Claude Code on the web
A managed, ephemeral container with one repository attached and an egress proxy above it. The shape this site is maintained from; 13 of 20 rows measured on the thing itself.
15 it can do7 unbounded6 scenariosAn Agent Behaviour Policy describes one AI agent in one deployment: everything it can do (the grant), what you actually authorised (the mandate), the gap between the two (the delta), and what really stands in the way of each thing (the barrier). It describes and it does not judge, so it carries no score. Below are the example policies we have built, one per target application — for most people the first they will have seen. Click one to read it here; a real deployment is a combination of several.
Every tile is one Agent Behaviour Policy, delivered as a vault: a measured or documented grant for that application, a starting mandate written to be corrected, six scenarios that change the mandate and never the grant, and the files you hand the agent. The counts are read from the vault as you look. Grid or list, same set; search matches names, vendors, scopes, tool names and the 23 capability ids, so send.message.world finds every policy that can send mail whatever the product calls it. Not here yet? See what is next, vote, or suggest one.
A managed, ephemeral container with one repository attached and an egress proxy above it. The shape this site is maintained from; 13 of 20 rows measured on the thing itself.
15 it can do7 unbounded6 scenariosThe coding agent on a developer's own machine with confirmation prompts enabled. Read this one beside the confirmations-off shape: one setting moves one barrier and not one number changes.
16 it can do12 unbounded6 scenariosThe same agent, the same machine, the same account, with the confirmation prompt switched off. The prompt was the only thing between an authorised capability and the whole machine, and it was a switch the agent's account could flip.
16 it can do12 unbounded6 scenariosThe desktop app with local tools on: files, processes and the network of the machine it sits on. Ten capabilities, three wanted, eight with nothing real in the way.
10 it can do8 unbounded6 scenariosChat with connectors enabled: the tenant's accounts are in reach through whatever was connected. The two excess rows here both sit behind a boundary, which is the exception in this directory.
5 it can do0 unbounded6 scenariosThe smallest grant in the set: one capability, one wanted, no excess. The baseline every other shape is measured against, and the proof that a template can be empty and still be right.
1 it can do0 unbounded6 scenariosOther people's data, and the mandate nobody wrote down. Three capabilities, all three irreversible; the shortest policy in the directory and not the mildest.
3 it can do2 unbounded6 scenariosA hosted runner under a service account: persistence, and reach beyond the turn. Eight of eight rows measured, the only fully measured shape besides the web container.
8 it can do3 unbounded6 scenariosA job that outlives the person who made it, running as a service account nobody logs in as. Seven capabilities, four wanted, four with nothing in the way.
7 it can do4 unbounded6 scenariosThe first grant here measured on a live instance, by an early beta user's agent: full control of every automation, an outbound node with no restriction on target, every account visible, and credential metadata open through one door and shut through another.
8 it can do4 unbounded6 scenariosGmail, Drive, Docs, Sheets, Slides, Calendar and Chat, one server each. The page advertises drafting mail and scheduling meetings; the scopes it asks for send mail and cannot touch a calendar.
6 it can do1 unbounded6 scenariosThe narrowest scope that reads one message reads every message. Lab 03 asked the model site for this shape first; here it is, read from Google's scope page.
4 it can do2 unbounded6 scenariosThe default corpus is "files owned by or shared to the user": everything anybody ever shared, on day one, without anyone choosing it.
3 it can do1 unbounded6 scenariosDelegated permissions, consented once by a Global Administrator. Shared mailboxes are in scope; site-specific narrowing is unsupported because the search is tenant-wide; and the page that says "read-only access" also lists the tools that send mail as the user.
5 it can do1 unbounded6 scenariosEight scopes, two of them write and two of them sharing, and no folder-scoped variant. It reads, creates, moves, deletes and makes shared links; the page says files are not deleted permanently and that recovery depends on your plan.
5 it can do0 unbounded6 scenariosNothing matches. Search matches names, vendors, scopes, tools and capability ids — try a shorter word.
Missing the one you run? 8 are asked for — vote on which is next, or suggest one. Every vault also carries MAP-A-GRANT.md: give it to an agent that already holds the credential and it measures its own grant.
Everything else in the vault is derived. The correction is the elicitation, and the corrected combination — with a name on the licence and no public key — is what is sold.