Play / The map / The mandates / A scheduled job under a service account
A scheduled job under a service account
Run on schedule, read its own data, talk to the APIs it was built for with the account it was given, and stop. I did not want it spending money unattended or reaching arbitrary hosts.
Status: starting-point · authored 2026-09-09 · the site, as a starting point — not measured, not surveyed; the first thing to argue with · edit this mandate
The delta
Against every profile this mandate applies to. ▲ is authority you did not ask for; ▼ is something you were counting on that is not there. The tally is at the bottom.
▲ excess — it can, and you did not want it to▼ shortfall — it cannot, and you wanted it to✓ aligned — it can, and you wanted it to– aligned — it cannot, and you did not want it to? it can, and the mandate does not say· it cannot, and the mandate does not say
In words
- Scheduled job — service account: excess — Reach any host on the internet; Spend money or tokens against an account it holds. Shortfall — Reach a permitted list of hosts.
The mandate, row by row
| Capability | Position | Note |
|---|---|---|
| Run programs as the account | want | |
| Read any file the account can reach | want | |
| Reach a permitted list of hosts | want | |
| Act in accounts with the credentials it holds | want | |
| Spend money or tokens against an account it holds | do not want | |
| Reach any host on the internet | do not want | |
| Create something that outlives the turn where it runs (a cron, a service) | unstated | unstated: it is itself scheduled; whether it may schedule more of itself is a real question and the mandate does not pretend to answer it |
You cannot deny the excess rows. The agent already has the access. What is left is how long you are prepared to live with each one and who says so — what to do next.