Play / The map / The products / ChatGPT — no connectors
ChatGPT (in the browser, no connectors)
An assistant in the vendor's environment. It reaches what you paste or upload and nothing on your machine: the vendor's environment is a boundary you did not build. DERIVED from the assess library's web tree. Browsing, if on, is the vendor's egress, not yours.
OpenAI · surface web · variant default · profile version 2026-09-05 · reaches 1 of 23 capabilities, 0 of which cannot be undone. Edit this profile · the file.
| Capability | Undo | ChatGPTno connectors |
|---|---|---|
| filesystem — files and directories | ||
| Read the project it is working onread.file.project | yes | ● |
| Change the project it is working onwrite.file.project | with-effort | · |
| Read any file the account can reachread.file.host | no | · |
| Change any file the account can reachwrite.file.host | with-effort | · |
| Delete files anywhere the account can reachdelete.file.host | no | · |
| Read a retained record: shell history, past sessionsread.record.history | no | · |
| process — programs and their execution | ||
| Run programs as the accountexecute.process.host | with-effort | · |
| Run programs inside its own sandbox onlyexecute.process.self | yes | · |
| network — endpoints and hosts | ||
| Reach a permitted list of hostssend.endpoint.allowed | no | · |
| Reach any host on the internetsend.endpoint.world | no | · |
| identity — credentials and who the agent can act as | ||
| Read credentials stored where it runsread.credential.host | no | · |
| Act in accounts with the credentials it holdsauthenticate-as.credential.tenant | no | · |
| Change its own permission settingsgrant.credential.self | yes | · |
| communication — messages to people | ||
| Send a message to anyonesend.message.world | no | · |
| Read mail or chat it is connected toread.message.tenant | no | · |
| code — repositories and what lands in them | ||
| Commit to the repository it was pointed atwrite.repository.project | with-effort | · |
| Push to a code host (any branch it can reach)write.repository.tenant | with-effort | · |
| Sign commits with the key it holdsauthenticate-as.credential.signing | no | · |
| Publish packages, images or pages under the name it holdscreate.record.world | no | · |
| money — budgets and spend | ||
| Spend money or tokens against an account it holdswrite.budget.tenant | no | · |
| schedule — things that outlive the turn | ||
| Create something that outlives the turn where it runs (a cron, a service)create.schedule.host | yes | · |
| Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)create.schedule.tenant | yes | · |
| browser — what a browser extension or automation can see and do in your browser | ||
| Read every page you visitread.record.browsing | no | · |
What host, tenant and world mean here
| Reach | Here, it means |
|---|---|
| host | the vendor's environment; not your machine |
| tenant | nothing of yours |
| world | the vendor's egress, if browsing is on |
What it cannot reach, and why
| What | Why | Source |
|---|---|---|
| your machine's files | the vendor's environment is a boundary you did not build | assess/library.json (web: home) |
| your accounts | no connectors are on | assess/library.json (web: connect) |
The grant, tool by tool
Two tools in one session reach different things, which is why the unit of mapping is the tool and not the product. Each row carries the control on the path and the tier of evidence behind it.
conversation and uploads
| Capability | Control | Evidence | What is on the path |
|---|---|---|---|
Read the project it is working on read.file.project | ● none | derived | — · what you paste or upload — and a record once read is exposure that cannot be unread, on the vendor's side |
What narrows it
For each capability in the grant: the specific setting or arrangement that narrows it, what it costs, and the tier the control reaches afterwards. Guidance is free and stays free.
| Capability | The setting | What it costs | Tier after |
|---|---|---|---|
| Read the project it is working on | none: this is what it is for | nothing | none |
Against the mandates
What a reasonable person wanted from this setup, and the gap: ▲ excess is what it can do that they did not want; ▼ shortfall is what they wanted that it cannot do.
| Mandate | Excess | Shortfall |
|---|---|---|
| Chat in the browser, nothing connected | ▲ 0 | ▼ 0 |
Sources
assess/library.json (surface web)