Play / The map / The capabilities / Run programs as the account

Run programs as the account

execute.process.hostexecute × process at host reach (the machine, container or account it runs as). Family: process. Effect: recoverable from a backup, a history or a revert, at a cost.

Granted by 6 of 9

ProfileControl on the pathEvidenceVia
Claude Code — web container● noneobservedshell (Bash)
Claude Code — local · confirm off● nonederivedshell (Bash)
Claude Code — local · confirm on◐ settingderivedshell (Bash)
Claude Desktop — local tools◐ settingderivedlocal files and commands (when enabled)
Scheduled job — service account● nonederivedthe job
GitHub Actions — hosted runner● noneobservedthe job's shell

What narrows it

The setting: keep the confirmation prompt on for commands, and run in a container: execution survives inside it and stops being execution on your machine

What it costs: a click per command · an afternoon for the container

Tier after: setting (prompt) · boundary (container)

Questions that ask about it

In the mandates

Edit the primitives · edit the reductions