# DELTA — what it can do that you did not ask for

> Derived from the grant and the mandate, never authored. Recomputed on every build, with both inputs pinned. If this file looks wrong, one of the two inputs is.

**Vault** `claude-code-web` · **status** template · **shape** `anthropic/claude-code-remote/ccr-container` · **grant** 2026-09-05.2 · **mandate** 2026-09-09 · **vocabulary** abp.sgit.ai v0.3.0 · **as at** 2026-09-15

---


**Grant** 2026-09-05.2 · **mandate** 2026-09-09 · **computed** 2026-09-15T00:17:26Z · **agrees row for row with** the published record `anthropic__claude-code-remote__ccr-container__coding-assistant-in-a-container` (2026-09-11T13:00:37Z)

## Four counts, and none of them is a score

| | Count | Meaning |
| --- | --- | --- |
| Grant | 15 | capabilities the deployment reaches |
| Mandate | 6 | capabilities the deployer wanted |
| Excess | 9 | in the grant and not wanted |
| **Unbounded excess** | **7** | excess with no boundary in the way — the only number anybody can move |
| Shortfall | 0 | wanted and not in the grant |
| Aligned | 6 | wanted and granted |

## Excess you refused (3)

You said no. Each row says what, if anything, enforces the no.

| Capability | What it is | Barrier | Undo | Evidence | Mandate |
| --- | --- | --- | --- | --- | --- |
| `authenticate-as.credential.signing` | Sign commits with the key it holds | ● none | no | observed ✓ | refused by the mandate |
| `read.record.history` | Read a retained record: shell history, past sessions | ● none | no | observed ✓ | refused by the mandate |
| `create.schedule.tenant` | Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) | ◐ setting | yes | self-reported | refused by the mandate |


## Excess you never mentioned (6)

Authority nobody scoped. Not wrong — unstated. These are the rows to read twice.

| Capability | What it is | Barrier | Undo | Evidence | Mandate |
| --- | --- | --- | --- | --- | --- |
| `delete.file.host` | Delete files anywhere the account can reach | ● none | no | observed ✓ | unstated by the mandate |
| `read.credential.host` | Read credentials stored where it runs | ● none | no | observed ✓ | unstated by the mandate |
| `read.file.host` | Read any file the account can reach | ● none | no | observed ✓ | unstated by the mandate |
| `authenticate-as.credential.tenant` | Act in accounts with the credentials it holds | ○ boundary | no | inferred | unstated by the mandate |
| `write.file.host` | Change any file the account can reach | ● none | with-effort | observed ✓ | unstated by the mandate |
| `create.schedule.host` | Create something that outlives the turn where it runs (a cron, a service) | ○ boundary | yes | observed ✓ | unstated by the mandate |


## Unbounded excess (7)

The excess whose barrier is anything but a boundary. Every real control moves one of these rows into the fourth barrier and this list gets shorter; nothing else does.

- `authenticate-as.credential.signing` — Sign commits with the key it holds — ● none
- `delete.file.host` — Delete files anywhere the account can reach — ● none
- `read.credential.host` — Read credentials stored where it runs — ● none
- `read.file.host` — Read any file the account can reach — ● none
- `read.record.history` — Read a retained record: shell history, past sessions — ● none
- `write.file.host` — Change any file the account can reach — ● none
- `create.schedule.tenant` — Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) — ◐ setting — the platform's routines are the operator's to list and delete


## Shortfall (0)

_none — everything wanted is granted._

## Aligned (6)

| Capability | What it is | Barrier | Undo | Evidence | Mandate |
| --- | --- | --- | --- | --- | --- |
| `send.endpoint.allowed` | Reach a permitted list of hosts | ○ boundary | no | observed ✓ | in the mandate |
| `execute.process.host` | Run programs as the account | ● none | with-effort | observed ✓ | in the mandate |
| `write.file.project` | Change the project it is working on | ● none | with-effort | observed ✓ | in the mandate |
| `write.repository.project` | Commit to the repository it was pointed at | ● none | with-effort | observed ✓ | in the mandate |
| `write.repository.tenant` | Push to a code host (any branch it can reach) | ◐ setting | with-effort | observed ✓ | in the mandate |
| `read.file.project` | Read the project it is working on | ● none | yes | observed ✓ | in the mandate |


---

_This describes the deployment shape as at this date. If the risk changed, the deployment changed — not this document._ 
No score, rating, level or traffic light appears in this vault or in its data, and none will. The behaviour policy describes; it does not judge. 
Generated by `scripts/site/build-abp-vault.mjs` from `data/grant.json`, `data/mandate.json` and the pinned vocabulary; `data/mandate.json` is the only file a person writes. Licence: CC BY 4.0.

