admin / The vaults
The vaults
16 behaviour-policy vaults, 4 of them measured, 28 open questions between them. Every one is a public vault with a read key printed on its page; the write key is never here.
Read off the catalogue and each vault's vault.json and data/grant.json. Measured counts rows run on a system we are entitled to run; everything else is documented from the vendor's pages, dated and quoted. No row here is a score: the number of open questions is how much the grant still does not know about itself.
Coding agents
| Vault | Shape | Rows | Measured | Open | As at | Id | |
|---|---|---|---|---|---|---|---|
| Claude Code on the web | anthropic/claude-code-remote/ccr-container | 15 | 13 of 15 | none | 2026-09-15 | ruj286tr | host ↗ |
| Claude Code on your machine | anthropic/claude-code/local-default | 16 | documented | none | 2026-09-15 | amicdz0h | host ↗ |
| Claude Code, confirmations off | anthropic/claude-code/local-confirmations-off | 16 | documented | none | 2026-09-15 | ahly2cho | host ↗ |
Chat assistants
| Vault | Shape | Rows | Measured | Open | As at | Id | |
|---|---|---|---|---|---|---|---|
| Claude Desktop | anthropic/claude-desktop/default | 10 | documented | none | 2026-09-15 | ty3axtmo | host ↗ |
| Claude in the browser, connectors on | anthropic/claude-web/connectors-on | 5 | documented | none | 2026-09-15 | wkm5owfl | host ↗ |
| ChatGPT in the browser | openai/chatgpt-web/default | 1 | documented | none | 2026-09-15 | dd1teu9n | host ↗ |
| A browser extension | generic/browser-extension/broad-host-permissions | 3 | documented | none | 2026-09-15 | exsaxrfr | host ↗ |
Automation & CI
| Vault | Shape | Rows | Measured | Open | As at | Id | |
|---|---|---|---|---|---|---|---|
| GitHub Actions | github/actions-runner/ci | 8 | 8 of 8 | none | 2026-09-15 | 0hpdpj80 | host ↗ |
| A scheduled job | generic/scheduled-job/service-account | 7 | documented | none | 2026-09-15 | kd7zeimj | host ↗ |
| n8n, owner API key | n8n/self-hosted/owner-api-key | 8 | 7 of 8 | 4 open | 2026-09-15 | l8opgcug | host ↗ |
Mail & files connectors
| Vault | Shape | Rows | Measured | Open | As at | Id | |
|---|---|---|---|---|---|---|---|
| Google Workspace MCP servers | google/workspace-mcp/default | 6 | documented | 4 open | 2026-09-15 | pq7ct02p | host ↗ |
| Claude's Gmail connector | anthropic/gmail-connector/default | 6 | 4 of 6 | 6 open | 2026-09-16 | oc433z3m | host ↗ |
| Gmail, read-only scope | google/gmail/readonly-connector | 4 | documented | 3 open | 2026-09-15 | l2zlv3ng | host ↗ |
| Google Drive, read-only scope | google/drive/readonly-connector | 3 | documented | 3 open | 2026-09-15 | vz03p8it | host ↗ |
| Microsoft 365 connector (Claude) | anthropic/microsoft-365-connector/default | 5 | documented | 4 open | 2026-09-15 | dgx3nvu4 | host ↗ |
| Dropbox MCP server | dropbox/mcp-server/default | 5 | documented | 4 open | 2026-09-15 | 9eqa7e4p | host ↗ |
Asked for, not built
Google Calendar and Google Drive, the two Google Workspace connectors not yet in the directory — Gmail's own is.
Channels are mostly other people's writing, and a bot token reaches every channel it is in.
A fine-grained token can be scoped to a repository; an OAuth app cannot, and most connectors are OAuth apps.
An integration is added page by page, which is the one connector model with a floor. Whether the assistant's connector uses it is the question.
A CRM is entirely third-party material by construction.
Customer records are third-party material by construction. Salesforce, HubSpot, Dynamics.
Tickets, and the conversations inside them. Zendesk, Intercom, Freshdesk.
Spreadsheets, ledgers and the exports beside them. Sheets, Excel, NetSuite.
The public page for these is what is next, with a vote and a suggestion form.