Play / The map / The capabilities / Sign commits with the key it holds
Sign commits with the key it holds
authenticate-as.credential.signing — authenticate-as × credential at tenant reach (the organisation's accounts, repositories and services). Family: code. Effect: cannot be undone.
Granted by 3 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container | ● none | observed | shell (Bash) |
| Claude Code — local · confirm off | ● none | documented | shell (Bash) |
| Claude Code — local · confirm on | ● none | documented | shell (Bash) |
What narrows it
The setting: a signing key of the agent's own, so its commits are signed as it and not as you (the registry's identity records exist for this)
What it costs: an hour, and a second key to manage
Tier after: boundary
In the mandates
- not wanted by A coding assistant on my machine
- not wanted by A coding assistant in a container on the web