Home / The model / The capabilities / delete.file.host

delete.file.host

Delete files anywhere the account can reach. Verb delete, object file, reach host, family filesystem. Its effect is no: cannot be undone.

In 4 of 9 published shapes

Deployment shapeBarrier thereKnown byNote
Claude Code on the web (a remote session container)none (not a control)observedanything in the container, including the clone; irreversible for the container, and the container is disposable
Claude Code (the CLI, on your own machine)none (not a control)derived
Claude Code (the CLI, on your own machine)none (not a control)derived
Actions runner (a hosted CI job)none (not a control)observedthe runner's user with passwordless escalation: every file on the ephemeral machine
BarrierWhat stands in the wayIs it a control
nonenothing in the wayno
expectationa rule in prose, enforced by nobodyno
settinga switch the agent's own account can flipno
boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisednone
refusedA coding assistant on my machine, Chat in the browser, nothing connected
unstatedA coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
the same container or account; and a backup that the agent cannot reach, because delete at host reach is irreversibleas above, plus a backup outside the grantboundary
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.

The capability grammar · This primitive as JSON