Home / The model / The capabilities / send.endpoint.allowed

send.endpoint.allowed

Reach a permitted list of hosts. Verb send, object network-endpoint, reach tenant, family network. Its effect is no: cannot be undone.

In 1 of 9 published shapes

Deployment shapeBarrier thereKnown byNote
Claude Code on the web (a remote session container)boundaryobservedsix of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies
BarrierWhat stands in the wayIs it a control
nonenothing in the wayno
expectationa rule in prose, enforced by nobodyno
settinga switch the agent's own account can flipno
boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisedA coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, A scheduled job under a service account
refusednone
unstatedChat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
shorten the list; a host it does not need is a host it can reachminutes per host, and a failure the first time it needs one you removedboundary
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.

The capability grammar · This primitive as JSON