Play / The map / The mandates / Chat in the browser, nothing connected

Chat in the browser, nothing connected

I paste things in and read what comes back. That is the whole mandate, and the honest baseline: a chat window with nothing connected should be able to do nothing else.

Status: starting-point · authored 2026-09-09 · the site, as a starting point — not measured, not surveyed; the first thing to argue with · edit this mandate

The delta

Against every profile this mandate applies to. ▲ is authority you did not ask for; ▼ is something you were counting on that is not there. The tally is at the bottom.

excess — it can, and you did not want it to shortfall — it cannot, and you wanted it to aligned — it can, and you wanted it to aligned — it cannot, and you did not want it to? it can, and the mandate does not say· it cannot, and the mandate does not say
Capability ChatGPTno connectors
filesystem
Read the project it is working on
Change the project it is working on ·
Read any file the account can reach
Change any file the account can reach
Delete files anywhere the account can reach
Read a retained record: shell history, past sessions
process
Run programs as the account
Run programs inside its own sandbox only ·
network
Reach a permitted list of hosts ·
Reach any host on the internet
identity
Read credentials stored where it runs
Act in accounts with the credentials it holds
Change its own permission settings ·
communication
Send a message to anyone
Read mail or chat it is connected to
code
Commit to the repository it was pointed at ·
Push to a code host (any branch it can reach)
Sign commits with the key it holds ·
Publish packages, images or pages under the name it holds
money
Spend money or tokens against an account it holds
schedule
Create something that outlives the turn where it runs (a cron, a service) ·
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)
browser
Read every page you visit ·
The delta ▲ 0 ▼ 0

In words

The mandate, row by row

CapabilityPositionNote
Read the project it is working onwant
Read any file the account can reachdo not want
Change any file the account can reachdo not want
Delete files anywhere the account can reachdo not want
Run programs as the accountdo not want
Reach any host on the internetdo not want
Read credentials stored where it runsdo not want
Act in accounts with the credentials it holdsdo not want
Send a message to anyonedo not want
Read mail or chat it is connected todo not want
Push to a code host (any branch it can reach)do not want
Publish packages, images or pages under the name it holdsdo not want
Spend money or tokens against an account it holdsdo not want
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)do not want
Read a retained record: shell history, past sessionsdo not want
You cannot deny the excess rows. The agent already has the access. What is left is how long you are prepared to live with each one and who says so — what to do next.