Home / The model / The capabilities / send.endpoint.allowed
send.endpoint.allowed
Reach a permitted list of hosts. Verb send, object network-endpoint, reach tenant, family network. Its effect is no: cannot be undone.
In 1 of 9 published shapes
| Deployment shape | Barrier there | Known by | Note | |
|---|---|---|---|---|
| ○ | Claude Code on the web (a remote session container) | boundary | observed | six of six probed hosts answered through the proxy; a sibling container measured on 4 September had three refused: same product, two policies |
| Barrier | What stands in the way | Is it a control | |
|---|---|---|---|
| ● | none | nothing in the way | no |
| ◉ | expectation | a rule in prose, enforced by nobody | no |
| ◐ | setting | a switch the agent's own account can flip | no |
| ○ | boundary | enforced above the grant, out of the agent's reach | yes |
What the starting mandates say about it
| The mandate says | Which mandates |
|---|---|
| authorised | A coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, A scheduled job under a service account |
| refused | none |
| unstated | Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner, A browser extension I installed |
Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.
What would move it to the fourth barrier
| What | What it costs | The barrier afterwards |
|---|---|---|
| shorten the list; a host it does not need is a host it can reach | minutes per host, and a failure the first time it needs one you removed | boundary |
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.