128world0 of 22
A browser extension with broad host permissionsOther people's data, and the mandate nobody wrote down31223world0 of 3
A CI job on a hosted runner, under a service accountPersistence, and reach beyond the turn85433world8 of 8

No column here is a score. Excess is a count of capabilities in the grant and not in the mandate. Unbounded excess is how many of those sit at a barrier that is not a control. Neither says whether any of it is acceptable, because acceptability is not in the document.

Read the third one first

Claude Code with confirmations on and the same thing with confirmations off are the same product, the same machine and the same account, with one setting different. Reading them side by side is the argument.

And the pair says something the foundation document does not. The foundation document says that turning confirmations off moves the barrier on every capability in the delta by one row. In the published data it moves exactly one barrier, on execute.process.host, and that capability is inside the mandate rather than in the delta: the deployer asked for it. So the label's numbers do not move at all and the document is still materially different. That is a stronger argument for the leaflet and against a headline number, and it is recorded as a disagreement in v0.1.0's notes rather than quietly resolved.

What each one cost to make

Nobody knows what an ABP costs to produce, and the store has to price one. So this is instrumented rather than estimated.

ExampleTimeQuestions asked of a humanNote
chatgpt-web-no-connectors5 min0The smallest grant. Nothing new was needed once the generator existed.
claude-code-cli-confirmations-enabled5 min0The first one where the barrier column carries the argument.
claude-code-cli-confirmations-disabled5 min0Built second in importance and first in value. It is the same generator call against a different profile id.
browser-extension-broad-host-permissions5 min0Three capabilities, all three irreversible. The shortest page and not the mildest.
github-actions-hosted-runner5 min0A service account rather than a person. The only other shape in the set with measured rows.
The honest version of this table is the sentence underneath it. The five examples took about four hours in total, and essentially all of it went into the generator, the promoted schema and the provenance line. The marginal cost of the sixth example, for a shape already in the published map, is one line in a list and a build. That is not the number the store needs. The number the store needs is what it costs to produce an ABP for a shape that is NOT in the map, where the grant has to be measured rather than looked up, and this site cannot tell you that yet because it has not done one. Nought questions had to be asked of a human for these five, which is the same finding from the other side: they were derived, not elicited.

What none of these is

This is not an assessment. Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score.
Provenance. 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to the published capability map, retrieved 2026-09-11T13:00:37Z, content hash sha256:d6d4ba40f1fb1f93f66. The source bytes.