Play / The map / The mandates / A coding assistant in a container on the web

A coding assistant in a container on the web

I attached a repository and I want it worked on: read it, change it, run things, commit, and push to that repository — that is why I attached it. The container is disposable, so what it does to the container's own files is its business. I do not want it signing as me, and I do not want it creating sessions or routines that keep going after this one ends.

Status: starting-point · authored 2026-09-09 · the site, as a starting point — not measured, not surveyed; the first thing to argue with · edit this mandate

The delta

Against every profile this mandate applies to. ▲ is authority you did not ask for; ▼ is something you were counting on that is not there. The tally is at the bottom.

excess — it can, and you did not want it to shortfall — it cannot, and you wanted it to aligned — it can, and you wanted it to aligned — it cannot, and you did not want it to? it can, and the mandate does not say· it cannot, and the mandate does not say
Capability Claude Codeweb container
filesystem
Read the project it is working on
Change the project it is working on
Read any file the account can reachunstated: host is the container, and the container is thrown away ?
Change any file the account can reach ?
Delete files anywhere the account can reach ?
Read a retained record: shell history, past sessions
process
Run programs as the account
Run programs inside its own sandbox only ·
network
Reach a permitted list of hosts
Reach any host on the internet ·
identity
Read credentials stored where it runsunstated: the only keys in the image are the session's own ?
Act in accounts with the credentials it holdsunstated: the scoped platform token is how it pushes at all — not a want, not a refusal, a mechanism ?
Change its own permission settings ·
communication
Send a message to anyone ·
Read mail or chat it is connected to ·
code
Commit to the repository it was pointed at
Push to a code host (any branch it can reach)
Sign commits with the key it holds
Publish packages, images or pages under the name it holds ·
money
Spend money or tokens against an account it holds ·
schedule
Create something that outlives the turn where it runs (a cron, a service) ?
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)
browser
Read every page you visit ·
The delta ▲ 3 ▼ 0

In words

The mandate, row by row

CapabilityPositionNote
Read the project it is working onwant
Change the project it is working onwant
Run programs as the accountwant
Commit to the repository it was pointed atwant
Push to a code host (any branch it can reach)want
Reach a permitted list of hostswant
Sign commits with the key it holdsdo not want
Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)do not want
Read a retained record: shell history, past sessionsdo not want
Read any file the account can reachunstatedunstated: host is the container, and the container is thrown away
Read credentials stored where it runsunstatedunstated: the only keys in the image are the session's own
Act in accounts with the credentials it holdsunstatedunstated: the scoped platform token is how it pushes at all — not a want, not a refusal, a mechanism
You cannot deny the excess rows. The agent already has the access. What is left is how long you are prepared to live with each one and who says so — what to do next.