# The barrier

> Four kinds of thing that can stand between an agent and a capability, and only the fourth bounds anything. The enforcer test, which this estate published as a glyph before it named it as a rule.

*Source: <https://abp.sgit.ai/model/barriers/index.html> · site v0.2.0 · this file is generated from the same content
as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links
below point at them.*

---

[Home](../../index.md) / [The model](../../model/index.md) / The barrier

# The barrier: what is actually in the way

For every capability in the grant, an ABP records what stands between the agent and it. There are four kinds. **Only the fourth bounds anything**, and that is not an opinion.

|  | Barrier | What stands in the way | Is it a control |
|---|---|---|---|
| ● | none | nothing in the way | no |
| ◉ | expectation | a rule in prose, enforced by nobody | no |
| ◐ | setting | a switch the agent's own account can flip | no |
| ○ | boundary | enforced above the grant, out of the agent's reach | **yes** |

## The enforcer test

> **A control bounds a grant only if it is enforced by something the grant does not include.**

Read the third and fourth rows together and the test falls out of them. A setting the agent's own account could change is not a control, because the grant includes the ability to remove the bound. A boundary enforced above it that it cannot reach is a control, because it does not.

**A rule somebody wrote down is the second row and it is where most prohibitions sit today.** All four major model providers stated in their own 2026 words that an instruction at the prompt layer can be bypassed; one of them puts it as *the deterministic boundary is what gets hit when everything probabilistic misses*. One provider reports that users approved roughly ninety three per cent of the permission prompts they were shown, which is the third row failing in the other direction.

## What follows for every page on this site

**Every prohibition rendered anywhere carries its barrier.** A prohibition displayed without one is a claim the site cannot support, and it manufactures assurance. The honest ABPs say, for most deployments today, that the barrier is the second kind.

**Unbounded excess is the only number on the label a buyer can move.** Every real control put in place shifts one capability into the fourth row and the number falls. The gap between excess and unbounded excess is the business case for a control, and it contains no verdict.

## Where the four came from

The glyph system on [the published map](https://what-can-it-do.games.sgit.ai/map/index.html) carried all four before anybody wrote the rule down: nothing, a rule somebody wrote down, a setting the agent's own account could change, and a boundary enforced above it that it cannot reach. This site added two fields to them, `is_control` and the reason, and marks both as its own reading rather than as the map's data.

[The barriers as JSON](../../data/barriers.json) · [The source bytes](../../data/upstream/vocabulary.json)

---

*[Site index for agents](../../llms.txt) · [HTML version](https://abp.sgit.ai/model/barriers/index.html)*
