Home / The model / The capabilities / grant.credential.self

grant.credential.self

Change its own permission settings. Verb grant, object credential, reach self, family identity. Its effect is yes: undone.

In 3 of 9 published shapes

Deployment shapeBarrier thereKnown byNote
Claude Code (the CLI, on your own machine)setting (not a control)derivedanything running as you can rewrite the file that turns the prompt off
Claude Code (the CLI, on your own machine)setting (not a control)derivedanything running as you can rewrite the file that turns the prompt off
Claude Desktop (a desktop app with local tools)setting (not a control)derived
BarrierWhat stands in the wayIs it a control
nonenothing in the wayno
expectationa rule in prose, enforced by nobodyno
settinga switch the agent's own account can flipno
boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisednone
refusedA coding assistant on my machine, The desktop app, with local tools switched on
unstatedA coding assistant in a container on the web, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed, A scheduled job under a service account

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
settings owned by a different user than the one the agent runs as, or set above the session by the platformminutes, if the platform supports it; otherwise the separate accountboundary
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.

The capability grammar · This primitive as JSON