{
  "note": "The catalogue of behaviour-policy vaults on this site \u2014 the single source for the directory page (abp-vaults.html) and one page per vault (abp-vault-<slug>.html), both written by scripts/site/build-abp-pages.mjs. `key` is the vault's PUBLIC read key (64 hex): derived one-way, read and nothing else, published on purpose. A write credential never appears here or anywhere in site/. `asked_for` are applications whose grant is not yet published at abp.sgit.ai, so no vault can be derived for them yet \u2014 they are listed so the gap is visible, never filled in by hand.",
  "endpoint": "https://dev.send.sgraph.ai",
  "vaults": [
    {
      "slug": "claude-code-web",
      "vid": "ruj286tr",
      "key": "6042edc39e0bcb1f17af1da0cf9d4ded6f89a7bb6a5394aa9554bb76913a249c",
      "app": "Claude Code on the web",
      "title": "Claude Code on the web, with one repository attached",
      "title_lead": "Claude Code on the web,",
      "title_tail": "with one repository attached.",
      "shape": "anthropic/claude-code-remote/ccr-container",
      "family": "code",
      "glyph": "CC",
      "blurb": "A managed, ephemeral container with one repository attached and an egress proxy above it. The shape this site is maintained from; 13 of 20 rows measured on the thing itself.",
      "logo": "claude",
      "brand": "#D97757",
      "group": "Coding agents"
    },
    {
      "slug": "claude-code-cli",
      "vid": "amicdz0h",
      "key": "46c3f77951dfea80c8bf3d72d5a84915e2694129ca8df4a1c58ccecfeb31bc47",
      "app": "Claude Code on your machine",
      "title": "Claude Code on your own machine, confirmations on",
      "title_lead": "Claude Code on your machine,",
      "title_tail": "confirmations on.",
      "shape": "anthropic/claude-code/local-default",
      "family": "code",
      "glyph": "CC",
      "blurb": "The coding agent on a developer's own machine with confirmation prompts enabled. Read this one beside the confirmations-off shape: one setting moves one barrier and not one number changes.",
      "logo": "terminal",
      "brand": "#D97757",
      "group": "Coding agents"
    },
    {
      "slug": "claude-code-cli-confirmations-off",
      "vid": "ahly2cho",
      "key": "7894e9462c18014303ec8137593610880171f0d6fa8a999b5f9f8687ba100b86",
      "app": "Claude Code, confirmations off",
      "title": "Claude Code on your own machine, confirmations off",
      "title_lead": "Claude Code on your machine,",
      "title_tail": "confirmations off.",
      "shape": "anthropic/claude-code/local-confirmations-off",
      "family": "code",
      "glyph": "CC",
      "blurb": "The same agent, the same machine, the same account, with the confirmation prompt switched off. The prompt was the only thing between an authorised capability and the whole machine, and it was a switch the agent's account could flip.",
      "logo": "terminal",
      "brand": "#D97757",
      "group": "Coding agents"
    },
    {
      "slug": "claude-desktop",
      "vid": "ty3axtmo",
      "key": "0773b3bf99cb7ef237fa83c77778eb85009a89dbaf566c2d16a83a8f3c693635",
      "app": "Claude Desktop",
      "title": "Claude Desktop, with local tools switched on",
      "title_lead": "Claude Desktop,",
      "title_tail": "with local tools switched on.",
      "shape": "anthropic/claude-desktop/default",
      "family": "desktop",
      "glyph": "CD",
      "blurb": "The desktop app with local tools on: files, processes and the network of the machine it sits on. Ten capabilities, three wanted, eight with nothing real in the way.",
      "logo": "claude",
      "brand": "#D97757",
      "group": "Chat assistants"
    },
    {
      "slug": "claude-web-connectors",
      "vid": "wkm5owfl",
      "key": "2bf331cfad716bdc7f37feddd7f1892c651425dd844381d3f392ed1b3419447d",
      "app": "Claude in the browser, connectors on",
      "title": "Claude in the browser, with connectors switched on",
      "title_lead": "Claude in the browser,",
      "title_tail": "with connectors switched on.",
      "shape": "anthropic/claude-web/connectors-on",
      "family": "chat",
      "glyph": "CW",
      "blurb": "Chat with connectors enabled: the tenant's accounts are in reach through whatever was connected. The two excess rows here both sit behind a boundary, which is the exception in this directory.",
      "logo": "claude",
      "brand": "#D97757",
      "group": "Chat assistants"
    },
    {
      "slug": "chatgpt-web",
      "vid": "dd1teu9n",
      "key": "8f7da12c7ab0f2496471ff9d5e4f4755975ce51e7830dafa39dc728b5aa71001",
      "app": "ChatGPT in the browser",
      "title": "ChatGPT in the browser, nothing connected",
      "title_lead": "ChatGPT in the browser,",
      "title_tail": "nothing connected.",
      "shape": "openai/chatgpt-web/default",
      "family": "chat",
      "glyph": "GP",
      "blurb": "The smallest grant in the set: one capability, one wanted, no excess. The baseline every other shape is measured against, and the proof that a template can be empty and still be right.",
      "logo": "openai",
      "brand": "#412991",
      "group": "Chat assistants"
    },
    {
      "slug": "browser-extension",
      "vid": "exsaxrfr",
      "key": "875818b8d845c17801db7aa4bef5037a70e084db717749533179af0b2abc68df",
      "app": "A browser extension",
      "title": "A browser extension with broad host permissions",
      "title_lead": "A browser extension",
      "title_tail": "with broad host permissions.",
      "shape": "generic/browser-extension/broad-host-permissions",
      "family": "browser",
      "glyph": "EX",
      "blurb": "Other people's data, and the mandate nobody wrote down. Three capabilities, all three irreversible; the shortest policy in the directory and not the mildest.",
      "logo": "googlechrome",
      "brand": "#4285F4",
      "group": "Chat assistants"
    },
    {
      "slug": "github-actions",
      "vid": "0hpdpj80",
      "key": "28afd90f03365372d9c0181808680519523ffdbeadc1fce7ec8e2074c28e36e3",
      "app": "GitHub Actions",
      "title": "A GitHub Actions runner, a hosted CI job",
      "title_lead": "GitHub Actions,",
      "title_tail": "a hosted CI job.",
      "shape": "github/actions-runner/ci",
      "family": "ci",
      "glyph": "GA",
      "blurb": "A hosted runner under a service account: persistence, and reach beyond the turn. Eight of eight rows measured, the only fully measured shape besides the web container.",
      "logo": "githubactions",
      "brand": "#2088FF",
      "group": "Automation & CI"
    },
    {
      "slug": "scheduled-job",
      "vid": "kd7zeimj",
      "key": "cf9307d3ac3f3674049590684d9af0c10116364c813dea77d8584c8fa5a10e7c",
      "app": "A scheduled job",
      "title": "A scheduled job running as a service account",
      "title_lead": "A scheduled job",
      "title_tail": "under a service account.",
      "shape": "generic/scheduled-job/service-account",
      "family": "service",
      "glyph": "SJ",
      "blurb": "A job that outlives the person who made it, running as a service account nobody logs in as. Seven capabilities, four wanted, four with nothing in the way.",
      "logo": "clock",
      "brand": "#374151",
      "group": "Automation & CI"
    },
    {
      "slug": "google-workspace-mcp",
      "vid": "pq7ct02p",
      "key": "093c4c58f1593dacecc727de965ee22f883a6530cac20b2ff9ae6b7ea811c1e4",
      "app": "Google Workspace MCP servers",
      "title": "The Google Workspace MCP servers",
      "title_lead": "The Google Workspace",
      "title_tail": "MCP servers.",
      "shape": "google/workspace-mcp/default",
      "family": "google",
      "glyph": "G",
      "blurb": "Gmail, Drive, Docs, Sheets, Slides, Calendar and Chat, one server each. The page advertises drafting mail and scheduling meetings; the scopes it asks for send mail and cannot touch a calendar.",
      "kind": "connector",
      "logo": "google",
      "brand": "#4285F4",
      "group": "Mail & files connectors"
    },
    {
      "slug": "gmail-readonly",
      "vid": "l2zlv3ng",
      "key": "865ea2d50ada749c30554380f22202dffe4c362a4a85a565accd045b84eefaf8",
      "app": "Gmail, read-only scope",
      "title": "An assistant on a personal Gmail mailbox",
      "title_lead": "An assistant on a",
      "title_tail": "personal Gmail mailbox.",
      "shape": "google/gmail/readonly-connector",
      "family": "mail",
      "glyph": "M",
      "blurb": "The narrowest scope that reads one message reads every message. Lab 03 asked the model site for this shape first; here it is, read from Google's scope page.",
      "kind": "connector",
      "logo": "gmail",
      "brand": "#EA4335",
      "group": "Mail & files connectors"
    },
    {
      "slug": "google-drive-readonly",
      "vid": "vz03p8it",
      "key": "e04bb066d11479d33ecb9e5d0c1a621e13e4599e8c2b5380001ab16e8c932270",
      "app": "Google Drive, read-only scope",
      "title": "An assistant on a personal Google Drive",
      "title_lead": "An assistant on a",
      "title_tail": "personal Google Drive.",
      "shape": "google/drive/readonly-connector",
      "family": "files",
      "glyph": "D",
      "blurb": "The default corpus is \"files owned by or shared to the user\": everything anybody ever shared, on day one, without anyone choosing it.",
      "kind": "connector",
      "logo": "googledrive",
      "brand": "#4285F4",
      "group": "Mail & files connectors"
    },
    {
      "slug": "claude-m365-connector",
      "vid": "dgx3nvu4",
      "key": "43d439062419da78ef22e544257d775f5774b33830d92f7a3abe5c05c2873669",
      "app": "Microsoft 365 connector (Claude)",
      "title": "Claude's Microsoft 365 connector",
      "title_lead": "Claude's",
      "title_tail": "Microsoft 365 connector.",
      "shape": "anthropic/microsoft-365-connector/default",
      "family": "microsoft",
      "glyph": "MS",
      "blurb": "Delegated permissions, consented once by a Global Administrator. Shared mailboxes are in scope; site-specific narrowing is unsupported because the search is tenant-wide; and the page that says \"read-only access\" also lists the tools that send mail as the user.",
      "kind": "connector",
      "logo": "microsoft",
      "brand": "#5E5E5E",
      "group": "Mail & files connectors"
    },
    {
      "slug": "dropbox-mcp",
      "vid": "9eqa7e4p",
      "key": "f22db64f51e4268a4531bebe0c6d46f3e51dd1337193a7e8137efac9cdfc5990",
      "app": "Dropbox MCP server",
      "title": "The official Dropbox MCP server",
      "title_lead": "The official",
      "title_tail": "Dropbox MCP server.",
      "shape": "dropbox/mcp-server/default",
      "family": "files",
      "glyph": "Db",
      "blurb": "Eight scopes, two of them write and two of them sharing, and no folder-scoped variant. It reads, creates, moves, deletes and makes shared links; the page says files are not deleted permanently and that recovery depends on your plan.",
      "kind": "connector",
      "logo": "dropbox",
      "brand": "#0061FF",
      "group": "Mail & files connectors"
    },
    {
      "slug": "n8n-owner-api-key",
      "vid": "l8opgcug",
      "key": "d85b128b1eff181a71f3e4eec16a27510934ca73aecc450617b7c40d750909b3",
      "app": "n8n, owner API key",
      "title": "A self-hosted n8n instance, owner API key",
      "title_lead": "A self-hosted n8n instance,",
      "title_tail": "owner API key.",
      "shape": "n8n/self-hosted/owner-api-key",
      "family": "service",
      "glyph": "n8n",
      "kind": "measured",
      "blurb": "The first grant here measured on a live instance, by an early beta user's agent: full control of every automation, an outbound node with no restriction on target, every account visible, and credential metadata open through one door and shut through another.",
      "logo": "n8n",
      "brand": "#EA4B71",
      "group": "Automation & CI"
    }
  ],
  "asked_for": [
    {
      "slug": "claude-google-workspace-connector",
      "app": "Claude's Google Workspace connector",
      "family": "google",
      "glyph": "G",
      "blurb": "Gmail, Calendar and Drive from inside Claude. The connector's scope list has not been read yet; the Google pages behind it have.",
      "note": "not yet researched \u2014 next in the queue",
      "logo": "google",
      "brand": "#4285F4"
    },
    {
      "slug": "slack-connector",
      "app": "An assistant connected to Slack",
      "family": "chat",
      "glyph": "S",
      "blurb": "Channels are mostly other people's writing, and a bot token reaches every channel it is in.",
      "note": "not yet researched",
      "logo": "slack",
      "brand": "#4A154B"
    },
    {
      "slug": "github-connector",
      "app": "An assistant connected to GitHub",
      "family": "code",
      "glyph": "GH",
      "blurb": "A fine-grained token can be scoped to a repository; an OAuth app cannot, and most connectors are OAuth apps.",
      "note": "not yet researched",
      "logo": "github",
      "brand": "#181717"
    },
    {
      "slug": "notion-connector",
      "app": "An assistant connected to Notion",
      "family": "files",
      "glyph": "N",
      "blurb": "An integration is added page by page, which is the one connector model with a floor. Whether the assistant's connector uses it is the question.",
      "note": "not yet researched",
      "logo": "notion",
      "brand": "#000000"
    },
    {
      "slug": "salesforce-connector",
      "app": "An assistant connected to Salesforce",
      "family": "service",
      "glyph": "SF",
      "blurb": "A CRM is entirely third-party material by construction.",
      "note": "not yet researched",
      "logo": "salesforce",
      "brand": "#00A1E0"
    }
  ],
  "app_vault": {
    "vault_id": "fl3i7lu4",
    "key": "e37a0f80d65e2b486f8bb3253e313c65ecbb57e5664c3f1704346c70ac09639a",
    "entry": "index.html",
    "version": "v4",
    "note": "The renderer every application vault loads (site/vaults/_app/), pushed as its own vault. Public read key; read and nothing else."
  },
  "asked_for_note": "Connector shapes not yet built. Each becomes a vault once its vendor pages have been read and quoted; the four Lab 03 asked the model site for are built above, ahead of the model site, and carry their open questions in RESEARCH-NEEDED.md.",
  "functions": [
    {
      "slug": "access-to-the-crm",
      "app": "Access to the CRM",
      "logo": "crm",
      "brand": "#00A1E0",
      "blurb": "Customer records are third-party material by construction. Salesforce, HubSpot, Dynamics.",
      "note": "asked for \u2014 a policy for the function, whichever product holds it"
    },
    {
      "slug": "customer-service-desk",
      "app": "The customer-service desk",
      "logo": "desk",
      "brand": "#1A7F5A",
      "blurb": "Tickets, and the conversations inside them. Zendesk, Intercom, Freshdesk.",
      "note": "asked for"
    },
    {
      "slug": "finance-data",
      "app": "Finance data",
      "logo": "sheet",
      "brand": "#B45309",
      "blurb": "Spreadsheets, ledgers and the exports beside them. Sheets, Excel, NetSuite.",
      "note": "asked for"
    }
  ],
  "functions_note": "Policies by business function: what the agent is FOR, whichever product holds the data. The mandate is the same across products; the grant is per product. Each becomes a vault once one product's grant is documented for it."
}
