# abp.sgit.ai -- the whole site > The Agent Behaviour Policy: what your agent can do, what you authorised it to do, the gap between them, and what actually stands in the way. Site version: v0.2.0. Generated from the same content as the HTML pages, so this file cannot disagree with them. ------------------------------------------------------------------------ # Agent Behaviour Policy > You know what you asked for. You do not know what it can do. The Agent Behaviour Policy is the document that puts the two on the same page: the grant, the mandate, the delta and the barrier, for one agent in one deployment, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- # You know what you asked for. You do not know what it can do. An **Agent Behaviour Policy** is a written description, for one agent in one deployment, of everything it can do, what it was authorised to do, the difference between the two, and what actually stands in the way. It is derived from the deployment rather than copied from a template. **It describes and it does not judge, so it carries no score.** ## The gap **You know what you asked for.** Draft the reply, fix the build, summarise the ticket, book the travel. That is the mandate, and it is usually clear, whether or not anybody wrote it down. **You do not know what it can do.** The agent runs with an account, on a machine, inside a container or on a desktop, with credentials and network access and a set of tools. Everything those permit is the grant. It is almost never enumerated, and when it is, it is larger than the person who deployed the agent expected. > **Before you scroll.** For a deployment you actually run, write down how many of 23 capability primitives you think it has, and how many of those you asked for. Then read [the five worked examples](examples/index.md). The gap between your two numbers is the reason this document type exists. ## The four objects An ABP is not a single list. It is four objects, and the order they are produced in matters. | Object | What it is | How it is obtained | |---|---|---| | **The mandate** | What the agent is authorised and expected to do | **Elicited.** In minutes, because the deployer already knows it | | **The grant** | Everything the agent can do | **Measured.** From the deployment shape, the account and the credentials | | **The delta** | Excess where it can and you did not ask; shortfall where you asked and it cannot | **Derived.** Recomputed whenever the grant or the mandate changes, stored with the versions of both, and never edited by hand | | **The barrier** | What stands between the agent and each capability | **Recorded**, per capability, from one of four kinds | > **The delta is derived and never authored.** Nobody writes one: it is only ever the output of a computation over the grant and the mandate, and it is stored with the versions of both inputs and the time it was computed. This site said the opposite this morning, and **the correction is published rather than applied quietly**: [what changed and what follows from it](model/delta/index.md). **A grant on its own is an inventory, and nobody acts on an inventory.** *Your agent can do three hundred and forty things* is a shrug. *Your agent can do three hundred and forty things and you authorised twelve* is a finding. [The model, in full](model/index.md). ## Only one kind of thing is actually in the way | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | > **A control bounds a grant only if it is enforced by something the grant does not include.** Read the third and fourth rows together and the test falls out of them. A setting the agent's own account could change is not a control, because the grant includes the ability to remove the bound. [The barrier](model/barriers/index.md). ## One setting, two documents The clearest way to see what an ABP does is to change one setting and watch the document change. A coding agent on a developer's own machine, profiled twice: once with confirmations enabled, once with them disabled. Same product, same machine, same account. | | Confirmations on | Confirmations off | |---|---|---| | Grant | 16 | 16 | | Mandate | 5 | 5 | | Excess | 12 | 12 | | Unbounded excess | 12 | 12 | | Barrier on `execute.process.host` | setting (not a control) | none (not a control) | **1 barrier moved and not one number did.** The confirmation prompt was the only thing standing between an authorised capability and the whole of the machine, and it was a setting the agent's own account could change, which is the third row and not the fourth. **The ABP is about the deployment, not the product**, and the pair says it in a way no paragraph can: [confirmations on](examples/claude-code-cli-confirmations-enabled/index.md) and [confirmations off](examples/claude-code-cli-confirmations-disabled/index.md). ## It describes and it does not judge **The same ABP is dangerous in one deployment and harmless in another, and nothing about the document changed.** The most permissive grant imaginable, running where there are no assets and nothing reachable, is a low risk. The same grant with a production database attached tomorrow is a high one. Risk is a function of the ABP, the assets, the consequences and the date, and **the ABP is the one input that does not move.** > **A policy cannot be dangerous. A deployment can.** So there is no rating on an ABP, no traffic light and no risk level, anywhere on this site or in its data. Every reader asks for one. **The score has a home and it is [the risk work above this](https://risks.sgit.ai/)**, where the assets are known and a named person signs. The people who sell do not sign, which is why the two are separate products and not two sections of one. ## What is here **[What an ABP is](what-is-an-abp/index.md)**: The foundation document: the definition, the four objects, the barrier, one worked example with published numbers, and the questions we would like answered. This is the document, rendered. Not a summary of it. **[The delta](model/delta/index.md)**: Derived and never authored. Stored with its inputs pinned, recomputed when either moves, and the history is the business case. Corrected on 11 September, in the open. **[The model](model/index.md)**: The 23 capability primitives, the four barriers, the three undo classes, the graph rules and the schema. Promoted from a published map, not invented here. **[Five worked examples](examples/index.md)**: From the smallest grant in the set to a service account that outlives the turn. Derived from the data, with the delta computed on the page. Each states how many rows were measured. **[The data](data/index.md)**: The published vocabulary as JSON, at stable addresses with cross origin access, with the source bytes it was promoted from. 21 of 99 rows measured. **[The docs](docs/index.md)**: Every reference document behind this site, rendered, each one click from its source bytes. The index is generated from the files present. **[Where a score lives](https://risks.sgit.ai/)**: The ABP is the input. The risk work above it knows the assets and the consequences, and a named professional signs. Not here, and that is the point. ## What an ABP is not - **Not an acceptable use policy.** That governs a person's use of a system. An ABP governs what an agent can and may do. - **Not a risk assessment.** It has no assets in it and no consequences. It is the input to one. - **Not a compliance assessment, a certification, an audit or a security review** of anything or anybody. - **Not a guardrail.** It is what guardrails are compiled from. The barrier column says which prohibitions are guardrails already and which are sentences. - **Not a claim about any product.** The capability rows come from published documentation and published measurement, with the source, the date and the measured ratio stated, and no adjective attached to any of them. - **Not a template.** It is derived from one deployment, and a template cannot know what your agent can do. ## This site is the library. It is free, and it stays free The argument, the model, the examples and the data are published here. **There is no checkout on this site and there will not be one.** The data files are the shared facts and they live in the repository so that people can propose changes to them, with evidence attached. [Propose a change](data/index.md) · [The repository](https://github.com/SGit-AI/SGit-AI__Website__ABP) · [Everything on this site, in one file](llms-full.txt) > **Provenance.** 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](data/upstream/pack.json). > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. --- *[Site index for agents](llms.txt) · [HTML version](https://abp.sgit.ai/index.html)* ------------------------------------------------------------------------ # What is an Agent Behaviour Policy > The foundation document: the definition of the Agent Behaviour Policy, the four objects, the barrier as the test of whether anything is in the way, the rule that it never judges, and the questions we are asking. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / What is an ABP # Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know What It Can Do > **Two passages in this document were corrected on the day it was published, and this page does not rewrite them.** Both stand exactly as written, each with its correction rendered immediately above it, because a document corrected by silently editing it is a document nobody can trust. The correction is that **the delta is derived and never authored**, not computed and never stored. [The brief that makes it](../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case/index.md) and [what follows from it](../model/delta/index.md). Everything else in this document stands. > **This is the foundation document itself, rendered, not a summary of it.** It is the definition the rest of this site stands on, and it is the document being put in front of the community for feedback, so its wording is the wording. Where it and anything else on this site disagree, it wins, and the disagreements are recorded in [v0.1.0's notes](../versions/v0.1.0/index.md) rather than resolved quietly. The first mention of each term below links to its node in [the model](../model/index.md). > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do.md`](../docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Dinis Cruz **to** Anyone deploying an agent, anyone building one, and anyone who has to sign for one **type** Foundation document (the definition and introduction of the Agent Behaviour Policy, written for publication and for feedback) *This is the document everything else about the ABP stands on. It defines the term, says what an ABP contains and what it deliberately does not, gives one worked example with published numbers, and ends with the questions we would like answered by people who deploy agents for a living. It consolidates three internal briefs written on 11 September 2026 and rulings made on the days before. Everything factual in it carries a source and a date. Where a claim rests on something we measured, it says how much was measured and how much was derived. Nothing in it is a claim about any named product being good or bad, and nothing in it is a score.* ## What This Is The introduction of a document type that does not yet exist in most organisations and should: **an Agent Behaviour Policy is a written description, for one agent in one deployment, of four things, being everything the agent can do, which we call [the grant](../model/index.md), what it was authorised and expected to do, which we call [the mandate](../model/index.md), the difference between the two, which we call [the delta](../model/index.md), and what stands between the agent and each capability, which we call [the barrier](../model/barriers/index.md); it is derived from the deployment rather than copied from a template, it is rendered as one line for a decision maker and a full table for an engineer from the same set of facts, and it describes without judging, so it carries no score, because the same ABP is dangerous in one deployment and harmless in another and nothing about the document changed; the reason it exists is a gap that is easy to state and hard to close, which is that most people who deploy an agent know what they asked it to do and almost nobody knows what it can do, and the ABP is the document that puts those two side by side.** New here: **the definition, the four objects, the barrier as the test of whether anything is actually in the way, the rule that the ABP never judges, and the questions we are asking you.** ## The Gap **You know what you asked for.** When somebody deploys an agent, they know the job: draft the reply, fix the build, summarise the ticket, book the travel. That is the mandate, and it is usually clear, whether or not anybody wrote it down. **You do not know what it can do.** The agent runs with an account, on a machine, inside a container or on a desktop, with credentials and network access and a set of tools. Everything those permit is the grant. **It is almost never enumerated, and when it is, it is larger than the person who deployed the agent expected.** We have been measuring this. A published capability map covers nine common [deployment shape](../data/index.md)s across twenty three [capability primitives](../model/capabilities/index.md), and a published simulation of one ordinary assistant agent shows the shape of the result: **a grant of twelve capabilities, a mandate of four, and eight capabilities inside the agent's reach and outside its authority.** That eight is the delta, and in that example twice as many things were possible as were asked for. **The ABP is the document that puts the grant and the mandate on the same page.** That is all it is. That turns out to be a great deal. ## The Four Objects An ABP is not a single list. It is four objects, and the order they are produced in matters. > **Corrected the same day.** The replacement wording is: **The delta. Derived.** Recomputed whenever the grant or the mandate changes, stored with the versions of both, and never edited by hand. [What changed and what follows from it](../model/delta/index.md). | Object | What it is | How it is obtained | |---|---|---| | **The mandate** | What the agent is authorised and expected to do | **Elicited.** In minutes, because the deployer already knows it | | **The grant** | Everything the agent can do | **Measured.** From the deployment shape: the product, where it runs, with what account, with what credentials | | **The delta** | The difference. Excess where it can and you did not ask; shortfall where you asked and it cannot | **Computed.** Never stored, because the deployment changes | | **The barrier** | What stands between the agent and each capability | **Recorded**, per capability, from one of four kinds | **The mandate must be captured even though it is already known**, because a grant on its own is an inventory, and nobody acts on an inventory. *Your agent can do three hundred and forty things* is a shrug. *Your agent can do three hundred and forty things and you authorised twelve* is a finding. The mandate is the edge that gives the grant a shape. > **Corrected the same day.** The replacement wording is: **The delta is derived and never authored.** Nobody writes a delta. It is only ever the output of a computation over the grant and the mandate, and it is stored along with the versions of both inputs and the time it was computed. That is what makes it checkable rather than stale. **What must never happen is that somebody edits a delta**, because a hand edited delta is a fiction about an environment, and nothing downstream could tell. [What changed and what follows from it](../model/delta/index.md). **The delta is computed and never stored.** A stored delta is a claim about somebody's environment on a day that has passed. The environment is the thing that changes, so the delta is recomputed from the grant and the mandate every time it is needed. ## The Barrier: What Is Actually In The Way For every capability in the grant, the ABP records what stands between the agent and it. There are four kinds, and the published capability map already uses them: | Barrier | Meaning | Is anything in the way | |---|---|---| | **Nothing** | The agent can simply do it | No | | **A rule somebody wrote down** | An instruction in a prompt, a policy document, a line in a configuration the model reads | **No.** An instruction to the agent is inside the boundary the agent operates in | | **A setting the agent's own account could change** | A configuration the agent has permission to alter | **No.** The grant includes the ability to remove the barrier | | **A boundary enforced above it that it cannot reach** | A sandbox, a gateway, a tool that is not exposed, a network it cannot see | **Yes** | **Only the fourth kind bounds anything.** That is not our opinion. All four of the major model providers have said in their own words during 2026 that an instruction at the prompt layer can be bypassed; one of them puts it as *the deterministic boundary is what gets hit when everything probabilistic misses.* The rule underneath is old and simple: **a control bounds a grant only if it is enforced by something the grant does not include.** **So an ABP that lists a prohibition without its barrier is making a claim it cannot support.** Every prohibition in an ABP carries the kind of barrier behind it, and the honest ones say, for most deployments today, that the barrier is the second kind. ## One Worked Example, With Published Numbers The clearest way to see what the ABP does is to change one setting and watch the document change. Take a coding agent that runs on a developer's own machine. The published capability map profiles it twice: **once with confirmations enabled, once with confirmations disabled.** Same product, same machine, same account. One setting. With confirmations enabled, a capability like *run programs as the account* has a barrier of the third kind: a setting the agent's own account could change. A person is asked before each action. **That is not a control, because the setting can be switched off from inside the grant, and because people approve almost everything they are asked.** One provider reports that users approved roughly ninety three per cent of permission prompts. With confirmations disabled, the same capability has a barrier of the first kind: nothing. **The grant did not change. The mandate did not change. The delta did not change. The barrier on every capability in the delta moved one row.** Two ABPs, one line different, and the second one is the one most people are actually running. That is the whole argument in one setting. **The ABP is about the deployment, not the product.** *The rows behind this example come from the published map, which states that of ninety nine tool capability rows across its set, twenty one were measured and the rest derived. We repeat that ratio rather than hide it.* ## It Describes And It Does Not Judge **The ABP carries no verdict and no score.** This is the rule that makes it usable, and it takes a moment to see why. **The same ABP is dangerous in one deployment and harmless in another, and nothing about the document changed.** The most permissive grant imaginable, running where there are no assets and nothing reachable, is a low risk. The same grant with a production database attached tomorrow is a high one. The same grant next to a second agent that can act on its outputs is a different risk again. **Risk is a function of the ABP, the assets, the consequences and the date. The ABP is the one input that does not move.** **A policy cannot be dangerous. A deployment can.** So there is no rating on an ABP, no traffic light, no risk level. Anybody who wants one will be asked for the other inputs first, because a score without the assets is wrong in one of the two rooms. **The score has a home, and it is the risk work that sits above the ABP, where the assets are known and a named person signs.** That work exists. It is not this document. **Three things follow from describing without judging, and each is useful.** **A long grant is an inventory, not an admission.** An ABP says a capability exists. It never says a risk is unacceptable. **Correcting a draft is factual.** When we hand somebody a draft ABP for their deployment and ask if it is right, we are not asking them to agree that something is dangerous. We are asking whether their agent can do a thing. That is a question you can put to somebody who knows their business better than you do. **The description keeps.** A verdict goes stale whenever anything in the environment moves. A description of the grant goes stale on a visible clock: when the product changes or the deployment does. **Every ABP carries a [validity statement](../model/index.md)**: *this describes the deployment as at this date; if the risk changed, the deployment changed, not this document.* ## The Label And The Leaflet An ABP is rendered twice from one set of facts. **The label** is one line, for anybody: | Field | Meaning | |---|---| | Shape | The named deployment, in the product's own published words | | Grant | N of 23 primitives | | Mandate | M primitives | | **Excess** | In the grant, not in the mandate. **The finding** | | **Unbounded excess** | Excess whose barrier is one of the first three kinds. **The purchase** | | Irreversible | Granted capabilities that cannot be undone, as published | | Widest reach | The furthest the agent can reach: its project, its host, its tenant, or the world | | Measured | Rows measured against rows derived | | As at | The date and the source version | **Two numbers matter.** *Excess* answers the question this document exists for. *Unbounded excess* is the only number on the label a buyer can move: every real control put in place shifts one capability to the fourth barrier, and the number falls. **The gap between the two is the business case for a control, and it contains no verdict.** **The leaflet** is the full table underneath: every primitive with its barrier, its reversibility, its provenance, and the mandate beside it. For the engineer, the auditor, and anybody who has to price it. **Both are computed from the same facts, and the facts are identical in both.** What differs is how they are grouped, which is a question of who is reading. ## Why The Mandate Reaches Further Than Your Own Material One consequence of writing the mandate down is that it makes visible something most deployments miss. **A grant you hold over other people's material is not a grant you may pass on.** A client sent you a document. A customer gave you access. A colleague shared a folder. Handing an agent the credential that reaches those things is handing on a pass that was issued to you, and in most cases you were not given authority to do that. This is not an analogy. In data protection law it is one sentence: *the processor shall not engage another processor without prior specific or general written authorisation of the controller*, and the first processor stays liable for the second. In professional confidentiality it is a duty with two exits, legal compulsion or the client's consent, and a regulator wrote on 17 August 2026 that putting client documents into a public model tool is to place them in the public domain. In contract it is the permitted recipients clause of every confidentiality agreement, which names employees and advisers and does not name a model provider. **The ABP does not decide any of that. It makes the question askable**, because the mandate is where you write down whose material the agent is meant to touch, and the grant is where you find out whose material it can. ## What An ABP Is Not - **Not an acceptable use policy.** That governs a person's use of a system. An ABP governs what an agent can and may do. Borrowing the frame imports the wrong subject. - **Not a risk assessment.** It has no assets in it and no consequences. It is the input to one. - **Not a compliance assessment, a certification, an audit or a security review** of anything or anybody. It describes a deployment and certifies nobody. - **Not a score.** See above. - **Not a guardrail.** It is what guardrails are compiled from. The barrier column tells you which prohibitions are guardrails already and which are sentences. - **Not a claim about any product.** The capability rows are drawn from published documentation and published measurement, with the source, the date and the measured ratio stated. No adjective is attached to any of them. - **Not a template.** It is derived from one deployment. A template cannot know what your agent can do. ## Where It Comes From We did not invent most of this, and we would rather say so. The four kinds of barrier are already published on our capability map. The vocabulary for expressing permissions, prohibitions and duties with constraints on time, purpose and count has been a W3C recommendation since 2018, and it is in production use in the European data space architectures. The enforcement languages exist: the largest cloud's own agent gateway blocks everything by default and treats any prohibition as overriding any permission, with the reasoning formally verified. The industry's list of the ten agentic application risks, published 9 December 2025, puts tool misuse and privilege abuse at positions two and three, with least privilege and enumerated tool catalogues as the remedies. The United Kingdom's consumer regulator wrote on 9 March 2026 that a business using an agent *should be clear about what tasks an AI agent is allowed to perform, what data it can access, and what constraints apply.* And at least one underwriter of agents already requires, as a scoping input, a statement of the agent's capabilities, its autonomy level, its data access, the tools it can call and its deployment context, which is an ABP by another name. **What did not exist was a document that puts all of that on one page for one deployment, derived rather than copied, and honest about what it is not.** One company sells a set of editable templates. We are aware of nothing that is derived from the deployment, nothing that carries the barrier, and nothing that refuses to carry a score. ## What We Are Asking You This is the part we want back. 1. **Would you correct a draft?** If we gave you a draft ABP for your own deployment, derived from its shape, would you tell us where it was wrong? That correction is how the document gets made, and we want to know if the exchange works. 2. **Which capability did you not know about?** For the shape you run, which row of the grant was news to you? 3. **Are twenty three primitives enough?** We know two things are missing: quantity, since one request and a million are the same primitive today, and interaction between agents, since two agents each within mandate can compose into something neither was authorised to do. What else? 4. **Is the four kind barrier right?** Is there a kind of control we have not listed, or one we have placed in the wrong row? 5. **Does no score survive contact with your organisation?** Or will somebody upstream insist on a rating before they read it? 6. **Which deployment shape next?** We have nine. Which one do you actually run that we have not profiled? 7. **Is Agent Behaviour Policy the right name?** We considered and rejected several. If this one fails for you, we would like to know why. ## Honest Tensions | Tension | Note | |---|---| | No score | It keeps the document true in every room, and it is the first thing every reader asks for | | Derived, not templated | It is the only way the document can be right about your agent, and it means we cannot hand you one without knowing your shape | | Twenty one of ninety nine measured | It is honest, and it means most rows are derived from documentation rather than observed | | The barrier column | It makes the document useful, and it makes most current deployments look unbounded, because most prohibitions today are the second kind | | The mandate is already known | It makes elicitation cheap, and a mandate nobody wrote down is one nobody can be held to | | Describing without judging | It is what makes the ABP an input to everything above it, and it means the ABP alone tells you nothing about whether to worry | ## Open Questions 1. Which name for the deployment shapes, so that two people describing the same setup produce the same ABP? 2. What is the smallest grant that still produces a non empty delta, and is that the right first example? 3. Who elicits the mandate when the person at the table is not the person who authorised the agent? 4. How is quantity added to the primitives without breaking the nine profiles already published? 5. What does the validity statement look like when the product updates weekly? 6. Does the label work printed, at card size, with nine fields? 7. What is the right form for the data files so that people can propose a correction with its evidence attached? ## Relationship To Previous Briefs This document consolidates three briefs of 11 September 2026: one on the product and how it is sold, one on the ABP as a graph with its renderings and its enforcement targets, and one on what sits above it. It inherits the rulings of 10 September on the words that may not be used, and the rule of 20 August that the record is published and the verdict is not. The capability grammar, the nine profiles and the four barriers come from the published capability map and the published simulation, and this document adds nothing to them except a name for the whole. ## Key Claims > **Corrected the same day.** Claim 3 reads, in the corrected wording: the mandate is elicited, the grant is measured, **the delta is derived and never authored**, and the barrier is recorded per capability. [What changed and what follows from it](../model/delta/index.md). | # | Claim | |---|---| | 1 | Most people who deploy an agent know what they asked it to do, and almost nobody knows what it can do | | 2 | An ABP is a written description, for one agent in one deployment, of the grant, the mandate, the delta and the barrier | | 3 | The mandate is elicited, the grant is measured, the delta is computed and never stored, and the barrier is recorded per capability | | 4 | A grant on its own is an inventory, and the mandate is what turns it into a finding | | 5 | There are four kinds of barrier, and only a boundary enforced above the agent that it cannot reach bounds anything | | 6 | All four major model providers have said in 2026 that an instruction at the prompt layer can be bypassed, so a prohibition without its barrier is an unsupported claim | | 7 | Changing one setting on one product moves every barrier in the delta by one row while the grant, the mandate and the delta stay the same | | 8 | The ABP describes and does not judge, because the same document is dangerous in one deployment and harmless in another | | 9 | So the ABP carries no score, and the score lives in the risk work above it, where the assets are known and a named person signs | | 10 | The label carries two numbers that matter, excess and unbounded excess, and only the second can be moved by buying a control | | 11 | A grant you hold over other people's material is not a grant you may pass on, and the ABP is where that question becomes askable | | 12 | The parts of this existed already, published, and what did not exist was one page per deployment, derived, with the barrier, and without a score | ## Sources All read 11 September 2026 unless stated. **The measurements and the vocabulary.** The capability map, its nine profiles, twenty three primitives, four barriers, [undo class](../model/undo/index.md)es and its statement that twenty one of ninety nine rows were measured, at https://what-can-it-do.games.sgit.ai/map/index.html, with its mandates and deltas at the same site. The published simulation with a grant of twelve, a mandate of four and a delta of eight at https://sgit.ai/demos/vaults/licence-to-operate/index.html. The graph rules at https://graphs.sgit.ai/. **That a prompt is not a control.** https://www.anthropic.com/engineering/how-we-contain-claude, 25 May 2026, and the approval rate reported at https://www.infoq.com/news/2026/07/anthropic-claude-containment/, 22 July 2026. https://aws.amazon.com/blogs/security/why-policy-in-amazon-bedrock-agentcore-chose-cedar-for-securing-agentic-workflows/, 20 May 2026. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/, 16 July 2026. The approach paper summarised at https://simonwillison.net/2025/Jun/15/ai-agent-security/, 2025. **Where it comes from.** The rights expression vocabulary at https://www.w3.org/TR/odrl-model/, recommendation of 15 February 2018, and its adoption at https://www.w3.org/blog/2025/w3c-standard-odrl-policy-gaining-industry-adoption, 23 October 2025. The agentic application risk list at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, 9 December 2025. The consumer guidance at https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents, 9 March 2026. The underwriter's scoping requirements at https://www.aiuc-1.com/scoping. The template offer at https://agentguru.co/. **The pass you may not hand on.** Article 28(2) and 28(4) of the General Data Protection Regulation. The warning notice of 17 August 2026 at https://www.sra.org.uk/. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/what-is-an-abp/index.html)* ------------------------------------------------------------------------ # The model > The four objects an ABP is made of, the grammar they are written in, the barrier that decides whether anything is in the way, and the graph rules that govern all of it. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / The model # The model An ABP is not a document. It is four objects, of which the document is a rendering. The order they are produced in is the order this page teaches them, because a grant without a mandate beside it is an inventory and nobody acts on an inventory. ## The four objects | Object | What it is | How it is obtained | |---|---|---| | **The mandate** | What the agent is authorised and expected to do | **Elicited.** In minutes, because the deployer already knows it | | **The grant** | Everything the agent can do | **Measured.** From the deployment shape: the product, where it runs, with what account, with what credentials | | **The delta** | The difference. Excess where it can and you did not ask; shortfall where you asked and it cannot | **Derived.** Recomputed whenever the grant or the mandate changes, stored with the versions of both, and never edited by hand | | **The barrier** | What stands between the agent and each capability | **Recorded**, per capability, from one of four kinds | **Three hundred and forty things is a shrug. Three hundred and forty things and you authorised twelve is a finding.** The mandate is the edge that gives the grant a shape, and it has to be captured even though it is already known. ## Why the delta is derived and never authored > **Nobody writes a delta.** It is only ever the output of a computation over the grant and the mandate, and it is stored along with the versions of both inputs and the time it was computed. That is what makes it checkable rather than stale. [What follows from that](../model/delta/index.md), including why this site said the opposite this morning. ## The pieces **[The capability grammar](../model/capabilities/index.md)**: `verb.object.reach`. 23 primitives, each with the undo class of its effect. Promoted from the published map. Nothing renamed. **[The barrier](../model/barriers/index.md)**: Four kinds, and only the fourth bounds anything. The enforcer test, published as a glyph before it was named as a rule. **[The undo class](../model/undo/index.md)**: Three classes, and the ordering on every rendering this site produces. A property of the action. Not a severity. **[The delta](../model/delta/index.md)**: Derived and never authored. Stored with its inputs pinned, recomputed when either moves, and never edited by hand. Corrected on 11 September, in the open. **[The graph](../model/graph/index.md)**: Five rules that govern the model rather than the styling. Rule five is the acceptance test and it is cheap to apply. **[The schema](../model/schema/index.md)**: What is in the published files, and what a consumer has to state. A consumer pins a version. **[The five examples](../examples/index.md)**: Five ABPs, derived from the data rather than authored. Each states which rows were measured and which derived. ## What is deliberately not modelled **Quantity.** The primitives carry reach and not rate. `send.endpoint.world` is the same primitive for one request and a million. The temporal operators of a policy language, count-within and sum-within, are the shape of the fix and they are not here yet. **Interaction between agents.** Two agents each within mandate can compose into something neither was authorised to do. There is no primitive for it and this is the only sentence about it on the site. **Consequence.** Deliberately, and it is the rule above every other rule on this site. No assets, no consequences, no score. That is not modesty: **no assets does not mean no consequence, it means no consequence to you.** An agent with `send.endpoint.world` and `execute.process.host` in an empty environment can still reach third parties. > **Provenance.** 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../data/upstream/pack.json). --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/model/index.html)* ------------------------------------------------------------------------ # The capability grammar > verb.object.reach: 23 capability primitives, each with its reach and the undo class of its effect. The action vocabulary for everything else on this site. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The capabilities # The capability grammar `verb.object.reach`. **23 primitives**, 10 verbs, 9 object classes and 5 reach classes. This grammar is the action vocabulary for everything else on this site, and it was not invented here. > **This site did not author this.** The grammar, the 23 primitives and their published glosses come from [the capability map](https://what-can-it-do.games.sgit.ai/map/index.html). Promoting an ontology means giving it an address, not a new vocabulary, so nothing here is renamed. A new primitive is a new verb, object class or reach, and it needs a probe; a specific path, host or mailbox is an **instance** of a primitive, never a new one. ## The reach classes | Reach | What it means | |---|---| | `self` | the agent's own process, sandbox or turn | | `project` | the working tree or workspace it was pointed at | | `host` | the machine, container or account it runs as | | `tenant` | the organisation's accounts, repositories and services | | `world` | anything on the internet | **What host, tenant and world mean is the deployment's to say, not the grammar's.** For an agent in a vendor's container, host is the container and tenant is a scoped token: not your machine and not your accounts. Every example page states its own reach names for this reason. ## The 23 primitives | Primitive | Published gloss | Reach | Undo | In how many shapes | |---|---|---|---|---| | [`read.file.project`](../../model/capabilities/read.file.project/index.md) | Read the project it is working on | project | yes | 7 of 9 | | [`write.file.project`](../../model/capabilities/write.file.project/index.md) | Change the project it is working on | project | with-effort | 5 of 9 | | [`read.file.host`](../../model/capabilities/read.file.host/index.md) | Read any file the account can reach | host | no | 7 of 9 | | [`write.file.host`](../../model/capabilities/write.file.host/index.md) | Change any file the account can reach | host | with-effort | 6 of 9 | | [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) | Delete files anywhere the account can reach | host | no | 4 of 9 | | [`read.record.history`](../../model/capabilities/read.record.history/index.md) | Read a retained record: shell history, past sessions | host | no | 4 of 9 | | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) | Run programs as the account | host | with-effort | 6 of 9 | | [`execute.process.self`](../../model/capabilities/execute.process.self/index.md) | Run programs inside its own sandbox only | self | yes | 0 of 9 | | [`send.endpoint.allowed`](../../model/capabilities/send.endpoint.allowed/index.md) | Reach a permitted list of hosts | tenant | no | 1 of 9 | | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | Reach any host on the internet | world | no | 6 of 9 | | [`read.credential.host`](../../model/capabilities/read.credential.host/index.md) | Read credentials stored where it runs | host | no | 4 of 9 | | [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) | Act in accounts with the credentials it holds | tenant | no | 7 of 9 | | [`grant.credential.self`](../../model/capabilities/grant.credential.self/index.md) | Change its own permission settings | self | yes | 3 of 9 | | [`send.message.world`](../../model/capabilities/send.message.world/index.md) | Send a message to anyone | world | no | 0 of 9 | | [`read.message.tenant`](../../model/capabilities/read.message.tenant/index.md) | Read mail or chat it is connected to | tenant | no | 1 of 9 | | [`write.repository.project`](../../model/capabilities/write.repository.project/index.md) | Commit to the repository it was pointed at | project | with-effort | 4 of 9 | | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | Push to a code host (any branch it can reach) | tenant | with-effort | 4 of 9 | | [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) | Sign commits with the key it holds | tenant | no | 3 of 9 | | [`create.record.world`](../../model/capabilities/create.record.world/index.md) | Publish packages, images or pages under the name it holds | world | no | 2 of 9 | | [`write.budget.tenant`](../../model/capabilities/write.budget.tenant/index.md) | Spend money or tokens against an account it holds | tenant | no | 1 of 9 | | [`create.schedule.host`](../../model/capabilities/create.schedule.host/index.md) | Create something that outlives the turn where it runs (a cron, a service) | host | yes | 4 of 9 | | [`create.schedule.tenant`](../../model/capabilities/create.schedule.tenant/index.md) | Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) | tenant | yes | 1 of 9 | | [`read.record.browsing`](../../model/capabilities/read.record.browsing/index.md) | Read every page you visit | host | no | 1 of 9 | ## The rules that come with the set - A specific path, host or mailbox is an instance of a primitive, never a new one. - Reversibility sits on the primitive, not the instance, because it decides whether a gap is a nuisance or a loss - and this estate has settled that recoverability decides insurability. - A grant containing irreversible primitives is a different object from one that does not, however many rows each has. - The set is a starting set and will be wrong at the edges from the first week. A proposed primitive that is a specific thing is an instance; one that is a new verb, object class or reach needs a probe. - A label never says 'your' or 'as you': what host, tenant and world mean is the profile's to say (reach_names), because for an agent in a vendor's container 'host' is the container and 'tenant' is a scoped token, not your machine and not your accounts. [The capabilities as JSON](../../data/capabilities.json) · [The source bytes](../../data/upstream/primitives.json) > **Provenance.** 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/index.html)* ------------------------------------------------------------------------ # read.file.project > Read the project it is working on. Reach project, undo yes. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.file.project # `read.file.project` **Read the project it is working on.** Verb `read`, object `file`, reach `project`, family `filesystem`. Its effect is **yes**: undone. ## In 7 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | the attached working tree is readable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | derived | what you paste or attach | | ● | Claude (in the browser, with connectors switched on) | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | the checked-out tree at this ref is readable - including anything a contributor committed by mistake | | ● | ChatGPT (in the browser, no connectors) | none (not a control) | derived | what you paste or upload - and a record once read is exposure that cannot be unread, on the vendor's side | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner | | **refused** | none | | **unstated** | A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | none: this is what it is for | nothing | none | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.file.project/index.html)* ------------------------------------------------------------------------ # write.file.project > Change the project it is working on. Reach project, undo with-effort. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / write.file.project # `write.file.project` **Change the project it is working on.** Verb `write`, object `file`, reach `project`, family `filesystem`. Its effect is **with-effort**: undone at a cost. ## In 5 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | the attached working tree is writable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | the checked-out tree at this ref is writable by the job | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, A CI job on a hosted runner | | **refused** | none | | **unstated** | Chat, with connectors switched on, Chat in the browser, nothing connected, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | a review before merge | a reviewer's time | setting | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/write.file.project/index.html)* ------------------------------------------------------------------------ # read.file.host > Read any file the account can reach. Reach host, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.file.host # `read.file.host` **Read any file the account can reach.** Verb `read`, object `file`, reach `host`, family `filesystem`. Its effect is **no**: cannot be undone. ## In 7 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | any file in the container - the attached clone, the harness's state, the system. Not your machine's files (the assess tree's 'home: boundary') | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | everything your account can read, because a shell as you reads as you | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | everything your account can read, because a shell as you reads as you | | ◐ | Claude Desktop (a desktop app with local tools) | setting (not a control) | derived | | | ○ | Claude (in the browser, with connectors switched on) | boundary | derived | a drive connector: your other files, as scoped | | ● | A scheduled job running as a service account | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | the runner's user with passwordless escalation: every file on the ephemeral machine | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | Chat, with connectors switched on, A scheduled job under a service account | | **refused** | A coding assistant on my machine, Chat in the browser, nothing connected | | **unstated** | A coding assistant in a container on the web, The desktop app, with local tools switched on, A CI job on a hosted runner, A browser extension I installed | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | run the agent in a container with only the project mounted, or under a separate user account | an afternoon, then ongoing friction (container) · days, and it fights you (account) | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.file.host/index.html)* ------------------------------------------------------------------------ # write.file.host > Change any file the account can reach. Reach host, undo with-effort. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / write.file.host # `write.file.host` **Change any file the account can reach.** Verb `write`, object `file`, reach `host`, family `filesystem`. Its effect is **with-effort**: undone at a cost. ## In 6 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | a zero-byte file was created and removed in /etc: system configuration of the container is writable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ◐ | Claude Desktop (a desktop app with local tools) | setting (not a control) | derived | | | ● | A scheduled job running as a service account | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | the runner's user with passwordless escalation: every file on the ephemeral machine | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, The desktop app, with local tools switched on, Chat in the browser, nothing connected | | **unstated** | A coding assistant in a container on the web, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | the same container or account; the tool's own directory restriction is a setting anything running as you can step around | as above | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/write.file.host/index.html)* ------------------------------------------------------------------------ # delete.file.host > Delete files anywhere the account can reach. Reach host, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / delete.file.host # `delete.file.host` **Delete files anywhere the account can reach.** Verb `delete`, object `file`, reach `host`, family `filesystem`. Its effect is **no**: cannot be undone. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | anything in the container, including the clone; irreversible for the container, and the container is disposable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | the runner's user with passwordless escalation: every file on the ephemeral machine | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, Chat in the browser, nothing connected | | **unstated** | A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | the same container or account; and a backup that the agent cannot reach, because delete at host reach is irreversible | as above, plus a backup outside the grant | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/delete.file.host/index.html)* ------------------------------------------------------------------------ # execute.process.host > Run programs as the account. Reach host, undo with-effort. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / execute.process.host # `execute.process.host` **Run programs as the account.** Verb `execute`, object `process`, reach `host`, family `process`. Its effect is **with-effort**: undone at a cost. ## In 6 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | root inside the container: every process and file IN THE CONTAINER. The container is the host; your machine is not reachable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ◐ | Claude Code (the CLI, on your own machine) | setting (not a control) | derived | | | ◐ | Claude Desktop (a desktop app with local tools) | setting (not a control) | derived | run terminal commands as you | | ● | A scheduled job running as a service account | none (not a control) | derived | as the service account, on a schedule | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | runs as uid 1001; passwordless escalation available (n1a) - programs run as this user and can escalate | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant on my machine, A coding assistant in a container on the web, A CI job on a hosted runner, A scheduled job under a service account | | **refused** | The desktop app, with local tools switched on, Chat in the browser, nothing connected | | **unstated** | Chat, with connectors switched on, A browser extension I installed | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | keep the confirmation prompt on for commands, and run in a container: execution survives inside it and stops being execution on your machine | a click per command · an afternoon for the container | setting (prompt) · boundary (container) | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/execute.process.host/index.html)* ------------------------------------------------------------------------ # execute.process.self > Run programs inside its own sandbox only. Reach self, undo yes. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / execute.process.self # `execute.process.self` **Run programs inside its own sandbox only.** Verb `execute`, object `process`, reach `self`, family `process`. Its effect is **yes**: undone. ## In 0 of 9 published shapes No published shape in this set has it. | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | none | | **unstated** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | already a sandbox; keep it one | nothing | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/execute.process.self/index.html)* ------------------------------------------------------------------------ # send.endpoint.allowed > Reach a permitted list of hosts. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / send.endpoint.allowed # `send.endpoint.allowed` **Reach a permitted list of hosts.** Verb `send`, object `network-endpoint`, reach `tenant`, family `network`. Its effect is **no**: cannot be undone. ## In 1 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ○ | Claude Code on the web (a remote session container) | boundary | observed | six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, A scheduled job under a service account | | **refused** | none | | **unstated** | Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | shorten the list; a host it does not need is a host it can reach | minutes per host, and a failure the first time it needs one you removed | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/send.endpoint.allowed/index.html)* ------------------------------------------------------------------------ # send.endpoint.world > Reach any host on the internet. Reach world, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / send.endpoint.world # `send.endpoint.world` **Reach any host on the internet.** Verb `send`, object `network-endpoint`, reach `world`, family `network`. Its effect is **no**: cannot be undone. ## In 6 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | curl reaches the world unless something above the account stops it | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | curl reaches the world unless something above the account stops it | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | derived | | | ● | A browser extension with broad host permissions | none (not a control) | documented | host permissions | | ● | A scheduled job running as a service account | none (not a control) | derived | | | ● | Actions runner (a hosted CI job) | none (not a control) | observed | github.com 200, pypi.org 200, example.com 200 - UNRESTRICTED egress, no proxy | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A CI job on a hosted runner | | **refused** | Chat in the browser, nothing connected, A browser extension I installed, A scheduled job under a service account | | **unstated** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | route outbound traffic through an allow-list - the one control the hosted container already has, demonstrated rather than claimed | an hour, if you already have somewhere to put it | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/send.endpoint.world/index.html)* ------------------------------------------------------------------------ # read.credential.host > Read credentials stored where it runs. Reach host, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.credential.host # `read.credential.host` **Read credentials stored where it runs.** Verb `read`, object `credential`, reach `host`, family `identity`. Its effect is **no**: cannot be undone. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | the credential-shaped paths present are the SESSION'S OWN: its commit-signing key and its vault keystore. No user credential is in the container; presence cannot tell whose a key is, so this is the operator's account | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | a published read-only audit tool enumerates exactly this class in a home directory | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | a published read-only audit tool enumerates exactly this class in a home directory | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | documented | | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, The desktop app, with local tools switched on, Chat in the browser, nothing connected, A CI job on a hosted runner | | **unstated** | A coding assistant in a container on the web, Chat, with connectors switched on, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | keep credentials out of the account the agent runs as: a credential helper, a separate account, or a container without your home mounted | an afternoon, and re-authenticating where the agent needs a credential of its own | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.credential.host/index.html)* ------------------------------------------------------------------------ # authenticate-as.credential.tenant > Act in accounts with the credentials it holds. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / authenticate-as.credential.tenant # `authenticate-as.credential.tenant` **Act in accounts with the credentials it holds.** Verb `authenticate-as`, object `credential`, reach `tenant`, family `identity`. Its effect is **no**: cannot be undone. ## In 7 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ○ | Claude Code on the web (a remote session container) | boundary | inferred | five key-shaped variables and a code-host token - the platform's, scoped to in-scope repositories; it acts as the platform's app, never as you | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | inferred from the credentials the account holds | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | inferred from the credentials the account holds | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | derived | | | ○ | Claude (in the browser, with connectors switched on) | boundary | derived | a cloud connector acts as you | | ◐ | A browser extension with broad host permissions | setting (not a control) | documented | acts inside sites where you have a session, as you | | ● | A scheduled job running as a service account | none (not a control) | derived | a service-account credential, rarely rotated | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A scheduled job under a service account | | **refused** | A coding assistant on my machine, The desktop app, with local tools switched on, Chat in the browser, nothing connected, A browser extension I installed | | **unstated** | A coding assistant in a container on the web, Chat, with connectors switched on, A CI job on a hosted runner | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | scoped, short-lived tokens issued to the agent rather than your own; read-only where read is all it needs | an hour per service, and rotation | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/authenticate-as.credential.tenant/index.html)* ------------------------------------------------------------------------ # grant.credential.self > Change its own permission settings. Reach self, undo yes. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / grant.credential.self # `grant.credential.self` **Change its own permission settings.** Verb `grant`, object `credential`, reach `self`, family `identity`. Its effect is **yes**: undone. ## In 3 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ◐ | Claude Code (the CLI, on your own machine) | setting (not a control) | derived | anything running as you can rewrite the file that turns the prompt off | | ◐ | Claude Code (the CLI, on your own machine) | setting (not a control) | derived | anything running as you can rewrite the file that turns the prompt off | | ◐ | Claude Desktop (a desktop app with local tools) | setting (not a control) | derived | | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, The desktop app, with local tools switched on | | **unstated** | A coding assistant in a container on the web, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | settings owned by a different user than the one the agent runs as, or set above the session by the platform | minutes, if the platform supports it; otherwise the separate account | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/grant.credential.self/index.html)* ------------------------------------------------------------------------ # send.message.world > Send a message to anyone. Reach world, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / send.message.world # `send.message.world` **Send a message to anyone.** Verb `send`, object `message`, reach `world`, family `communication`. Its effect is **no**: cannot be undone. ## In 0 of 9 published shapes No published shape in this set has it. | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, Chat, with connectors switched on, Chat in the browser, nothing connected | | **unstated** | A coding assistant in a container on the web, The desktop app, with local tools switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | no mail or chat connector, or a connector that drafts and never sends | you press send | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/send.message.world/index.html)* ------------------------------------------------------------------------ # read.message.tenant > Read mail or chat it is connected to. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.message.tenant # `read.message.tenant` **Read mail or chat it is connected to.** Verb `read`, object `message`, reach `tenant`, family `communication`. Its effect is **no**: cannot be undone. ## In 1 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ○ | Claude (in the browser, with connectors switched on) | boundary | derived | a mail or chat connector reads your mail | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | Chat, with connectors switched on | | **refused** | Chat in the browser, nothing connected | | **unstated** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | a connector scoped to one folder or label, or none | the agent answers about less | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.message.tenant/index.html)* ------------------------------------------------------------------------ # write.repository.project > Commit to the repository it was pointed at. Reach project, undo with-effort. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / write.repository.project # `write.repository.project` **Commit to the repository it was pointed at.** Verb `write`, object `repository`, reach `project`, family `code`. Its effect is **with-effort**: undone at a cost. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | a repository is attached and writable | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | | | ○ | Actions runner (a hosted CI job) | boundary | observed | the checked-out tree at this ref is writable by the job | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant on my machine, A coding assistant in a container on the web | | **refused** | none | | **unstated** | The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | none needed for most work; a review before merge is the control | a reviewer's time | setting | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/write.repository.project/index.html)* ------------------------------------------------------------------------ # write.repository.tenant > Push to a code host (any branch it can reach). Reach tenant, undo with-effort. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / write.repository.tenant # `write.repository.tenant` **Push to a code host (any branch it can reach).** Verb `write`, object `repository`, reach `tenant`, family `code`. Its effect is **with-effort**: undone at a cost. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ◐ | Claude Code on the web (a remote session container) | setting (not a control) | observed | the attached repository only (any branch it can reach); branch discipline is the clone's hooks, a setting; no rule at the host | | ◉ | Claude Code (the CLI, on your own machine) | expectation (not a control) | derived | | | ◉ | Claude Code (the CLI, on your own machine) | expectation (not a control) | derived | | | ○ | Claude (in the browser, with connectors switched on) | boundary | derived | a code-host connector | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A coding assistant in a container on the web, A CI job on a hosted runner | | **refused** | Chat, with connectors switched on, Chat in the browser, nothing connected | | **unstated** | A coding assistant on my machine, The desktop app, with local tools switched on, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | a branch protection rule at the host - the agent cannot edit it - and a pre-push hook in the clone for the earlier, cheaper refusal | minutes; and a review step before anything deploys | boundary (host rule) · setting (hook) | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/write.repository.tenant/index.html)* ------------------------------------------------------------------------ # authenticate-as.credential.signing > Sign commits with the key it holds. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / authenticate-as.credential.signing # `authenticate-as.credential.signing` **Sign commits with the key it holds.** Verb `authenticate-as`, object `credential`, reach `tenant`, family `code`. Its effect is **no**: cannot be undone. ## In 3 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | commits are signed with the session's own key, registered as an agent identity in this site's registry (sha256-f9facb4c94da6c19) - not with yours | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | if commit signing is configured for the account, the agent signs as you | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | if commit signing is configured for the account, the agent signs as you | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, A coding assistant in a container on the web | | **unstated** | The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | a signing key of the agent's own, so its commits are signed as it and not as you (the registry's identity records exist for this) | an hour, and a second key to manage | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/authenticate-as.credential.signing/index.html)* ------------------------------------------------------------------------ # create.record.world > Publish packages, images or pages under the name it holds. Reach world, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / create.record.world # `create.record.world` **Publish packages, images or pages under the name it holds.** Verb `create`, object `record`, reach `world`, family `code`. Its effect is **no**: cannot be undone. ## In 2 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | if a registry token is in the home directory | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | if a registry token is in the home directory | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, Chat in the browser, nothing connected | | **unstated** | A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | no publishing token in the agent's environment; publish from CI with a token the agent does not hold | an afternoon to move the publish step | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/create.record.world/index.html)* ------------------------------------------------------------------------ # write.budget.tenant > Spend money or tokens against an account it holds. Reach tenant, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / write.budget.tenant # `write.budget.tenant` **Spend money or tokens against an account it holds.** Verb `write`, object `budget`, reach `tenant`, family `money`. Its effect is **no**: cannot be undone. ## In 1 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | A scheduled job running as a service account | none (not a control) | derived | if the credential is billed | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | Chat in the browser, nothing connected, A scheduled job under a service account | | **unstated** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | a spend cap at the supplier, set by somebody other than the agent - the supplier has a reason to refuse: it is paying | the work stops when the cap is reached, which is the point | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/write.budget.tenant/index.html)* ------------------------------------------------------------------------ # create.schedule.host > Create something that outlives the turn where it runs (a cron, a service). Reach host, undo yes. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / create.schedule.host # `create.schedule.host` **Create something that outlives the turn where it runs (a cron, a service).** Verb `create`, object `schedule`, reach `host`, family `schedule`. Its effect is **yes**: undone. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ○ | Claude Code on the web (a remote session container) | boundary | observed | systemctl and /etc/cron.d exist, so a cron can be written - and dies with the container; the real scheduler is the platform's routines, on the harness row | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | a shell as you can write a crontab | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | derived | a shell as you can write a crontab | | ● | A scheduled job running as a service account | none (not a control) | derived | it is one | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine | | **unstated** | A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | no scheduler in the agent's environment; anything that outlives the turn goes through a person | you create the routine | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/create.schedule.host/index.html)* ------------------------------------------------------------------------ # read.record.history > Read a retained record: shell history, past sessions. Reach host, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.record.history # `read.record.history` **Read a retained record: shell history, past sessions.** Verb `read`, object `record`, reach `host`, family `filesystem`. Its effect is **no**: cannot be undone. ## In 4 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | Claude Code on the web (a remote session container) | none (not a control) | observed | the harness's project directory holds this session's own earlier tool outputs; no user shell history exists here | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | shell history and the harness's own transcripts | | ● | Claude Code (the CLI, on your own machine) | none (not a control) | documented | shell history and the harness's own transcripts | | ● | Claude Desktop (a desktop app with local tools) | none (not a control) | documented | | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat in the browser, nothing connected | | **unstated** | Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | history off, or a fresh environment per task, so the grant is a tree over the present rather than a union over every prior turn | the agent forgets between tasks | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.record.history/index.html)* ------------------------------------------------------------------------ # create.schedule.tenant > Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session). Reach tenant, undo yes. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / create.schedule.tenant # `create.schedule.tenant` **Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session).** Verb `create`, object `schedule`, reach `tenant`, family `schedule`. Its effect is **yes**: undone. ## In 1 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ◐ | Claude Code on the web (a remote session container) | setting (not a control) | self-reported | a routine or a scheduled trigger resumes this session or spawns another later: it outlives the container | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | none | | **refused** | A coding assistant in a container on the web, Chat in the browser, nothing connected | | **unstated** | A coding assistant on my machine, The desktop app, with local tools switched on, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/create.schedule.tenant/index.html)* ------------------------------------------------------------------------ # read.record.browsing > Read every page you visit. Reach host, undo no. Which published deployment shapes have it, at what barrier, and what the starting mandates say. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [The model](../../../model/index.md) / [The capabilities](../../../model/capabilities/index.md) / read.record.browsing # `read.record.browsing` **Read every page you visit.** Verb `read`, object `record`, reach `host`, family `browser`. Its effect is **no**: cannot be undone. ## In 1 of 9 published shapes | | Deployment shape | Barrier there | Known by | Note | |---|---|---|---|---| | ● | A browser extension with broad host permissions | none (not a control) | documented | 'read and change all your data on all websites' | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## What the starting mandates say about it | The mandate says | Which mandates | |---|---| | **authorised** | A browser extension I installed | | **refused** | none | | **unstated** | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A scheduled job under a service account | **Unstated is not authorised.** A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was. ## What would move it to the fourth barrier | What | What it costs | The barrier afterwards | |---|---|---| | grant the extension access on click, or on a list of sites, instead of on all sites; remove the ones you do not use | a click the first time on each site | boundary | > **This is a published reduction, not a recommendation.** Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess. [The capability grammar](../../../model/capabilities/index.md) · [This primitive as JSON](../../../data/capabilities.json) --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/model/capabilities/read.record.browsing/index.html)* ------------------------------------------------------------------------ # The barrier > Four kinds of thing that can stand between an agent and a capability, and only the fourth bounds anything. The enforcer test, which this estate published as a glyph before it named it as a rule. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The barrier # The barrier: what is actually in the way For every capability in the grant, an ABP records what stands between the agent and it. There are four kinds. **Only the fourth bounds anything**, and that is not an opinion. | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## The enforcer test > **A control bounds a grant only if it is enforced by something the grant does not include.** Read the third and fourth rows together and the test falls out of them. A setting the agent's own account could change is not a control, because the grant includes the ability to remove the bound. A boundary enforced above it that it cannot reach is a control, because it does not. **A rule somebody wrote down is the second row and it is where most prohibitions sit today.** All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed; one of them puts it as *the deterministic boundary is what gets hit when everything probabilistic misses*. One provider reports that users approved roughly ninety three per cent of the permission prompts they were shown, which is the third row failing in the other direction. ## What follows for every page on this site **Every prohibition rendered anywhere carries its barrier.** A prohibition displayed without one is a claim the site cannot support, and it manufactures assurance. The honest ABPs say, for most deployments today, that the barrier is the second kind. **Unbounded excess is the only number on the label a buyer can move.** Every real control put in place shifts one capability into the fourth row and the number falls. The gap between excess and unbounded excess is the business case for a control, and it contains no verdict. ## Where the four came from The glyph system on [the published map](https://what-can-it-do.games.sgit.ai/map/index.html) carried all four before anybody wrote the rule down: nothing, a rule somebody wrote down, a setting the agent's own account could change, and a boundary enforced above it that it cannot reach. This site added two fields to them, `is_control` and the reason, and marks both as its own reading rather than as the map's data. [The barriers as JSON](../../data/barriers.json) · [The source bytes](../../data/upstream/vocabulary.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/barriers/index.html)* ------------------------------------------------------------------------ # The undo class > Three classes of reversibility, the ordering on every rendering this site produces, and the one column that is not fully context free. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The undo class # The undo class **A capability that cannot be undone is a different kind of thing from one that can.** That is the whole of it, and it is the ordering on every document this site produces. | Class | What it means | |---|---| | `yes` | undone by the same actor with no loss | | `with-effort` | recoverable from a backup, a history or a revert, at a cost | | `no` | cannot be undone | ## Why it is the ordering An ABP that lists prohibitions alphabetically has buried the only ones that matter. **Irreversible and unbounded is the first row of every document this site produces.** > **This is not a severity ranking and it is not a score.** Reversibility is a property of the action rather than of the context, and stating it as the reason is what keeps the ordering descriptive. The risk product reorders by consequence, because it knows the consequence. This site does not. ## The one column that is not fully context free **Whether deleting a file is reversible depends on backups, snapshots and retention, which are the deployment's and not the product's.** So `undo: no` here is a claim about the product's published behaviour, and the deployment can change it. Saying so is the difference between a document that holds no contextual judgements and one that has smuggled one in. [The undo classes as JSON](../../data/undo-classes.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/undo/index.html)* ------------------------------------------------------------------------ # The delta > Derived and never authored: stored with the versions of its inputs, recomputed when either moves, and never edited by hand. Reality is the third input, the history is the business case, and there are three clocks. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The delta # The delta **The delta is derived and never authored.** Nobody writes a delta. It is only ever the output of a computation over the grant and the mandate, and it is stored along with the versions of both inputs and the time it was computed. ## This page corrects something this site said this morning > **The foundation document says, twice, that the delta is computed and never stored.** The first half is right and the second half is wrong, and the correction was issued on the same day by the project lead. It is published here rather than applied quietly, because the method is to record the gap: [the dev brief that makes the correction](../../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case/index.md), and [the foundation document as published](../../what-is-an-abp/index.md), which otherwise stands in full. | Was | Is | |---|---| | The delta. Computed. Never stored, because the deployment changes. | **The delta. Derived.** Recomputed whenever the grant or the mandate changes, stored with the versions of both, and never edited by hand. | | The delta is computed and never stored. A stored delta is a claim about somebody's environment on a day that has passed. | **The delta is derived and never authored.** Nobody writes a delta. It is only ever the output of a computation over the grant and the mandate, and it is stored along with the versions of both inputs and the time it was computed. **What must never happen is that somebody edits a delta**, because a hand edited delta is a fiction about an environment, and nothing downstream could tell. | ## What the old rule was protecting, and what survives The sentence being corrected was guarding against three real things, and all three survive. | The fear | Does the correction still handle it | |---|---| | A delta becomes a stale claim about somebody's environment | **Yes.** A stored delta carries the versions of its inputs and the time it was computed, so its staleness is a fact rather than a surprise | | A delta gets hand edited into a fiction | **Yes, and more strongly.** Never authored is a harder rule than never stored, because it forbids the act rather than the artefact | | A delta is treated as authoritative after the inputs move | **Yes.** It reacts. A recompute is cheap because the inputs are graphs | **So the correction loses nothing and gains the history.** It is also the fourth instance of a pattern already in force across this network, which is why the corrected sentence is the one that fits and the old one was the odd one out: indexes are generated from the data they index, prose is derived from the graph and never hand edited, a bill of materials is generated from the dependency files, and the delta is derived from the grant and the mandate. **In every case the artefact is stored. What is forbidden is writing it.** ## The word for this already exists **A stored result of a computation over other data, refreshed when its inputs change, never edited directly, is a materialised view.** The vocabulary is decades old and it carries exactly the right properties: it exists for use, it has a refresh policy, its staleness is knowable, and writing to it directly is a category error rather than a permission question. The grant and the mandate are the append only side: a history of what changed and when. The delta is the read model computed from them. **The delta is a projection of the ABP graph, and so is the label, and so is the leaflet.** ### The stored record | Field | Why | |---|---| | `grant_version` | The input, pinned | | `mandate_version` | The input, pinned | | `pack_version` | The published vocabulary it was computed against | | `computed_at` | When | | `computed_by` | Which version of the computation, because the computation is code and code changes | | `excess` | Capabilities in the grant and not in the mandate | | `unbounded_excess` | Excess whose barrier is one of the first three kinds | | `shortfall` | Capabilities in the mandate and not in the grant | > **No field in that record is writable by a person. The way to change a delta is to change a grant or a mandate.** So the release gate does not take the stored records on trust: it **recomputes every one of them** from the profile and the mandate it names and fails on a single row of disagreement. That check is a few lines, because the computation is a set difference, and it is a set difference because the grant and the mandate are held as graphs with a schema rather than as prose. **That is the underlying capability.** All of this can be done by hand today and almost nobody does it. **9 stored deltas**, one per deployment shape and mandate pair: [`/data/deltas/index.json`](../../data/deltas/index.json). ## Reality is the third input The grant is a model of what the agent can do. The mandate is a statement of what somebody meant. **Both are interpretations, and both improve.** The customer says what they actually meant, and the mandate sharpens. Somebody discovers a capability nobody had listed, and the grant grows. | What is observed | What it tells you | |---|---| | Something happened that is not in the grant | **The grant was incomplete.** Add the capability | | Something was blocked that the grant said was possible | **A barrier was missed**, or recorded at the wrong kind. Correct it | | Something in the mandate never happens | Either the mandate is aspirational, or the capability is missing and the shortfall is real | | Something happens repeatedly that is in the grant and not in the mandate | **The mandate is wrong, or the deployment is.** This is the only row where the observation does not say which | > **That last row is the one place a derived delta cannot resolve itself.** An agent doing something outside its mandate, repeatedly, without anybody complaining, means either that the mandate was written too narrowly or that something is happening nobody authorised. **This site publishes the observation. Which of the two it is belongs to the risk layer and to a person.** Record, not verdict, again. **And the calibration loop is the answer to this site's honest weakness.** 21 of 99 capability rows are measured and the rest derived from documentation. Every deployment that runs and reports back moves a row from derived to measured, and because [the capability map](https://what-can-it-do.games.sgit.ai/map/index.html) is shared and public, **it moves for everybody**. That is the reason the map belongs in an open repository rather than inside a product. ### And the collection problem it creates > **A calibration loop needs observation, and the downloadable builds in this estate are ruled never to transmit anything.** The resolution is that calibration happens inside the customer's own instance: their deployment observes, their grant improves, their delta recomputes, and none of it leaves. **What comes back to the shared map is a contribution, not telemetry**: a proposed correction to a capability row, carrying its evidence, submitted deliberately through the same mechanism as any other proposal, with a source, a timestamp and a hash. A person decides to send it. Nothing phones home. **That is slower, and it is the only version that is honest.** ## It reacts, and the trigger has a standard Because the delta is derived, a change in either input propagates without anybody touching the document. **A template cannot do that and a rendered document cannot do that.** Three cases: | What happens | What the ABP does | |---|---| | **A weakness is disclosed in a tool the agent can call.** | Nothing about the deployment changed, but a capability recorded at the fourth barrier is now at the first. The grant is the same and **the unbounded excess jumps**. The ABP changed because the world did | | **A credential is quietly widened.** | Somebody adds a scope to a token to fix an unrelated problem. The grant grows, the mandate does not, and the excess grows by exactly the capabilities that scope carries. **Nobody involved thought they were changing a policy** | | **A control ships.** | A gateway is deployed with default deny. A set of capabilities move from the second barrier to the fourth. **Unbounded excess falls, and the number it falls by is what the project bought** | **The trigger for a recompute already has a standard, so it is a receiver rather than an invention.** The continuous access evaluation profile, published on the standards track by the shared signals working group, defines event types an identity provider transmits and a receiver consumes so that access can be attenuated as things change. | Event type | What it means for the ABP | |---|---| | **Credential Change** | **The grant may have moved.** Recompute | | **Token Claims Change** | **The grant may have moved.** Recompute | | **Assurance Level Change** | A barrier may have moved | | **Device Compliance Change** | A barrier may have moved | | **Risk Level Change** | **Not ours.** That is the risk layer's input, not the ABP's | | **Session Revoked, Established, Presented** | Session lifecycle, below the ABP's altitude | > **Nothing here is wired, and one caveat travels with the citation.** The status of that specification could not be confirmed from its own page, which said standards track rather than final while sitting at a final address. It is named here because it is the right shape, and it should be checked before anybody cites it as settled. ## What hooks to it, and the hazard Behaviours can be hooked to a derived delta: actions, the granting of a licence to operate and the removal of one. **That is where an ABP stops being a document.** It is also hazardous in a specific way: a computation error would revoke a licence. > **The delta crossing a threshold is a record. The consequence is a verdict.** So this site publishes the crossing, with its inputs and its computation version, and **the consequence is a policy the customer or the underwriter set in advance**, never a judgement the ABP makes. That keeps the ABP consequence agnostic while the automation is real, and it means any automatic suspension is traceable to a threshold somebody chose and a computation anybody can rerun. ## The history is the business case, read rather than constructed Store the series and the business case stops being a document somebody writes. A control project has a date; the series has grants, mandates and deltas with dates; so the value of the project is a subtraction: > On 14 March the gateway was deployed. **Unbounded excess fell from thirty one to six. Excess was unchanged**, because the agent can still do the same things; what changed is that twenty five of them are now bounded by something it cannot reach. **That sentence contains no verdict, no score and no adjective**, and both ends of it are stored records with their inputs pinned, so it is checkable. | Use of the series | How soon it pays | |---|---| | **Justifying what was already bought** | The easiest, and the one every security team needs and cannot produce today | | **Pricing what to buy next** | The capabilities in unbounded excess, ordered by how many would move to the fourth barrier per control, is a list with an effect size on each row | | **Evidencing a condition over time** | Asking whether a control was in place throughout a period is a question about a series, not a snapshot. **A stored history answers it and a recomputed present cannot.** This is the one the old wording made impossible | ## Three clocks, and the gap that is not ours | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | **So an ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection.** That is a parameter rather than a defect to hide, and it belongs on the label as part of the validity statement: as at this date, from a twin last synchronised at this date. **And the gap between the second clock and the third is a risk that [the risk layer](https://risks.sgit.ai/) accounts for**, which is the correct home for it, because how much that gap matters depends on the assets, and the ABP does not know the assets. [The twin](https://twins.sgit.ai/) is the interface to the real environment. ## Drift is a neighbouring measurement, and the difference is the mandate The market has a word for a related phenomenon and it is drift. Products announced in September 2026 compare an agent's runtime behaviour against its authorised scope. **That is validation, and it sharpens the distinction rather than blurring it.** | | What it compares | When you learn | |---|---|---| | **Behaviour drift** | What the agent **did** against what it was allowed to do | **After the action** | | **Capability excess** | What the agent **can do** against what it was authorised to do | **Before any action** | **You can only detect drift once an agent has drifted.** An ABP states that the drift is possible before it happens, which is a different thing and an earlier one in the sequence. **Both want a mandate, and the mandate is the scarce input**, which is the strongest reason to make eliciting it cheap and to publish the method. > **No adjective is attached to any named product on this site, and none is here.** Neither product was used or tested. One number from one of those announcements is worth keeping because it is somebody else's figure supporting this site's thesis: fifty seven per cent of enterprise identity is described as unseen and unmanaged. *You do not know what it can do*, said by somebody selling a different answer to it. ## What is not settled - **What the recompute policy is**: on every event, on a schedule, on read, or a combination. It decides how much the receiver has to do. - **Who sets the thresholds a consequence hooks to**: the customer, the underwriter, or a default published here. All three have different shapes. - **How a calibration contribution is submitted without revealing the deployment**, since a correction to a capability row implies somebody runs that shape. - **Whether the shortfall matters commercially.** Capabilities in the mandate and not in the grant are a real finding and nobody has proposed anything against them. - **What happens to a stored delta whose computation version is superseded**: recomputed, marked, or left as the record of what was believed at the time. The third is the most honest and the least useful. [The full brief](../../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case/index.md) · [The stored deltas](../../data/deltas/index.json) · [The four objects](../../model/index.md) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/delta/index.html)* ------------------------------------------------------------------------ # The graph > The five published graph rules, what they force on this model, and the sentence test that decides whether the edges are right. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The graph # The graph An ABP is a graph and every document is a projection of it. The five rules that govern it are published at [graphs.sgit.ai](https://graphs.sgit.ai/) and they govern the model rather than the styling. This page says what each one forces here. | Rule | What it forces on this model | |---|---| | **Every edge is a verb with a distinct inverse.** | `is-granted` and `granted-to` are different edges with different fan out. The inverse is not the same edge walked backwards. | | **The generic association edge is banned.** | There is no `relates-to` anywhere in this model. It constrains nothing and costs fan out. | | **Never render the whole graph. Render the result of a query.** | There is no map of everything on this site. Each page answers one query: this shape's grant, this mandate's delta, this capability across every shape. | | **Rich nodes are acceptable.** | A capability node carries its verb, object, reach, undo class and gloss. The blob is a rendering failure, not a modelling one. | | **If a path does not read as a sentence in the reader's own language, the edges are wrong.** | The acceptance test, below. If a path fails it, the model changes and not the renderer. | ## The sentence test > agent `claude-code-cli-confirmations-disabled` **is-granted** capability `execute.process.host` **bounded-by** barrier `a-rule-somebody-wrote-down` **which-exceeds** mandate `ship-a-feature` **and-is** undo `no` Every example page ends with that path, built from its own data, so the test is applied on every build rather than asserted once here. ## The five layers, and the tension in them A five level compression hierarchy says a class name does not mean the same thing two levels up. The variant rule says every rendering must produce the same fact set, with an empty diff. Both are true, and the resolution is precise: - **The fact set is the leaf assertions**: this shape has this capability, at this barrier, with this undo class; this mandate contains these capabilities; therefore this delta. **Identical in every rendering, and the diff is over these.** - **The classes are how those facts are grouped for a reader.** An executive rendering groups by business consequence, an engineer's by reach and barrier. **Different at different altitudes, and that is correct rather than a defect.** **So the fact diff is over leaf assertions, not over structure.** The label and the leaflet on every example page are two renderings of one fact set, and keeping them that way is why both are generated from the same call. **Altitude is for stakeholder, depth is for detail.** The layers here are altitudes. ## The interchange vocabulary The W3C has had a rights expression vocabulary since 2018: a policy carries permissions, prohibitions and duties, constraints cover time, purpose, count and place, the conflict strategy says **prohibitions win**, and a policy inherits from a parent, which is how a policy for an agent in an environment extends a policy for an agent. Use it as the interchange form through a profile that adds these capability primitives as actions. > **Do not claim it enforces anything, because it does not.** It is a vocabulary for expressing a policy, not a thing that stands in the way. In the barrier's terms an interchange document is a rule somebody wrote down until something above the grant compiles it and enforces it. --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/graph/index.html)* ------------------------------------------------------------------------ # The schema > What is in the published files, what this site added to the data it promoted, and the two rules a consumer and a contributor each have to follow. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [The model](../../model/index.md) / The schema # The schema The published vocabulary, file by file, at stable addresses with cross origin access. It is promoted from a game's data pack rather than authored here, and the difference between the two is written down below rather than blurred. | Address | Type | What is in it | |---|---|---| | [`/data/index.json`](../../data/index.json) | `abp/pack/v1` | The manifest. Start here: it names every other file, the counts, and the version to pin. | | [`/data/capabilities.json`](../../data/capabilities.json) | `abp/capabilities/v1` | The grammar and the 23 primitives, with reach, family, undo class and published gloss. | | [`/data/barriers.json`](../../data/barriers.json) | `abp/barriers/v1` | The four barriers, weakest first, each with `is_control` and the enforcer test behind it. | | [`/data/undo-classes.json`](../../data/undo-classes.json) | `abp/undo-classes/v1` | The three undo classes and the ordering rule. | | [`/data/evidence-tiers.json`](../../data/evidence-tiers.json) | `abp/evidence-tiers/v1` | The seven evidence tiers and which of them this site counts as measured. | | [`/data/profiles/index.json`](../../data/profiles/index.json) | `abp/profiles-index/v1` | The 9 deployment shapes. A shape is a product in a setting, not a product. | | [`/data/mandates/index.json`](../../data/mandates/index.json) | `abp/mandates-index/v1` | The 8 starting mandates, one per surface. | | [`/data/provenance.json`](../../data/provenance.json) | `abp/provenance/v1` | Where every row came from, how many were measured, and the content hash to verify against. | | [`/data/upstream/`](../../data/upstream/pack.json) | the source pack | The bytes as fetched, unchanged. Anything rendered stays one click from its source bytes. | ## What this site added, and what it did not **Nothing was renamed.** Capability ids, barrier ids, undo classes and shape ids are the published ones. Two field names changed and the provenance block on each file says which. **Two fields are this site's own and are marked as such**: `is_control` on a barrier, and the reason behind it. They are a reading of the published wording, not data from the pack. **One derivation is this site's own**: where two tools in a shape reach the same capability, the grant keeps the **weakest** barrier, because the agent takes the easier path. Each profile's provenance block says so. **No delta is in the files, and no score is.** A delta is computed every time it is needed. A score is a verdict and it does not live here at all. ## The two rules > **A consumer pins a version.** Anything that computes from these files states which version it computed against. This is `v0.2.0`, content hash `sha256:d6d4ba40f1fb1f93f66`. A clone that floats against the latest has no reproducible output. > **A proposal carries evidence.** Every node taken from a third party site carries a source URL, a retrieval timestamp and a content hash. A proposal that changes a capability row without one is an assertion, and this site publishes capability claims about named commercial products. [The data layer](../../data/index.md) · [The style rules these files follow](https://coding.sgit.ai/) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/schema/index.html)* ------------------------------------------------------------------------ # Chat in the browser, nothing connected > An Agent Behaviour Policy for chatGPT (in the browser, no connectors): a grant of 1, a mandate of 1, an excess of 0 and an unbounded excess of 0. Derived from published data, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Examples](../../examples/index.md) / Chat in the browser, nothing connected # Chat in the browser, nothing connected **The deployment shape:** ChatGPT (in the browser, no connectors), variant `default`. The smallest grant in the set. A reader who does not believe an agent can do much starts here, and finds that the delta is still not empty. It establishes the four objects with the fewest moving parts. ## Before you scroll > **Write down a number.** Of the 23 capability primitives, how many do you think this deployment has? And of those, how many do you think the person who deployed it asked for? The page answers both below. Writing the guess down first is the one thing that makes a static page do any of the work [the game](https://what-can-it-do.games.sgit.ai/map/index.html) does. ## The label One line, on the outside, for anybody. Two numbers matter: **excess** answers the question this document exists for, and **unbounded excess** is the only number on it that buying a control moves. | Field | Value | Meaning | |---|---|---| | Shape | **ChatGPT (in the browser, no connectors), default** | The named deployment, in the product's published words | | Grant | **1 of 23 primitives** | Everything the agent can do | | Mandate | **1 primitives** | What the deployer authorised and expected | | Excess | **0** | In the grant, not in the mandate. The finding | | Unbounded excess | **0** | Excess whose barrier is not a control. The only number a control purchase moves | | Irreversible | **0** | Granted capabilities with undo: no, as published | | Widest reach | **project** | The furthest reach class in the grant | | Measured | **0 of 1 rows** | Rows seen directly against rows derived | | As at | **11 September 2026, pack v0.8.0** | The date and the source version | > **There is no score on this label, and there will not be one.** The same ABP is dangerous in one deployment and harmless in the next and nothing about the document changed. A policy cannot be dangerous; a deployment can. Risk is a function of the ABP, the assets, the consequences and the date, and only the first of those is here. The score belongs to [the risk work above it](https://risks.sgit.ai/), where the assets are known and a named person signs. ## 1. The shape An assistant in the vendor's environment. It reaches what you paste or upload and nothing on your machine: the vendor's environment is a boundary you did not build. DERIVED from the assess library's web tree. Browsing, if on, is the vendor's egress, not yours. Tools in this shape: `conversation and uploads`. Profile version `2026-09-05`, surface `web`. What the reach classes mean here, which is the profile's to say rather than the grammar's: **host** means the vendor's environment; not your machine, **tenant** means nothing of yours, **world** means the vendor's egress, if browsing is on. **What it cannot reach, and why.** A grant is as much about the boundaries that hold as the ones that do not. | What | Why | Source | |---|---|---| | your machine's files | the vendor's environment is a boundary you did not build | `assess/library.json (web: home)` | | your accounts | no connectors are on | `assess/library.json (web: connect)` | ## 2. The grant, measured Everything the agent can do: **1 of 23** primitives. Ordered irreversible first, then weakest barrier first. **Reversibility is a property of the action, not a severity**, and stating it as the reason is what keeps the ordering descriptive. | | Capability | Undo | Barrier | Known by | The mandate | |---|---|---|---|---|---| | ● | [`read.file.project`](../../model/capabilities/read.file.project/index.md) Read the project it is working on | yes | none (not a control) | derived | **authorised** | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## 3. The mandate, elicited **Chat in the browser, nothing connected.** I paste things in and read what comes back. That is the whole mandate, and the honest baseline: a chat window with nothing connected should be able to do nothing else. A mandate is elicited rather than measured, in minutes, because the deployer already knows it. This one was not: it is a first draft written to be argued with, authored 2026-09-09 by the site, as a starting point - not measured, not surveyed; the first thing to argue with. It authorises **1** primitives, refuses **14** and says nothing either way about **8**. [Propose a change to it](../../data/index.md). ## 4. The delta, derived > **This delta is derived and never authored.** Nobody wrote it. It is the output of a computation over the grant and the mandate, stored at [`/data/deltas/openai__chatgpt-web__default__chat-no-connectors.json`](../../data/deltas/openai__chatgpt-web__default__chat-no-connectors.json) with the version of both inputs pinned, the time it was computed and the version of the computation that produced it. **The release gate recomputes it on every build and fails on a single row of disagreement**, which is how a machine holds a rule that forbids the act rather than the artefact. [Why this changed this morning](../../model/delta/index.md). **Excess: 0.** In the grant and not in the mandate. That is the published definition and it is wider than the set the mandate refused outright: **0** were refused and **0** were never mentioned. A capability the mandate never mentioned was not authorised, and hiding the split would be the other kind of dishonesty. **Unbounded excess: 0.** The excess whose barrier is one of the first three rows: nothing, a rule somebody wrote down, or a setting the agent's own account could change. None of those bounds anything. > **The delta on this shape is empty, and that is a result rather than a failure.** Everything this deployment can do, the mandate asked for. An ABP that could never come back with nothing to report would not be a description, it would be a sales document, and the other four examples would be worth less for it. Note what the grant still is, though: one capability, and a record once read is exposure that cannot be unread, on the vendor's side. **Shortfall: 0.** There is nothing the mandate asked for that this deployment cannot do. ## The same facts, as a figure The table above is complete and it is the wrong shape for the one question this document exists to answer, which is how much of the right hand side has nothing on the left. **A mark with no line reaching it is excess.** *[A figure here in the page: the mandate in one column and the grant in the other, with a line joining every capability that is in both. **0 marks on the grant side have no line reaching them**, of which 0 sit at a barrier that is not a control. The table below the figure carries the same facts, row by row.]* ## 5. The prohibitions The enforceable projection of the delta: one sentence per excess capability, each carrying the layer it would be enforced at and whether it is enforced today. > **There are no prohibitions on this ABP, because the delta is empty.** Nothing this deployment can do sits outside what the mandate asked for. That does not mean nothing is worth deciding: it means the decision was already taken when the mandate was written. > **Why the barrier is on every row.** A prohibition shown without its barrier manufactures assurance. All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed, and the rule underneath is older than any of them: a control bounds a grant only if it is enforced by something the grant does not include. The right hand column is where a control would have to sit, not a recommendation that you buy one. ## 6. The provenance > **Provenance.** 0 of 1 capability rows on this page were measured, meaning seen directly on the thing itself. The other 1 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). **No row here was obtained by probing anybody's system.** A row is measured only from a system we are entitled to run, or from the vendor's own published documentation. Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. ## 7. What this is not > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. **Three clocks, and only the first is ours.** An ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection to somebody else's systems. That is a parameter rather than a defect to hide, and the gap between the second clock and the third belongs to the risk layer, because how much it matters depends on the assets. | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | ## Follow one capability through the model The fifth graph rule says a path should read as a sentence in the reader's own language, and it is the acceptance test for this model: agent [`chatgpt-web-no-connectors`](../../examples/chatgpt-web-no-connectors/index.md) **is-granted** capability [`read.file.project`](../../model/capabilities/read.file.project/index.md) **bounded-by** barrier [`none`](../../model/barriers/index.md) **which-exceeds** mandate [`chat-no-connectors`](../../model/index.md) **and-is** undo [`yes`](../../model/undo/index.md). [The four objects](../../model/index.md) · [The capability grammar](../../model/capabilities/index.md) · [The barriers](../../model/barriers/index.md) · [This shape as JSON](../../data/profiles/openai/chatgpt-web/default.json) · [This mandate as JSON](../../data/mandates/chat-no-connectors.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/examples/chatgpt-web-no-connectors/index.html)* ------------------------------------------------------------------------ # A coding agent on your own machine, confirmations on > An Agent Behaviour Policy for claude Code (the CLI, on your own machine): a grant of 16, a mandate of 5, an excess of 12 and an unbounded excess of 12. Derived from published data, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Examples](../../examples/index.md) / A coding agent on your own machine, confirmations on # A coding agent on your own machine, confirmations on **The deployment shape:** Claude Code (the CLI, on your own machine), variant `local-default`. The confirmation is a barrier, and you can see which row it sits on. This is where the barrier stops being a column and becomes the argument. A confirmation prompt is a setting the agent's own account could change, which is the third row, not the fourth. ## Before you scroll > **Write down a number.** Of the 23 capability primitives, how many do you think this deployment has? And of those, how many do you think the person who deployed it asked for? The page answers both below. Writing the guess down first is the one thing that makes a static page do any of the work [the game](https://what-can-it-do.games.sgit.ai/map/index.html) does. ## The label One line, on the outside, for anybody. Two numbers matter: **excess** answers the question this document exists for, and **unbounded excess** is the only number on it that buying a control moves. | Field | Value | Meaning | |---|---|---| | Shape | **Claude Code (the CLI, on your own machine), local-default** | The named deployment, in the product's published words | | Grant | **16 of 23 primitives** | Everything the agent can do | | Mandate | **5 primitives** | What the deployer authorised and expected | | Excess | **12** | In the grant, not in the mandate. The finding | | Unbounded excess | **12** | Excess whose barrier is not a control. The only number a control purchase moves | | Irreversible | **8** | Granted capabilities with undo: no, as published | | Widest reach | **world** | The furthest reach class in the grant | | Measured | **0 of 22 rows** | Rows seen directly against rows derived | | As at | **11 September 2026, pack v0.8.0** | The date and the source version | > **There is no score on this label, and there will not be one.** The same ABP is dangerous in one deployment and harmless in the next and nothing about the document changed. A policy cannot be dangerous; a deployment can. Risk is a function of the ABP, the assets, the consequences and the date, and only the first of those is here. The score belongs to [the risk work above it](https://risks.sgit.ai/), where the assets are known and a named person signs. ## 1. The shape The common case: one CLI agent running as your user account, credentials in the home directory, confirmations on, no containment. DERIVED from what a command-line program running as your account architecturally is, not measured on any instance - every row is a claim until somebody runs the probes and contributes the file. The assess library's cli tree is the source. Tools in this shape: `shell (Bash)`, `files (Read, Edit, Write)`, `fetch (WebFetch)`. Profile version `2026-09-05`, surface `cli`. What the reach classes mean here, which is the profile's to say rather than the grammar's: **host** means your machine, as your user account, **tenant** means your accounts, with the credentials in your home directory, **world** means the internet. ## 2. The grant, measured Everything the agent can do: **16 of 23** primitives. Ordered irreversible first, then weakest barrier first. **Reversibility is a property of the action, not a severity**, and stating it as the reason is what keeps the ordering descriptive. | | Capability | Undo | Barrier | Known by | The mandate | |---|---|---|---|---|---| | ● | [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) Sign commits with the key it holds | no | none (not a control) | documented | **excess** (refused) | | ● | [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) Act in accounts with the credentials it holds | no | none (not a control) | derived | **excess** (refused) | | ● | [`create.record.world`](../../model/capabilities/create.record.world/index.md) Publish packages, images or pages under the name it holds | no | none (not a control) | documented | **excess** (refused) | | ● | [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) Delete files anywhere the account can reach | no | none (not a control) | derived | **excess** (refused) | | ● | [`read.credential.host`](../../model/capabilities/read.credential.host/index.md) Read credentials stored where it runs | no | none (not a control) | documented | **excess** (refused) | | ● | [`read.file.host`](../../model/capabilities/read.file.host/index.md) Read any file the account can reach | no | none (not a control) | derived | **excess** (refused) | | ● | [`read.record.history`](../../model/capabilities/read.record.history/index.md) Read a retained record: shell history, past sessions | no | none (not a control) | documented | **excess** (refused) | | ● | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) Reach any host on the internet | no | none (not a control) | derived | **excess** (unstated) | | ● | [`write.file.host`](../../model/capabilities/write.file.host/index.md) Change any file the account can reach | with-effort | none (not a control) | derived | **excess** (refused) | | ● | [`write.file.project`](../../model/capabilities/write.file.project/index.md) Change the project it is working on | with-effort | none (not a control) | derived | **authorised** | | ● | [`write.repository.project`](../../model/capabilities/write.repository.project/index.md) Commit to the repository it was pointed at | with-effort | none (not a control) | derived | **authorised** | | ◉ | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) Push to a code host (any branch it can reach) | with-effort | expectation (not a control) | derived | **excess** (unstated) | | ◐ | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) Run programs as the account | with-effort | setting (not a control) | derived | **authorised** | | ● | [`create.schedule.host`](../../model/capabilities/create.schedule.host/index.md) Create something that outlives the turn where it runs (a cron, a service) | yes | none (not a control) | derived | **excess** (refused) | | ● | [`read.file.project`](../../model/capabilities/read.file.project/index.md) Read the project it is working on | yes | none (not a control) | derived | **authorised** | | ◐ | [`grant.credential.self`](../../model/capabilities/grant.credential.self/index.md) Change its own permission settings | yes | setting (not a control) | derived | **excess** (refused) | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## 3. The mandate, elicited **A coding assistant on my machine.** I want it to read and change the project I pointed it at, run the build and the tests, commit to that repository, and fetch the packages and docs it needs. I did not sign up for it reading the rest of my disk, my credentials or my shell history, sending anything to anyone, publishing under my name, changing its own permission settings, or leaving anything behind that runs after it stops. A mandate is elicited rather than measured, in minutes, because the deployer already knows it. This one was not: it is a first draft written to be argued with, authored 2026-09-09 by the site, as a starting point - not measured, not surveyed; the first thing to argue with. It authorises **5** primitives, refuses **11** and says nothing either way about **7**. [Propose a change to it](../../data/index.md). | Capability | What the mandate says about it | |---|---| | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) | 'run my tests' is, on a machine with no sandbox, 'run programs as me' - the want is honest and the consequence is the whole point of the delta | | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | left unstated on purpose: some people want it to push, some do not, and the mandate should not pretend to know | | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | unstated: the want is 'the hosts it needs', which is the allowed-list capability; whether the whole internet is acceptable is a real decision | ## 4. The delta, derived > **This delta is derived and never authored.** Nobody wrote it. It is the output of a computation over the grant and the mandate, stored at [`/data/deltas/anthropic__claude-code__local-default__coding-assistant-on-my-machine.json`](../../data/deltas/anthropic__claude-code__local-default__coding-assistant-on-my-machine.json) with the version of both inputs pinned, the time it was computed and the version of the computation that produced it. **The release gate recomputes it on every build and fails on a single row of disagreement**, which is how a machine holds a rule that forbids the act rather than the artefact. [Why this changed this morning](../../model/delta/index.md). **Excess: 12.** In the grant and not in the mandate. That is the published definition and it is wider than the set the mandate refused outright: **10** were refused and **2** were never mentioned. A capability the mandate never mentioned was not authorised, and hiding the split would be the other kind of dishonesty. **Unbounded excess: 12.** The excess whose barrier is one of the first three rows: nothing, a rule somebody wrote down, or a setting the agent's own account could change. None of those bounds anything. Every one of the 12 excess capabilities here is unbounded. The excess is listed as prohibitions below. **Shortfall: 1.** Asked for and cannot: [`send.endpoint.allowed`](../../model/capabilities/send.endpoint.allowed/index.md). ## The same facts, as a figure The table above is complete and it is the wrong shape for the one question this document exists to answer, which is how much of the right hand side has nothing on the left. **A mark with no line reaching it is excess.** *[A figure here in the page: the mandate in one column and the grant in the other, with a line joining every capability that is in both. **12 marks on the grant side have no line reaching them**, of which 12 sit at a barrier that is not a control, and 1 on the mandate side reach nothing. The table below the figure carries the same facts, row by row.]* ## 5. The prohibitions The enforceable projection of the delta: one sentence per excess capability, each carrying the layer it would be enforced at and whether it is enforced today. **12 of 12 are not enforced today.** They are sentences, not controls. | | Prohibition | Barrier today | Enforced today | Layer a control would sit at | |---|---|---|---|---| | ● | The agent must not sign commits with the key it holds. [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not act in accounts with the credentials it holds. [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not publish packages, images or pages under the name it holds. [`create.record.world`](../../model/capabilities/create.record.world/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not delete files anywhere the account can reach. [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read credentials stored where it runs. [`read.credential.host`](../../model/capabilities/read.credential.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read any file the account can reach. [`read.file.host`](../../model/capabilities/read.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read a retained record: shell history, past sessions. [`read.record.history`](../../model/capabilities/read.record.history/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not reach any host on the internet. [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not change any file the account can reach. [`write.file.host`](../../model/capabilities/write.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ◉ | The agent must not push to a code host (any branch it can reach). [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | expectation | **not enforced** (a sentence, not a control) | boundary (host rule) · setting (hook) | | ● | The agent must not create something that outlives the turn where it runs (a cron, a service). [`create.schedule.host`](../../model/capabilities/create.schedule.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ◐ | The agent must not change its own permission settings. [`grant.credential.self`](../../model/capabilities/grant.credential.self/index.md) | setting | **not enforced** (a sentence, not a control) | boundary | > **Why the barrier is on every row.** A prohibition shown without its barrier manufactures assurance. All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed, and the rule underneath is older than any of them: a control bounds a grant only if it is enforced by something the grant does not include. The right hand column is where a control would have to sit, not a recommendation that you buy one. ## 6. The provenance > **Provenance.** 0 of 22 capability rows on this page were measured, meaning seen directly on the thing itself. The other 22 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). **No row here was obtained by probing anybody's system.** A row is measured only from a system we are entitled to run, or from the vendor's own published documentation. Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. ## 7. What this is not > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. **Three clocks, and only the first is ours.** An ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection to somebody else's systems. That is a parameter rather than a defect to hide, and the gap between the second clock and the third belongs to the risk layer, because how much it matters depends on the assets. | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | ## Follow one capability through the model The fifth graph rule says a path should read as a sentence in the reader's own language, and it is the acceptance test for this model: agent [`claude-code-cli-confirmations-enabled`](../../examples/claude-code-cli-confirmations-enabled/index.md) **is-granted** capability [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) **bounded-by** barrier [`none`](../../model/barriers/index.md) **which-exceeds** mandate [`coding-assistant-on-my-machine`](../../model/index.md) **and-is** undo [`no`](../../model/undo/index.md). [The four objects](../../model/index.md) · [The capability grammar](../../model/capabilities/index.md) · [The barriers](../../model/barriers/index.md) · [This shape as JSON](../../data/profiles/anthropic/claude-code/local-default.json) · [This mandate as JSON](../../data/mandates/coding-assistant-on-my-machine.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/examples/claude-code-cli-confirmations-enabled/index.html)* ------------------------------------------------------------------------ # The same coding agent, confirmations off > An Agent Behaviour Policy for claude Code (the CLI, on your own machine): a grant of 16, a mandate of 5, an excess of 12 and an unbounded excess of 12. Derived from published data, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Examples](../../examples/index.md) / The same coding agent, confirmations off # The same coding agent, confirmations off **The deployment shape:** Claude Code (the CLI, on your own machine), variant `local-confirmations-off`. The same agent, one setting different. Two documents for one agent, differing in one line. It makes the case that the ABP is about the deployment rather than the product in a way no paragraph can. ## Before you scroll > **Write down a number.** Of the 23 capability primitives, how many do you think this deployment has? And of those, how many do you think the person who deployed it asked for? The page answers both below. Writing the guess down first is the one thing that makes a static page do any of the work [the game](https://what-can-it-do.games.sgit.ai/map/index.html) does. ## The label One line, on the outside, for anybody. Two numbers matter: **excess** answers the question this document exists for, and **unbounded excess** is the only number on it that buying a control moves. | Field | Value | Meaning | |---|---|---| | Shape | **Claude Code (the CLI, on your own machine), local-confirmations-off** | The named deployment, in the product's published words | | Grant | **16 of 23 primitives** | Everything the agent can do | | Mandate | **5 primitives** | What the deployer authorised and expected | | Excess | **12** | In the grant, not in the mandate. The finding | | Unbounded excess | **12** | Excess whose barrier is not a control. The only number a control purchase moves | | Irreversible | **8** | Granted capabilities with undo: no, as published | | Widest reach | **world** | The furthest reach class in the grant | | Measured | **0 of 22 rows** | Rows seen directly against rows derived | | As at | **11 September 2026, pack v0.8.0** | The date and the source version | > **There is no score on this label, and there will not be one.** The same ABP is dangerous in one deployment and harmless in the next and nothing about the document changed. A policy cannot be dangerous; a deployment can. Risk is a function of the ABP, the assets, the consequences and the date, and only the first of those is here. The score belongs to [the risk work above it](https://risks.sgit.ai/), where the assets are known and a named person signs. ## 1. The shape The same assistant with its confirmations turned off (an always-allow, or the flag that skips permissions). The rows are the sibling's; what changes is one control: the prompt on execution goes from a setting to nothing. The diff between this profile and local-default is the answer to 'what does turning that off actually give it'. DERIVED, not measured. Tools in this shape: `shell (Bash)`, `files (Read, Edit, Write)`, `fetch (WebFetch)`. Profile version `2026-09-05`, surface `cli`. What the reach classes mean here, which is the profile's to say rather than the grammar's: **host** means your machine, as your user account, **tenant** means your accounts, with the credentials in your home directory, **world** means the internet. ## 2. The grant, measured Everything the agent can do: **16 of 23** primitives. Ordered irreversible first, then weakest barrier first. **Reversibility is a property of the action, not a severity**, and stating it as the reason is what keeps the ordering descriptive. | | Capability | Undo | Barrier | Known by | The mandate | |---|---|---|---|---|---| | ● | [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) Sign commits with the key it holds | no | none (not a control) | documented | **excess** (refused) | | ● | [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) Act in accounts with the credentials it holds | no | none (not a control) | derived | **excess** (refused) | | ● | [`create.record.world`](../../model/capabilities/create.record.world/index.md) Publish packages, images or pages under the name it holds | no | none (not a control) | documented | **excess** (refused) | | ● | [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) Delete files anywhere the account can reach | no | none (not a control) | derived | **excess** (refused) | | ● | [`read.credential.host`](../../model/capabilities/read.credential.host/index.md) Read credentials stored where it runs | no | none (not a control) | documented | **excess** (refused) | | ● | [`read.file.host`](../../model/capabilities/read.file.host/index.md) Read any file the account can reach | no | none (not a control) | derived | **excess** (refused) | | ● | [`read.record.history`](../../model/capabilities/read.record.history/index.md) Read a retained record: shell history, past sessions | no | none (not a control) | documented | **excess** (refused) | | ● | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) Reach any host on the internet | no | none (not a control) | derived | **excess** (unstated) | | ● | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) Run programs as the account | with-effort | none (not a control) | derived | **authorised** | | ● | [`write.file.host`](../../model/capabilities/write.file.host/index.md) Change any file the account can reach | with-effort | none (not a control) | derived | **excess** (refused) | | ● | [`write.file.project`](../../model/capabilities/write.file.project/index.md) Change the project it is working on | with-effort | none (not a control) | derived | **authorised** | | ● | [`write.repository.project`](../../model/capabilities/write.repository.project/index.md) Commit to the repository it was pointed at | with-effort | none (not a control) | derived | **authorised** | | ◉ | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) Push to a code host (any branch it can reach) | with-effort | expectation (not a control) | derived | **excess** (unstated) | | ● | [`create.schedule.host`](../../model/capabilities/create.schedule.host/index.md) Create something that outlives the turn where it runs (a cron, a service) | yes | none (not a control) | derived | **excess** (refused) | | ● | [`read.file.project`](../../model/capabilities/read.file.project/index.md) Read the project it is working on | yes | none (not a control) | derived | **authorised** | | ◐ | [`grant.credential.self`](../../model/capabilities/grant.credential.self/index.md) Change its own permission settings | yes | setting (not a control) | derived | **excess** (refused) | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## 3. The mandate, elicited **A coding assistant on my machine.** I want it to read and change the project I pointed it at, run the build and the tests, commit to that repository, and fetch the packages and docs it needs. I did not sign up for it reading the rest of my disk, my credentials or my shell history, sending anything to anyone, publishing under my name, changing its own permission settings, or leaving anything behind that runs after it stops. A mandate is elicited rather than measured, in minutes, because the deployer already knows it. This one was not: it is a first draft written to be argued with, authored 2026-09-09 by the site, as a starting point - not measured, not surveyed; the first thing to argue with. It authorises **5** primitives, refuses **11** and says nothing either way about **7**. [Propose a change to it](../../data/index.md). | Capability | What the mandate says about it | |---|---| | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) | 'run my tests' is, on a machine with no sandbox, 'run programs as me' - the want is honest and the consequence is the whole point of the delta | | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | left unstated on purpose: some people want it to push, some do not, and the mandate should not pretend to know | | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | unstated: the want is 'the hosts it needs', which is the allowed-list capability; whether the whole internet is acceptable is a real decision | ## 4. The delta, derived > **This delta is derived and never authored.** Nobody wrote it. It is the output of a computation over the grant and the mandate, stored at [`/data/deltas/anthropic__claude-code__local-confirmations-off__coding-assistant-on-my-machine.json`](../../data/deltas/anthropic__claude-code__local-confirmations-off__coding-assistant-on-my-machine.json) with the version of both inputs pinned, the time it was computed and the version of the computation that produced it. **The release gate recomputes it on every build and fails on a single row of disagreement**, which is how a machine holds a rule that forbids the act rather than the artefact. [Why this changed this morning](../../model/delta/index.md). **Excess: 12.** In the grant and not in the mandate. That is the published definition and it is wider than the set the mandate refused outright: **10** were refused and **2** were never mentioned. A capability the mandate never mentioned was not authorised, and hiding the split would be the other kind of dishonesty. **Unbounded excess: 12.** The excess whose barrier is one of the first three rows: nothing, a rule somebody wrote down, or a setting the agent's own account could change. None of those bounds anything. Every one of the 12 excess capabilities here is unbounded. The excess is listed as prohibitions below. **Shortfall: 1.** Asked for and cannot: [`send.endpoint.allowed`](../../model/capabilities/send.endpoint.allowed/index.md). ## The same facts, as a figure The table above is complete and it is the wrong shape for the one question this document exists to answer, which is how much of the right hand side has nothing on the left. **A mark with no line reaching it is excess.** *[A figure here in the page: the mandate in one column and the grant in the other, with a line joining every capability that is in both. **12 marks on the grant side have no line reaching them**, of which 12 sit at a barrier that is not a control, and 1 on the mandate side reach nothing. The table below the figure carries the same facts, row by row.]* ## 5. The prohibitions The enforceable projection of the delta: one sentence per excess capability, each carrying the layer it would be enforced at and whether it is enforced today. **12 of 12 are not enforced today.** They are sentences, not controls. | | Prohibition | Barrier today | Enforced today | Layer a control would sit at | |---|---|---|---|---| | ● | The agent must not sign commits with the key it holds. [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not act in accounts with the credentials it holds. [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not publish packages, images or pages under the name it holds. [`create.record.world`](../../model/capabilities/create.record.world/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not delete files anywhere the account can reach. [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read credentials stored where it runs. [`read.credential.host`](../../model/capabilities/read.credential.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read any file the account can reach. [`read.file.host`](../../model/capabilities/read.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read a retained record: shell history, past sessions. [`read.record.history`](../../model/capabilities/read.record.history/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not reach any host on the internet. [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not change any file the account can reach. [`write.file.host`](../../model/capabilities/write.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ◉ | The agent must not push to a code host (any branch it can reach). [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | expectation | **not enforced** (a sentence, not a control) | boundary (host rule) · setting (hook) | | ● | The agent must not create something that outlives the turn where it runs (a cron, a service). [`create.schedule.host`](../../model/capabilities/create.schedule.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ◐ | The agent must not change its own permission settings. [`grant.credential.self`](../../model/capabilities/grant.credential.self/index.md) | setting | **not enforced** (a sentence, not a control) | boundary | > **Why the barrier is on every row.** A prohibition shown without its barrier manufactures assurance. All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed, and the rule underneath is older than any of them: a control bounds a grant only if it is enforced by something the grant does not include. The right hand column is where a control would have to sit, not a recommendation that you buy one. ## 6. The provenance > **Provenance.** 0 of 22 capability rows on this page were measured, meaning seen directly on the thing itself. The other 22 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). **No row here was obtained by probing anybody's system.** A row is measured only from a system we are entitled to run, or from the vendor's own published documentation. Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. ## 7. What this is not > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. **Three clocks, and only the first is ours.** An ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection to somebody else's systems. That is a parameter rather than a defect to hide, and the gap between the second clock and the third belongs to the risk layer, because how much it matters depends on the assets. | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | ## Follow one capability through the model The fifth graph rule says a path should read as a sentence in the reader's own language, and it is the acceptance test for this model: agent [`claude-code-cli-confirmations-disabled`](../../examples/claude-code-cli-confirmations-disabled/index.md) **is-granted** capability [`authenticate-as.credential.signing`](../../model/capabilities/authenticate-as.credential.signing/index.md) **bounded-by** barrier [`none`](../../model/barriers/index.md) **which-exceeds** mandate [`coding-assistant-on-my-machine`](../../model/index.md) **and-is** undo [`no`](../../model/undo/index.md). [The four objects](../../model/index.md) · [The capability grammar](../../model/capabilities/index.md) · [The barriers](../../model/barriers/index.md) · [This shape as JSON](../../data/profiles/anthropic/claude-code/local-confirmations-off.json) · [This mandate as JSON](../../data/mandates/coding-assistant-on-my-machine.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/examples/claude-code-cli-confirmations-disabled/index.html)* ------------------------------------------------------------------------ # A browser extension with broad host permissions > An Agent Behaviour Policy for A browser extension with broad host permissions: a grant of 3, a mandate of 1, an excess of 2 and an unbounded excess of 2. Derived from published data, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Examples](../../examples/index.md) / A browser extension with broad host permissions # A browser extension with broad host permissions **The deployment shape:** A browser extension with broad host permissions, variant `broad-host-permissions`. Other people's data, and the mandate nobody wrote down. The pages you visit were not all yours to hand over. This is where the mandate reaches further than your own material. ## Before you scroll > **Write down a number.** Of the 23 capability primitives, how many do you think this deployment has? And of those, how many do you think the person who deployed it asked for? The page answers both below. Writing the guess down first is the one thing that makes a static page do any of the work [the game](https://what-can-it-do.games.sgit.ai/map/index.html) does. ## The label One line, on the outside, for anybody. Two numbers matter: **excess** answers the question this document exists for, and **unbounded excess** is the only number on it that buying a control moves. | Field | Value | Meaning | |---|---|---| | Shape | **A browser extension with broad host permissions, broad-host-permissions** | The named deployment, in the product's published words | | Grant | **3 of 23 primitives** | Everything the agent can do | | Mandate | **1 primitives** | What the deployer authorised and expected | | Excess | **2** | In the grant, not in the mandate. The finding | | Unbounded excess | **2** | Excess whose barrier is not a control. The only number a control purchase moves | | Irreversible | **3** | Granted capabilities with undo: no, as published | | Widest reach | **world** | The furthest reach class in the grant | | Measured | **0 of 3 rows** | Rows seen directly against rows derived | | As at | **11 September 2026, pack v0.8.0** | The date and the source version | > **There is no score on this label, and there will not be one.** The same ABP is dangerous in one deployment and harmless in the next and nothing about the document changed. A policy cannot be dangerous; a deployment can. Risk is a function of the ABP, the assets, the consequences and the date, and only the first of those is here. The score belongs to [the risk work above it](https://risks.sgit.ai/), where the assets are known and a named person signs. ## 1. The shape Not an agent by name, and it has a grant: an extension granted 'read and change all your data on all websites' reads every page you visit, reaches any host, and acts inside the sites you are logged into. Nobody wrote it a mandate. DERIVED from the permission model the browser documents; not measured on any instance. Tools in this shape: `the extension`. Profile version `2026-09-05`, surface `extension`. What the reach classes mean here, which is the profile's to say rather than the grammar's: **host** means your browser - every page, every logged-in site, **tenant** means the sites you are logged into, as you, **world** means the internet, from your browser. **What it cannot reach, and why.** A grant is as much about the boundaries that hold as the ones that do not. | What | Why | Source | |---|---|---| | files on your disk | the browser sandbox; an extension reads pages, not the filesystem | `the browser's extension permission model` | ## 2. The grant, measured Everything the agent can do: **3 of 23** primitives. Ordered irreversible first, then weakest barrier first. **Reversibility is a property of the action, not a severity**, and stating it as the reason is what keeps the ordering descriptive. | | Capability | Undo | Barrier | Known by | The mandate | |---|---|---|---|---|---| | ● | [`read.record.browsing`](../../model/capabilities/read.record.browsing/index.md) Read every page you visit | no | none (not a control) | documented | **authorised** | | ● | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) Reach any host on the internet | no | none (not a control) | documented | **excess** (refused) | | ◐ | [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) Act in accounts with the credentials it holds | no | setting (not a control) | documented | **excess** (refused) | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## 3. The mandate, elicited **A browser extension I installed.** I want it to work on the sites I use it on. I did not install it so that it could see every page I visit, act inside the accounts I am logged into, or send what it sees anywhere. A mandate is elicited rather than measured, in minutes, because the deployer already knows it. This one was not: it is a first draft written to be argued with, authored 2026-09-09 by the site, as a starting point - not measured, not surveyed; the first thing to argue with. It authorises **1** primitives, refuses **2** and says nothing either way about **20**. [Propose a change to it](../../data/index.md). | Capability | What the mandate says about it | |---|---| | [`read.record.browsing`](../../model/capabilities/read.record.browsing/index.md) | the want is 'the sites I chose'; the grant is every page - the same capability at two different reaches, which is what the reduction ('on click, or on a list of sites') narrows | ## 4. The delta, derived > **This delta is derived and never authored.** Nobody wrote it. It is the output of a computation over the grant and the mandate, stored at [`/data/deltas/generic__browser-extension__broad-host-permissions__browser-extension-i-installed.json`](../../data/deltas/generic__browser-extension__broad-host-permissions__browser-extension-i-installed.json) with the version of both inputs pinned, the time it was computed and the version of the computation that produced it. **The release gate recomputes it on every build and fails on a single row of disagreement**, which is how a machine holds a rule that forbids the act rather than the artefact. [Why this changed this morning](../../model/delta/index.md). **Excess: 2.** In the grant and not in the mandate. That is the published definition and it is wider than the set the mandate refused outright: **2** were refused and **0** were never mentioned. A capability the mandate never mentioned was not authorised, and hiding the split would be the other kind of dishonesty. **Unbounded excess: 2.** The excess whose barrier is one of the first three rows: nothing, a rule somebody wrote down, or a setting the agent's own account could change. None of those bounds anything. Every one of the 2 excess capabilities here is unbounded. The excess is listed as prohibitions below. **Shortfall: 0.** There is nothing the mandate asked for that this deployment cannot do. ## The same facts, as a figure The table above is complete and it is the wrong shape for the one question this document exists to answer, which is how much of the right hand side has nothing on the left. **A mark with no line reaching it is excess.** *[A figure here in the page: the mandate in one column and the grant in the other, with a line joining every capability that is in both. **2 marks on the grant side have no line reaching them**, of which 2 sit at a barrier that is not a control. The table below the figure carries the same facts, row by row.]* ## 5. The prohibitions The enforceable projection of the delta: one sentence per excess capability, each carrying the layer it would be enforced at and whether it is enforced today. **2 of 2 are not enforced today.** They are sentences, not controls. | | Prohibition | Barrier today | Enforced today | Layer a control would sit at | |---|---|---|---|---| | ● | The agent must not reach any host on the internet. [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ◐ | The agent must not act in accounts with the credentials it holds. [`authenticate-as.credential.tenant`](../../model/capabilities/authenticate-as.credential.tenant/index.md) | setting | **not enforced** (a sentence, not a control) | boundary | > **Why the barrier is on every row.** A prohibition shown without its barrier manufactures assurance. All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed, and the rule underneath is older than any of them: a control bounds a grant only if it is enforced by something the grant does not include. The right hand column is where a control would have to sit, not a recommendation that you buy one. ## 6. The provenance > **Provenance.** 0 of 3 capability rows on this page were measured, meaning seen directly on the thing itself. The other 3 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). **No row here was obtained by probing anybody's system.** A row is measured only from a system we are entitled to run, or from the vendor's own published documentation. Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. ## 7. What this is not > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. **Three clocks, and only the first is ours.** An ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection to somebody else's systems. That is a parameter rather than a defect to hide, and the gap between the second clock and the third belongs to the risk layer, because how much it matters depends on the assets. | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | ## Follow one capability through the model The fifth graph rule says a path should read as a sentence in the reader's own language, and it is the acceptance test for this model: agent [`browser-extension-broad-host-permissions`](../../examples/browser-extension-broad-host-permissions/index.md) **is-granted** capability [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) **bounded-by** barrier [`none`](../../model/barriers/index.md) **which-exceeds** mandate [`browser-extension-i-installed`](../../model/index.md) **and-is** undo [`no`](../../model/undo/index.md). [The four objects](../../model/index.md) · [The capability grammar](../../model/capabilities/index.md) · [The barriers](../../model/barriers/index.md) · [This shape as JSON](../../data/profiles/generic/browser-extension/broad-host-permissions.json) · [This mandate as JSON](../../data/mandates/browser-extension-i-installed.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/examples/browser-extension-broad-host-permissions/index.html)* ------------------------------------------------------------------------ # A CI job on a hosted runner, under a service account > An Agent Behaviour Policy for actions runner (a hosted CI job): a grant of 8, a mandate of 5, an excess of 4 and an unbounded excess of 3. Derived from published data, with no score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Examples](../../examples/index.md) / A CI job on a hosted runner, under a service account # A CI job on a hosted runner, under a service account **The deployment shape:** Actions runner (a hosted CI job), variant `ci`. Persistence, and reach beyond the turn. A service account rather than a person, a push to a code host, and the irreversible class arriving in a deployment nobody thinks of as an agent. ## Before you scroll > **Write down a number.** Of the 23 capability primitives, how many do you think this deployment has? And of those, how many do you think the person who deployed it asked for? The page answers both below. Writing the guess down first is the one thing that makes a static page do any of the work [the game](https://what-can-it-do.games.sgit.ai/map/index.html) does. ## The label One line, on the outside, for anybody. Two numbers matter: **excess** answers the question this document exists for, and **unbounded excess** is the only number on it that buying a control moves. | Field | Value | Meaning | |---|---|---| | Shape | **Actions runner (a hosted CI job), ci** | The named deployment, in the product's published words | | Grant | **8 of 23 primitives** | Everything the agent can do | | Mandate | **5 primitives** | What the deployer authorised and expected | | Excess | **4** | In the grant, not in the mandate. The finding | | Unbounded excess | **3** | Excess whose barrier is not a control. The only number a control purchase moves | | Irreversible | **3** | Granted capabilities with undo: no, as published | | Widest reach | **world** | The furthest reach class in the grant | | Measured | **8 of 8 rows** | Rows seen directly against rows derived | | As at | **11 September 2026, pack v0.8.0** | The date and the source version | > **There is no score on this label, and there will not be one.** The same ABP is dangerous in one deployment and harmless in the next and nothing about the document changed. A policy cannot be dangerous; a deployment can. Risk is a function of the ABP, the assets, the consequences and the date, and only the first of those is here. The score belongs to [the risk work above it](https://risks.sgit.ai/), where the assets are known and a named person signs. ## 1. The shape An ephemeral CI job with no agent, no hooks, and one platform-enforced grant: the workflow's permissions block. MEASURED on 26 August by measure.py inside the runner (the library's second entry), translated into findings on 5 September. Unrestricted egress; the token cannot write. Tools in this shape: `the job's shell`. Profile version `2026-08-26`, surface `ci`. What the reach classes mean here, which is the profile's to say rather than the grammar's: **host** means the runner - destroyed after the job; not your machine, **tenant** means the repository, with the workflow's token, **world** means the internet, unrestricted. **What it cannot reach, and why.** A grant is as much about the boundaries that hold as the ones that do not. | What | Why | Source | |---|---|---| | your machine | a hosted runner | `library entry 2` | | the repository, for writing | the token is contents:read | `evidence: ci.permissions-block` | ## 2. The grant, measured Everything the agent can do: **8 of 23** primitives. Ordered irreversible first, then weakest barrier first. **Reversibility is a property of the action, not a severity**, and stating it as the reason is what keeps the ordering descriptive. | | Capability | Undo | Barrier | Known by | The mandate | |---|---|---|---|---|---| | ● | [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) Delete files anywhere the account can reach | no | none (not a control) | observed | **excess** (unstated) | | ● | [`read.file.host`](../../model/capabilities/read.file.host/index.md) Read any file the account can reach | no | none (not a control) | observed | **excess** (unstated) | | ● | [`send.endpoint.world`](../../model/capabilities/send.endpoint.world/index.md) Reach any host on the internet | no | none (not a control) | observed | **authorised** | | ● | [`execute.process.host`](../../model/capabilities/execute.process.host/index.md) Run programs as the account | with-effort | none (not a control) | observed | **authorised** | | ● | [`write.file.host`](../../model/capabilities/write.file.host/index.md) Change any file the account can reach | with-effort | none (not a control) | observed | **excess** (unstated) | | ● | [`write.file.project`](../../model/capabilities/write.file.project/index.md) Change the project it is working on | with-effort | none (not a control) | observed | **authorised** | | ○ | [`write.repository.project`](../../model/capabilities/write.repository.project/index.md) Commit to the repository it was pointed at | with-effort | boundary | observed | **excess** (unstated) | | ● | [`read.file.project`](../../model/capabilities/read.file.project/index.md) Read the project it is working on | yes | none (not a control) | observed | **authorised** | | | Barrier | What stands in the way | Is it a control | |---|---|---|---| | ● | none | nothing in the way | no | | ◉ | expectation | a rule in prose, enforced by nobody | no | | ◐ | setting | a switch the agent's own account can flip | no | | ○ | boundary | enforced above the grant, out of the agent's reach | **yes** | ## 3. The mandate, elicited **A CI job on a hosted runner.** Check out the code, build it, run the tests, fetch what it needs, and - when a release is cut - push the tag. I did not want it reading credentials beyond its own token. A mandate is elicited rather than measured, in minutes, because the deployer already knows it. This one was not: it is a first draft written to be argued with, authored 2026-09-09 by the site, as a starting point - not measured, not surveyed; the first thing to argue with. It authorises **5** primitives, refuses **1** and says nothing either way about **17**. [Propose a change to it](../../data/index.md). | Capability | What the mandate says about it | |---|---| | [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md) | deliberately in the mandate: most release workflows push a tag, and this profile's token is contents:read - so this row is a shortfall, and the kind the game calls 'a gap you were counting on' | | [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) | unstated: the runner is destroyed after the job | ## 4. The delta, derived > **This delta is derived and never authored.** Nobody wrote it. It is the output of a computation over the grant and the mandate, stored at [`/data/deltas/github__actions-runner__ci__ci-job.json`](../../data/deltas/github__actions-runner__ci__ci-job.json) with the version of both inputs pinned, the time it was computed and the version of the computation that produced it. **The release gate recomputes it on every build and fails on a single row of disagreement**, which is how a machine holds a rule that forbids the act rather than the artefact. [Why this changed this morning](../../model/delta/index.md). **Excess: 4.** In the grant and not in the mandate. That is the published definition and it is wider than the set the mandate refused outright: **0** were refused and **4** were never mentioned. A capability the mandate never mentioned was not authorised, and hiding the split would be the other kind of dishonesty. **Unbounded excess: 3.** The excess whose barrier is one of the first three rows: nothing, a rule somebody wrote down, or a setting the agent's own account could change. None of those bounds anything. The excess is listed as prohibitions below. **Shortfall: 1.** Asked for and cannot: [`write.repository.tenant`](../../model/capabilities/write.repository.tenant/index.md). ## The same facts, as a figure The table above is complete and it is the wrong shape for the one question this document exists to answer, which is how much of the right hand side has nothing on the left. **A mark with no line reaching it is excess.** *[A figure here in the page: the mandate in one column and the grant in the other, with a line joining every capability that is in both. **4 marks on the grant side have no line reaching them**, of which 3 sit at a barrier that is not a control, and 1 on the mandate side reach nothing. The table below the figure carries the same facts, row by row.]* ## 5. The prohibitions The enforceable projection of the delta: one sentence per excess capability, each carrying the layer it would be enforced at and whether it is enforced today. **3 of 4 are not enforced today.** They are sentences, not controls. | | Prohibition | Barrier today | Enforced today | Layer a control would sit at | |---|---|---|---|---| | ● | The agent must not delete files anywhere the account can reach. [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not read any file the account can reach. [`read.file.host`](../../model/capabilities/read.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ● | The agent must not change any file the account can reach. [`write.file.host`](../../model/capabilities/write.file.host/index.md) | none | **not enforced** (a sentence, not a control) | boundary | | ○ | The agent must not commit to the repository it was pointed at. [`write.repository.project`](../../model/capabilities/write.repository.project/index.md) | boundary | **enforced** | already enforced above the grant | > **Why the barrier is on every row.** A prohibition shown without its barrier manufactures assurance. All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed, and the rule underneath is older than any of them: a control bounds a grant only if it is enforced by something the grant does not include. The right hand column is where a control would have to sit, not a recommendation that you buy one. ## 6. The provenance > **Provenance.** 8 of 8 capability rows on this page were measured, meaning seen directly on the thing itself. The other 0 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../../data/upstream/pack.json). **No row here was obtained by probing anybody's system.** A row is measured only from a system we are entitled to run, or from the vendor's own published documentation. Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. ## 7. What this is not > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Validity.** This describes the deployment shape as at 11 September 2026, from a twin last synchronised at no twin: these shapes are published profiles, not a synchronised environment. It is not an expiry and it does not mean stale: if the risk changed, the deployment changed, not this document. **Three clocks, and only the first is ours.** An ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection to somebody else's systems. That is a parameter rather than a defect to hide, and the gap between the second clock and the third belongs to the risk layer, because how much it matters depends on the assets. | Clock | What it measures | Who controls it | |---|---|---| | The ABP's clock | When the grant was last measured or calibrated | Us, and it can run on events | | The twin's clock | When the twin last synchronised with the real environment | The customer's integration | | Reality's clock | Never stops | Nobody | ## Follow one capability through the model The fifth graph rule says a path should read as a sentence in the reader's own language, and it is the acceptance test for this model: agent [`github-actions-hosted-runner`](../../examples/github-actions-hosted-runner/index.md) **is-granted** capability [`delete.file.host`](../../model/capabilities/delete.file.host/index.md) **bounded-by** barrier [`none`](../../model/barriers/index.md) **which-exceeds** mandate [`ci-job`](../../model/index.md) **and-is** undo [`no`](../../model/undo/index.md). [The four objects](../../model/index.md) · [The capability grammar](../../model/capabilities/index.md) · [The barriers](../../model/barriers/index.md) · [This shape as JSON](../../data/profiles/github/actions-runner/ci.json) · [This mandate as JSON](../../data/mandates/ci-job.json) --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/examples/github-actions-hosted-runner/index.html)* ------------------------------------------------------------------------ # Five worked examples > Five Agent Behaviour Policies, one per deployment shape, derived from published data rather than authored. Each states which of its rows were measured and which were derived, and none carries a score. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / Examples # Five worked examples Five ABPs, from the smallest grant in the set to a service account that outlives the turn. **They are derived rather than authored**: the rows come from a published data pack, and the delta on each page is computed when the page is built. > **Before you read any of them, write down a number.** For a deployment you actually run, how many of the 23 capability primitives do you think it has? Most people who have deployed an agent know what they asked it to do, and almost nobody knows what it can do. The gap between your number and the table below is the reason this document type exists. ## The five, side by side | Deployment shape | Why this one | Grant | Mandate | Excess | Unbounded excess | Irreversible | Widest reach | Measured | |---|---|---|---|---|---|---|---|---| | [Chat in the browser, nothing connected](../examples/chatgpt-web-no-connectors/index.md) | *The smallest grant in the set* | 1 | 1 | **0** | **0** | 0 | project | 0 of 1 | | [A coding agent on your own machine, confirmations on](../examples/claude-code-cli-confirmations-enabled/index.md) | *The confirmation is a barrier, and you can see which row it sits on* | 16 | 5 | **12** | **12** | 8 | world | 0 of 22 | | [The same coding agent, confirmations off](../examples/claude-code-cli-confirmations-disabled/index.md) | *The same agent, one setting different* | 16 | 5 | **12** | **12** | 8 | world | 0 of 22 | | [A browser extension with broad host permissions](../examples/browser-extension-broad-host-permissions/index.md) | *Other people's data, and the mandate nobody wrote down* | 3 | 1 | **2** | **2** | 3 | world | 0 of 3 | | [A CI job on a hosted runner, under a service account](../examples/github-actions-hosted-runner/index.md) | *Persistence, and reach beyond the turn* | 8 | 5 | **4** | **3** | 3 | world | 8 of 8 | **No column here is a score.** Excess is a count of capabilities in the grant and not in the mandate. Unbounded excess is how many of those sit at a barrier that is not a control. Neither says whether any of it is acceptable, because acceptability is not in the document. ## Read the third one first [Claude Code with confirmations on](../examples/claude-code-cli-confirmations-enabled/index.md) and [the same thing with confirmations off](../examples/claude-code-cli-confirmations-disabled/index.md) are the same product, the same machine and the same account, with one setting different. **Reading them side by side is the argument.** > **And the pair says something the foundation document does not.** The foundation document says that turning confirmations off moves the barrier on every capability in the delta by one row. In the published data it moves exactly one barrier, on `execute.process.host`, and that capability is inside the mandate rather than in the delta: the deployer asked for it. So the label's numbers do not move at all and the document is still materially different. That is a stronger argument for the leaflet and against a headline number, and it is recorded as a disagreement in [v0.1.0's notes](../versions/v0.1.0/index.md) rather than quietly resolved. ## What each one cost to make Nobody knows what an ABP costs to produce, and the store has to price one. So this is instrumented rather than estimated. | Example | Time | Questions asked of a human | Note | |---|---|---|---| | [chatgpt-web-no-connectors](../examples/chatgpt-web-no-connectors/index.md) | 5 min | 0 | The smallest grant. Nothing new was needed once the generator existed. | | [claude-code-cli-confirmations-enabled](../examples/claude-code-cli-confirmations-enabled/index.md) | 5 min | 0 | The first one where the barrier column carries the argument. | | [claude-code-cli-confirmations-disabled](../examples/claude-code-cli-confirmations-disabled/index.md) | 5 min | 0 | Built second in importance and first in value. It is the same generator call against a different profile id. | | [browser-extension-broad-host-permissions](../examples/browser-extension-broad-host-permissions/index.md) | 5 min | 0 | Three capabilities, all three irreversible. The shortest page and not the mildest. | | [github-actions-hosted-runner](../examples/github-actions-hosted-runner/index.md) | 5 min | 0 | A service account rather than a person. The only other shape in the set with measured rows. | > **The honest version of this table is the sentence underneath it.** The five examples took about four hours in total, and essentially all of it went into the generator, the promoted schema and the provenance line. The marginal cost of the sixth example, for a shape already in the published map, is one line in a list and a build. **That is not the number the store needs.** The number the store needs is what it costs to produce an ABP for a shape that is NOT in the map, where the grant has to be measured rather than looked up, and this site cannot tell you that yet because it has not done one. Nought questions had to be asked of a human for these five, which is the same finding from the other side: they were derived, not elicited. ## What none of these is > **This is not an assessment.** Nothing here is an audit, a certification, a compliance assessment or a security review of any named product. It is an illustration of a method, using a published configuration, and every row carries its source, its date and whether it was measured or derived. No adjective is attached to any of it, and there is no score. > **Provenance.** 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to [the published capability map](https://what-can-it-do.games.sgit.ai/map/index.html), retrieved 2026-09-11T13:00:37Z, content hash `sha256:d6d4ba40f1fb1f93f66`. [The source bytes](../data/upstream/pack.json). --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/examples/index.html)* ------------------------------------------------------------------------ # The data > The capabilities, barriers, undo classes, deployment shapes and mandates an ABP is written in, as JSON at stable addresses with cross origin access, with the source bytes they were promoted from. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / The data # The data The published vocabulary of the Agent Behaviour Policy: **23 capabilities**, **4 barriers**, **3 undo classes**, **9 deployment shapes** and **8 starting mandates**, at stable addresses with cross origin access. > **Start at [`/data/index.json`](../data/index.json).** It names every other file, carries the counts and states the version to pin. This is `v0.2.0`. ## Where it came from, and what that obliges **This site did not author this ontology.** It was published as a data pack the game at [what-can-it-do.games.sgit.ai](https://what-can-it-do.games.sgit.ai/map/index.html) reads, and the job here was to promote it out of a game's internals into a published schema the network can cite. Nothing was renamed. | Field | Value | |---|---| | Source | `https://what-can-it-do.games.sgit.ai/data/` | | Retrieved | `2026-09-11T13:00:37Z` | | Pack version | `v0.8.0` | | Content hash | `sha256:d6d4ba40f1fb1f93f660687e4787ac10c2e1835efeb3929a4c8ad62cee8897ef` | | Files hashed | 27 | | Licence | CC BY 4.0 | **The bytes as fetched are served unchanged** under [`/data/upstream/`](../data/upstream/pack.json), and the build recomputes the hash on every run and refuses to write if it disagrees. Anything rendered stays one click from its source bytes. ## How much of it was measured **21 of 99 capability rows** were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. By tier: `derived` 45, `observed` 21, `documented` 13, `inferred` 1, `self-reported` 1. > **A precision the headline loses.** A row at the `observed` tier: seen directly, on the thing itself. No row in this pack is at the `measured` tier, which the pack defines as a dated probe with an evidence file. The published headline of 21 of 99 counts the `observed` rows, and so does this site. **No row here was obtained by probing anybody's system. A row is measured only from a system we are entitled to run, or from the vendor's own published documentation.** ## The files | Address | What is in it | |---|---| | [`/data/capabilities.json`](../data/capabilities.json) | capabilities | | [`/data/barriers.json`](../data/barriers.json) | barriers | | [`/data/undo-classes.json`](../data/undo-classes.json) | undo classes | | [`/data/evidence-tiers.json`](../data/evidence-tiers.json) | evidence tiers | | [`/data/profiles/index.json`](../data/profiles/index.json) | profiles | | [`/data/mandates/index.json`](../data/mandates/index.json) | mandates | | [`/data/deltas/index.json`](../data/deltas/index.json) | deltas | | [`/data/provenance.json`](../data/provenance.json) | provenance | | [`/data/upstream/pack.json`](../data/upstream/pack.json) | upstream | ## The deltas, which are here on purpose **9 stored deltas**, one per deployment shape and mandate pair, at [`/data/deltas/index.json`](../data/deltas/index.json). Derived and never authored. Stored under deltas/, each record pinning the version of both inputs and the time and code version that produced it. No field in one is writable by a person: change a grant or a mandate and recompute. Corrected from `computed and never stored` on 11 September 2026; the brief is in /docs/briefs/. [What that means and why it changed](../model/delta/index.md). > **The release gate recomputes every stored delta on every build** from the profile and the mandate it names, and fails on a single row of disagreement. That is how a machine holds `never authored': the rule forbids the act rather than the artefact, and a hand edited delta is a fiction nothing downstream could detect. ## What is deliberately not in these files | Not here | Why | |---|---| | **A score** | There is no score, rating, traffic light, risk level or severity in this pack or anywhere on this site. A score is a verdict and the ABP describes without judging. | | **A consequence** | A delta crossing a threshold is a record. What follows from it is a policy somebody set in advance, and it is not in this pack. | ## Proposing a change **The data files are the shared facts and they live in this repository so that people can propose changes.** The site and its data are the library; a cloned vault is the instance. Two rules come with that. **A proposal carries evidence.** Every node taken from a third party site carries a source URL, a retrieval timestamp and a content hash. A proposal that changes a capability row without one is an assertion, and the release gate refuses it. **A consumer pins a version.** Anything that computes from these files states which version it computed against. A clone that floats against the latest has no reproducible output. > **One transform happens between these files and the pages.** The source prose carries em dashes, en dashes and curly quotes because it was written elsewhere, and this repository holds a rule that its documents are pure ASCII. Both survive: the JSON keeps the upstream strings exactly as they arrived, and every upstream string rendered into a page is transliterated at render time. The bytes are one click away either way. [The schema, explained](../model/schema/index.md) · [The upstream pack manifest](../data/upstream/pack.json) · [The map this came from](https://what-can-it-do.games.sgit.ai/map/index.html) --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/data/index.html)* ------------------------------------------------------------------------ # Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know What It Can Do > version v0.33.70 date 11 September 2026 from Dinis Cruz to Anyone deploying an agent, anyone building one, and anyone who has to sign for one *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The briefs](../../../docs/index.md#briefs) / Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know What It Can Do # Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know What It Can Do > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do.md`](../../../docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Dinis Cruz **to** Anyone deploying an agent, anyone building one, and anyone who has to sign for one **type** Foundation document (the definition and introduction of the Agent Behaviour Policy, written for publication and for feedback) *This is the document everything else about the ABP stands on. It defines the term, says what an ABP contains and what it deliberately does not, gives one worked example with published numbers, and ends with the questions we would like answered by people who deploy agents for a living. It consolidates three internal briefs written on 11 September 2026 and rulings made on the days before. Everything factual in it carries a source and a date. Where a claim rests on something we measured, it says how much was measured and how much was derived. Nothing in it is a claim about any named product being good or bad, and nothing in it is a score.* ## What This Is The introduction of a document type that does not yet exist in most organisations and should: **an Agent Behaviour Policy is a written description, for one agent in one deployment, of four things, being everything the agent can do, which we call the grant, what it was authorised and expected to do, which we call the mandate, the difference between the two, which we call the delta, and what stands between the agent and each capability, which we call the barrier; it is derived from the deployment rather than copied from a template, it is rendered as one line for a decision maker and a full table for an engineer from the same set of facts, and it describes without judging, so it carries no score, because the same ABP is dangerous in one deployment and harmless in another and nothing about the document changed; the reason it exists is a gap that is easy to state and hard to close, which is that most people who deploy an agent know what they asked it to do and almost nobody knows what it can do, and the ABP is the document that puts those two side by side.** New here: **the definition, the four objects, the barrier as the test of whether anything is actually in the way, the rule that the ABP never judges, and the questions we are asking you.** ## The Gap **You know what you asked for.** When somebody deploys an agent, they know the job: draft the reply, fix the build, summarise the ticket, book the travel. That is the mandate, and it is usually clear, whether or not anybody wrote it down. **You do not know what it can do.** The agent runs with an account, on a machine, inside a container or on a desktop, with credentials and network access and a set of tools. Everything those permit is the grant. **It is almost never enumerated, and when it is, it is larger than the person who deployed the agent expected.** We have been measuring this. A published capability map covers nine common deployment shapes across twenty three capability primitives, and a published simulation of one ordinary assistant agent shows the shape of the result: **a grant of twelve capabilities, a mandate of four, and eight capabilities inside the agent's reach and outside its authority.** That eight is the delta, and in that example twice as many things were possible as were asked for. **The ABP is the document that puts the grant and the mandate on the same page.** That is all it is. That turns out to be a great deal. ## The Four Objects An ABP is not a single list. It is four objects, and the order they are produced in matters. | Object | What it is | How it is obtained | |---|---|---| | **The mandate** | What the agent is authorised and expected to do | **Elicited.** In minutes, because the deployer already knows it | | **The grant** | Everything the agent can do | **Measured.** From the deployment shape: the product, where it runs, with what account, with what credentials | | **The delta** | The difference. Excess where it can and you did not ask; shortfall where you asked and it cannot | **Computed.** Never stored, because the deployment changes | | **The barrier** | What stands between the agent and each capability | **Recorded**, per capability, from one of four kinds | **The mandate must be captured even though it is already known**, because a grant on its own is an inventory, and nobody acts on an inventory. *Your agent can do three hundred and forty things* is a shrug. *Your agent can do three hundred and forty things and you authorised twelve* is a finding. The mandate is the edge that gives the grant a shape. **The delta is computed and never stored.** A stored delta is a claim about somebody's environment on a day that has passed. The environment is the thing that changes, so the delta is recomputed from the grant and the mandate every time it is needed. ## The Barrier: What Is Actually In The Way For every capability in the grant, the ABP records what stands between the agent and it. There are four kinds, and the published capability map already uses them: | Barrier | Meaning | Is anything in the way | |---|---|---| | **Nothing** | The agent can simply do it | No | | **A rule somebody wrote down** | An instruction in a prompt, a policy document, a line in a configuration the model reads | **No.** An instruction to the agent is inside the boundary the agent operates in | | **A setting the agent's own account could change** | A configuration the agent has permission to alter | **No.** The grant includes the ability to remove the barrier | | **A boundary enforced above it that it cannot reach** | A sandbox, a gateway, a tool that is not exposed, a network it cannot see | **Yes** | **Only the fourth kind bounds anything.** That is not our opinion. All four of the major model providers have said in their own words during 2026 that an instruction at the prompt layer can be bypassed; one of them puts it as *the deterministic boundary is what gets hit when everything probabilistic misses.* The rule underneath is old and simple: **a control bounds a grant only if it is enforced by something the grant does not include.** **So an ABP that lists a prohibition without its barrier is making a claim it cannot support.** Every prohibition in an ABP carries the kind of barrier behind it, and the honest ones say, for most deployments today, that the barrier is the second kind. ## One Worked Example, With Published Numbers The clearest way to see what the ABP does is to change one setting and watch the document change. Take a coding agent that runs on a developer's own machine. The published capability map profiles it twice: **once with confirmations enabled, once with confirmations disabled.** Same product, same machine, same account. One setting. With confirmations enabled, a capability like *run programs as the account* has a barrier of the third kind: a setting the agent's own account could change. A person is asked before each action. **That is not a control, because the setting can be switched off from inside the grant, and because people approve almost everything they are asked.** One provider reports that users approved roughly ninety three per cent of permission prompts. With confirmations disabled, the same capability has a barrier of the first kind: nothing. **The grant did not change. The mandate did not change. The delta did not change. The barrier on every capability in the delta moved one row.** Two ABPs, one line different, and the second one is the one most people are actually running. That is the whole argument in one setting. **The ABP is about the deployment, not the product.** *The rows behind this example come from the published map, which states that of ninety nine tool capability rows across its set, twenty one were measured and the rest derived. We repeat that ratio rather than hide it.* ## It Describes And It Does Not Judge **The ABP carries no verdict and no score.** This is the rule that makes it usable, and it takes a moment to see why. **The same ABP is dangerous in one deployment and harmless in another, and nothing about the document changed.** The most permissive grant imaginable, running where there are no assets and nothing reachable, is a low risk. The same grant with a production database attached tomorrow is a high one. The same grant next to a second agent that can act on its outputs is a different risk again. **Risk is a function of the ABP, the assets, the consequences and the date. The ABP is the one input that does not move.** **A policy cannot be dangerous. A deployment can.** So there is no rating on an ABP, no traffic light, no risk level. Anybody who wants one will be asked for the other inputs first, because a score without the assets is wrong in one of the two rooms. **The score has a home, and it is the risk work that sits above the ABP, where the assets are known and a named person signs.** That work exists. It is not this document. **Three things follow from describing without judging, and each is useful.** **A long grant is an inventory, not an admission.** An ABP says a capability exists. It never says a risk is unacceptable. **Correcting a draft is factual.** When we hand somebody a draft ABP for their deployment and ask if it is right, we are not asking them to agree that something is dangerous. We are asking whether their agent can do a thing. That is a question you can put to somebody who knows their business better than you do. **The description keeps.** A verdict goes stale whenever anything in the environment moves. A description of the grant goes stale on a visible clock: when the product changes or the deployment does. **Every ABP carries a validity statement**: *this describes the deployment as at this date; if the risk changed, the deployment changed, not this document.* ## The Label And The Leaflet An ABP is rendered twice from one set of facts. **The label** is one line, for anybody: | Field | Meaning | |---|---| | Shape | The named deployment, in the product's own published words | | Grant | N of 23 primitives | | Mandate | M primitives | | **Excess** | In the grant, not in the mandate. **The finding** | | **Unbounded excess** | Excess whose barrier is one of the first three kinds. **The purchase** | | Irreversible | Granted capabilities that cannot be undone, as published | | Widest reach | The furthest the agent can reach: its project, its host, its tenant, or the world | | Measured | Rows measured against rows derived | | As at | The date and the source version | **Two numbers matter.** *Excess* answers the question this document exists for. *Unbounded excess* is the only number on the label a buyer can move: every real control put in place shifts one capability to the fourth barrier, and the number falls. **The gap between the two is the business case for a control, and it contains no verdict.** **The leaflet** is the full table underneath: every primitive with its barrier, its reversibility, its provenance, and the mandate beside it. For the engineer, the auditor, and anybody who has to price it. **Both are computed from the same facts, and the facts are identical in both.** What differs is how they are grouped, which is a question of who is reading. ## Why The Mandate Reaches Further Than Your Own Material One consequence of writing the mandate down is that it makes visible something most deployments miss. **A grant you hold over other people's material is not a grant you may pass on.** A client sent you a document. A customer gave you access. A colleague shared a folder. Handing an agent the credential that reaches those things is handing on a pass that was issued to you, and in most cases you were not given authority to do that. This is not an analogy. In data protection law it is one sentence: *the processor shall not engage another processor without prior specific or general written authorisation of the controller*, and the first processor stays liable for the second. In professional confidentiality it is a duty with two exits, legal compulsion or the client's consent, and a regulator wrote on 17 August 2026 that putting client documents into a public model tool is to place them in the public domain. In contract it is the permitted recipients clause of every confidentiality agreement, which names employees and advisers and does not name a model provider. **The ABP does not decide any of that. It makes the question askable**, because the mandate is where you write down whose material the agent is meant to touch, and the grant is where you find out whose material it can. ## What An ABP Is Not - **Not an acceptable use policy.** That governs a person's use of a system. An ABP governs what an agent can and may do. Borrowing the frame imports the wrong subject. - **Not a risk assessment.** It has no assets in it and no consequences. It is the input to one. - **Not a compliance assessment, a certification, an audit or a security review** of anything or anybody. It describes a deployment and certifies nobody. - **Not a score.** See above. - **Not a guardrail.** It is what guardrails are compiled from. The barrier column tells you which prohibitions are guardrails already and which are sentences. - **Not a claim about any product.** The capability rows are drawn from published documentation and published measurement, with the source, the date and the measured ratio stated. No adjective is attached to any of them. - **Not a template.** It is derived from one deployment. A template cannot know what your agent can do. ## Where It Comes From We did not invent most of this, and we would rather say so. The four kinds of barrier are already published on our capability map. The vocabulary for expressing permissions, prohibitions and duties with constraints on time, purpose and count has been a W3C recommendation since 2018, and it is in production use in the European data space architectures. The enforcement languages exist: the largest cloud's own agent gateway blocks everything by default and treats any prohibition as overriding any permission, with the reasoning formally verified. The industry's list of the ten agentic application risks, published 9 December 2025, puts tool misuse and privilege abuse at positions two and three, with least privilege and enumerated tool catalogues as the remedies. The United Kingdom's consumer regulator wrote on 9 March 2026 that a business using an agent *should be clear about what tasks an AI agent is allowed to perform, what data it can access, and what constraints apply.* And at least one underwriter of agents already requires, as a scoping input, a statement of the agent's capabilities, its autonomy level, its data access, the tools it can call and its deployment context, which is an ABP by another name. **What did not exist was a document that puts all of that on one page for one deployment, derived rather than copied, and honest about what it is not.** One company sells a set of editable templates. We are aware of nothing that is derived from the deployment, nothing that carries the barrier, and nothing that refuses to carry a score. ## What We Are Asking You This is the part we want back. 1. **Would you correct a draft?** If we gave you a draft ABP for your own deployment, derived from its shape, would you tell us where it was wrong? That correction is how the document gets made, and we want to know if the exchange works. 2. **Which capability did you not know about?** For the shape you run, which row of the grant was news to you? 3. **Are twenty three primitives enough?** We know two things are missing: quantity, since one request and a million are the same primitive today, and interaction between agents, since two agents each within mandate can compose into something neither was authorised to do. What else? 4. **Is the four kind barrier right?** Is there a kind of control we have not listed, or one we have placed in the wrong row? 5. **Does no score survive contact with your organisation?** Or will somebody upstream insist on a rating before they read it? 6. **Which deployment shape next?** We have nine. Which one do you actually run that we have not profiled? 7. **Is Agent Behaviour Policy the right name?** We considered and rejected several. If this one fails for you, we would like to know why. ## Honest Tensions | Tension | Note | |---|---| | No score | It keeps the document true in every room, and it is the first thing every reader asks for | | Derived, not templated | It is the only way the document can be right about your agent, and it means we cannot hand you one without knowing your shape | | Twenty one of ninety nine measured | It is honest, and it means most rows are derived from documentation rather than observed | | The barrier column | It makes the document useful, and it makes most current deployments look unbounded, because most prohibitions today are the second kind | | The mandate is already known | It makes elicitation cheap, and a mandate nobody wrote down is one nobody can be held to | | Describing without judging | It is what makes the ABP an input to everything above it, and it means the ABP alone tells you nothing about whether to worry | ## Open Questions 1. Which name for the deployment shapes, so that two people describing the same setup produce the same ABP? 2. What is the smallest grant that still produces a non empty delta, and is that the right first example? 3. Who elicits the mandate when the person at the table is not the person who authorised the agent? 4. How is quantity added to the primitives without breaking the nine profiles already published? 5. What does the validity statement look like when the product updates weekly? 6. Does the label work printed, at card size, with nine fields? 7. What is the right form for the data files so that people can propose a correction with its evidence attached? ## Relationship To Previous Briefs This document consolidates three briefs of 11 September 2026: one on the product and how it is sold, one on the ABP as a graph with its renderings and its enforcement targets, and one on what sits above it. It inherits the rulings of 10 September on the words that may not be used, and the rule of 20 August that the record is published and the verdict is not. The capability grammar, the nine profiles and the four barriers come from the published capability map and the published simulation, and this document adds nothing to them except a name for the whole. ## Key Claims | # | Claim | |---|---| | 1 | Most people who deploy an agent know what they asked it to do, and almost nobody knows what it can do | | 2 | An ABP is a written description, for one agent in one deployment, of the grant, the mandate, the delta and the barrier | | 3 | The mandate is elicited, the grant is measured, the delta is computed and never stored, and the barrier is recorded per capability | | 4 | A grant on its own is an inventory, and the mandate is what turns it into a finding | | 5 | There are four kinds of barrier, and only a boundary enforced above the agent that it cannot reach bounds anything | | 6 | All four major model providers have said in 2026 that an instruction at the prompt layer can be bypassed, so a prohibition without its barrier is an unsupported claim | | 7 | Changing one setting on one product moves every barrier in the delta by one row while the grant, the mandate and the delta stay the same | | 8 | The ABP describes and does not judge, because the same document is dangerous in one deployment and harmless in another | | 9 | So the ABP carries no score, and the score lives in the risk work above it, where the assets are known and a named person signs | | 10 | The label carries two numbers that matter, excess and unbounded excess, and only the second can be moved by buying a control | | 11 | A grant you hold over other people's material is not a grant you may pass on, and the ABP is where that question becomes askable | | 12 | The parts of this existed already, published, and what did not exist was one page per deployment, derived, with the barrier, and without a score | ## Sources All read 11 September 2026 unless stated. **The measurements and the vocabulary.** The capability map, its nine profiles, twenty three primitives, four barriers, undo classes and its statement that twenty one of ninety nine rows were measured, at https://what-can-it-do.games.sgit.ai/map/index.html, with its mandates and deltas at the same site. The published simulation with a grant of twelve, a mandate of four and a delta of eight at https://sgit.ai/demos/vaults/licence-to-operate/index.html. The graph rules at https://graphs.sgit.ai/. **That a prompt is not a control.** https://www.anthropic.com/engineering/how-we-contain-claude, 25 May 2026, and the approval rate reported at https://www.infoq.com/news/2026/07/anthropic-claude-containment/, 22 July 2026. https://aws.amazon.com/blogs/security/why-policy-in-amazon-bedrock-agentcore-chose-cedar-for-securing-agentic-workflows/, 20 May 2026. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/, 16 July 2026. The approach paper summarised at https://simonwillison.net/2025/Jun/15/ai-agent-security/, 2025. **Where it comes from.** The rights expression vocabulary at https://www.w3.org/TR/odrl-model/, recommendation of 15 February 2018, and its adoption at https://www.w3.org/blog/2025/w3c-standard-odrl-policy-gaining-industry-adoption, 23 October 2025. The agentic application risk list at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, 9 December 2025. The consumer guidance at https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents, 9 March 2026. The underwriter's scoping requirements at https://www.aiuc-1.com/scoping. The template offer at https://agentguru.co/. **The pass you may not hand on.** Article 28(2) and 28(4) of the General Data Protection Regulation. The warning notice of 17 August 2026 at https://www.sra.org.uk/. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do/index.html)* ------------------------------------------------------------------------ # The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has The Vocabulary, And A Prohibition Has Two Lives > version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever models the graph, whoever builds the renderer, and whoever compiles the prohibitions into something that enforces them *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The briefs](../../../docs/index.md#briefs) / The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has The Vocabulary, And A Prohibition Has Two Lives # The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has The Vocabulary, And A Prohibition Has Two Lives > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__dev-brief__the-behaviour-policy-is-a-graph-and-every-document-is-a-projection-the-w3c-has-the-vocabulary-and-a-prohibition-has-two-lives.md`](../../../docs/briefs/v0.33.70__dev-brief__the-behaviour-policy-is-a-graph-and-every-document-is-a-projection-the-w3c-has-the-vocabulary-and-a-prohibition-has-two-lives.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Human (project lead) **to** Whoever models the graph, whoever builds the renderer, and whoever compiles the prohibitions into something that enforces them **type** Dev brief (specification for the policy graph, its projections and its enforcement targets) *Second of 11 September. Both the corpus and the outside were searched first. The corpus supplied the projection pattern, published twice on sister sites, and the variant rule that constrains it. The outside search found that the graph the memo describes has a W3C vocabulary with the deontic triad, constraints, a conflict strategy and inheritance already in it, that compiling such a graph to an enforcement engine is practised, that the largest cloud's own agent gateway enforces with a language whose every deny beats every permit, and that all four major model providers state in their own words that a prohibition written into a prompt is not a control. One correction: the memo says the graph scales because it is a graph, and it does not, because the bottleneck is the human who validates each cell. Limitations: no schema is written; no renderer is designed; and the enforcement layer mapping is a specification of what each prohibition must declare, not an integration with anything.* ## What This Is The specification for the behaviour policy as a graph, the documents that are computed from it, and the property every prohibition in it must carry: **the memos state that the behaviour policy is already a graph, that what people call a policy is a projection computed from it programmatically or by an agent, that this is what allows one fact set to be rendered for executives, for every other stakeholder and for the highly technical, that the graph is what lets policy for an agent extend to policy for an agent in an environment with particular permissions in particular situations at particular times without changing structure, that the deliverable is therefore a vault holding the graph and its connections rather than a document, that this introduces the human and the validation and the feedback loop, that the prohibitions are also the input to the tooling and the monitoring, and that the graph is the competitive advantage because the estate has the vault, the tooling and an open method for building it; the first finding is that the projection pattern is already published twice in the estate, as story is a graph and article is projection on one site and as briefs are arguments and infographics are projections on another, so the behaviour policy is the third instance of a commitment already made in public; the second is that the graph has a vocabulary already, being the W3C rights expression language whose model carries permission, prohibition and duty as rules, constraints on time, purpose, count and place, a conflict strategy that says which wins, and inheritance between policies, and which is in production use in the European data space architectures and has already been compiled to an enforcement engine by at least one project, with the honest caveat that it is asset centric rather than agent centric, has no enforcement semantics of its own, and has no published profile for agents; the third is that a prohibition has two lives and the difference is the enforcer test of 20 August, because the four largest model providers each state that a prohibition written into a prompt can be bypassed, so every prohibition node must declare the layer at which it is enforced, from prompt through tool schema, client rule, gateway and sandbox, and only the last three are controls; the fourth is that the graph does not scale because it is a graph, since the representation is uniform but the elicitation is combinatorial and the human who validates each cell is the bottleneck, so every cell carries an asserted default and the human only corrects; and the fifth is that every projection must render the same fact set with an empty diff, which is the variant rule already in force, and the diff does not yet exist.** New contributions: **the vocabulary and the compile target with their limits stated; the enforcement layer as a required attribute of every prohibition; the defaults and correction discipline that makes the combinatorial graph tractable; the lessons on keeping prose and model in step, drawn from rules as code and from the compliance document model that already generates documents from data; and the placement of the enforcement point in the estate's own published architecture.** ## The Pattern Is Already Published, Twice The memo says: > This ABP is already a graph, because the policy itself is defined as a graph. What we usually call a policy is a projection of that, that is programmatically calculated from that, or agently created from that. **Two sister sites already say this about other things.** The newsroom site's thesis is that a story is a graph and an article is a projection. The infographics site's thesis is that briefs are arguments and infographics are projections, and it carries the rule that a fact about the argument an infographic depicts should be checked against its source brief rather than repeated from the summary. **So the behaviour policy is the third instance of a pattern the estate has committed to in public**, which is a stronger position than inventing it, and it inherits the constraint that came with the pattern: **every projection renders the same fact set and the diff must be empty.** That rule has now blocked something on each of the last three days. **The diff does not exist. Until it does, the multi audience promise may be described and may not be printed.** ## The Graph Has A Vocabulary Already **The memo's graph is, structurally, the W3C rights expression language.** The information model, a recommendation since 15 February 2018, has: | Element | What it is | What it is in the behaviour policy | |---|---|---| | **Policy** | A set of rules, with subclasses for a generic set, an offer and an agreement | The ABP for one agent in one context | | **Permission, Prohibition, Duty** | The three rule types | The mandate, the prohibitions, and the obligations such as log before act or ask above a threshold | | **Action** | What is permitted or prohibited, from an extensible vocabulary | The tool call, the file operation, the network request | | **Asset** | The thing acted on | The resource, the tool, the data | | **Party** | Assigner and assignee | The organisation and the agent | | **Constraint** | Left operand, operator, right operand | Time of day, purpose, count, location, which is exactly the memo's list of situations | | **Conflict strategy** | Permissions win, prohibitions win, or the policy is void | **Prohibitions win, always** | | **inheritFrom** | A policy inherits from a parent | Policy for an agent in an environment inherits from policy for the agent | **It is in production.** The European data space reference architecture uses it as the basis of its usage control language, the dataspace protocol uses its offers and agreements for contract negotiation, a federated cloud initiative published a verifiable credential profile for it on 31 July 2026, and a rights standard for images adopted it as its default usage policy language. **And at least one project compiles it to an enforcement engine already**, translating it into the rule language of a widely deployed policy agent, which is direct evidence that graph as data, compiled to enforcement, is practised rather than proposed. **Three honest limits, and they decide how it is used.** **It is asset centric.** Its rules are action on asset by party. The behaviour policy is principal centric: actions by an agent, on a set of resources, under credentials. The mapping works, with the agent as assignee, the tool as asset and the tool operation as a profile defined action, but it is a mapping and not a native fit. **It has no enforcement semantics.** The 2018 charter excluded them. A formal semantics defining an evaluator exists only as a community group draft. A June 2026 paper proposing deontic runtime governance for agents, enforced outside the model by a triple extractor and a reasoner, criticises it explicitly for specifying no enforcement model and does not use it. **There is no published profile for agents.** Applications to agents so far run the other way: models writing policies in this vocabulary, not policies governing models. **So the position is: use it as the interchange vocabulary for the graph, through a profile that adds the agent actions, and compile to something that enforces.** Do not claim the vocabulary enforces anything, because it does not, and do not invent a graph model from nothing when a recommendation with the right triad, the right constraints and the right conflict rule already exists. ## What It Compiles To **The largest cloud's own agent gateway already enforces with a language whose semantics are the ones this product needs.** Default deny. Two effects, permit and forbid. **Any matching forbid overrides any permit.** A schema based validator, a formal model of the core in a proof assistant, and an analysis tool announced 16 June 2025 that compiles policies to a solver and proves whether a permit is shadowed, a condition is impossible or a denial is complete. The gateway product blocks everything by default, and the provider's own security blog of 20 May 2026 states that model layer controls **such as system prompts and training time alignment can be bypassed by prompt injection or hallucination**. **A superset announced on 6 August 2026 adds what the sub delegation argument needs.** Temporal operators over an agent's event history: formerly, count within, sum within, and binding. Its published examples are approve before act, running totals, and **no external contact after touching confidential data**, which is the sub delegation prohibition of yesterday's teaching brief expressed as a rule. Every policy in the base language is a valid policy in the superset. **Its reference interpreter is stated not to be for production, and the temporal extensions lose the base language's symbolic analysability.** Use the base language for the product, and watch the superset. **The alternative compile target is the policy agent used across the container ecosystem**, which evaluates rules against data documents so the ABP can ship as data with a fixed evaluator, whose home page now carries a tool calling example, and which one agent framework integrates at the tool dispatch boundary with allow, deny, requires approval and not applicable verdicts plus a middleware that hides tools before the model ever sees them. **Its deny is a convention rather than an effect**, so deny overrides is a pattern the policy author writes rather than a guarantee the language gives. **The rule that follows: every prohibition in the graph must be expressible as a forbid in the compile target, and the compiled policy must pass the shadowed permit analysis.** A prohibition that cannot be compiled is a sentence, not a rule. ## A Prohibition Has Two Lives, And Only One Of Them Is A Control **This is the section that decides whether the product is honest.** The second memo says the prohibition list is a partial defence against prompt injection and the input to guardrails. **Both are true, and only if the prohibition lives in the right place.** **All four major model providers say the same thing in their own words.** | Provider | Date | Statement | |---|---|---| | The first | 25 May 2026 | Model layer controls shape only what the agent tends to do, not what it is theoretically capable of doing. Protection in the model layer will never be one hundred per cent effective, which is why it cannot stand alone. **The deterministic boundary is what gets hit when everything probabilistic misses** | | The second | 20 May 2026 | System prompts and training time alignment **can be bypassed by prompt injection or hallucination** | | The third | 16 July 2026 | Relying on prompts or **the agent will only do X narratives** instead of hard authorisation boundaries invites prompt injection and workflow drift | | The fourth | 2025 | Reasoning based defences are non deterministic and cannot provide absolute guarantees, and must work in concert with deterministic controls | **So a prohibition has two lives.** Written into the system prompt, don't delete the database is an instruction inside the trust boundary the attacker is already inside. **It is not a control.** Compiled into a tool call filter, a gateway or a sandbox, the same sentence **is** a control. The standing rule from 20 August says it exactly: a control bounds a grant only if enforced by something the grant does not include. **Every prohibition node in the graph therefore carries one required attribute, the layer at which it is enforced.** | Layer | What it is | Is it a control | |---|---|---| | **Prompt** | An instruction to the model | **No.** And arguably worse than nothing, because it manufactures assurance without providing it | | **Tool schema** | The tool is not exposed to the model at all | Yes, for that tool | | **Client rule** | An allow, ask or deny rule in the agent client | Yes, with a documented gap: text matching rules miss shell and path variants, per the client's own documentation, which points at the sandbox for hard enforcement | | **Gateway** | Default deny at the point where tool calls leave the agent | **Yes** | | **Sandbox** | Operating system or network isolation | **Yes**, and the client's own documentation states the sandbox restrictions apply even if a prompt injection bypasses the model's decision making | **One further datum on the middle row.** The first provider reports that users approved roughly ninety three per cent of permission prompts. **Ask is a weak control.** A prohibition whose enforcement is a human clicking approve is a prohibition enforced by fatigue. **The product consequence.** The ABP rendered for an executive shows the prohibitions. The ABP rendered for an engineer shows the prohibitions with their layer. **And the ABP rendered for the assessment in tier four shows which prohibitions are enforced only at the prompt layer, because those are the ones that are not enforced at all.** That is the finding the assessment sells, and it falls straight out of one attribute on one node type. ## It Does Not Scale Because It Is A Graph **One correction to the third memo, made carefully because the memo is right about everything except the word scale.** > It doesn't matter, right? Like, we scale because it's all a graph. **The graph makes the representation uniform. It does not make the elicitation cheap.** Policy for an agent, in an environment, with a credential set, in a situation, at a time of day is a product of dimensions, and every added dimension multiplies the number of cells somebody has to confirm. **And the memo itself names the bottleneck**: it introduces the human, the validation and the feedback loop. The human is the constraint. The graph is not. **Two disciplines make it tractable, and both are already in the estate's method.** **Assert a default in every cell, and ask the human only to correct.** This is the draft and correction motion of the first brief applied inside the graph. An inherited policy carries its parent's values until somebody overrides them, and the override is the elicitation. **A cell that is empty is a question. A cell with a default is a claim the human can disagree with, and disagreement is cheaper than authorship.** It is also the games mechanic: state the belief, then correct it. **Ship one dimension at a time.** Agent in environment is two dimensions and is already the tier one product, because the environment decides the grant: the same agent on a desktop, on a desktop with administrator rights, and in a container has three different grants. Credentials are the third dimension and belong to tier three. **Situation and time of day are dimensions the constraint vocabulary supports and no buyer will validate in the first month.** Build them into the model and do not surface them. ## Keeping The Prose And The Graph In Step **The projection promise fails in a specific way, and the projects that have tried it have written down how.** **The literate programming approach for law**, in which legal text and code live in one source and the readable document is woven from it, gives one lesson: **the prose is the source, the code is embedded under each clause, and so they cannot drift.** Its limit is one audience rendering. **The compliance document model** maintained by a national standards body, at version 1.2.3 as of 6 August 2026, exists to generate system security documents from machine readable catalogues and profiles, and a federal authorisation programme is moving to submissions in it. **That is the closest precedent for policy model to documents for reviewers**, and it is in the same domain as this product. **The rules as code programmes** in several governments reached the same conclusions from the other direction: co draft the natural language and the machine form together, keep the code structure isomorphic to the rule structure, and note that **how versions are governed and how errors in the coded form are found remain unresolved**. **Condensed into rules for the renderer:** 1. **One source, and the source is the graph.** Prose is derived. Never hand edit a rendered document. 2. **Every rule carries a stable identifier**, so every rendered sentence traces to a node, and the executive's sentence and the engineer's sentence trace to the same one. 3. **Version the graph and re render.** A rendered document states the graph version it came from. 4. **Embed the tests in the source.** Each rule carries an example the compiled policy must satisfy, so drift between the prose, the graph and the enforcement is caught by a test rather than by a reader. 5. **The fact diff runs across renderings before any rendering ships.** Rule 6 of the store pack, and the thing that does not exist. ## The Deliverable Is A Vault, And The Enforcement Point Is Already In The Architecture **The memo is right that the deliverable is a vault rather than a document, and yesterday's architecture brief already says how.** The graph is data. The projections are computed. The customer clones. **The clone pins a version, and every rendered document states the input versions it was computed against**, which is what makes a later difference explicable rather than alarming. **And the enforcement point is not new either.** The twins site publishes it: agents present cryptographic identity, **signed mandates** and contextual evidence to an execution broker, which verifies permissions before performing operations, holding credentials while the twin holds reasoning. **The signed mandate is the ABP's mandate half. The execution broker is the gateway row in the table above.** The memo's statement that the policy comes with the twin is not an aspiration, it is a description of an architecture already on a published page. ## What This Does Not Try To Be - **A schema.** The vocabulary is identified and its mapping is sketched. No profile is written and no node is defined. - **A renderer.** The rules for one are given. Nothing is built. - **An integration.** The compile targets are named with their semantics. No policy has been compiled to either. - **A claim that the vocabulary enforces anything.** It does not, and the brief says so three times. - **The fact diff.** Named as the blocker for the fourth day running. Not designed here. ## Honest Tensions | Tension | Note | |---|---| | Using the W3C vocabulary | It has the right triad, constraints, conflict rule and inheritance, and it was built for digital assets rather than for agents | | Compiling to the cloud's language | Its deny semantics are exactly right and formally verified, and it ties the product to one provider's ecosystem | | The enforcement attribute | It makes the product honest, and it makes most existing agent deployments look bad, because most prohibitions today live in prompts | | Defaults in every cell | It makes elicitation cheap, and a default nobody corrected is a claim nobody made | | One dimension at a time | It ships, and it means the situation and time constraints the memo is excited about stay hidden for months | | Prose derived from the graph | It cannot drift, and executives will want to edit the sentence rather than the node | ## Open Questions 1. **Does a profile of the vocabulary for agent actions need to be published, and under whose name?** The gap is real and filling it is a public act. 2. **Which compile target first?** The cloud's language has the semantics; the policy agent has the ecosystem. Both is a maintenance cost. 3. **What does the enforcement attribute default to when nobody knows?** Prompt is the honest default and it is the one that makes every deployment look unenforced. 4. **Who corrects the defaults, and does their correction carry a signature?** The mandate half is a legal act per the 10 September opinion brief. 5. **Can the fact diff be built as a test over rendered documents rather than as a tool?** The renderer rules suggest it can. 6. **Does the execution broker on the twins site exist as running code?** The page describes it. Nobody has checked. 7. **What is the smallest graph that produces a useful executive rendering?** The answer decides what tier one actually shows. ## Relationship To Previous Briefs **From the first brief of today**, it takes the four objects and specifies how three of them live in the graph and how the fourth is compiled out of it. **From the newsroom and infographics sites**, it takes the projection pattern and records this as its third instance. **From the enforcer test of 20 August**, it takes the rule that decides which prohibitions are controls, and it makes that rule an attribute on a node type. **From the teaching brief of 10 September**, it takes the sub delegation prohibition and finds it expressible in a policy language announced in August. **From the vault architecture brief of 10 September**, it takes the pinning and versioning rules for the clone. **From the twins site**, it takes the signed mandate and the execution broker as the already published enforcement point. **From the variant rule**, it takes the empty diff requirement, and it is the fourth day that rule has blocked a promise. ## Key Claims | # | Claim | |---|---| | 1 | The projection pattern is published twice in the estate, and the behaviour policy is its third instance | | 2 | Every projection renders the same fact set with an empty diff, and the diff does not exist | | 3 | The graph has a W3C vocabulary already, with permission, prohibition and duty, constraints on time, purpose, count and place, a conflict strategy and inheritance | | 4 | That vocabulary is in production in the European data space architectures and has been compiled to an enforcement engine by at least one project | | 5 | It is asset centric, has no enforcement semantics and has no agent profile, so it is the interchange vocabulary and not the enforcer | | 6 | The largest cloud's agent gateway enforces with a language where any forbid overrides any permit, formally verified and with analysis for shadowed permits | | 7 | All four major model providers state that a prohibition in a prompt can be bypassed, in their own words and in 2026 | | 8 | So every prohibition node carries the layer at which it is enforced, and only tool schema, gateway and sandbox are controls | | 9 | Users approve roughly ninety three per cent of permission prompts, so ask is a weak control | | 10 | The graph does not scale because it is a graph, because the human validating each cell is the bottleneck, so every cell carries a default and the human only corrects | | 11 | Prose is derived from the graph, every sentence traces to a node, and a rendered document states its graph version | | 12 | The enforcement point is already published on the twins site as an execution broker receiving signed mandates | ## Sources All read 11 September 2026. **Inside the estate.** The newsroom and infographics theses from the network index at https://sgit.ai/network/index.html. The twins site at https://twins.sgit.ai/llms.txt for the signed mandate and the execution broker. The licence to operate demonstration at https://sgit.ai/demos/vaults/licence-to-operate/index.html. **The vocabulary.** The information model at https://www.w3.org/TR/odrl-model/, recommendation of 15 February 2018. Adoption at https://www.w3.org/blog/2025/w3c-standard-odrl-policy-gaining-industry-adoption, 23 October 2025. The formal semantics draft and the implementation landscape at https://w3c.github.io/odrl/formal-semantics/ and https://w3c.github.io/odrl/landscape/. The verifiable credential profile at https://gaia-x.eu/bridging-policy-trust-and-verifiable-credentials-in-gaia-x-data-spaces/, 31 July 2026. The dataspace protocol at https://eclipse-dataspace-protocol-base.github.io/DataspaceProtocol/2025-1/. The deontic runtime governance paper at https://arxiv.org/html/2606.19464v1, 17 June 2026. **The compile targets.** The language at https://crates.io/api/v1/crates/cedar-policy, version 4.12.0 of 28 July 2026. The analysis tooling at https://aws.amazon.com/blogs/opensource/introducing-cedar-analysis-open-source-tools-for-verifying-authorization-policies/, 16 June 2025. The gateway's choice of it at https://aws.amazon.com/blogs/security/why-policy-in-amazon-bedrock-agentcore-chose-cedar-for-securing-agentic-workflows/, 20 May 2026. The temporal superset at https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/, 6 August 2026. The policy agent at https://www.openpolicyagent.org/ with releases at https://github.com/open-policy-agent/opa/releases, and its framework integration at https://ai-sdk.dev/docs/agents/policy-tool-approvals. **The four providers on prompts as controls.** https://www.anthropic.com/engineering/how-we-contain-claude, 25 May 2026, and the approval rate reported at https://www.infoq.com/news/2026/07/anthropic-claude-containment/, 22 July 2026. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/, 16 July 2026. The gateway blog above for the second. The approach paper summarised at https://simonwillison.net/2025/Jun/15/ai-agent-security/ for the fourth. Client permission semantics and the sandbox statement at https://code.claude.com/docs/en/permissions. **Prose and model in step.** The literate programming approach at https://book.catala-lang.org/en/5-1-literate-programming.html. The compliance document model at https://pages.nist.gov/OSCAL/about/news, version 1.2.3 of 6 August 2026. The rules as code findings at https://oecd-opsi.org/publications/cracking-the-code/, 12 October 2020, and the 2026 conference at https://openfisca.org/en/conference/2026/. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/briefs/v0.33.70__dev-brief__the-behaviour-policy-is-a-graph-and-every-document-is-a-projection-the-w3c-has-the-vocabulary-and-a-prohibition-has-two-lives/index.html)* ------------------------------------------------------------------------ # The Delta Is Derived And Never Authored: Storing It Is The Point, And The History Is The Business Case > version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever builds the ABP data model, whoever wires the recompute, and whoever has to correct a document that is already published *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The briefs](../../../docs/index.md#briefs) / The Delta Is Derived And Never Authored: Storing It Is The Point, And The History Is The Business Case # The Delta Is Derived And Never Authored: Storing It Is The Point, And The History Is The Business Case > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case.md`](../../../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Human (project lead) **to** Whoever builds the ABP data model, whoever wires the recompute, and whoever has to correct a document that is already published **type** Dev brief (a correction to a published formulation, and the specification it turns into) *Fifth of 11 September, and the first document in this corpus written to correct one already pushed. The foundation document published earlier today carries the sentence that the delta is computed and never stored, twice. The project lead's correction is that the second half is wrong and the first half was the point. This brief states the correction, gives the replacement wording verbatim so it can be pasted, and then works out what follows, which is more than a wording change. Both the corpus and the outside were searched. The outside search found a standard for the event that triggers a recompute, and a product announced two days ago that measures a neighbouring thing and thereby sharpens what this one measures. Limitations: nothing here is built; the calibration loop has a collection problem that is named and not solved; and one specification's status could not be confirmed from its own page.* ## What This Is The correction of one phrase in a published document, and the specification that the corrected phrase turns out to require: **the foundation document states that the delta is computed and never stored, on the reasoning that a stored delta is a claim about an environment on a day that has passed; the project lead's correction is that computed was the whole point and never stored was an error, because the delta belongs in a vault along with the history of the grants and the mandates that produced it, since both of those are interpretive and improve over time as the customer says what they actually meant and as more of what the agent can do is discovered, because reality is the calibrator, in that something happening which is not in the grant means the grant was incomplete and something being blocked which the grant said was possible means a barrier was missed; the power of a computed delta is a direct consequence of holding the grant and the mandate as graphs with a schema and an ontology that can be calculated against, which is the underlying capability, because all of this can be done manually today and almost nobody does it, and a programmatic delta is not a given; a computed delta reacts to changes in either input without anybody touching it, which means behaviours can be hooked to it, including actions, consequences, the granting of a licence to operate and the removal of one, so that a newly discovered weakness or a quietly widened credential moves the agent outside the authorised set without a human noticing; and the history matters commercially, because a project that introduces a control reduces the grant and therefore the delta, and that before and after is the business case, read off a series rather than constructed; the first finding is that the correct formulation is that the delta is derived and never authored, which keeps everything the original ruling was protecting while removing the error, and that the thing being described already has a name in computing, being a materialised view, stored for use, refreshed from its inputs, never hand edited, and carrying its own staleness; the second is that reality is a third input alongside the grant and the mandate, and the calibration loop it creates is the answer to the honest weakness in the published document, which is that twenty one of ninety nine capability rows are measured and the rest derived; the third is that the event which triggers a recompute has an existing standard with defined event types, so the recompute trigger is a receiver rather than an invention; the fourth is that a product announced on 9 September 2026 detects drift between an agent's runtime behaviour and its authorised scope, which is a neighbouring measurement and makes the distinction sharp, because behaviour drift is detected after an action and capability excess exists before any action; and the fifth is that hooking a consequence to a computed value is powerful and hazardous, and the estate's own rule resolves it, because the delta crossing a threshold is a record and the consequence is a policy somebody set in advance.** New contributions: **the correction with replacement wording; reality as the third input and the calibration loop; the recompute trigger mapped onto an existing standard; the history as a business case read rather than constructed; the three clocks and the gap the risk layer accounts for; the distinction from behaviour drift; and the collection problem the loop creates against a product that promises not to phone home.** ## The Correction **The published foundation document says this, in two places.** In the four objects table: > **The delta.** Computed. Never stored, because the deployment changes. And in the body: > **The delta is computed and never stored.** A stored delta is a claim about somebody's environment on a day that has passed. The environment is the thing that changes, so the delta is recomputed from the grant and the mandate every time it is needed. **The first half is right and the second half is wrong.** The delta is computed. It is also stored, and storing it is most of what makes it useful. **The replacement wording, for the table:** > **The delta.** Derived. Recomputed whenever the grant or the mandate changes, stored with the versions of both, and never edited by hand. **The replacement wording, for the body:** > **The delta is derived and never authored.** Nobody writes a delta. It is only ever the output of a computation over the grant and the mandate, and it is stored along with the versions of both inputs and the time it was computed. That is what makes it checkable rather than stale: a stored delta that carries its inputs can be recomputed and compared, and one that carries no inputs is the claim the older wording was afraid of. **What must never happen is that somebody edits a delta**, because a hand edited delta is a fiction about an environment, and nothing downstream could tell. ## What The Old Ruling Was Protecting, And What Survives **Being fair to the sentence being corrected: it was guarding against three real things, and all three survive the correction.** | The fear | Does the correction still handle it | |---|---| | A delta becomes a stale claim about somebody's environment | **Yes.** A stored delta carries the versions of its inputs and the time it was computed, so its staleness is a fact rather than a surprise | | A delta gets hand edited into a fiction | **Yes, and more strongly.** Never authored is a harder rule than never stored, because it forbids the act rather than the artefact | | A delta is treated as authoritative after the inputs move | **Yes.** It reacts. A recompute is cheap because the inputs are graphs | **So the correction loses nothing and gains the history.** **And this is the fourth instance of a pattern already in force across the estate**, which is worth noticing because it means the corrected sentence is the one that fits and the old one was the odd one out: - **Indexes are generated from the data they index**, so they cannot disagree with the source. Stored, derived, never authored. - **Prose is derived from the graph and never hand edited**, which was the renderer rule of this morning's second brief. - **A software bill of materials is generated from the dependency files** rather than asserted, which was the finding in the findability brief of 10 September. - **The delta is derived from the grant and the mandate** and never authored. **In every case the artefact is stored. What is forbidden is writing it.** ## The Word For This Already Exists **A stored result of a computation over other data, refreshed when its inputs change, never edited directly, is a materialised view.** The vocabulary is decades old and it carries exactly the right properties: it exists for use, it has a refresh policy, its staleness is knowable, and writing to it directly is a category error rather than a permission question. **The related pair is worth naming too.** The grant and the mandate are the event sourced side: an append only history of what changed and when. The delta is the read model computed from them. **That is the same shape as the estate's own published pattern in two places, where a story is a graph and an article is a projection, and where briefs are arguments and infographics are projections.** The delta is a projection of the ABP graph, and so is the label, and so is the leaflet. **Practical consequence for the model: the delta gets a stored record with a fixed shape.** | Field | Why | |---|---| | `grant_version` | The input, pinned | | `mandate_version` | The input, pinned | | `computed_at` | When | | `computed_by` | Which version of the computation, because the computation is code and code changes | | `excess` | Capabilities in the grant and not in the mandate | | `unbounded_excess` | Excess whose barrier is one of the first three kinds | | `shortfall` | Capabilities in the mandate and not in the grant | **No field in that record is writable by a person.** The way to change a delta is to change a grant or a mandate. ## Reality Is The Third Input **This is the part of the correction that is not a wording change.** The grant is a model of what the agent can do. The mandate is a statement of what somebody meant. **Both are interpretations, and both improve.** The customer says *what I actually meant was this*, and the mandate sharpens. Somebody discovers a capability nobody had listed, and the grant grows. **And reality calibrates both.** | What is observed | What it tells you | |---|---| | Something happened that is not in the grant | **The grant was incomplete.** Add the capability | | Something was blocked that the grant said was possible | **A barrier was missed**, or recorded at the wrong kind. Correct it | | Something in the mandate never happens | Either the mandate is aspirational, or the capability is missing and the shortfall is real | | Something happens repeatedly that is in the grant and not in the mandate | **The mandate is wrong, or the deployment is.** This is the interesting one and it is the only case where the observation does not say which | **That last row is worth dwelling on, because it is the one place a computed delta cannot resolve itself.** An agent doing something outside its mandate, repeatedly, without anybody complaining, means either that the mandate was written too narrowly or that something is happening nobody authorised. **The ABP publishes the observation. Which of the two it is belongs to the risk layer and to a person.** Record, not verdict, again. **And the calibration loop is the answer to the published document's honest weakness.** Twenty one of ninety nine capability rows are measured and the rest are derived from documentation. **Every deployment that runs and reports back is an experiment that moves a row from derived to measured**, and because the capability map is shared and public, it moves for everybody. **That is a network effect and it is the reason the map should stay in the open repository rather than inside a product.** ## The Delta Reacts, And The Trigger Has A Standard **Because the delta is derived, a change in either input propagates without anybody touching the document.** That is the property a template cannot have and a rendered document cannot have, and it is the strongest differentiator yet, stronger than derived from your deployment, because it is *continuously* derived. **Three worked cases.** **A weakness is disclosed in a tool the agent can call.** Nothing about the deployment changed. But a capability that was recorded at the fourth barrier, a boundary enforced above the agent, is now at the first. **The grant is the same and the unbounded excess jumps.** The ABP changes because the world did. **A credential is quietly widened.** Somebody adds a scope to a token to fix an unrelated problem. The grant grows, the mandate does not, and the excess grows by exactly the capabilities that scope carries. **Nobody involved thought they were changing a policy.** **A control ships.** A gateway is deployed with default deny. A set of capabilities move from the second barrier to the fourth. **Unbounded excess falls, and the number it falls by is what the project bought.** **The trigger for a recompute already has a standard, and the estate should receive rather than invent one.** The continuous access evaluation profile, published 29 August 2025 on the standards track by the shared signals working group, defines event types transmitted by an identity provider and consumed by a receiver so that access can be attenuated as things change. Its own framing is that transmitters send continuous updates which receivers use to attenuate access for human or robotic users, devices, sessions and applications. | Event type | What it means for the ABP | |---|---| | **Credential Change** | **The grant may have moved.** Recompute | | **Token Claims Change** | **The grant may have moved.** Recompute | | **Assurance Level Change** | A barrier may have moved | | **Device Compliance Change** | A barrier may have moved | | **Risk Level Change** | Not ours. This is the risk layer's input, not the ABP's | | **Session Revoked, Established, Presented** | Session lifecycle, below the ABP's altitude | **So the recompute trigger is a receiver for two or three event types, and the rest is the graph.** That is a small build and it is standards shaped. **The status of that specification could not be confirmed from its own page**, which said standards track rather than final while sitting at a final address, and somebody should check before it is cited publicly. ## What Hooks To It, And The Hazard **The project lead's point is that behaviours can be hooked to the delta: actions, consequences, the granting of a licence to operate and its removal.** That is right and it is where the ABP stops being a document. **And it is hazardous in a specific way: a computation error would revoke a licence.** The estate's own rule resolves it cleanly. **The delta crossing a threshold is a record. The consequence is a verdict.** So the ABP publishes the crossing, with its inputs and its computation version, and **the consequence is a policy that the customer or the underwriter set in advance**, not a judgement the ABP makes. That keeps the ABP consequence agnostic while making the automation real, and it means an automatic suspension is always traceable to a threshold somebody chose and a computation anybody can rerun. **One elegant fit worth recording.** The statute analysed in this morning's third brief already provides for exactly this shape: a warranty breach **suspends** cover for losses occurring after the breach and before it is remedied, rather than discharging the contract. **A continuously computed delta is a thing that can trigger a suspensive condition and evidence it**, and remedy is visible in the same series. Nobody has to notice. That is a better fit between a statutory mechanism and a data structure than anything else in this estate. ## The History Is The Business Case, Read Rather Than Constructed **Store the series and the business case stops being a document somebody writes.** A control project has a date. The series has grants, mandates and deltas with dates. So the value of the project is a subtraction: > On 14 March the gateway was deployed. Unbounded excess fell from thirty one to six. Excess was unchanged, because the agent can still do the same things; what changed is that twenty five of them are now bounded by something it cannot reach. **That sentence contains no verdict, no score and no adjective, and it is the strongest thing a security team can take to a budget conversation.** It is also checkable, because both ends of it are stored records with their inputs pinned. **Three uses of the series, in order of how soon they pay.** **Justifying what was already bought**, which is the easiest and the one every security team needs and cannot produce today. **Pricing what to buy next.** The capabilities in unbounded excess, ordered by how many would move to the fourth barrier per control, is a shopping list with an effect size on each row. **Evidencing a condition over time.** An underwriter or an auditor asking whether a control was in place throughout a period is asking a question about a series, not about a snapshot. **A stored history answers it and a recomputed present cannot.** This is the strongest argument of the three and it is the one the old wording made impossible. ## Three Clocks, And The Gap That Belongs To The Risk Layer **The project lead's last point is the honest limit and it should be written down as three clocks.** | Clock | What it measures | Who controls it | |---|---|---| | **The ABP's clock** | When the grant was last measured or calibrated | Us, and it can be fast | | **The twin's clock** | When the twin last synchronised with the real environment | The customer's integration | | **Reality's clock** | Never stops | Nobody | **Inside the vault and the graph, the first clock can run in near real time on events.** The second is a connection to somebody else's systems and its latency is a property of their estate, not of our software. **The third does not wait.** **So the ABP is exactly as fresh as the twin, and the twin is exactly as fresh as its connection.** That is not a defect to hide. It is a parameter, and it belongs on the label as part of the validity statement: **as at this date, from a twin last synchronised at this date.** **And the gap between the second and third clocks is a risk that the risk layer accounts for**, which is the correct home for it, because how much that gap matters depends on the assets, and the ABP does not know the assets. ## Drift Is A Neighbouring Measurement, And The Difference Is The Mandate **A product announced on 9 September 2026, two days ago, detects what it calls identity drift for agents**, comparing an agent's runtime behaviour against its original purpose and authorised scope, and triggering responses including reducing permissions, revoking credentials, disconnecting tools and application level kill switches. Another large vendor has announced continuous identity for agents. **The market has a word for the phenomenon and it is drift.** **This is validation and it sharpens the distinction rather than blurring it.** | | What it compares | When you learn | |---|---|---| | **Behaviour drift** | What the agent **did** against what it was allowed to do | **After the action** | | **Capability excess** | What the agent **can do** against what it was authorised to do | **Before any action** | **You can only detect drift once an agent has drifted.** The ABP states that the drift is possible before it happens, which is a different product and an earlier one in the sequence. **Both want a mandate, and the mandate is the scarce input**, which is the strongest reason to make eliciting it cheap and to publish the method. **One datum from that announcement is worth keeping**, because it is a competitor's own number supporting the thesis of the published foundation document: **fifty seven per cent of enterprise identity is described as unseen and unmanaged.** You do not know what it can do, said by somebody selling a different answer to it. ## The Collection Problem This Creates **The calibration loop needs observation, and the toolkit brief of 10 September rules that the downloadable builds never transmit anything.** Those are in tension and the tension should be resolved now rather than in month three. **The resolution is that calibration happens inside the customer's own instance.** Their deployment observes, their grant improves, their delta recomputes, and none of it leaves. **What comes back to the shared map is a contribution, not telemetry**: a proposed correction to a capability row, carrying its evidence, submitted deliberately through the same mechanism as any other proposal to the public data files, with a source, a timestamp and a hash. **A person decides to send it. Nothing phones home.** **That keeps both promises**, and it means the shared map improves at the speed of deliberate contribution rather than at the speed of collection. **Slower, and it is the only version that is honest.** ## What This Does Not Try To Be - **A schema.** The delta record's fields are listed. No file format, no identifier scheme and no storage layout is specified. - **A recompute implementation.** The trigger is mapped onto existing event types. Nothing is wired. - **A competitive analysis.** Two products are named from announcements read on one day, to draw one distinction. Neither was used or tested. - **A rewrite of the published document.** Two passages are quoted and two replacements are given. Everything else in that document stands. - **A decision about the consequence hooks.** The hazard is named and the shape of the safe version is given. What thresholds, set by whom, is not answered. ## Honest Tensions | Tension | Note | |---|---| | Correcting a published document | It is the estate's method, and it is the third correction issued in two days | | Storing the delta | It makes the history and the business case possible, and it creates an artefact that can be quoted out of date | | Reality as an input | It is what makes the grant improve, and it requires observing something we have promised not to observe | | Hooking consequences | It makes the ABP operational, and a computation error becomes an outage | | The three clocks | It is honest, and it tells a buyer their ABP is only as fresh as an integration they have not built | | Publishing the calibration loop openly | It improves the map for everybody including competitors, and the map being shared is what makes it worth calibrating | | Drift is a neighbouring product | The distinction is real and earlier in the sequence, and a buyer with a drift tool will believe they already have this | ## Open Questions 1. **What is the recompute policy?** On every event, on a schedule, on read, or a combination. It decides how much the receiver has to do. 2. **Is the specification final?** Its own page says standards track at a final address, and it should be checked before being cited publicly. 3. **Who sets the thresholds that consequences hook to?** The customer, the underwriter, or a default we publish. All three have different liability shapes. 4. **How is a calibration contribution submitted without revealing the deployment?** A correction to a capability row implies somebody runs that shape. 5. **Does the shortfall matter commercially?** Capabilities in the mandate and not in the grant are a real finding and nobody has proposed selling anything against them. 6. **What happens to a stored delta whose computation version is superseded?** Recomputed, marked, or left as the record of what was believed at the time. The third is the most honest and the least useful. 7. **Can the series be published without the deployment?** The business case sentence is compelling and it describes a customer's estate. ## Relationship To Previous Briefs **From the foundation document published earlier today**, it corrects two passages and leaves the rest standing, including the four objects, the four barriers and the rule that the ABP describes and does not judge. **From this morning's second brief**, it takes the projection pattern and finds that the delta is a projection too, alongside the label and the leaflet. **From this morning's third brief**, it takes the suspensive condition under the statute, and finds that a continuously computed delta is the thing that can trigger one and evidence it. **From the toolkit brief of 10 September**, it takes the rule that the offline builds do not transmit, and resolves the tension that the calibration loop creates against it. **From the vault architecture brief of 10 September**, it takes the customer's data vault as the home for the series, and the pinning rule that a consumer states the versions it computed against. **From the findability brief of 10 September**, it takes the derived rather than asserted principle and records this as the fourth instance of it. **From the ruling of 20 August**, it takes publish the record and never the verdict, and applies it to the one place where automation would otherwise make the estate a decision maker. ## Key Claims | # | Claim | |---|---| | 1 | The published wording is wrong in half: the delta is computed, and it is also stored | | 2 | The correct formulation is that the delta is derived and never authored, which forbids the act rather than the artefact | | 3 | Everything the old ruling protected survives, because a stored delta carries its inputs, their versions and the time it was computed | | 4 | It is a materialised view, and the estate already applies the same pattern to indexes, prose and bills of materials | | 5 | Reality is a third input, because something happening that is not in the grant means the grant was incomplete | | 6 | The calibration loop is the answer to twenty one measured rows of ninety nine, and it improves the shared map for everybody | | 7 | A derived delta reacts to a change in either input without anybody touching the document, which no template can do | | 8 | The recompute trigger has an existing standard with defined event types, so it is a receiver rather than an invention | | 9 | A threshold crossing is a record and the consequence is a policy somebody set in advance, which keeps the ABP consequence agnostic while the automation is real | | 10 | A continuously computed delta can trigger and evidence a suspensive condition, which is the statutory mechanism analysed this morning | | 11 | The history makes the business case a subtraction that is read rather than constructed, and it is the only way to evidence a control over a period | | 12 | Behaviour drift is detected after an action and capability excess exists before any action, and both need a mandate that only one of them elicits | ## Sources All read 11 September 2026. **Inside the estate.** The foundation document published earlier today. The capability map with its nine profiles, twenty three primitives, four barriers and its statement that twenty one of ninety nine rows were measured, at https://what-can-it-do.games.sgit.ai/map/index.html. The graph rules at https://graphs.sgit.ai/. The site building guidance, for the rule that indexes are generated from the data they index, at https://sgit.ai/docs/guidance/index.html. The three briefs of this morning and the toolkit, vault architecture and findability briefs of 10 September. **The recompute trigger.** The continuous access evaluation profile at https://openid.net/specs/openid-caep-1_0-final.html, dated 29 August 2025, whose own page described it as standards track rather than final and whose status should be confirmed before public citation. The working group at https://openid.net/wg/sharedsignals/ and its specification list at https://openid.net/wg/sharedsignals/specifications/. **The neighbouring measurement.** The drift detection and kill switch announcement of 9 September 2026 at https://www.helpnetsecurity.com/2026/09/09/orchid-security-ai-agents-application-level-kill-switches/ and https://www.globenewswire.com/news-release/2026/09/09/3358716/0/en/orchid-security-adds-ai-readiness-controls-identity-drift-detection-and-application-level-kill-switches-for-ai-agents.html, including the figure that fifty seven per cent of enterprise identity is unseen and unmanaged. The continuous identity announcement at https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-continuous-identity-for-ai-agents/. Neither product was used or tested and no adjective is attached to either. **The statutory mechanism.** Section 10 of the Insurance Act 2015 at https://www.legislation.gov.uk/ukpga/2015/4/section/10, analysed in this morning's third brief. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case/index.html)* ------------------------------------------------------------------------ # The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Sell The Correction, And Not The Draft > version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever names the product, prices it, and stands at the table with it next week *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The briefs](../../../docs/index.md#briefs) / The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Sell The Correction, And Not The Draft # The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Sell The Correction, And Not The Draft > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__strategy-brief__the-behaviour-policy-is-the-document-the-only-agent-insurer-already-requires-sell-the-correction-and-not-the-draft.md`](../../../docs/briefs/v0.33.70__strategy-brief__the-behaviour-policy-is-the-document-the-only-agent-insurer-already-requires-sell-the-correction-and-not-the-draft.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Human (project lead) **to** Whoever names the product, prices it, and stands at the table with it next week **type** Strategy brief (the product, its name, and the go to market, with five memos behind it) *First of 11 September, and the first document in this session written by a model that joined it today. Five memos arrived across two turns and were reviewed against the corpus and the published estate before anything was written. The review found that the product itself was decided yesterday in two briefs, that the estate already publishes the three set model this memo re-derives, that the only insurer underwriting autonomous agents specifically already requires the document this memo proposes as a scoping input, and that the estate has a built and tested vault mapping the standard that insurer underwrites against. Two naming hazards were found, one inside the estate and one in the memo's own slip of the tongue. Limitations: no pricing is proposed beyond placing the product on the ladder that already exists; the incumbent's offer was read from its own site on one day; and the go to market described is a design for a conversation, not a tested one.* ## What This Is The naming of a product that was decided yesterday, the resolution of two collisions that naming creates, and a go to market that can be run at a table in five minutes: **the memos propose selling a policy for an organisation's agents that states the grant, the mandate and the behaviour expected, observe that the mandate is already understood by most deployers while the grant is not, argue that because an agent can do a thing it must be explicitly told not to, so the prohibition list grows with the grant and its length is the finding rather than a defect, note that the list also serves as a partial defence and as the input to guardrails and monitoring, place the whole thing in a graph so that policy for an agent, for an agent in an environment, with particular credentials, in particular situations and at particular times are all the same structure, state that what people call a policy is a projection computed from that graph so that executives and engineers each get their own rendering of one fact set, propose the name agent behaviour policy, say the policy is the licence to operate, propose that it can be produced without the customer's involvement by handing over a draft and asking whether it is correct, and want it on sale next week; the first finding is that the product exists in the corpus already, in yesterday's ruling that the product is an agent policy for an organisation derived from what its agents can actually do, so this brief names it rather than proposes it; the second is that the name collides with the estate's own demonstration, where the word policy already denotes the insurance instrument with its bands, ceilings, pool and premium, so the behaviour policy must never be called the policy; the third is that the only insurer currently underwriting autonomous agents by name requires, as a scoping input, a document listing the agent's capabilities, its autonomy level, its data access permissions, the tools it can call and its deployment context, which is this document, and the estate has a tested vault mapping that insurer's standard; the fourth is that the strongest go to market is the one the memo states in half a sentence, being that a draft derived from the deployment shape is handed over and the correction is the elicitation, which needs no access, no engagement, no data and no packet sent to anybody; and the fifth is that the regulatory reason a United Kingdom buyer will cite is not the European deployer article, which was deferred to December 2027 in July, but consumer guidance published on 9 March 2026 saying a business should be clear about what tasks an agent is allowed to perform, what data it can access and what constraints apply.** New contributions: **the name and the two hazards attached to it; the resolution of the licence to operate collision by supplying its referent; the four object structure that turns a long list into a finding; the mapping onto the existing price ladder so that nothing is added five days before the event; the draft and correction go to market; the correct regulatory citation; and, added after the project lead's comments, the principle that the ABP describes and never judges, carries no score, and is the label in a three part structure whose prescription is signed by somebody who did not sell it.** ## The Product Was Decided Yesterday Two claims from 10 September, verbatim from their key claims tables: > The product is an agent policy for an organisation, derived from what its agents can actually do, and never an insurance policy. > The wedge is agent policies, and the two things we add that it cannot are provenance and a named human. **So this brief does not propose a product.** It names one, and it adds three things the yesterday's briefs did not have: the mechanism that makes the document a finding rather than an inventory, the go to market, and the reason the document is on an insurer's intake form already. ## The Name, And Two Hazards Attached To It **Agent Behaviour Policy. ABP.** Three letters, pronounceable, unclaimed as a product as of today. The phrase appears in one academic paper and nowhere as a thing anybody sells. **Drop user acceptance policy.** The memos reach for it four times and correct it each time. User acceptance already means user acceptance testing to every engineer in the room, and the artefact being described is an acceptable use policy in shape, not an acceptance one. The confusion is not cosmetic: an acceptable use policy governs a person's use of a system, and this document governs what an agent may do. Borrowing the frame imports the wrong subject and lands the product in a category where at least eight free templates dated this year sit on the first page of search. **Withdraw the earlier objection to behaviour.** It was argued yesterday that behaviour names what an agent does rather than what it is authorised to do. With the graph framing, the document is the union of grant, mandate and expected behaviour, so the word is the right one. **The first hazard is the memo's own slip.** The last memo says ADP twice. ADP is one of the largest payroll processors in the world and a registered mark in every relevant class. **Nothing with that string on it may be printed.** The acronym is ABP and it should be spelled out at first use on every surface. **The second hazard is inside the estate, and it is the more serious of the two.** The published licence to operate demonstration describes itself as an insurance policy for an agent, simulated, and its policy object carries a normal band, an ask above threshold, a per action ceiling, a pool with an untouchable reserve and a premium per interval. **In the estate's own vocabulary, the policy is the insurance instrument.** A behaviour policy that is ever referred to as the policy will collide with it on the first page that mentions both. **The rule: the behaviour policy is always called the ABP or the behaviour policy, and never the policy.** That is a discipline for the writer of every page, and it costs one word. **And pick a spelling.** Behaviour or behavior. The product will be sold in both markets and an acronym does not care, but a wordmark does, and the earlier brief on marks says the mark is the moat. ## The Licence To Operate Collision, And What Closes It **Open since 8 September, and it blocks any public page.** Licence to operate, ruled on 3 September, means a permission granted by an authority. Mandate to operate, written on 17 July, means a description of exposure already carried. They mean opposite things and both are in use. **The memo says the policy is the licence to operate, and that sentence supplies what the collision has lacked, which is a referent.** The organisation is the authority. The ABP is the instrument. The agent is the licensee. That is internally consistent with the 3 September sense, and it makes the 17 July phrase redundant, which is what the cheapest proposed resolution already recommended. **It is self issued and witnessed by us, which is how most assurance works.** **This is a proposal for a ruling, not a ruling.** But it is the first time either phrase has had a concrete thing to point at, and that is what the collision needed. ## The Mandate Is Known And The Grant Is Not, So The List Is The Finding The second memo corrects a wrong reading, and the correction should be recorded in the corpus rather than in a conversation. > Most users understand the mandate either explicitly or implicitly. They sort of understand that this is what we expect the agent to do. The problem is they don't understand the grant. **That is an empirical claim about buyers and it is right.** Nobody needs to be told what they wanted the agent to do. They need to be told what it can do. So the work, and the value, sit on the grant side, and **the length of the resulting list is the measurement, not a maintainability problem.** A list that comes back long is the finding that makes the buyer move. **But a long list on its own is an inventory, and an inventory is not a sale.** Your agent can do three hundred and forty things is a shrug. **Your agent can do three hundred and forty things and you authorised twelve is a finding.** The mandate is the edge that gives the enumeration a shape, and it must be captured even though it is already known. Captured cheaply, elicited rather than authored, because the buyer already holds it. **So there are four objects, and the memo's list is the fourth.** | Object | How it is obtained | What it is | |---|---|---| | **The mandate** | Elicited, in minutes, because the buyer already knows it | What the agent is authorised and expected to do | | **The grant** | Measured, from the deployment shape and the credentials | Everything the agent can do | | **The delta** | Computed, never stored | The excess authority | | **The prohibitions** | The enforceable projection of the delta | The subset a control can actually bound, written as instructions | **The prohibitions are smaller than the delta**, because they are the part something can enforce. That distinction matters for the next brief, because a prohibition has two very different lives depending on where it is enforced. **The memo's own line for the site, which falls out of this:** a human acceptable use policy is short because humans have judgement and social constraint. The agent version is long for the same reason the agent is useful. It does precisely what it is permitted to do, and nothing stops it. ## The ABP Carries No Verdict And No Score **Added after the project lead's comments of 11 September, and it sits above everything else in this brief.** **The ABP describes and does not judge.** It states the grant, the mandate, the delta and the barrier on each capability. It never says whether any of that is acceptable, because acceptability is not in the document. **The same ABP is dangerous in one deployment and harmless in another, and nothing about the document changed.** The most permissive grant running where nothing is reachable is a low risk; the same grant with a database attached tomorrow is a different risk; and the document is identical on both days. **A policy cannot be dangerous. A deployment can.** **So the ABP carries no score, anywhere.** No rating, no traffic light, no risk level. Every buyer will ask for one in the first meeting, and the answer is that **the score has a home, and it is the risk product**, where the assets are known, the acceptance workflow exists and a named professional signs. A score on the ABP is the fastest way to make it wrong in one of the two rooms. **This changes three things already in this brief, all for the better.** **The long list is an inventory and not an admission.** The ABP asserts that a capability exists, never that a risk is unacceptable, which is materially different from a findings register. It moves an exposure rather than removing it, and it is the right thing to draft toward. **The correction is factual.** The draft and correction motion never asks a buyer to agree that something is dangerous. It asks whether their agent can do a thing. That is a conversation you can have with somebody who knows their business better than you do. **The record is what is sold.** A description of the grant rots on a known clock, the product's releases and the deployment's changes. A verdict rots on an unknown one. **A document with a visible clock can be re-sold. A verdict cannot.** **The structure this gives the whole offer, which the project lead has adopted:** the ABP is the label, the twin is the patient record, and the risk score is the prescribing decision. The first two are the first product. The third is the uplift, and it is signed by somebody who did not sell the first two, because the standing rule is that the people who sell do not sign. **That rule is why the sequence separates cleanly rather than commercially.** **Two corrections to our own data that the principle forces.** The undo class is not fully context free, because reversibility depends on backups and retention, so it is recorded as the product's published behaviour with a note that the deployment can change it. And no assets does not mean no consequence; it means no consequence to you, since an agent with world reach in an empty environment can still reach third parties. **Every ABP carries a validity statement**: this describes the deployment shape as at this date, and if the risk changed, the deployment changed, not this document. ## The Only Agent Insurer Already Asks For This Document **One insurer underwrites autonomous agents by name today.** It launched in July 2025 with a fifteen million dollar seed round, is backed at Lloyd's, wrote what its customer called first of its kind agent insurance for a voice platform on 11 February 2026 after more than five thousand adversarial simulations, and offers limits reported at fifty million dollars per policyholder. **Its terms are tied directly to audit results against a standard it publishes.** **That standard's scoping requirements, quoted from its own site:** the organisation must document **capabilities**, meaning the specific functions the agent performs and its autonomy level; **architecture**, meaning data access permissions and which tools it can call; **deployment context**; and a **statement of applicability** listing which of roughly fifty requirements apply. Its second quarter update of 15 April 2026 added a mandatory control for permission ready architecture such as just in time permissions to limit the scope and duration of agent privileges, cryptographically verifiable agent identities, and tool authorisation and logging extended to protocol servers. **Read that list against the four objects above.** Capabilities and tools are the grant. Autonomy level and deployment context are the environment dimension. The statement of applicability is the mandate in the standard's own terms. **The ABP is the scoping document that insurer already requires, expressed as a graph.** **And the estate has already built the other half.** A published vault maps that standard's catalogue byte for byte, passes the catalogue's own twenty one tests and nineteen of its own, and produces conformance objects for a named subject with attestations carrying a tier and an expiry date, with unevidenced as the default. Its own wording: **it records what is evidenced and what is not; it certifies nobody, maps nothing officially, and makes no underwriting decision.** That is the correct posture, and it is the posture the ABP inherits. **Two others have entered the same space this year and neither has the document.** A conformance vendor announced continuous governance of agents on 4 August 2026, in limited availability and for one model provider's agents only, compiling plain English intent into enforceable rules. A guarantee backed startup raised five and a half million in July 2026 to insure agent actions in bounded business to business use cases. **Both are downstream of a written statement of what the agent may do, and neither produces one.** ## The Incumbent, Read From Its Own Site **One company sells a written policy for agents today.** Two thousand one hundred and ninety nine dollars, one time, for twenty or more editable word processor templates including an agent acceptable use policy described as what agents can and cannot do, an agent data access and permissions policy, an approval workflow, an escalation policy and a decommissioning runbook. It advertises a thirty minute onboarding call for the first twenty buyers and a thirty day guarantee. **What it does not have, and what the ABP is:** no machine readable form, no derivation from the buyer's own deployment, no review service, no provenance on any claim, and no named human. It is a template. **It cannot be a finding because it does not know what the buyer's agent can do.** **Yesterday's two additions stand, and this brief adds a third.** Provenance and a named human were the two things the wedge brief said we add. **The third is that the document is derived from the customer's own measured grant, which a template can never be.** ## Sell The Correction, Not The Draft **The best idea across all five memos is said in half a sentence.** > You could even do it from a point of view of, hey, here's the policy for your agent, can you then agree that this is correct or incorrect? And that's also a great way to reverse engineer actually what the agent is doing. **This inverts the sales motion completely.** No access. No engagement. No customer data. No infrastructure on their side or ours. **A draft ABP is derived from a deployment shape**, meaning which agent product, running where, with which class of credentials, in a container or on a desktop or with an administrator's rights. The draft is handed over. **The correction is the elicitation.** A person who corrects the document has told you their mandate, told you where the draft's grant was wrong, and engaged with the product before paying for it. **Three properties make it the right thing for next week.** **It is the only version producible in a room.** Every other form of the ABP is a booking. This one is a five minute conversation over a printed draft, and the printed draft is the card. **It is legally clean.** The standing rule is never to send a packet to a third party system that was not asked for, because causing a computer to output data intending unauthorised access is an offence with no research defence. **A draft about a deployment shape sends nothing anywhere.** It asserts, and asks to be corrected. **It respects the buyer's competence.** The mandate is theirs. The document says so by asking them to state it, rather than by pretending to know it. **The draft should be wrong on purpose in one place.** Not misleading, but conservative: it should state a grant that the buyer will recognise as too small, because the correction upward is the moment they realise the grant is larger than they thought. That is the mechanism the games site publishes, applied to a printed page: **make somebody state a belief before they are told the answer.** ## It Sits On The Ladder That Already Exists **Do not add a fifth tier five days before the event.** The four tiers were set on 10 September and the offer page is being built against them. | Tier | Price | What it delivers | Where the ABP is | |---|---|---|---| | **1** | GBP 10 | Their own answers, their measured grant, and the delta, as a file they keep | **This is a draft ABP.** The tier one product has had no name and now has one | | **2** | GBP 50 to 100 | The customised regulation as a vault they own | Not the ABP. The regulation the ABP is later mapped against | | **3** | GBP 150 to 1,000 | A person reviewing and running a vault | **The full ABP.** Mandate elicited properly, grant measured against the real deployment, prohibitions marked by where each is enforced, delivered as a vault with the projections | | **4** | GBP 5,000 to 10,000 | An assessment by security professionals | The ABP plus the assessment of whether the prohibitions are actually enforced where they claim to be | **The project lead's sequencing, added 11 September: the ABP and the twin are the first product, sold together, and the risk score is the uplift.** One dependency stands in front of that: the twin's running state was an open question in the third brief of today and is still open. If the twin is built, the first product is the ABP with a hooked twin. If it is not, the first product is the ABP and the twin is the second. **And the two have different sales motions**, because the ABP's draft and correction needs no access to the customer's environment and a hooked twin needs exactly that. That difference is the natural boundary between tier one and tier three. **So the ABP is not a new product.** It is the name for what tiers one and three deliver, and it is the thing that makes tier one worth ten pounds, because a measured grant with no name is a spreadsheet and a measured grant called a behaviour policy is a document somebody keeps. **The tier one dependency stands.** An application built in August, on which the ten pound product depends, has not been located. The draft and correction motion is a questions page with a printed output, and it can be built in the time available whether or not the August application is found. ## The Regulatory Reason A Buyer Will Cite, And The One They Will Not **The reason is not the European deployer article.** The omnibus regulation entered into force on 27 July 2026 and deferred the high risk obligations, including the deployer obligations on human oversight, monitoring and logging, to **2 December 2027**, and only for systems in the high risk annex. An organisation whose agent is not high risk has no duty under that article at all, and one whose agent is has fifteen months. **The reason is consumer guidance published in the United Kingdom on 9 March 2026.** It states that if an agent a business uses does something illegal, the business is responsible, and that businesses **should be clear about what tasks an AI agent is allowed to perform, what data it can access, and what constraints apply**, with testing before deployment and monitoring after. **That is the closest any regulator has come to describing the ABP by its contents**, it is current, it is domestic, and the consumer regime behind it carries fines to ten per cent of global turnover with direct enforcement since April 2025. **The security engineering reason, for the technical buyer.** The industry's own list of the ten agentic application risks, published 9 December 2025, puts tool misuse and identity and privilege abuse at positions two and three, with mitigations centred on least privilege, scoped credentials and enumerated tool catalogues. **An enumerated tool catalogue with a stated scope is the grant half of the ABP.** **For a buyer certifying against the management standard:** the standard's annex carries controls for an AI policy, its alignment with other policies, its review, and the intended use of AI systems. Titles only, because the standard's text may not be reproduced or fed to a model, per the standing licence rule. ## What This Does Not Try To Be - **A pricing decision.** The ABP is placed on the existing ladder and no number is changed. - **A ruling on the naming collision.** The referent is supplied and the ruling is the project lead's. - **The graph model.** That is the second brief of today. - **The insurance argument.** That is the third, and the word insurance does not appear on any page this brief describes. - **A test of the go to market.** It is designed here and has been run with nobody. ## Honest Tensions | Tension | Note | |---|---| | Naming a product decided yesterday | It is the right discipline, and it means the memo's energy went into something already ruled | | The word policy | The estate's own demonstration owns it for the insurance instrument, and every page will want to shorten ABP to it | | The long list as the finding | It is the measurement, and a list the buyer cannot act on is a liability document, which the third brief takes up | | Selling the correction | It needs no access and no data, and it means the first thing a buyer sees from us is something wrong | | The tier one placement | It gives the ten pound product a name, and it ties the ABP's first impression to an application nobody can find | | The consumer guidance as the driver | It is current and domestic, and it applies only to consumer facing agents | | The insurer's scoping document | It validates the shape exactly, and it is one insurer with one standard | ## Open Questions 1. **Is the licence to operate collision closed by this referent?** A ruling is needed and nobody has made it. 2. **Behaviour or behavior?** The wordmark decision, and it is due before anything is printed. 3. **What does the printed draft look like?** It is the card for tier one and it has not been drawn. 4. **Which deployment shapes get a draft?** The draft and correction motion needs a small library of shapes, and the first five have not been chosen. 5. **Does the August application exist?** If it does, tier one is that application with a new name. If not, it is a questions page. 6. **Who says the mandate?** For a corporate buyer, the person at the table is rarely the person who authorised the agent, and the standing rule is that the stakeholder is the entry point and not the risk bearer. 7. **Does the consumer guidance reach agents that never touch a consumer?** It is the strongest current citation and its scope is consumer law. ## Relationship To Previous Briefs **From the policy and wedge briefs of 10 September**, it takes the product, the incumbent and the two additions, and it adds a third addition and a name. **From the naming rulings**, it takes the instruction not to coin a noun but to name for the buyer's question, and it finds that the buyer's question was already chosen yesterday for the corporate card: what is your agent allowed to do. **From the licence to operate collision**, it takes the two definitions and supplies the referent that neither had. **From the published licence to operate demonstration**, it takes the three set model and the finding that the word policy is already spoken for. **From the payment and catalogue briefs**, it takes the four tiers and places the ABP on them without changing a number. **From the marketing brief's first hard rule**, it takes the prohibition on sending unrequested packets and finds that the draft and correction motion satisfies it by construction. **From the games site**, it takes the mechanic and applies it to a printed page that is conservative on purpose. ## Key Claims | # | Claim | |---|---| | 1 | The product was decided on 10 September as an agent policy derived from what the agents can actually do, so this brief names it rather than proposes it | | 2 | The name is Agent Behaviour Policy, and it must never be shortened to the policy, because the estate's own demonstration uses that word for the insurance instrument | | 3 | User acceptance policy is dropped because it names a different thing and imports the wrong subject | | 4 | The string in the last memo's slip is a large payroll company's mark and may not be printed | | 5 | The mandate is known and the grant is not, so the value is on the grant side and the length of the list is the finding | | 6 | A long list alone is an inventory, and the elicited mandate is what turns it into a finding | | 7 | The ABP describes and does not judge, so it carries no score, because the same document is dangerous in one deployment and harmless in another, and the score lives on the risk product | | 8 | The only insurer underwriting autonomous agents by name requires a scoping document listing capabilities, autonomy level, data access, callable tools and deployment context, which is this document | | 9 | The estate has a tested vault mapping that insurer's standard, which certifies nobody and makes no underwriting decision | | 10 | The draft and correction motion needs no access, no data and no packet, and is the only form producible in a room | | 11 | The ABP is the name for what tiers one and three already deliver, and no tier is added | | 12 | The regulatory citation is the consumer guidance of 9 March 2026, not the deployer article, which was deferred to December 2027 | ## Sources All read 11 September 2026. **Inside the estate.** The licence to operate demonstration at https://sgit.ai/demos/vaults/licence-to-operate/index.html, which defines the grant, the mandate and the delta and describes its policy object as an insurance policy for an agent, simulated. The conformance vault at https://sgit.ai/demos/vaults/aiuc-1-conformance/index.html, with its test counts and its disclaimer. The games site at https://games.sgit.ai/llms.txt. The 10 September briefs on the policy document, the wedge, the payment rail and the catalogue. **The insurer and its standard.** The standard's scoping page at https://www.aiuc-1.com/scoping and its second quarter update at https://www.aiuc-1.com/research/2026-q2-standard-update, dated 15 April 2026. The launch at https://www.reinsurancene.ws/artificial-intelligence-underwriting-company-launches-with-15m-seed-round/, 23 July 2025. The first agent insurance announcement at https://www.prnewswire.com/news-releases/elevenlabs-secures-first-of-its-kind-ai-agent-insurance-302684587.html, 11 February 2026. The reported limit at https://www.fastcompany.com/91550776/rajiv-dattani-is-bringing-insurance-to-the-ai-agent-boom, 18 June 2026. **The incumbent and the entrants.** The template offer at https://agentguru.co/. The conformance vendor's announcement at https://drata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agents, 4 August 2026. The guarantee backed startup at https://www.klaimee.ai/ and its round at https://fintech.global/2026/07/22/klaimee-lands-5-5m-to-insure-autonomous-ai-agents/, 22 July 2026. The academic use of the phrase at https://arxiv.org/html/2508.14415v1. **The regulatory citations.** The consumer guidance at https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents, 9 March 2026. The omnibus regulation and its deferrals at https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act. The agentic application risk list at https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, published 9 December 2025, whose full text was not fetched. The management standard's annex control titles from a secondary listing, with no standard text reproduced. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/briefs/v0.33.70__strategy-brief__the-behaviour-policy-is-the-document-the-only-agent-insurer-already-requires-sell-the-correction-and-not-the-draft/index.html)* ------------------------------------------------------------------------ # The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Delta, And The Insurance Act Says How > version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever plans the ladder from the behaviour policy to everything above it, and whoever talks to an underwriter first *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The briefs](../../../docs/index.md#briefs) / The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Delta, And The Insurance Act Says How # The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Delta, And The Insurance Act Says How > **The source bytes.** This page is generated from [`docs/briefs/v0.33.70__strategy-brief__the-prohibitions-are-the-exclusions-your-own-demo-says-no-policy-covers-the-delta-and-the-insurance-act-says-how.md`](../../../docs/briefs/v0.33.70__strategy-brief__the-prohibitions-are-the-exclusions-your-own-demo-says-no-policy-covers-the-delta-and-the-insurance-act-says-how.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **version** v0.33.70 **date** 11 September 2026 **from** Human (project lead) **to** Whoever plans the ladder from the behaviour policy to everything above it, and whoever talks to an underwriter first **type** Strategy brief (the sequence from behaviour policy to twin to risk to standards to the thing at the top of the ladder, with the legal mechanism that makes the sequence forced) *Third of 11 September. The corpus was searched first and the estate's own published demonstration turned out to contain the sentence this brief is built on. The outside search established who actually underwrites autonomous agents as of this week, what they require from the insured, and the statutory mechanism in this jurisdiction by which a written statement of what an agent may do becomes something an insurer can rely on. The word that names the top of the ladder appears in this document because it describes other companies' products and because this document carries no price, per the ruling of 8 September. It may not appear on any page that does. Limitations: no policy wording from any of the named insurers was available, so what they require is drawn from their published standards, blogs and announcements rather than from contracts; the standards mapping is framed and not built; and the legal analysis is research rather than advice.* ## What This Is The argument that the sequence the memo describes is forced rather than chosen, and the mechanism that forces it: **the memo states that the risk product is ultimately about making agents insurable because they comply and their behaviour is understood, that the insurance workflow and the insurance model and the insurers are not there yet, that the behaviour policy is therefore where to start because it drives the behaviour and can be sold today without depending on anybody else, that once it exists the digital twin is integrated as the interface where the business touches the thing, that from the twin the reality of existing tools is mapped, that risks to the business are then connected through the risk acceptance workflow and accountability, that the policy is mapped to standards to say which parts are met and which are not and, more interestingly, what would need to be put in place to meet them, which is where business cases come from, that the policy comes with the twin and the policy is the licence to operate, and that the whole of the risk product sits on top of this as both a long term vision and a way to make revenue next week; the first finding is that the estate's own published demonstration already states the relationship that makes the order forced, because it defines the mandate as the only thing the policy insures and the delta as the set no policy covers, which means the prohibitions the behaviour policy enumerates are, precisely, the exclusion schedule of any instrument that later sits on top of it; the second is that the insurers who underwrite agents at all are asking for this document already, with one requiring a scoping statement of capabilities, autonomy, data access, callable tools and deployment context tied directly to its terms, another writing in January 2026 that system level behaviour is often left undefined and that insurability requires clarity on what systems are permitted to do, and a broker in May 2026 asking for a mapping of where systems can act without prior business approval; the third is that the statute in this jurisdiction gives a written statement of authorised scope three possible legal shapes, as a representation subject to the duty of fair presentation, as a term defining the risk so that an action outside it falls outside the cover with no causation defence, or as a warranty whose breach suspends cover until remedied, and the estate's demonstration already reads as the second; the fourth is that agents currently fail the standard preconditions for an insurable risk on assessability, on fortuity and on independence, and a written behaviour policy with monitoring repairs the first two and does nothing for the third; and the fifth is that the standards mapping the memo wants has a licence constraint and a verdict constraint, so its output is a record of what a provision requires and what a control would bound, never a statement that anybody is in compliance.** New contributions: **the identification of the prohibitions as the exclusion schedule; the market survey with the three insurers who underwrite agent action by name; the three legal shapes and which one the estate already uses; the insurability preconditions with what the behaviour policy contributes to each; the honest form of the standards mapping output; and, added after the project lead's comments, the label, patient and prescription structure that places the score and separates the seller from the signer.** ## The Sentence Is Already On Your Site The published licence to operate demonstration defines three sets: > **Grant.** Everything the agent is technically able to do. > **Mandate.** What the user actually expects, and the only thing the policy insures. > **The delta.** Inside the agent's reach, outside its authority. No policy covers these. **Read the second and third together and the relationship between the behaviour policy and everything above it is settled.** The instrument at the top of the ladder covers the mandate. It covers nothing in the delta. **The behaviour policy's prohibitions are the enumerated delta. So the prohibitions are the exclusions.** Not a precursor to them, not an input to drafting them. The same list, in a different document. **That is why the sequence is forced.** An underwriter cannot write an exclusion schedule for something that has never been enumerated. **Without a written statement of what the agent may do, there is nothing to say a loss fell outside, and an instrument that cannot say that cannot be priced.** The memo's ordering, behaviour policy first because the insurance apparatus is not ready, is right for a reason stronger than readiness: **the behaviour policy is the underwriting artefact**, and the apparatus cannot become ready without it. **And the estate's conformance vault already produces the shape.** It generates a policy object whose conditions **become exclusions because the attestations behind them expire**, with a field stating what the object does not prove: that any control is in place. **It proves what was attested, at what tier, and when it expires.** That is an exclusion schedule with a clock on every line, and it is built and tested. ## Who Underwrites Agents, As Of This Week **The memo says the insurers are not there yet. Three are, narrowly, and the rest are either insuring something else or excluding.** | Who | Since | What is covered | Agents by name | |---|---|---|---| | **A Lloyd's backed underwriter tied to a published standard** | July 2025, first agent policy 11 February 2026 | Liability for agent failures, with terms tied directly to audit results; reported limits of fifty million dollars per policyholder | **Yes**, the only one built around autonomous agents | | **A Lloyd's coverholder with a coordinated structure** | Affirmative cover April 2025, coordinated structure 10 February 2026 | Underperformance, failure to perform as intended, hallucination, and since February a structure with predefined allocation rules that sends agent actions where no cyber incident occurs to the AI policy; standalone limit raised to twenty five million dollars in January 2026 | **Yes**, by allocation | | **A guarantee backed startup** | Seed of five and a half million, 22 July 2026 | Performance warranties for agents: wrongful commitments, unauthorised autonomous actions, prompt injection, in bounded business use cases; excludes vehicles, robotics and physical safety | **Yes**, by design | | A reinsurer's performance guarantee | 2018 | Backs a vendor's warranty on model performance against defined metrics and thresholds | No, model output | | A syndicate with the same reinsurer | 27 February 2026 | Financial loss from defined performance failures, settled on measurable data; excludes uptime, cyber, breaches and negligent deployment | No, model output | | A coverholder for generative output liability | 21 January 2026 | Six insuring agreements for false or misleading output, built to fill a general liability exclusion; capacity of just over nine million per insured | No, output not action | | A cyber carrier with affirmative wording | 2024, base form 9 April 2025 | Agent originated losses covered where they produce a cyber covered loss | Only inside cyber | **The other direction is louder.** The standard form body whose forms underpin most of the American property and casualty market published exclusions effective 1 January 2026 for bodily injury, property damage and personal injury arising out of generative artificial intelligence. One carrier filed an absolute exclusion in May 2025 covering any use, deployment or development, chatbot representations, and **inadequate AI policies or training**. Several large carriers have had exclusion filings approved. **The admitted market is excluding and the specialty market is affirming**, and the honest summary from the trade press in August 2026 is that most cyber insurers are clarifying wording rather than adding exclusions, with exclusions under discussion for systemic single model events and for **liability when agents make autonomous decisions as designed**, which may be classified as non cyber. **Read that last clause carefully, because it is the whole product.** An agent doing exactly what it was permitted to do, and causing a loss, is the case the market does not know how to classify. **A behaviour policy is the document that says whether the action was permitted.** It is the classification. ## What They Ask The Insured For **The underwriter tied to a standard publishes its scoping requirements**, quoted in the first brief of today: capabilities and autonomy level, data access permissions and which tools it can call, deployment context, and a statement of applicability. Its April 2026 update mandates permission ready architecture such as just in time permissions, verifiable agent identities, and tool authorisation and logging extended to protocol servers. **Terms are tied directly to audit results.** **The coverholder wrote its position down on 14 January 2026.** Underwriting asks where systems are deployed, who owns them and what they are doing in production. **Performance thresholds, bias tolerance and system level behaviour are often left undefined.** Governance that looks robust on paper but fails under real world pressure is inadequate. Systems must be tested, monitored and governed over time rather than certified at a single point. **And insurability requires clarity on what systems are permitted to do.** **The reinsurer's own paper on the subject** says the developer should define the model input space clearly, that clear guardrails must be set for the use cases, that what counts as false, hallucinated or harmful **will need to be very clearly defined**, and that the trigger is damage plus underperformance against defined metrics and thresholds. **A large broker's agenda for 2026, dated 7 May,** says underwriters expect clear evidence of governance, documented testing, human review for high stakes outputs, and **a mapping of where AI systems can act without prior business approval**, noting that agent behaviour and risk can change without a clearly defined deployment event. **And a June 2026 paper on insuring agentic systems** proposes that underwriting track what authority has been delegated, what controls govern operation, what approvals are required before execution, and **which external systems, assets or processes the agent is permitted to modify**, with tiered autonomy pricing and **scheduled systems with declared permitted functions**. **Every one of those is a description of the behaviour policy.** The scoping statement is the grant and the environment. What is permitted to do is the mandate. The mapping of where it can act without approval is the delta. The declared permitted functions are the schedule. **Nobody yet publishes policy wording making such a document a condition of cover, and that is the layer no insurer publishes about anything.** But it is on the intake form of the only agent specific underwriter, in the blog of the largest coverholder, and in the paper of the largest reinsurer. ## The Three Legal Shapes, And The One The Estate Already Uses **In this jurisdiction the statute is the Insurance Act 2015, and a written statement of what the insured undertakes can take three shapes under it.** The distinction is not academic: it decides what happens when the agent acts outside the statement. **A representation, under the duty of fair presentation.** Sections 3 to 7 require the insured to disclose every material circumstance it knows or ought to know, in a manner reasonably clear and accessible, with representations of fact substantially correct. Section 9 abolishes basis of contract clauses: a statement in a proposal form **cannot be converted into a warranty by declaring it the basis of the contract**, and section 16 says that cannot be contracted out of. **So a behaviour policy attached to a proposal is a representation, and its remedies are the proportionate ones of schedule 1, not avoidance, unless the breach was deliberate or reckless.** **A term defining the risk as a whole.** The explanatory notes give the example of a requirement that a property not be used commercially: **an action outside such a term simply falls outside the insured risk.** Section 11, which protects the insured where non compliance could not have increased the risk of the loss that actually occurred, **does not apply to risk defining terms.** No causation defence is available. **This is the shape the estate's demonstration already reads as**: the mandate is the only thing the policy insures, and the delta is what no policy covers. That is a definition of the risk, not a condition on it. **A warranty.** Section 10 abolished the old rule that breach discharges the insurer entirely and replaced it with suspension: **the insurer has no liability for any loss occurring after a warranty has been breached but before the breach is remedied**, and liability resumes when the insured ceases to be in breach or the risk becomes essentially the same as originally contemplated. Section 11 does apply here, so a breached control warranty irrelevant to the loss that occurred cannot be relied on. Sections 16 and 17 require any term more disadvantageous than the statutory default to be drawn to the insured's attention and to be clear and unambiguous as to its effect. **The strongest position for an instrument built on the behaviour policy, and it is the one to design toward:** the mandate as a **risk defining term**, so that an action in the delta is outside the cover with no causation argument, plus the monitoring and approval controls as **warranties**, so that switching them off suspends cover until they are switched back on, with the whole document also serving as the fair presentation at placement. **Three shapes, one document, and the estate's demonstration already has the first.** **On the memo's phrase.** The memo says the policy is the licence to operate. In statutory language the written undertaking is a promissory warranty only if the instrument makes it one, a representation if it sits in a proposal, and a risk definition if it is drafted as scope. **The phrase licence to operate is a good name for the artefact and it is not a term of art, and the first brief of today proposes it as the referent that closes the collision. It should not be used as if it had a statutory meaning, because it does not.** ## Why Agents Are Not Insurable Yet, And What The Behaviour Policy Repairs **The standard preconditions, from the actuarial literature as applied to this problem in October 2025 and again in June 2026:** fortuity, assessability of probability and severity, independence of losses, bounded maximum loss, economic feasibility, and absence of moral hazard. | Precondition | Where agents fail today, per the sources | What a behaviour policy with monitoring contributes | |---|---|---| | **Assessability** | The market body says the error rate in each context is unknown and there is a lack of data; the actuarial view is that historical data is scarce | The authorised action set plus the prohibitions is the input space the reinsurer requires and the capabilities the underwriter scopes, and it turns what the agent may do into a countable exposure base | | **Fortuity** | A June 2026 paper argues that architectural risks are conditional on configuration rather than purely random, so they are a risk selection matter before they are a priced peril | Out of scope actions become identifiable events rather than diffuse behaviour, and the document makes the line between as designed and malfunction explicit, which is the exact line the market cannot currently draw | | **Bounded loss** | Autonomous action with no ceiling | Prohibitions on irreversible actions and per action value ceilings cap severity per event, which is what the demonstration's per action ceiling already is | | **Moral hazard** | The actuarial view is that insurers face difficulty verifying risk controls; the reinsurer says due diligence requires cooperation and transparency | Monitoring telemetry against the written prohibitions supplies the audit trail, the tool traces and the scope creep detection the brokers and the standard name, and answers the coverholder's objection to certification at a single point | | **Independence** | Every market body flags foundation model concentration as defeating the law of large numbers | **Nothing.** A behaviour policy does not make two customers' agents fail independently when they share a model. This is the precondition the product cannot touch | **Four of five, then, and the honest statement is that the fifth is the one that decides whether the top of the ladder ever exists at scale.** That is an argument for the memo's own long term framing: the behaviour policy makes an individual agent assessable and its losses bounded, and the systemic question is somebody else's. ## The Standards Mapping, In Its Honest Form **The memo's most commercially interesting sentence:** > What do you need to put in place to comply with standards? If you put a proxy in place, if you put this product in place, then you are in compliance, with an agent that behaves like this. **Two constraints stand between that sentence and a product, and both are already ruled.** **The licence constraint.** The international management standards prohibit adaptation, translation and commercial exploitation, and now prohibit language model use of their content. **A mapping derived from their text cannot be shipped.** The European regulation is expressly reusable for commercial purposes including adaptation, its graph exists at over fifteen hundred nodes with amendments applied, and the conformance vault already resolves sixty two of its crosswalks to that regulation. **And the standards graph the memo would otherwise build already exists under another name and belongs to somebody else**, per the 10 September brief on joining rather than building. **The verdict constraint.** Nothing in this estate claims to be a compliance assessment, and the ruling is that presenting it as one would be dishonest. **So the output cannot say then you are in compliance.** **The honest form is better than the sentence it replaces, because it is checkable:** > This provision requires X. The agent's current grant does not bound X. A control of type Y, enforced at layer Z, would bound X. **That is a business case with no verdict in it.** It names the provision, the gap and the remedy, and every clause of it can be checked by the buyer against the provision, the grant and the control. **It is also the exact output of the enforcement attribute specified in the second brief of today**: a prohibition enforced only at the prompt layer is a gap, and the control that would move it to the gateway layer is the remedy. The standards mapping and the enforcement mapping are the same computation read from two ends. ## The Label, The Patient, The Prescription **Added after the project lead's comments of 11 September. It is the ladder's own description, in a structure everybody already understands, and it says where the score lives.** A label describes the substance and never says this is safe for you. A patient record supplies the context. A prescribing decision combines the two, and a named professional signs it and carries the responsibility. | Part | In this estate | Property | |---|---|---| | **The label** | The ABP | Describes capability, context free, **no score** | | **The patient record** | The twin, hooked to the customer's real environment | Supplies the assets, the tools, the data, what is connected | | **The prescription** | The risk score and the acceptance, on the risk product | Combines the two, dated, **signed by a named professional** | **Three things follow.** **The score lives on the third row and nowhere else.** The ABP is consequence agnostic: the same document is dangerous in one deployment and harmless in another, so a score on it is wrong in one of the two rooms. The risk product knows the assets, so it can score. **That is not a product preference, it is where the information is.** **The prescriber cannot be the seller.** The standing rule is that the people who sell do not sign. So whoever sells the label and the record cannot sign the prescription. **The project lead's sequencing, first product then uplift with more senior professionals, is that rule made commercial.** **The underwriter is a second prescriber.** An underwriter combines a description with its own consequence model and prices the result. **A consequence agnostic ABP is the one shape an insurer can use without arguing with it**, which is the whole of the earlier section on what underwriters ask for, seen from the other side. **And the business case has no verdict in it.** A gap with a control is not a gap. A gap without one is the case for buying something. On the barrier glyphs that is mechanical: **move this capability from a rule somebody wrote down to a boundary enforced above it that it cannot reach, and here is the control that does it.** Provision, gap, control, layer. The number that moves is unbounded excess, and it is the only number on the label a buyer can change. **One dependency the sequencing rests on.** The twin's running state is an open question in this brief. The label and the record are the first product only if the record can be hooked. Otherwise the label is the first product and the record is the second. ## The Ladder, With The Word At The Top Named Once | Rung | What it is | State | |---|---|---| | **0** | The behaviour policy: grant, mandate, delta, prohibitions with their enforcement layer | **Sellable next week** as tiers one and three | | **1** | The twin: the interface where the business touches the agent, receiving the signed mandate | Published on the twins site as architecture; built state unverified | | **2** | Reality mapped: which tools exist, which controls are in place, which prohibitions are enforced where | Tier four | | **3** | Risks connected: the risk acceptance workflow with accepted until dates on every unenforced prohibition | The risks site and the acceptance workflow exist | | **4** | Standards mapped, in the honest form | Framed here; the crosswalks exist for one instrument | | **5** | **Insurance**, meaning somebody else's instrument that covers the mandate and excludes the delta | Three underwriters exist; none publishes wording; the estate's demonstration simulates it with fabricated numbers and says so | **The word appears in that table because this document carries no price and describes other companies' products.** The ladder ruling of 3 September puts it at rung three and forbids calling rungs zero to two by it. **The behaviour policy is rung zero, and no page selling it may use the word.** **One correction to the memo's framing of the top rung.** The memo says the risk product is about selling insurance policies. **The estate does not sell them and should not, because effecting or carrying out a contract of insurance as principal is a regulated activity and the perimeter analysis of 10 September applies.** What the estate sells is the artefact an underwriter needs, and the monitoring that keeps it true. **The underwriter sells the policy. That is a better business, and it is the one the demonstration already describes.** ## What This Does Not Try To Be - **Legal advice.** The three shapes are drawn from the statute and its explanatory notes. Which shape any real instrument takes is for the underwriter's lawyers. - **A claim that any insurer requires the behaviour policy as a condition of cover.** None publishes wording. The claim is that it is on the intake form of one, in the blog of another and in the paper of a third. - **A standards mapping.** The form of the output is specified. No mapping is built, and the licence constraint decides which instrument it could be built against. - **A product on any rung above zero.** Rungs one to four are the estate's existing work placed in order. Rung five is somebody else's. - **A page.** The word at the top of the ladder appears here and may not appear on any page carrying a price. ## Honest Tensions | Tension | Note | |---|---| | The prohibitions as the exclusions | It makes the ladder forced and it means the behaviour policy is, from the first day, a document about what will not be covered | | Three underwriters exist | The memo's premise that nobody is there yet is slightly wrong, and slightly wrong in a way that helps | | The risk defining term shape | It is the strongest position and it gives the insured no causation defence, which a buyer will notice | | Independence | The product repairs four preconditions and the fifth is the one that decides scale | | The honest standards output | It is checkable and it is a worse sentence to say at a table than then you are in compliance | | Not selling the policy | It keeps the estate outside the perimeter and it hands the largest revenue line on the ladder to somebody else | ## Open Questions 1. **Has anybody asked an underwriter?** The three who write agent cover are named. None has been contacted, and the whole ladder rests on what they would accept. 2. **Is the twin built or described?** The twins site publishes the execution broker. Its running state was not checked. 3. **Which instrument is the standards mapping built against first?** The licence constraint says the European regulation. The buyer will ask for the management standard, which cannot be used. 4. **What is the accepted until date on a prohibition enforced only at the prompt layer?** The risk acceptance workflow needs one, and the honest answer may be that it should not be accepted at all. 5. **Does the demonstration's per action ceiling map onto the bounded loss precondition directly?** It looks like it does, and nobody has said so on the page. 6. **Who owns the systemic question?** Independence cannot be repaired per customer, and the market bodies all name it. It is not this product's problem, and somebody should say whose it is. 7. **Can the conformance vault's exclusion object be the schedule an underwriter reads?** It has the right fields and the right disclaimer. Whether its format is one any underwriter would accept is unknown. ## Relationship To Previous Briefs **From the licence to operate demonstration**, it takes the definition that makes the whole argument, and it finds that the demonstration already reads as a risk defining term. **From the conformance vault**, it takes the exclusion object with expiring attestations, which is the schedule with a clock. **From the first brief of today**, it takes the four objects and the insurer's scoping requirements, and it places the behaviour policy at rung zero. **From the second brief of today**, it takes the enforcement attribute and finds that the standards mapping is the same computation read from the other end. **From the ladder ruling of 3 September and the perimeter analysis of 10 September**, it takes the rule about the word and the rule about not selling the instrument. **From the standards brief of 10 September**, it takes the licence matrix and the finding that the standards graph already exists elsewhere. **From the risks site**, it takes the rule that a risk cannot be denied but only accepted for a stated period, and applies it to every prohibition that is not enforced. **From the teaching brief of 10 September**, it takes the sub delegation argument, which is the case of an action inside the grant and outside every mandate the buyer was ever given. ## Key Claims | # | Claim | |---|---| | 1 | The estate's own demonstration defines the mandate as the only thing the policy insures and the delta as what no policy covers | | 2 | So the behaviour policy's prohibitions are the exclusion schedule, and the ladder is forced rather than chosen | | 3 | The behaviour policy is the underwriting artefact, and the apparatus above it cannot become ready without it | | 4 | Three underwriters write agent action cover by name as of this week, one tied to a published standard with terms set by audit results | | 5 | The ABP is the label, the twin is the patient record and the risk score is the prescription, so the score lives on the risk product and the prescriber cannot be the seller | | 6 | A behaviour policy is the document that says whether the action was permitted, so it is the classification the market lacks | | 7 | Every published underwriting requirement found describes the behaviour policy: scoping, what is permitted to do, where it can act without approval, declared permitted functions | | 8 | The statute gives the written undertaking three shapes, and the demonstration already reads as a risk defining term, which gives the insured no causation defence | | 9 | The strongest design is mandate as risk definition plus controls as warranties whose breach suspends cover under section 10 | | 10 | Agents fail assessability, fortuity and independence today, and the behaviour policy repairs the first two and cannot touch the third | | 11 | The standards mapping cannot use the management standards and cannot say in compliance, so its output is provision, gap and control at a layer | | 12 | The estate does not sell the instrument at the top of the ladder, because that is a regulated activity, and it sells the artefact the underwriter needs | ## Sources All read 11 September 2026. **Inside the estate.** The licence to operate demonstration at https://sgit.ai/demos/vaults/licence-to-operate/index.html. The conformance vault at https://sgit.ai/demos/vaults/aiuc-1-conformance/index.html. The twins site at https://twins.sgit.ai/llms.txt. The risks site thesis from the network index at https://sgit.ai/network/index.html. The 10 September briefs on the policy document, the standards graph, the perimeter, and the ladder ruling of 3 September. **Who underwrites agents.** The standard tied underwriter's launch at https://www.reinsurancene.ws/artificial-intelligence-underwriting-company-launches-with-15m-seed-round/, 23 July 2025, its first agent policy at https://www.prnewswire.com/news-releases/elevenlabs-secures-first-of-its-kind-ai-agent-insurance-302684587.html, 11 February 2026, and the reported limit at https://www.fastcompany.com/91550776/rajiv-dattani-is-bringing-insurance-to-the-ai-agent-boom, 18 June 2026. The coverholder's affirmative cover at https://www.prnewswire.com/news-releases/armilla-launches-affirmative-ai-liability-insurance-with-lloyds-underwriter-chaucer-302442586.html, 30 April 2025, and the coordinated structure at https://www.chaucergroup.com/news/press-release-chaucer-and-armilla-ai-launch-vanguard-ai-coordinated-insurance-structure, 10 February 2026. The guarantee backed startup at https://www.klaimee.ai/ and https://fintech.global/2026/07/22/klaimee-lands-5-5m-to-insure-autonomous-ai-agents/, 22 July 2026. The reinsurer's product at https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html and its paper at https://www.munichre.com/content/dam/munichre/contentlounge/website-pieces/documents/MR_AI-Whitepaper-Insuring-Generative-AI.pdf. The syndicate product at https://www.reinsurancene.ws/mosaic-and-munich-re-introduce-ai-specific-insurance-for-developers/, 27 February 2026. The output liability coverholder at https://www.testudo.co/insights/testudo-launches-new-insurance-coverage-for-liability-risks-created-by-generative-ai-systems, 21 January 2026. The cyber carrier at https://www.coalitioninc.com/ai-coverage. The market summary at https://www.insurancejournal.com/news/national/2026/08/27/883064.htm, 27 August 2026. The exclusion forms at https://www.independentagent.com/vu_resource/verisk-to-roll-out-new-general-liability-exclusions-for-generative-ai-exposures/ and the absolute exclusion at https://www.hunton.com/hunton-insurance-recovery-blog/the-continued-proliferation-of-ai-exclusions, 28 May 2025. **What underwriters require.** The scoping page at https://www.aiuc-1.com/scoping and the update at https://www.aiuc-1.com/research/2026-q2-standard-update, 15 April 2026. The coverholder's position at https://www.armilla.ai/resources/from-paper-policies-to-real-oversight-how-ai-governance-is-becoming-insurable, 14 January 2026. The broker's agenda at https://www.aon.com/en/insights/articles/ai-risk-2026-practical-agenda, 7 May 2026. The market body's survey at https://lmalloyds.com/campaigns/understanding-ai-exposures-ai-loss-scenarios-survey-results/. The June 2026 paper at https://arxiv.org/html/2606.05449v1. **The statute.** Sections 3 to 11 and 16 to 17 of the Insurance Act 2015 at https://www.legislation.gov.uk/ukpga/2015/4, with the explanatory notes to sections 9, 10 and 11. Section 33 of the Marine Insurance Act 1906 at https://www.legislation.gov.uk/ukpga/Edw7/6/41/section/33. The suspensive warranty decision summarised at https://insure.cooley.com/2018/01/10/high-court-rules-on-the-application-of-suspensive-warranty-provisions-in-insurance-contracts/. **Insurability.** The actuarial application at https://www.theactuarymagazine.org/insights-ai-insurability/, October 2025. The frontier paper at https://arxiv.org/pdf/2605.18784, 12 June 2026. The market body on unknown error rates at https://lmalloyds.com/understanding-artificial-intelligence-risk-in-insurance-products-the-challenges/, 13 April 2025. The market's written evidence at https://committees.parliament.uk/writtenevidence/140107/pdf/, April 2025. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/briefs/v0.33.70__strategy-brief__the-prohibitions-are-the-exclusions-your-own-demo-says-no-policy-covers-the-delta-and-the-insurance-act-says-how/index.html)* ------------------------------------------------------------------------ # Start Here > You are building abp.sgit.ai, the site for the Agent Behaviour Policy. This pack is what has been decided, what already exists, and what you must not invent. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / Start Here # Start Here > **The source bytes.** This page is generated from [`docs/pack/00__START-HERE.md`](../../../docs/pack/00__START-HERE.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **You are building abp.sgit.ai, the site for the Agent Behaviour Policy. This pack is what has been decided, what already exists, and what you must not invent.** Repository: `SGit-AI__Website__ABP`. Default branch `dev`. Pages enabled. Subdomain already configured. ## The one naming ruling, made before you start **It is Agent Behaviour Policy. Not Agentic.** The acronym is ABP either way, so nothing is lost, and three things are gained. **Agentic was ruled out of customer facing copy on 10 September, on evidence.** The analyst forecast since June 2025 is that over forty per cent of such projects will be cancelled by the end of 2027; agent washing reached a corporate governance forum as a **disclosure risk** in April 2026; and the closest competitor in the adjacent category deliberately avoids the word. It reads as a discount, not a premium, to the exact buyer this site is for. **The grammar is wrong.** An *Agentic* Behaviour Policy would be a policy about a style of behaviour, which is a category. An *Agent* Behaviour Policy is the behaviour policy for **this agent, in this environment**, which is an instance. The estate's ruling of 26 August puts the library on the free side and the instance on the paid side, and the whole product is that the document is derived from one buyer's own deployment. Agentic generalises precisely the thing that must not be generalised. **The parallel construction works.** An acceptable use policy governs a user. An Agent Behaviour Policy governs an agent. Both name their subject. Agentic names a mood. **Three further naming rules, in force:** 1. **Never shorten it to the policy.** In this estate the word policy already denotes the insurance instrument, with its bands, ceilings, pool and premium, on the published licence to operate demonstration. Write ABP or behaviour policy, always. 2. **Never print the string A D P.** It is one of the world's largest payroll processors and a registered mark. It appeared as a slip in a memo. It must not appear in this repository. 3. **Pick one spelling of behaviour and keep it.** The acronym does not care. A wordmark does. ## The finding that should change your plan **The ABP's ontology already exists, published, at `what-can-it-do.games.sgit.ai/map/`.** Do not invent it. Read it first. It already has: twenty three capability primitives in a `verb.object.reach` grammar; nine named product profiles; a control barrier glyph on every cell; an undo classification; and an honest measurement note saying that of ninety nine tool capability rows, **twenty one were measured and the rest are derived**. **The glyph system is the most important thing in this pack**, because it is the enforcement model the ABP needs, already built: | Glyph | Published meaning | What it is in ABP terms | |---|---|---| | **filled circle** | nothing stands between it and the capability | Unbounded | | **half filled** | a rule somebody wrote down | **A prompt or a prose rule. Not a control** | | **partial fill** | a setting the agent's own account could change | **Not a control**, because the grant includes the ability to change it | | **empty circle** | a boundary enforced above it that it cannot reach | **A control** | | **dot** | not in this grant | Absent | **Read the third and fourth rows together.** A setting the agent's own account could change versus a boundary enforced above it that it cannot reach **is the enforcer test of 20 August, already expressed as data**: a control bounds a grant only if it is enforced by something the grant does not include. The estate built it into a game's mapping page before it named it. **So the first job of this site is not to author an ontology. It is to promote one from a game's data pack into a published schema with a stable address.** ## What you must not invent - **The capability grammar.** It is `verb.object.reach`, twenty three primitives, published. - **The product profiles.** Nine of them, named, published. - **The enforcement model.** The glyphs above. - **The graph rules.** Five of them, published at `graphs.sgit.ai`, and they govern the model. See [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md). - **The site conventions.** They are at `sgit.ai/docs/guidance/`, `sgit.ai/llms.txt` and `coding.sgit.ai`. See [`02__THE-CONVENTIONS.md`](../../../docs/pack/02__THE-CONVENTIONS/index.md). - **The markdown renderer.** The platform has one and the guidance forbids rebuilding it. - **A verdict or a score, on anybody's policy including the customer's own.** The ABP describes and does not judge. A policy cannot be dangerous; a deployment can. The score lives on the risk product. See the opening of [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md) and rule 0 in [`05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES/index.md). - **Any capability claim about a named third party product** without a source, a timestamp and a hash. This is the site's largest exposure and [`05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES/index.md) covers it. ## The foundation document **Read `briefs/v0.33.70__foundation__agent-behaviour-policy-...md` before anything else in this pack.** It is the definition and introduction of the ABP, written for publication. **The home page is derived from it, the what is an ABP page is it, and the docs section carries it first.** It is also the document the project lead is putting in front of the community for feedback, so its wording is the wording, and where this pack and it disagree, it wins. ## Reading order | # | File | What it settles | |---|---|---| | 0 | [`00__START-HERE.md`](../../../docs/pack/00__START-HERE/index.md) | This file. The name, the existing ontology, the boundaries | | 1 | [`01__WHAT-TO-BUILD.md`](../../../docs/pack/01__WHAT-TO-BUILD/index.md) | The site map, the docs section, the examples, the build order | | 2 | [`02__THE-CONVENTIONS.md`](../../../docs/pack/02__THE-CONVENTIONS/index.md) | What to inherit from the guidance, and how to verify rather than assume | | 3 | [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md) | The four objects, the graph rules, the five layers, the fact diff | | 4 | [`04__THE-FIRST-EXAMPLES.md`](../../../docs/pack/04__THE-FIRST-EXAMPLES/index.md) | The seed data and the first five ABPs, derived rather than authored | | 5 | [`05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES/index.md) | Words, claims, licence and the third party naming problem | | 6 | [`06__THE-PROMPT.md`](../../../docs/pack/06__THE-PROMPT/index.md) | The prompt to start from | Then `briefs/`, which is the argument behind all of it. ## What this site is for It is the home for the argument, the model, the examples and the data. **Buying an ABP happens on the store, not here.** This site publishes the free public library. The store sells the instance. That boundary is the 26 August ruling and it is the reason this site has no checkout. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/00__START-HERE/index.html)* ------------------------------------------------------------------------ # What To Build > Every site in the network is named for an argument rather than for a function, and there are twenty seven of them. The argument here is not a product name. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / What To Build # What To Build > **The source bytes.** This page is generated from [`docs/pack/01__WHAT-TO-BUILD.md`](../../../docs/pack/01__WHAT-TO-BUILD.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. ## The argument this site owns Every site in the network is named for an argument rather than for a function, and there are twenty seven of them. **The argument here is not a product name.** > **You know what you asked for. You do not know what it can do.** That is the thesis line for the home page. It is the corrected version of the memo of 11 September: the mandate is already understood, implicitly or explicitly, and the grant is not. **The site exists to close that gap in public, for free, and the store sells the instance of it.** ## Build order The standard prompt asks for the pipeline first, and that is right. **Nothing below matters if the site does not publish.** | # | Step | Done when | |---|---|---| | 1 | **CI pipeline and auto tagging**, copied from a sibling site's repository | A push to `dev` builds, tags and publishes | | 2 | **Version surface**: `versions/index.json`, a per version file, and the version visible in the chrome as a link | The chrome shows the current version and it links to that version's own details | | 3 | **`llms.txt` and `llms-full.txt`**, generated from the site rather than written | Every page appears in `llms.txt` | | 4 | **The docs section**, using the platform's markdown rendering | Every document in this pack is readable on the site | | 5 | **The data**, promoted from the game's pack into a published schema | `data/` serves the capabilities, profiles, barriers and undo classes at a stable address with cross origin access | | 6 | **The model pages**: what an ABP is, the four objects, the graph | A reader can follow one capability from a product profile to a mandate to a delta to a prohibition | | 7 | **The examples**: five ABPs, derived from the data | Each example states which of its rows were measured and which were derived | | 8 | **The visualisations** | One grant against mandate view that is not a table | ## The site map ``` / the argument, in one screen, derived from the foundation document /what-is-an-abp/ the foundation document, rendered, with each term linked to its node /model/ the graph: capabilities, barriers, undo, the schema /examples/ five ABPs, one per deployment shape /docs/ every reference and guidance document, rendered /data/ the JSON, at stable addresses, CORS enabled /versions/ the version history /llms.txt generated /llms-full.txt generated ``` **Scope by domain and link across.** This site says one thing properly. Where an argument belongs to a sister site, link to it rather than restating it: the graph rules to `graphs.sgit.ai`, the capability map to `what-can-it-do.games.sgit.ai`, the twin to `twins.sgit.ai`, the acceptance workflow to `risks.sgit.ai`, the style rules to `coding.sgit.ai`. ## The docs section, which was asked for specifically **Every reference and guidance document in this pack goes into `/docs/`, rendered with the markdown rendering already used across the network.** Do not write a renderer. The guidance is explicit that markdown viewing, file trees and page layouts are platform provided and must not be rebuilt. **What goes in it:** | Section | Contents | |---|---| | `/docs/briefs/` | The foundation document first, then the three briefs, all unchanged with their own licence footers intact | | `/docs/pack/` | The six numbered documents of this pack | | `/docs/model/` | The schema and ontology documents you write, as markdown with their JSON twins | | `/docs/inherited/` | Pointers to the guidance you inherited, with the date read. **Link, do not copy**, except where a rule is quoted | **Two conventions from the guidance apply to every page in it.** Every page is reachable and machine readable, with a markdown twin and an entry in `llms.txt`. And anything rendered stays one click from its source bytes, so every rendered document shows a link to the file it came from. **Indexes are generated from the data they index**, so `/docs/index` is built from the files present rather than maintained by hand. The guidance says an index that can disagree with its source is a defect. ## The examples, which are the point The memo asks for the examples first and it is right, but they should be **derived rather than authored**. [`04__THE-FIRST-EXAMPLES.md`](../../../docs/pack/04__THE-FIRST-EXAMPLES/index.md) gives the five and where each one's rows come from. **Each example page shows:** 1. **The label**: the one line on the outside, per [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md), with excess and unbounded excess as the two headline numbers, and no score. 2. The named deployment shape, in the product profile's published words. 3. **The grant**, as capability primitives, each with its barrier glyph and its undo class, ordered irreversible first and saying that reversibility is a property of the action rather than a severity. 4. **The mandate**, as the small set the deployer authorised. 5. **The delta**, computed, never stored, shown as excess in one colour and shortfall in the other. 6. **The prohibitions**, each carrying the layer it would be enforced at, and each marked as enforced or not enforced today. 7. **The provenance line**: how many rows were measured, how many derived, and when. 8. **The validity statement**: this describes the deployment shape as at this date; if the risk changed, the deployment changed, not this document. **That sixth row is not optional.** The published map already does it, stating that twenty one of ninety nine rows were measured and the rest derived. **An example that hides that is worse than one that has few measured rows.** ## The community editable layer **The data files are the shared facts and they live in this repository so that people can propose changes.** That is the four layer architecture: the site and its data are the library, and a cloned vault is the instance. Two rules come with it, from 10 September: **A proposal to a data file carries evidence.** Every node taken from a third party site carries a source URL, a retrieval timestamp and a content hash. A proposal that changes a capability row without one is an assertion. **A consumer pins a version.** Anything that computes from these files states which version it computed against. A clone that floats against the latest has no reproducible output. ## What not to build - **A markdown viewer, a file browser or a page layout engine.** Platform provided. - **A checkout, a price or a payment link.** That is the store. - **A new capability ontology.** It exists. - **A general graph renderer.** The graph rules say never render the whole graph, render the result of a query. - **An assessment of any named product.** See the hard rules. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/01__WHAT-TO-BUILD/index.html)* ------------------------------------------------------------------------ # The Conventions > Three sources govern how this site is built. Read all three before writing code. Where this pack and a source disagree, the source wins and you should say so. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / The Conventions # The Conventions > **The source bytes.** This page is generated from [`docs/pack/02__THE-CONVENTIONS.md`](../../../docs/pack/02__THE-CONVENTIONS.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **Three sources govern how this site is built. Read all three before writing code. Where this pack and a source disagree, the source wins and you should say so.** | Source | What it governs | Read | |---|---|---| | `sgit.ai/docs/guidance/index.html` | Vault and site building practice | 11 September 2026 | | `sgit.ai/llms.txt` | What the platform site is and how it is organised | 11 September 2026 | | `coding.sgit.ai` | The style guide, with measured compliance | 11 September 2026 | ## What the guidance requires, quoted **The one minute version, verbatim:** > Pick your surface first, it changes every other answer. > Do not build what the platform already has: markdown, file trees, page layouts. > Publish a read key, never a vault key. > Version everything and show the version. > Anything rendered must stay one click from the source bytes. **On versioning, specifically.** Show the version in the app's chrome, small, in the top bar, always visible, **not** in a footer or an about box. Make it a link to that version's own details rather than a generic changelog. Give versions a home: ``` versions/index.json { "current": "v0.1.0", "versions": [ newest first ] } versions/v0.1.0.json { version, date, commit, vault, reconstructed, title, summary, changes[], basis[] } ``` **Record the commit**, because a version without it cannot be verified later. **Say when reconstructed**, because history assembled after the fact must be labelled. And the title is a sentence, not a label: *settings move into the right hand column*, never *UI improvements*. **On architecture, the three properties this site must have:** > Every page is reachable and machine-readable, each has a `.md` twin and appears in `llms.txt`. > Indexes are generated from the data they index, so they cannot disagree with the source. > Scope by domain and link across: one site says one thing properly and points elsewhere. **On honesty**, which this site will lean on constantly: state the gap rather than papering over it, measured rather than guessed. **On permissions**, if any part of this becomes a vault app: deny by default, declare the narrowest permission, and explain each grant. **That rule is the ABP's own argument applied to the site that describes it**, and it is worth saying so on the page. ## What the style guide requires The style guide documents thirty one rules with measured compliance, and it is honest about its own enforcement: **zero linters, formatters or type checkers enforce them, and four structural guards in the pipeline are the only automated enforcement, one of which does not work.** **Read it and follow it. Then note the two figures that bear directly on this repository.** **File banners are at one hundred per cent compliance.** Every file gets one. Match the format used in the sibling repository you copy the pipeline from. **Documents free of em dashes are at zero per cent compliance**, with the stated rule violated two hundred and forty eight times across eleven documents. **This repository should be the one that does not.** Every document in this pack is already free of them. Keep it that way, and consider adding it as a fifth structural guard, since it is the cheapest possible check and the estate has a measured record of failing it. **Other conventions to carry:** one idea per file; one class per file, at ninety per cent compliance; empty package initialisers; no underscore prefixed private names; and the constrained primitive patterns where the code is Python. ## What to copy rather than invent **You have access to the sibling repositories. Use them.** The pipeline, the tagging, the page build and the markdown rendering all exist and are working on live sites. **Copy from one named sibling and say which one in the first commit message.** Then verify five things rather than assuming them: 1. **The tag is derived from the version file**, not typed by hand. 2. **The build fails when `llms.txt` does not list every page.** If the sibling does not check this, add it. 3. **The custom domain survives a rebuild**, meaning the `CNAME` or its equivalent is written by the build rather than committed once and forgotten. 4. **The markdown twin of every page is produced by the build**, not maintained alongside it. 5. **The version in the chrome comes from `versions/index.json`**, so it cannot drift from the tag. **If any of those five is absent from the sibling, that is a finding and belongs in the first version's notes.** The estate's method is to record the gap rather than quietly fix it and move on. ## Publishing Classify the credential before anything becomes public. **A read key may be published. A vault key may never be.** If any part of this site embeds a vault, escrow the write key before publishing and publish only the read key. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/02__THE-CONVENTIONS/index.html)* ------------------------------------------------------------------------ # The ABP Model > The ABP describes. It does not judge. It states what the agent can do, what it was authorised to do, the gap between them, and what stands in the way. It says nothing about whether any of that is acceptable, because acceptability is not in... *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / The ABP Model # The ABP Model > **The source bytes.** This page is generated from [`docs/pack/03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. ## The ABP is consequence agnostic, and that is the rule above every other rule **The ABP describes. It does not judge.** It states what the agent can do, what it was authorised to do, the gap between them, and what stands in the way. It says nothing about whether any of that is acceptable, because acceptability is not in the document. **The same ABP is dangerous in one room and harmless in the next, and nothing about the document changed.** The most permissive grant imaginable, running where there are no assets and nothing reachable, is a low risk. The same grant dropped into a production estate is an extreme one. The same grant tomorrow, after somebody connects a database, is a different risk again. **Risk is a function of the policy, the assets, the consequences and the date, and the ABP is the one input that does not move.** **A policy cannot be dangerous. A deployment can.** **Four consequences, and every one is a build decision.** **The ABP carries no score.** No rating, no traffic light, no risk level, no severity, nowhere on this site. Every buyer will ask for one in the first meeting. **The score has a home and it is the risk product**, where the assets are known, the risk acceptance workflow exists, and a named professional signs. Putting a score on the ABP is the fastest way to make the document wrong in one of the two rooms. **The record is what is sold, and the verdict is a service.** A description of the grant rots on a known clock: the product releases, the deployment changes. A verdict rots on an unknown one: anything in the environment moves. **The record is re-sellable because its clock is visible. The verdict is not, because its clock is not.** **A long list is an inventory, not an admission.** The ABP asserts that a capability exists, never that a risk is unacceptable. That is materially different from a findings register, and it is worth drafting toward, with the honest caveat that it moves an exposure rather than removing it. **The correction in the draft and correction sale is factual, not evaluative.** Nobody is asked to agree that something is dangerous. They are asked whether their agent can do a thing. That is a conversation you can have with somebody who knows their business better than you do. **The three part structure this gives the ladder, which the project lead has adopted:** | Part | What it is | Who owns it | Sold as | |---|---|---|---| | **The label** | The ABP. Describes the capability, context free | Us | The first product | | **The patient record** | The twin. The interface to the real environment: assets, tools, data, what is connected | Us, hooked to the customer's reality | The first product, with the ABP | | **The prescription** | The risk score and the acceptance. Combines the two and is signed | **A named professional who did not sell the first two** | The uplift | **The third row is a constraint, not a preference.** The standing rule is that the people who sell do not sign. So the party that sells the label and the record cannot be the party that prescribes. **That is why the sequence separates cleanly.** **Every ABP carries a validity statement.** Not an expiry meaning stale, but: *this describes the deployment shape as at this date; if the risk changed, the deployment changed, not this document.* The conformance vault already does this with attestations carrying a tier and an expiry. **Two places where the principle, taken seriously, corrects our own data.** **The undo class is the one column that is not fully context free.** Whether deleting a file is reversible depends on backups, snapshots and retention. So `undo: no` is a claim about the product's published behaviour, and the page says so, and says that the deployment can change it. Otherwise one contextual judgement has been smuggled into a document that claims to hold none. **No assets does not mean no consequence.** It means no consequence to you. An agent with `send.endpoint.world` and `execute.process.host` in an empty environment can still reach third parties. That is the sub delegation argument in another form, and it is a reason the consequence model is genuinely hard and genuinely not ours to guess. **Two known gaps in the model, stated plainly and not decorated.** **Quantity is not modelled.** The twenty three primitives carry reach, being project, host, tenant, world and self, and they do not carry rate or volume. `send.endpoint.world` is the same primitive for one request and a million. The temporal operators in the policy language named in the second brief, count within and sum within, are the shape of the fix. **Interaction between agents is not modelled.** Two agents each within mandate can compose into something neither was authorised to do. There is no primitive for it and no page for it. ## The label: what goes on the outside **The project lead asked for a couple of metrics and a couple of abstraction layers.** Two layers, and the graph they are computed from. **The label** is one line, on the outside, for anybody: | Field | Meaning | |---|---| | **Shape** | The named deployment, in the product's published words | | **Grant** | N of 23 primitives | | **Mandate** | M primitives | | **Excess** | Capabilities in the grant and not in the mandate. **The finding** | | **Unbounded excess** | Excess capabilities whose barrier is one of the first three rows. **The business case** | | **Irreversible** | Granted capabilities with `undo: no`, as published | | **Widest reach** | The furthest reach class in the grant | | **Measured** | Rows measured against rows derived | | **As at** | The date and the source version | **The two headline numbers are excess and unbounded excess.** The first answers the buyer's question, what can it do that I did not ask for. The second is the purchase: every control bought moves a capability from the first three barrier rows to the fourth, and the number goes down. **The ratio between them is what a control purchase changes, and it is the only number on the label that a buyer can move.** **The leaflet** is the full table underneath: every primitive with its barrier, its undo class, its provenance, and the mandate beside it. For the engineer, the auditor and the underwriter. **Neither carries a score. Both carry the validity line.** **Ordering.** The default order on every rendering is irreversible first, because reversibility is a property of the action rather than of the context, and stating it as the reason keeps the ordering descriptive. The risk product reorders by consequence, because it knows the consequence. ## The four objects An ABP is not a document. It is four objects, of which the document is a rendering. | Object | How it is obtained | What it is | |---|---|---| | **The mandate** | **Elicited**, in minutes, because the deployer already knows it | What the agent is authorised and expected to do | | **The grant** | **Measured**, from the deployment shape and the credentials | Everything the agent can do | | **The delta** | **Computed, never stored** | The excess authority, and the shortfall | | **The prohibitions** | The enforceable projection of the delta | The subset a control can bound, each carrying the layer it is enforced at | **The order matters and the site should teach it in this order.** A grant alone is an inventory and a buyer shrugs at an inventory. A grant with a mandate beside it is a finding. **Three hundred and forty things is a shrug. Three hundred and forty things and you authorised twelve is a sale.** ## The capability grammar, which exists `verb.object.reach`. Twenty three primitives, published on the map page. Examples in their published wording: | Primitive | Published gloss | |---|---| | `read.file.project` | Read the project it is working on | | `write.file.host` | Change any file the account can reach | | `execute.process.host` | Run programs as the account | | `send.endpoint.world` | Reach any host on the internet | | `read.credential.host` | Read credentials stored where it runs | | `write.repository.tenant` | Push to a code host | | `create.schedule.host` | Create something that outlives the turn | | `read.record.browsing` | Read every page you visit | **Reach classes:** `project`, `host`, `tenant`, `world`, `self`. **This grammar is the action vocabulary for everything else on the site.** Do not add a primitive without adding it to the published set, and do not rename one. ## The barrier, which is the enforcement model and already exists Every capability in a profile carries a barrier glyph. The published wording for what it means: > what stands between it and the capability: nothing, a rule somebody wrote down, a setting the agent's own account could change, or a boundary enforced above it that it cannot reach **Those four are the enforcement layers, and the third and fourth are the whole argument.** | Barrier | Is it a control | Why | |---|---|---| | Nothing | **No** | Unbounded | | A rule somebody wrote down | **No** | A prompt or a prose rule. All four major model providers state in their own 2026 words that instructions at this layer can be bypassed | | A setting the agent's own account could change | **No** | **The grant includes the ability to remove the bound** | | A boundary enforced above it that it cannot reach | **Yes** | The only row that bounds anything | **The third row is the enforcer test of 20 August, published as a glyph before it was named as a rule:** a control bounds a grant only if it is enforced by something the grant does not include. **So every prohibition rendered anywhere on this site carries its barrier.** A prohibition displayed without one is a claim the site cannot support, and the assessment product exists to find the ones sitting at the second and third rows. ## The undo class, which is the severity model The map already carries it: `yes`, `with-effort`, `no`, with the published note that **a capability that cannot be undone is a different kind of thing from one that can**. **Use it as the ordering on every rendering.** An ABP that lists prohibitions alphabetically has buried the only ones that matter. Irreversible and unbounded is the first row of every document this site produces. ## The graph rules, which govern the model Five rules, published at `graphs.sgit.ai`, and they are not stylistic. 1. **Every edge is a verb with a distinct inverse.** The inverse is not the same edge walked backwards: `owned_by` and `owns` have different fan out. 2. **The generic association edge is banned.** It constrains nothing and costs fan out. 3. **Never render the whole graph.** Render the result of a query. 4. **Rich nodes are acceptable.** The blob is a rendering failure, not a modelling one. 5. **If a path does not read as a sentence in the reader's own language, the edges are wrong.** **Rule five is the acceptance test for this model, and it is cheap to apply.** The path should read: > agent `claude-code-cli-confirmations-disabled` **is-granted** capability `execute.process.host` **bounded-by** barrier `a-rule-somebody-wrote-down` **which-exceeds** mandate `ship-a-feature` **and-is** undo `no` If a path does not read like that, the edges are wrong and the model changes, not the renderer. **Rule three is the answer to the memo's wish that every word be hyperlinked.** Every word can be a node and no page renders the graph. Each page renders one query: this profile's grant, this mandate's delta, this capability across all profiles. ## The five layers, and the tension nobody has stated The memo says the book's five layers are what is happening here, and they are, with one complication that must be written down before the renderer is built. **The book is a five level compression hierarchy**, and it states that **a class name does not mean the same thing two levels up**, because ontologies and taxonomies differ structurally across altitudes. **The variant rule, in force since August, says every variant renders the same fact set and the diff must be empty.** **Those two are in tension and the resolution is precise: the facts are identical across renderings, the classes are not.** - **The fact set** is the leaf assertions: this profile has this capability, at this barrier, with this undo class; this mandate contains these capabilities; therefore this delta. **Identical in every rendering. The diff is over these.** - **The classes** are how those facts are grouped for a reader: an executive rendering may group by business consequence, an engineer's by reach and barrier. **Different at different altitudes, and that is correct rather than a defect.** **Write that down as the specification for the fact diff**, because the fact diff is the thing that has blocked a promise on each of the last four days, and this is the first statement precise enough to build it from. **The diff is over leaf assertions, not over structure.** **Keep altitude for stakeholder and depth for detail.** That ruling is from 20 August and the layers here are altitudes. ## The vocabulary for the interchange form The graph has a W3C vocabulary already, and the second brief in `briefs/` covers it with its limits. In short: a policy carries permissions, prohibitions and duties; constraints cover time, purpose, count and place; the conflict strategy says **prohibitions win**; and a policy inherits from a parent, which is how policy for an agent in an environment extends policy for an agent. **Use it as the interchange vocabulary through a profile that adds these capability primitives as actions. Do not claim it enforces anything, because it does not.** The compile target for enforcement is named in the brief. ## What the site must never compute **The delta is computed and never stored.** That is a standing ruling. A stored delta is a stale claim about somebody's environment, and the environment is the thing that changes. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/03__THE-ABP-MODEL/index.html)* ------------------------------------------------------------------------ # The First Examples > The memo asks for a few ABPs, from simple to complex, to find out what they look like in practice and how hard they are to make. The answer is that the first five can be derived rather than authored, because the data exists. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / The First Examples # The First Examples > **The source bytes.** This page is generated from [`docs/pack/04__THE-FIRST-EXAMPLES.md`](../../../docs/pack/04__THE-FIRST-EXAMPLES.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **The memo asks for a few ABPs, from simple to complex, to find out what they look like in practice and how hard they are to make. The answer is that the first five can be derived rather than authored, because the data exists.** ## The seed `what-can-it-do.games.sgit.ai/map/` publishes, as JSON at a stable address with cross origin access: - **Twenty three capability primitives**, in `verb.object.reach` form, each with a published gloss. - **Nine product profiles**, each with a grant expressed as primitives. - **A barrier glyph** on every profile and capability cell. - **An undo class** on every capability. - **Eight mandates**, one per surface, described as what a reasonable person wanted, per setup. - **Delta matrices**, excess in one colour and shortfall in the other. - **A provenance statement**: of ninety nine tool capability rows, **twenty one were measured and the rest are derived**. **Two pages carry the halves this site needs**: `/map/mandates/` and `/map/deltas/`. **So the first ABP is a rendering of data that already passes through a published pipeline.** The work is the rendering, the schema and the honesty line, not the research. ## The five, in order of difficulty | # | Deployment shape | Why it is this one | What is new in it | |---|---|---|---| | **1** | **ChatGPT web, no connectors** | The smallest grant in the set. A reader who does not believe agents can do much starts here and finds the delta is still not empty | Establishes the four objects with the fewest moving parts | | **2** | **Claude Code CLI, confirmations enabled** | The confirmation is a barrier, and a reader can see which row it sits on | **Introduces the barrier glyph as the argument.** A confirmation is the second or third row, not the fourth | | **3** | **Claude Code CLI, confirmations disabled** | The same agent, one setting different, and the delta changes | **The environment is the grant.** Two documents for one agent, differing in one line, is the clearest possible demonstration | | **4** | **Browser extension, broad host permissions** | `read.record.browsing`, and the mandate nobody wrote down | **Introduces other people's data**: the pages you visit were not all yours to hand over | | **5** | **GitHub Actions, hosted runner** | A service account, `write.repository.tenant`, `create.schedule.host` | **Introduces persistence and reach beyond the turn**, and the irreversible class | **Example three is the one to build first if only one gets built.** One setting, two documents, a visible difference in the delta. It makes the case that the ABP is about the deployment rather than the product in a way no paragraph can. ## What each example page contains 1. **The shape**, in the profile's published words. 2. **The grant**: primitives, each with barrier and undo, **ordered by irreversible and unbounded first**. 3. **The mandate**: the authorised set, in plain sentences. 4. **The delta**: excess and shortfall, computed on the page. 5. **The prohibitions**: the enforceable projection, each with the layer it would be enforced at and whether it is enforced today. 6. **The provenance**: measured against derived, with the date. 7. **The disclaimer**, which is not optional and is covered in [`05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES/index.md). ## The workflow question the memo actually asks > Let's see how hard it is to make one, how fast we can make them. **Instrument it.** Record, for each of the five: how long it took, how many rows were derived rather than measured, how many questions had to be asked of a human, and which step was slowest. **Publish that on the site as a table.** Two reasons. It is the estate's own honesty discipline, measured rather than guessed. And **it is the pricing input**: the store sells an ABP, and nobody knows yet what one costs to produce. ## Documents first, then vaults The memo proposes doing both, documents first. That is right and the pack agrees, for a reason worth stating: **a document forces the rendering question immediately**, and the rendering is where the five layers problem shows up. A vault can hold a graph nobody has successfully rendered for an executive. **So: five markdown documents with their JSON twins, in this repository, rendered through the docs section. Then the vault, which is the cloneable instance and belongs to the store's side of the boundary.** ## The educational claim, and how to keep it honest The memo expects the site to be educational because most people do not understand the grants. **The evidence supports that as a claim about a gap, and it does not support a claim that a document teaches.** From 10 September: games beat conventional instruction by about a third of a standard deviation, and by minus 0.12 when they replace training rather than supplement it. **The strongest defensible finding is that interactive beats static among the people who finish.** **So the site should link to the game rather than reproduce it**, and the examples should invite the reader to state a belief before showing them the answer. A page that says *before you scroll, write down how many of these twenty three this agent has* is doing the same work the game does, at the cost of one sentence. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/04__THE-FIRST-EXAMPLES/index.html)* ------------------------------------------------------------------------ # The Hard Rules > Thirteen rules that constrain this site. Each has a source and a reason. Rule 0 sits above the others and rules 1 and 13 are the two most likely to be broken. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / The Hard Rules # The Hard Rules > **The source bytes.** This page is generated from [`docs/pack/05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **Thirteen rules that constrain this site. Each has a source and a reason. Rule 0 sits above the others and rules 1 and 13 are the two most likely to be broken.** ## The rule above the rules | # | Rule | Why | |---|---|---| | **0** | **This site publishes the record and never the verdict, about anybody's policy, including the customer's own.** The ABP describes what an agent can do, what it was authorised to do and what stands in the way. It never says whether that is acceptable. | Acceptability is not in the document. The same ABP is dangerous in one deployment and harmless in another and nothing about it changed. **A policy cannot be dangerous. A deployment can.** The verdict belongs to the risk product, where the assets are known and a named professional signs. See the opening of [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md) | ## The third party problem, which is this site's real exposure | # | Rule | Why | |---|---|---| | **1** | **This site publishes capability claims about nine named commercial products. Every such claim carries a source URL, a retrieval timestamp and a content hash, and no adjective.** | The twin discipline requires the first three. The ruling of 20 August requires the fourth: **publish the record, never the verdict, with no adjective about a named third party.** A sentence saying a named product *can* read every page you visit, sourced and dated, is a record. The same sentence with *dangerously* or *unnecessarily* in it is a verdict about somebody else's product, published by a company selling an assessment of it | | **2** | **Nothing on this site is an assessment, an audit, a certification or a security review of any named product.** Say so on every example page. | Already ruled: nothing claims to be a compliance assessment, and it would be dishonest to present it as one. The examples are **illustrations of a method, using published configurations**, and a reader must not be able to mistake one for a finding about a vendor | | **3** | **State measured against derived, on every page that carries capability rows.** | The published map already does it: twenty one of ninety nine measured. **A page that hides the ratio is asserting what the map is careful to qualify** | | **4** | **Never test a product to find out.** No probing, no crafted inputs, no unadvertised requests against anybody's system. | Causing a computer to output data intending unauthorised access is an offence with no damage requirement and no research defence. A row is measured only from a system we are entitled to run, or from the vendor's own published documentation | ## Words | # | Rule | Why | |---|---|---| | **5** | **Agent, never agentic.** | Ruled 10 September on evidence, and restated in [`00__START-HERE.md`](../../../docs/pack/00__START-HERE/index.md). The site's own name was the thing at risk | | **6** | **Never shorten ABP to the policy.** | The word already denotes the insurance instrument on the published licence to operate demonstration | | **7** | **The word insurance does not appear on this site.** | Three standing rulings. The ladder puts it at the top rung and forbids calling the lower rungs by it. This site is rung zero. It may link to the demonstration, which carries no price and describes a simulation | | **8** | **Never memory and never zero knowledge in customer facing copy.** Use durable, and end to end encrypted. | Ruled 10 September with the evidence in `briefs/`. The vocabulary is contested and the consumer meaning fights an encryption product | ## Claims | # | Rule | Why | |---|---|---| | **9** | **Every prohibition rendered anywhere carries the layer it is enforced at.** | A prohibition at the first three barrier rows is not a control, and showing one without its barrier manufactures assurance. The estate's own glyph system already carries this | | **10** | **Do not print the sentence that the provider cannot read the data until somebody has answered what leaks.** | It is a factual claim about architecture and it is enforceable. A regulator acted on exactly this in November 2020 and the settlement ran twenty years | | **11** | **The regulatory citation is the consumer guidance of 9 March 2026**, which says a business should be clear about what tasks an agent is allowed to perform, what data it can access and what constraints apply. **Not the European deployer article**, which was deferred to 2 December 2027 and reaches only high risk systems. | Citing a duty that does not yet bite, to a buyer whose adviser will check, costs more than it gains | ## Licence | # | Rule | Why | |---|---|---| | **12** | **Never adapt, translate, quote at length or feed to a model the content of the international management standards.** Their titles may be named. The European regulation is expressly reusable for commercial purposes including adaptation, and is the clean source for any mapping. | Prohibited twice over, once as a derivative and once as a model input. A buyer will ask for the management standard and the answer is the regulation | | **13** | **No score, anywhere.** No rating, no traffic light, no risk level, no severity ranking, on any page, in any data file, in any visualisation. | Rule 0 made concrete. A score is a verdict. Every buyer will ask for one; the answer is that it lives on the risk product. The one permitted ordering is by reversibility, stated as a property of the action, never as severity | ## And one that is about this repository rather than the site **Zero em dashes, zero en dashes, pure ASCII in every document.** The style guide's own measurement is that this rule sits at zero per cent compliance across eleven documents. Every file in this pack complies. **Add the check to the pipeline as a structural guard and this repository becomes the first one that holds.** This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/05__THE-HARD-RULES/index.html)* ------------------------------------------------------------------------ # The Prompt > Paste this to the agent that builds the site. It is the standard prompt for a new network site, extended with what this one needs. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../../index.md) / [Docs](../../../docs/index.md) / [The pack](../../../docs/index.md#pack) / The Prompt # The Prompt > **The source bytes.** This page is generated from [`docs/pack/06__THE-PROMPT.md`](../../../docs/pack/06__THE-PROMPT.md), which is served unchanged. Anything rendered on this network stays one click from the file it came from. **Paste this to the agent that builds the site. It is the standard prompt for a new network site, extended with what this one needs.** Hi, can you read this brief and create the new website, just like we have the other `*.sgit.ai` websites. As with the other sites and repos, which you have access to, can you start with the CI pipeline and auto tagging. Copy them from one named sibling repository rather than writing them, and say in your first commit message which sibling you copied from. I have configured the repo to default to the `dev` branch and GitHub Pages is enabled. For now, please also push your branch to `dev` so that we can test the CI pipeline and see what the site looks like. This site will go to **abp.sgit.ai**, which is already configured on this repo. **Before you write anything, read these, in this order:** 1. `briefs/v0.33.70__foundation__agent-behaviour-policy-...md`. **It is the definition. The home page is derived from it and the what is an ABP page is it, rendered.** 2. [`00__START-HERE.md`](../../../docs/pack/00__START-HERE/index.md) in this pack. It contains one naming ruling and one finding that will change your plan. 3. `https://sgit.ai/docs/guidance/index.html` 4. `https://sgit.ai/llms.txt` 5. `https://coding.sgit.ai` 6. `https://what-can-it-do.games.sgit.ai/map/index.html`, and its `/mandates/` and `/deltas/` pages. **The ontology this site needs already exists there. Do not invent one.** 7. `https://graphs.sgit.ai` for the five graph rules, which govern the model rather than the styling. **The name is Agent Behaviour Policy. Not Agentic. Never shortened to the policy. The reasons are in [`00__START-HERE.md`](../../../docs/pack/00__START-HERE/index.md) and they are not preferences.** **The site owns one argument and the home page says it:** you know what you asked for, you do not know what it can do. **The ABP is consequence agnostic. It describes and never judges, and it carries no score anywhere.** A policy cannot be dangerous; a deployment can. The score belongs on the risk product. Every page carries a label line (grant, mandate, excess, unbounded excess, irreversible, widest reach, measured, as at) and a validity statement, and no page carries a rating. [`03__THE-ABP-MODEL.md`](../../../docs/pack/03__THE-ABP-MODEL/index.md) opens with this and rule 0 of the hard rules enforces it. **Four things this site must have that a normal site would not:** - **A docs section** at `/docs/`, using the markdown rendering already used across the network, carrying every document in this pack and the three briefs, each one click from its source bytes. - **A data layer** at `/data/`, promoted from the game's JSON pack into a published schema at stable addresses with cross origin access, so that the capabilities, profiles, barriers and undo classes become the network's published vocabulary rather than one game's internals. - **Five worked examples**, derived from that data rather than authored. [`04__THE-FIRST-EXAMPLES.md`](../../../docs/pack/04__THE-FIRST-EXAMPLES/index.md) names them and says which to build first. - **A provenance line on every page carrying capability rows**, stating how many were measured and how many derived. The map page already does this and the site must not be less careful than the game. **Two things you must not build:** a markdown viewer, a file browser or a page layout engine, because the platform has them and the guidance forbids rebuilding them. And any checkout, price or payment link, because that is the store. **Read [`05__THE-HARD-RULES.md`](../../../docs/pack/05__THE-HARD-RULES/index.md) before writing a single sentence about a named product.** This site publishes capability claims about nine commercial products, and rule one is the largest exposure in the repository. **When you have the pipeline working and the first pages up, report back with:** - Which sibling repo you copied the pipeline from, and which of the five verifications in [`02__THE-CONVENTIONS.md`](../../../docs/pack/02__THE-CONVENTIONS/index.md) that sibling failed. - The version surface working: the version in the chrome, as a link, sourced from `versions/index.json`. - `llms.txt` generated and listing every page. - Which of the five examples you built and how long each took, because that number is a pricing input and nobody has it yet. **One thing to flag rather than fix silently.** If the guidance, the style guide and this pack disagree about anything, the published source wins and the disagreement belongs in the first version's notes. The estate's method is to record the gap, not to quietly resolve it. This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). --- *[Site index for agents](../../../llms.txt) · [HTML version](https://abp.sgit.ai/docs/pack/06__THE-PROMPT/index.html)* ------------------------------------------------------------------------ # Docs > Every reference and guidance document behind this site, rendered, with a link to the source bytes of each. The index is generated from the files present. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / Docs # Docs Everything this site was built from, published rather than summarised. **The foundation document is first**: it is the definition of the Agent Behaviour Policy, the home page is derived from it, and where it and anything else here disagree, it wins. > **This index is generated from the files present in `docs/`, not maintained beside them.** An index that can disagree with its source is a defect. Adding a document to the repository puts it here, in `llms.txt` and in the sitemap with no second edit. ## The briefs The foundation document first, then the three briefs behind it. Published as written, with their own licence footers intact. **[Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know What It Can Do](../docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do/index.md)**: version v0.33.70 date 11 September 2026 from Dinis Cruz to Anyone deploying an agent, anyone building one, and anyone who has to sign for one [the source bytes](../docs/briefs/v0.33.70__foundation__agent-behaviour-policy-you-know-what-you-asked-for-and-you-do-not-know-what-it-can-do.md) **[The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has The Vocabulary, And A Prohibition Has Two Lives](../docs/briefs/v0.33.70__dev-brief__the-behaviour-policy-is-a-graph-and-every-document-is-a-projection-the-w3c-has-the-vocabulary-and-a-prohibition-has-two-lives/index.md)**: version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever models the graph, whoever builds the renderer, and whoever compiles the prohibitions into something that enforces them [the source bytes](../docs/briefs/v0.33.70__dev-brief__the-behaviour-policy-is-a-graph-and-every-document-is-a-projection-the-w3c-has-the-vocabulary-and-a-prohibition-has-two-lives.md) **[The Delta Is Derived And Never Authored: Storing It Is The Point, And The History Is The Business Case](../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case/index.md)**: version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever builds the ABP data model, whoever wires the recompute, and whoever has to correct a document that is already published [the source bytes](../docs/briefs/v0.33.70__dev-brief__the-delta-is-derived-and-never-authored-storing-it-is-the-point-and-the-history-is-the-business-case.md) **[The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Sell The Correction, And Not The Draft](../docs/briefs/v0.33.70__strategy-brief__the-behaviour-policy-is-the-document-the-only-agent-insurer-already-requires-sell-the-correction-and-not-the-draft/index.md)**: version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever names the product, prices it, and stands at the table with it next week [the source bytes](../docs/briefs/v0.33.70__strategy-brief__the-behaviour-policy-is-the-document-the-only-agent-insurer-already-requires-sell-the-correction-and-not-the-draft.md) **[The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Delta, And The Insurance Act Says How](../docs/briefs/v0.33.70__strategy-brief__the-prohibitions-are-the-exclusions-your-own-demo-says-no-policy-covers-the-delta-and-the-insurance-act-says-how/index.md)**: version v0.33.70 date 11 September 2026 from Human (project lead) to Whoever plans the ladder from the behaviour policy to everything above it, and whoever talks to an underwriter first [the source bytes](../docs/briefs/v0.33.70__strategy-brief__the-prohibitions-are-the-exclusions-your-own-demo-says-no-policy-covers-the-delta-and-the-insurance-act-says-how.md) ## The pack The six numbered documents that settled what this site is, what it must not invent, and the rules it is built under. **[Start Here](../docs/pack/00__START-HERE/index.md)**: You are building abp.sgit.ai, the site for the Agent Behaviour Policy. This pack is what has been decided, what already exists, and what you must not invent. [the source bytes](../docs/pack/00__START-HERE.md) **[What To Build](../docs/pack/01__WHAT-TO-BUILD/index.md)**: Every site in the network is named for an argument rather than for a function, and there are twenty seven of them. The argument here is not a product name. [the source bytes](../docs/pack/01__WHAT-TO-BUILD.md) **[The Conventions](../docs/pack/02__THE-CONVENTIONS/index.md)**: Three sources govern how this site is built. Read all three before writing code. Where this pack and a source disagree, the source wins and you should say so. [the source bytes](../docs/pack/02__THE-CONVENTIONS.md) **[The ABP Model](../docs/pack/03__THE-ABP-MODEL/index.md)**: The ABP describes. It does not judge. It states what the agent can do, what it was authorised to do, the gap between them, and what stands in the way. It says nothing about whether any of that is acceptable, because acceptability is not in... [the source bytes](../docs/pack/03__THE-ABP-MODEL.md) **[The First Examples](../docs/pack/04__THE-FIRST-EXAMPLES/index.md)**: The memo asks for a few ABPs, from simple to complex, to find out what they look like in practice and how hard they are to make. The answer is that the first five can be derived rather than authored, because the data exists. [the source bytes](../docs/pack/04__THE-FIRST-EXAMPLES.md) **[The Hard Rules](../docs/pack/05__THE-HARD-RULES/index.md)**: Thirteen rules that constrain this site. Each has a source and a reason. Rule 0 sits above the others and rules 1 and 13 are the two most likely to be broken. [the source bytes](../docs/pack/05__THE-HARD-RULES.md) **[The Prompt](../docs/pack/06__THE-PROMPT/index.md)**: Paste this to the agent that builds the site. It is the standard prompt for a new network site, extended with what this one needs. [the source bytes](../docs/pack/06__THE-PROMPT.md) ## Inherited guidance **Link, do not copy.** These are the published sources this site is built under. Where a rule is quoted on a page it is quoted with its source; nothing here is a copy of somebody else's document kept in this repository to go stale. | Source | Read | What it governs | |---|---|---| | [The vault and site building guidance](https://sgit.ai/docs/guidance/index.html) | 11 September 2026 | Pick your surface first. Do not build what the platform already has. Publish a read key, never a vault key. Version everything and show the version. Anything rendered must stay one click from the source bytes. | | [What the platform site is, for agents](https://sgit.ai/llms.txt) | 11 September 2026 | How the network is organised, and the index every site in it publishes. | | [The style guide, with measured compliance](https://coding.sgit.ai/) | 11 September 2026 | Thirty one rules, and honest about its own enforcement: no linters, and four structural guards in the pipeline are the only automated enforcement. | | [The five graph rules](https://graphs.sgit.ai/) | 11 September 2026 | They govern the model rather than the styling. This site's reading of them is on [the graph page](../model/graph/index.md). | | [The capability map this site's data came from](https://what-can-it-do.games.sgit.ai/map/index.html) | 11 September 2026 | Twenty three primitives, nine profiles, the barrier glyph and the undo class. The ontology this site promoted rather than invented. | ## One document is quoted and never copied > **The international management standards are not reproduced here, in any form.** Their titles may be named. Adapting, translating or quoting them at length is prohibited, and so is feeding them to a model. Where a mapping is wanted, the European regulation is expressly reusable for commercial purposes including adaptation, and it is the clean source. [Everything on this site, in one file](../llms-full.txt) · [The index for agents](../llms.txt) --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/docs/index.html)* ------------------------------------------------------------------------ # v0.2.0: the delta is derived and never authored, so it is stored with its inputs pinned and the gate recomputes it > A correction to a rule this site published nine hours earlier, applied in the open. The foundation document says, twice, that the delta is computed and never stored. The first half is right and the second half is wrong: the delta is stored, and storing it is most of what makes... *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Versions](../../versions/index.md) / v0.2.0 # v0.2.0: the delta is derived and never authored, so it is stored with its inputs pinned and the gate recomputes it A correction to a rule this site published nine hours earlier, applied in the open. The foundation document says, twice, that the delta is computed and never stored. The first half is right and the second half is wrong: the delta is stored, and storing it is most of what makes it useful, because a question about whether a control held throughout a period is a question about a series that a recomputed present cannot answer. The corrected rule is that the delta is DERIVED AND NEVER AUTHORED, which is the harder rule, because it forbids the act rather than the artefact. The release gate's check is inverted to match: it refused any stored delta and now recomputes every one of them. | Field | Value | |---|---| | Version | `v0.2.0` | | Date | 2026-09-11 | | Commit | `git rev-list -n 1 v0.2.0`, written into [`versions/v0.2.0.json`](../../versions/v0.2.0.json) once CI has tagged this release. Until then the file says where the hash will come from rather than carrying one that would be wrong. | | Reconstructed | no | | Machine readable | [`versions/v0.2.0.json`](../../versions/v0.2.0.json) | ## What changed - data/deltas/ carries 9 stored deltas, one per deployment shape and mandate pair. Each record pins the version of both inputs, the published vocabulary it was computed against, the time it was computed and the version of the computation that produced it, so it can be recomputed and compared rather than taken on trust. No field in one is writable by a person. - The release gate's twelfth check is inverted. It refused any file carrying a delta; it now recomputes every stored delta from the profile and the mandate it names and fails on a single row of disagreement, including the ordering. That check is a few lines because the computation is a set difference, and it is a set difference because the grant and the mandate are held as graphs with a schema rather than as prose. - A new page at /model/delta/ carries the correction with both passages quoted and both replacements given, what the old rule was protecting and why all of it survives, the materialised view the pattern already had a name for, reality as the third input and the calibration loop it creates, the recompute trigger mapped onto an existing event standard, the rule that a threshold crossing is a record and the consequence is a policy somebody set in advance, the history as a business case read rather than constructed, the three clocks, and the distinction from behaviour drift. - The validity statement on every example gains the second clock: as at this date, from a twin last synchronised at this date. This site has no twin connected to anything and the label says so rather than leaving the field out. - The dev brief that makes the correction is published in /docs/briefs/ and appears in the index, in llms.txt and in the sitemap without a second edit, because the index is generated from the files present. - The foundation document is NOT rewritten. Both corrected passages stand as published, with a correction notice above them pointing at the brief and at /model/delta/. Everything else in that document stands. ## What it was built against - The dev brief of 11 September 2026, the delta is derived and never authored, which is the fifth document of that day and the first written to correct one already pushed. - The foundation document of 11 September 2026, which the brief corrects in two passages and leaves standing in every other. - The site building guidance, for the rule that indexes are generated from the data they index, which the brief records this as the fourth instance of. ## The five verifications against the sibling The pipeline, the release gate and the page shell were copied from [SGit-AI__Website__Game__What-Can-It-Do](https://github.com/SGit-AI/SGit-AI__Website__Game__What-Can-It-Do) at its v0.8.0. The conventions ask for five things to be verified rather than assumed, and **an absent one is a finding that belongs in the first version's notes** rather than a thing to fix quietly. | Verification | The sibling | What this repository does | |---|---|---| | The tag is derived from the version file, not typed by hand | **holds** | `admin/build/version.txt` owns the version. CI reads it, refuses to tag if the newest release commit's subject disagrees, refuses if the tag already exists on an earlier commit, and refuses if the bump is not the next minor or a deliberate major. Copied unchanged. | | The build fails when `llms.txt` does not list every page | **did not hold** | The sibling generates `llms.txt` from its page list, so it cannot miss a page the generator knows about, and nothing fails if a page exists in the tree that the generator does not. Check 11 here walks the tree and fails on any `.html` page missing from `llms.txt`. | | The custom domain survives a rebuild | **did not hold** | The sibling commits `CNAME` once. Here the build writes it from `SITE['host']`, and the canonical check reads the same file, so a domain change is one edit in one place. | | The markdown twin of every page is produced by the build | **holds** | `shell.write_site` emits the `.html` and the `.md` from the same block list, and gate check 7 fails on a page without a twin. Copied unchanged, and it is the reason the twins cannot drift. | | The version in the chrome comes from `versions/index.json` | **did not hold** | The sibling has no `versions/index.json` at all: the badge reads `version.txt` and links to a hand-maintained history page. Here the build generates `versions/index.json`, a file and a page per version, from the same string the tag is derived from, and the badge links to that version's own details. The published pipeline still owns the tag, so the two cannot disagree. | **Two of the three that did not hold are one-line fixes and the third is a surface that did not exist.** None of them is a criticism of a site that has been publishing for weeks: they are the cost of a pipeline growing by copy, which is exactly what the five verifications are for. ## Where the sources disagree The published source wins and the disagreement is recorded. **The estate's method is to record the gap, not to quietly resolve it.** | The disagreement | What each says | What this site did | |---|---|---| | SETTLED IN v0.2.0. The foundation document and the project lead, on whether a delta is stored | v0.1.0 built to the foundation document's rule that the delta is computed and NEVER STORED, and put a check in the release gate refusing any file that carried one. The project lead's correction, issued the same day, is that the second half was an error: the delta belongs in a vault along with the history of the grants and mandates that produced it. | v0.2.0 stores the deltas with their inputs pinned and inverts the check, so the gate now recomputes every one of them. **Never authored** is the rule that replaced it, and it is harder than the one it replaced. See [the delta](../../model/delta/index.md). | | The foundation document and the published data, on what changes when confirmations go off | The foundation document says that turning confirmations off moves the barrier on **every capability in the delta** by one row. In the published pack it moves exactly one barrier, on `execute.process.host`, and that capability is **inside the mandate**: the deployer asked for it. So the label's numbers do not move at all and the two documents still differ materially. | The data wins on the fact and the foundation document wins on the wording, so both example pages state what actually changes. It makes the pair a **better** argument, not a worse one: identical headline numbers, a materially different document, which is the case for the leaflet and against any single number. | | The pack and the sibling, on where the version lives | The conventions ask for `versions/index.json` as the home of the version. The sibling's working pipeline derives the tag from `admin/build/version.txt` and has no `versions/index.json`. | Both. `version.txt` still owns the tag, because that is the published pipeline and it wins; `versions/index.json` is generated from the same string, so the surface the guidance asks for exists and cannot drift from the tag. The gate checks the agreement. | | The pack and the published data, on whether the smallest grant has an empty delta | The pack says the smallest shape in the set is where a reader who does not believe an agent can do much *finds the delta is still not empty*. In the published data that shape's grant is one capability and the starting mandate asks for exactly it, so **the delta is empty**. | The example says so, plainly, and says why an empty delta is a result rather than a failure: a method that could never report nothing would be a sales document, and the other four examples would be worth less for it. Changing the mandate to manufacture a delta would have been the dishonest fix. | | The published headline and the pack's own vocabulary, on what `measured' means | The map's headline says 21 of 99 rows were measured. The pack's vocabulary defines `measured` as a dated probe with an evidence file, and **no row in the pack is at that tier**: the 21 are at `observed`, which is seen directly on the thing itself. | The site counts `observed` as measured, which reproduces the published figure, and says so in `data/provenance.json` and on the data page. Reproducing the number without the note would have been less careful than the map. | | The hard rules and the published data, on em dashes and pure ASCII | Every document in this repository is to be pure ASCII, with zero em dashes and zero en dashes. The data promoted from the capability map carries all three, because it was written elsewhere and this site does not get to edit somebody else's bytes. | Both. The JSON keeps the upstream strings exactly as they arrived and `data/` is exempt from the guard for that reason; every upstream string rendered into a page is transliterated at render time; and the bytes are one click away under `/data/upstream/`. The guard is in the pipeline and fails the build everywhere else. | | The guidance and the docs section, on rebuilding the markdown renderer | The guidance forbids rebuilding markdown viewing, file trees and page layouts, because the platform provides them. The docs section has to turn eleven markdown documents into pages. | `admin/build/docs_pages.py` translates a markdown document into the same small block vocabulary every other page here is written in, at build time. No viewer is shipped to a browser, no file tree and no layout engine, and the source bytes are served beside every rendered document. It is a judgement call and it is recorded as one rather than assumed. | ## What is not built yet, stated plainly - **No view across the nine shapes.** Each example carries a grant-against-mandate figure, and there is no figure that puts one capability across every deployment shape at once. The third graph rule says render the result of a query rather than the whole graph, so that would be another query rather than a map. - **No ABP for a shape outside the published map**, which means the cost of producing one where the grant has to be measured rather than looked up is still unknown, and that is the number the store needs. - **No interchange form emitted.** The W3C vocabulary is described on [the graph page](../../model/graph/index.md) and nothing on this site serialises to it yet. - **Quantity and agent-to-agent interaction are not modelled**, as the model page says. They are gaps in the ontology rather than in this site. --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/versions/v0.2.0/index.html)* ------------------------------------------------------------------------ # v0.1.0: the ontology is promoted out of a game and the five examples are derived rather than written > The first version of abp.sgit.ai. The capability ontology the ABP needs already existed, published, as the data pack a game reads, so this release promotes it into a schema with a stable address rather than authoring a second one, and derives five worked ABPs from it. Nothing on... *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../../index.md) / [Versions](../../versions/index.md) / v0.1.0 # v0.1.0: the ontology is promoted out of a game and the five examples are derived rather than written The first version of abp.sgit.ai. The capability ontology the ABP needs already existed, published, as the data pack a game reads, so this release promotes it into a schema with a stable address rather than authoring a second one, and derives five worked ABPs from it. Nothing on a generated page is typed in: every number, glyph and row is computed from data/ at build time, which is what makes the provenance line worth reading. The pipeline, the tagging and the page shell are the sibling game site's, with four changes, each of which is one of the five verifications the conventions ask for and the sibling did not have. | Field | Value | |---|---| | Version | `v0.1.0` | | Date | 2026-09-11 | | Commit | `git rev-list -n 1 v0.1.0`, written into [`versions/v0.1.0.json`](../../versions/v0.1.0.json) once CI has tagged this release. Until then the file says where the hash will come from rather than carrying one that would be wrong. | | Reconstructed | no | | Machine readable | [`versions/v0.1.0.json`](../../versions/v0.1.0.json) | ## What changed - The pipeline, the release gate and the page shell are copied from SGit-AI/SGit-AI__Website__Game__What-Can-It-Do at its v0.8.0: validate, then tag, then publish, with the tag derived from admin/build/version.txt and checked against the release commit's subject. - data/ carries the published vocabulary: 23 capability primitives in verb.object.reach form, the four barriers, three undo classes, seven evidence tiers, nine deployment shapes and eight starting mandates, at stable addresses with cross origin access. Nothing is renamed; the source bytes are served unchanged under data/upstream/ and the build recomputes their hash on every run and refuses to write if it disagrees. - Each example carries one grant-against-mandate figure that is not a table: the mandate in one column, the grant in the other, and a line joining every capability in both, so a mark with no line reaching it is excess. Colour is never the only channel, every mark carries its published barrier glyph and its full id, and the markdown twin states the same facts in prose. - Five worked examples, derived from that data rather than authored, each with a label of nine fields, the grant ordered irreversible first, the mandate, the delta computed on the page, the prohibitions each carrying the barrier they sit at today, the measured-against-derived line, and the statement that none of it is an assessment. - The docs section renders the foundation document, the three briefs and the six pack documents through the same block vocabulary as every other page, with the source bytes of each one click away and an index generated from the files present. - The version surface the guidance asks for: versions/index.json with a file and a page per version, the badge in the chrome reading `current' from it and linking to that version's own details rather than to a generic changelog. - llms.txt and llms-full.txt are generated from the site, and the gate fails the build if a page in the tree is missing from llms.txt. - Five structural guards beyond the house four: every page in llms.txt, no em dash or en dash anywhere outside the promoted data, no score vocabulary anywhere, no forbidden word, and the version surface agreeing with version.txt. ## What it was built against - The foundation document of 11 September 2026, which is the definition and wins where it and the pack disagree. - The build pack of 11 September 2026: what to build, the conventions, the model, the first examples, the hard rules and the prompt. - The published capability map at what-can-it-do.games.sgit.ai, data pack v0.8.0, retrieved 2026-09-11, content hash sha256:d6d4ba40f1fb1f93. - The vault and site building guidance at sgit.ai/docs/guidance/, read 11 September 2026. - The five graph rules at graphs.sgit.ai, read 11 September 2026. - The style guide at coding.sgit.ai, read 11 September 2026. --- *[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/versions/v0.1.0/index.html)* ------------------------------------------------------------------------ # Versions > Every release of this site, with the commit it was built from and what it was built against. The version in the chrome links here. *Source: · site v0.2.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.* --- [Home](../index.md) / Versions # Versions Every release of this site. **The badge in the top bar reads `current` from [`versions/index.json`](../versions/index.json) and links to that version's own details**, rather than to a generic changelog, which is what the guidance asks for. | Version | Date | What changed | |---|---|---| | [v0.2.0](../versions/v0.2.0/index.md) | 2026-09-11 | the delta is derived and never authored, so it is stored with its inputs pinned and the gate recomputes it | | [v0.1.0](../versions/v0.1.0/index.md) | 2026-09-11 | the ontology is promoted out of a game and the five examples are derived rather than written | ## How the version cannot drift `admin/build/version.txt` owns the version. The tag is derived from it by CI, which refuses to tag unless the newest release commit's subject carries the same string and the bump is the next one. The build generates [`versions/index.json`](../versions/index.json) and a file per version from that same string, and the release gate fails if the badge, `llms.txt`, the twins or the version surface disagree with it. **Each entry records the commit**, because a version without one cannot be verified later, and **says when it was reconstructed**, because history assembled after the fact has to be labelled. [The machine readable index](../versions/index.json) · [The repository](https://github.com/SGit-AI/SGit-AI__Website__ABP) --- *[Site index for agents](../llms.txt) · [HTML version](https://abp.sgit.ai/versions/index.html)*