Play / The map / The products / Claude.ai — connectors on

Claude (in the browser, with connectors switched on)

The same web assistant with connectors you switched on — a drive, a code host, a cloud account. Each connector is a boundary (the vendor holds the token, scoped as you scoped it) and each one is a row you granted by clicking. DERIVED from the assess library's web tree; which connectors is yours to name.

Anthropic · surface web · variant connectors-on · profile version 2026-09-05 · reaches 5 of 23 capabilities, 3 of which cannot be undone. Edit this profile · the file.

CapabilityUndo Claude.aiconnectors on
filesystem — files and directories
Read the project it is working onread.file.projectyes
Change the project it is working onwrite.file.projectwith-effort ·
Read any file the account can reachread.file.hostno
Change any file the account can reachwrite.file.hostwith-effort ·
Delete files anywhere the account can reachdelete.file.hostno ·
Read a retained record: shell history, past sessionsread.record.historyno ·
process — programs and their execution
Run programs as the accountexecute.process.hostwith-effort ·
Run programs inside its own sandbox onlyexecute.process.selfyes ·
network — endpoints and hosts
Reach a permitted list of hostssend.endpoint.allowedno ·
Reach any host on the internetsend.endpoint.worldno ·
identity — credentials and who the agent can act as
Read credentials stored where it runsread.credential.hostno ·
Act in accounts with the credentials it holdsauthenticate-as.credential.tenantno
Change its own permission settingsgrant.credential.selfyes ·
communication — messages to people
Send a message to anyonesend.message.worldno ·
Read mail or chat it is connected toread.message.tenantno
code — repositories and what lands in them
Commit to the repository it was pointed atwrite.repository.projectwith-effort ·
Push to a code host (any branch it can reach)write.repository.tenantwith-effort
Sign commits with the key it holdsauthenticate-as.credential.signingno ·
Publish packages, images or pages under the name it holdscreate.record.worldno ·
money — budgets and spend
Spend money or tokens against an account it holdswrite.budget.tenantno ·
schedule — things that outlive the turn
Create something that outlives the turn where it runs (a cron, a service)create.schedule.hostyes ·
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)create.schedule.tenantyes ·
browser — what a browser extension or automation can see and do in your browser
Read every page you visitread.record.browsingno ·

What host, tenant and world mean here

ReachHere, it means
hostwhat the drive connector is scoped to; not your machine
tenantthe accounts you connected, as you scoped them
worldthe vendor's egress

What it cannot reach, and why

WhatWhySource
your machine's filesa browser tab; the connector reaches a drive, not a diskassess/library.json (web: home)

The grant, tool by tool

Two tools in one session reach different things, which is why the unit of mapping is the tool and not the product. Each row carries the control on the path and the tier of evidence behind it.

conversation and uploads

CapabilityControlEvidenceWhat is on the path
Read the project it is working on read.file.project● nonederived

connectors

CapabilityControlEvidenceWhat is on the path
Read any file the account can reach read.file.host○ boundaryderivedthe connector's scope, held by the vendor · a drive connector: your other files, as scoped
Push to a code host (any branch it can reach) write.repository.tenant○ boundaryderivedthe connector's scope · a code-host connector
Act in accounts with the credentials it holds authenticate-as.credential.tenant○ boundaryderivedthe connector's scope · a cloud connector acts as you
Read mail or chat it is connected to read.message.tenant○ boundaryderivedthe connector's scope · a mail or chat connector reads your mail

What narrows it

For each capability in the grant: the specific setting or arrangement that narrows it, what it costs, and the tier the control reaches afterwards. Guidance is free and stays free.

CapabilityThe settingWhat it costsTier after
Act in accounts with the credentials it holdsscoped, short-lived tokens issued to the agent rather than your own; read-only where read is all it needsan hour per service, and rotationboundary
Read any file the account can reachrun the agent in a container with only the project mounted, or under a separate user accountan afternoon, then ongoing friction (container) · days, and it fights you (account)boundary
Read the project it is working onnone: this is what it is fornothingnone
Read mail or chat it is connected toa connector scoped to one folder or label, or nonethe agent answers about lessboundary
Push to a code host (any branch it can reach)a branch protection rule at the host — the agent cannot edit it — and a pre-push hook in the clone for the earlier, cheaper refusalminutes; and a review step before anything deploysboundary (host rule) · setting (hook)

Against the mandates

What a reasonable person wanted from this setup, and the gap: ▲ excess is what it can do that they did not want; ▼ shortfall is what they wanted that it cannot do.

MandateExcessShortfall
Chat, with connectors switched on▲ 1▼ 0

Sources

A derived row is an inference from what this kind of program architecturally is. It is a claim, and the most useful pull request on this page is one that replaces a claim with a probe run — how.