Play / The map / The capabilities
The capabilities
A capability is a verb crossed with an object class crossed with a reach, carrying whether its effect can be undone. Read a file in the project and read a file anywhere the account can are two capabilities; /etc/passwd is not a third — a specific path is an instance, never a new primitive.
The rules the set is written under
- A specific path, host or mailbox is an instance of a primitive, never a new one.
- Reversibility sits on the primitive, not the instance, because it decides whether a gap is a nuisance or a loss — and this estate has settled that recoverability decides insurability.
- A grant containing irreversible primitives is a different object from one that does not, however many rows each has.
- The set is a starting set and will be wrong at the edges from the first week. A proposed primitive that is a specific thing is an instance; one that is a new verb, object class or reach needs a probe.
- A label never says 'your' or 'as you': what host, tenant and world mean is the profile's to say (reach_names), because for an agent in a vendor's container 'host' is the container and 'tenant' is a scoped token, not your machine and not your accounts.
Reach
| Reach | Means |
|---|---|
| self | the agent's own process, sandbox or turn |
| project | the working tree or workspace it was pointed at |
| host | the machine, container or account it runs as |
| tenant | the organisation's accounts, repositories and services |
| world | anything on the internet |
Reach is the axis people get wrong. Host for an agent in a vendor's container is the container, and tenant is a scoped token; each product's page says what the words mean there.