Home / The model / The capabilities / read.record.browsing

read.record.browsing

Read every page you visit. Verb read, object record, reach host, family browser. Its effect is no: cannot be undone.

In 1 of 9 published shapes

Deployment shapeBarrier thereKnown byNote
A browser extension with broad host permissionsnone (not a control)documented'read and change all your data on all websites'
BarrierWhat stands in the wayIs it a control
nonenothing in the wayno
expectationa rule in prose, enforced by nobodyno
settinga switch the agent's own account can flipno
boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisedA browser extension I installed
refusednone
unstatedA coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A scheduled job under a service account

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
grant the extension access on click, or on a list of sites, instead of on all sites; remove the ones you do not usea click the first time on each siteboundary
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.

The capability grammar · This primitive as JSON