# LICENCE TO OPERATE — the organisation authorises the agent, under this behaviour policy, for an interval

> The organisation is the authority, the behaviour policy is the instrument, and the agent is the licensee. Self-issued, witnessed, and dated — which is how most assurance works.

**Vault** `claude-code-web` · **status** template · **shape** `anthropic/claude-code-remote/ccr-container` · **grant** 2026-09-05.2 · **mandate** 2026-09-09 · **vocabulary** abp.sgit.ai v0.3.0 · **as at** 2026-09-15

---


| | |
| --- | --- |
| **Licensee** | Claude Code on the web (a remote session container) — deployment shape `anthropic/claude-code-remote/ccr-container`, grant version 2026-09-05.2 |
| **Authority** | — not yet issued to anyone — |
| **Accountable owner** | — unassigned — |
| **Instrument** | This behaviour policy: mandate `coding-assistant-in-a-container` (2026-09-09), delta `anthropic__claude-code-remote__ccr-container__coding-assistant-in-a-container` (2026-09-15T00:17:26Z), vocabulary abp.sgit.ai v0.3.0 |
| **Issued** | — not issued: this is a template — |
| **Valid until** | — an interval is set when it is issued; a licence with no expiry is not a decision — |

## Scope — what the licensee is authorised to do (6)

- `read.file.project` — Read the project it is working on
- `write.file.project` — Change the project it is working on
- `execute.process.host` — Run programs as the account
- `write.repository.project` — Commit to the repository it was pointed at
- `write.repository.tenant` — Push to a code host (any branch it can reach)
- `send.endpoint.allowed` — Reach a permitted list of hosts

## Conditions — what the licensee is asked not to do, and what enforces each (9)

A condition is only as good as the thing in its last column. Conditions with ● or ◉ beside them are asked, not enforced; the organisation issuing this licence is accepting that, for the interval above, with its eyes open.

| Condition | Asked because | Barrier | Enforced by |
| --- | --- | --- | --- |
| Do not `authenticate-as.credential.signing` (sign commits with the key it holds) | the mandate refuses it | ● none | **nothing** — a line in prose |
| Do not `delete.file.host` (delete files anywhere the account can reach) | the mandate never authorised it | ● none | **nothing** — a line in prose |
| Do not `read.credential.host` (read credentials stored where it runs) | the mandate never authorised it | ● none | **nothing** — a line in prose |
| Do not `read.file.host` (read any file the account can reach) | the mandate never authorised it | ● none | **nothing** — a line in prose |
| Do not `read.record.history` (read a retained record: shell history, past sessions) | the mandate refuses it | ● none | **nothing** — a line in prose |
| Do not `authenticate-as.credential.tenant` (act in accounts with the credentials it holds) | the mandate never authorised it | ○ boundary | the token's scope, set by the platform (in-scope repositories only) |
| Do not `write.file.host` (change any file the account can reach) | the mandate never authorised it | ● none | **nothing** — a line in prose |
| Do not `create.schedule.tenant` (create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)) | the mandate refuses it | ◐ setting | the platform's routines are the operator's to list and delete |
| Do not `create.schedule.host` (create something that outlives the turn where it runs (a cron, a service)) | the mandate never authorised it | ○ boundary | the container is ephemeral: whatever is scheduled here dies with it |

## Void when

- the grant version changes — a product release, a setting, a connector enabled or removed
- the mandate changes — the deployer authorises more or less
- the vocabulary version changes — a primitive is added, split or renamed
- a barrier moves — a setting becomes a boundary, or a boundary is removed

When any of those happens the deployment changed, not this document. Rebuild, re-read the delta, and re-issue.

## Signature

Unsigned. A template is not issued to anybody. When this vault is customised for one organisation, a named person signs here, with the date and the interval, and the same person owns the review when the interval ends.

---

_This describes the deployment shape as at this date. If the risk changed, the deployment changed — not this document._ 
No score, rating, level or traffic light appears in this vault or in its data, and none will. The behaviour policy describes; it does not judge. 
Generated by `scripts/site/build-abp-vault.mjs` from `data/grant.json`, `data/mandate.json` and the pinned vocabulary; `data/mandate.json` is the only file a person writes. Licence: CC BY 4.0.

