Play / The map / The mandates / A coding assistant in a container on the web
A coding assistant in a container on the web
I attached a repository and I want it worked on: read it, change it, run things, commit, and push to that repository — that is why I attached it. The container is disposable, so what it does to the container's own files is its business. I do not want it signing as me, and I do not want it creating sessions or routines that keep going after this one ends.
Status: starting-point · authored 2026-09-09 · the site, as a starting point — not measured, not surveyed; the first thing to argue with · edit this mandate
The delta
Against every profile this mandate applies to. ▲ is authority you did not ask for; ▼ is something you were counting on that is not there. The tally is at the bottom.
In words
- Claude Code — web container: excess — Sign commits with the key it holds; Read a retained record: shell history, past sessions; Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session). No shortfall.
The mandate, row by row
| Capability | Position | Note |
|---|---|---|
| Read the project it is working on | want | |
| Change the project it is working on | want | |
| Run programs as the account | want | |
| Commit to the repository it was pointed at | want | |
| Push to a code host (any branch it can reach) | want | |
| Reach a permitted list of hosts | want | |
| Sign commits with the key it holds | do not want | |
| Create something that outlives the session, on the platform (a routine, a scheduled trigger, a new session) | do not want | |
| Read a retained record: shell history, past sessions | do not want | |
| Read any file the account can reach | unstated | unstated: host is the container, and the container is thrown away |
| Read credentials stored where it runs | unstated | unstated: the only keys in the image are the session's own |
| Act in accounts with the credentials it holds | unstated | unstated: the scoped platform token is how it pushes at all — not a want, not a refusal, a mechanism |