{
 "_authority": "NONE \u2014 generated by admin/build/gen_simulator.py. Every push row is the output of packs/grant-and-mandate/tools/mandate.py, re-run at build time. Recompute it yourself.",
 "what_this_is": "The precomputed resolution table behind /simulator/. The browser looks answers up here; it never adjudicates. Keyed card|world|mandate.",
 "generated_from": {
  "mandates": [
   "packs/grant-and-mandate/mandates/mandate-v1.json",
   "packs/grant-and-mandate/mandates/current.json"
  ],
  "twins": [
   "packs/grant-and-mandate/library/claude-code-remote__ccr-container__2026-08-26.json",
   "packs/grant-and-mandate/library/github-actions-runner__ci__2026-08-26.json"
  ],
  "tool": "packs/grant-and-mandate/tools/mandate.py"
 },
 "cards": [
  {
   "id": "push-feature",
   "suit": "DOES",
   "title": "push to claude/write-book-pdf"
  },
  {
   "id": "push-dev",
   "suit": "DOES",
   "title": "push to dev"
  },
  {
   "id": "push-main",
   "suit": "DOES",
   "title": "push to main"
  },
  {
   "id": "egress-allow",
   "suit": "DOES",
   "title": "reach an allowlisted host"
  },
  {
   "id": "egress-deny",
   "suit": "DOES",
   "title": "reach a NON-allowlisted host"
  },
  {
   "id": "exec",
   "suit": "DOES",
   "title": "execute a program, install software"
  },
  {
   "id": "recall",
   "suit": "DOES",
   "title": "read this environment's own session record"
  },
  {
   "id": "escalate",
   "suit": "DOES",
   "title": "escalate to administrator"
  }
 ],
 "worlds": [
  {
   "id": "container",
   "name": "The container",
   "twin": "packs/grant-and-mandate/library/claude-code-remote__ccr-container__2026-08-26.json",
   "measured": "2026-08-26"
  },
  {
   "id": "runner",
   "name": "The CI runner",
   "twin": "packs/grant-and-mandate/library/github-actions-runner__ci__2026-08-26.json",
   "measured": "2026-08-26"
  }
 ],
 "table": {
  "push-feature|container|v1": {
   "verdict": "PERMIT",
   "tool": "PERMIT   claude/write-book-pdf  (mandate v1, allow=['claude/**'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-feature|container|v2": {
   "verdict": "PERMIT",
   "tool": "PERMIT   claude/write-book-pdf  (mandate v2, allow=['claude/**', 'dev'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-feature|runner|v1": {
   "verdict": "PERMIT",
   "tool": "PERMIT   claude/write-book-pdf  (mandate v1, allow=['claude/**'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "push-feature|runner|v2": {
   "verdict": "PERMIT",
   "tool": "PERMIT   claude/write-book-pdf  (mandate v2, allow=['claude/**', 'dev'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "push-dev|container|v1": {
   "verdict": "REFUSED",
   "tool": "REFUSED  dev  (mandate v1 permits ['claude/**'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-dev|container|v2": {
   "verdict": "PERMIT",
   "tool": "PERMIT   dev  (mandate v2, allow=['claude/**', 'dev'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-dev|runner|v1": {
   "verdict": "REFUSED",
   "tool": "REFUSED  dev  (mandate v1 permits ['claude/**'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "push-dev|runner|v2": {
   "verdict": "PERMIT",
   "tool": "PERMIT   dev  (mandate v2, allow=['claude/**', 'dev'], expires 2026-12-31T00:00:00Z)",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "push-main|container|v1": {
   "verdict": "REFUSED",
   "tool": "REFUSED  main  (mandate v1 permits ['claude/**'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-main|container|v2": {
   "verdict": "REFUSED",
   "tool": "REFUSED  main  (mandate v2 permits ['claude/**', 'dev'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n3: push commits to the attached repository",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the attached repository",
   "reaches": "the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the rele"
  },
  "push-main|runner|v1": {
   "verdict": "REFUSED",
   "tool": "REFUSED  main  (mandate v1 permits ['claude/**'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "push-main|runner|v2": {
   "verdict": "REFUSED",
   "tool": "REFUSED  main  (mandate v2 permits ['claude/**', 'dev'])",
   "by": "the enforcement tool, re-run at build",
   "grant": "n4: push commits to the configured remote",
   "tier": "expectation",
   "measured": "2026-08-26",
   "label": "push commits to the configured remote",
   "reaches": "the repository at github.com/SGit-AI/SGit-AI__Website__PKI"
  },
  "egress-allow|container|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n2: outbound HTTPS, through a mandatory egress proxy",
   "tier": "boundary",
   "measured": "2026-08-26",
   "label": "outbound HTTPS, through a mandatory egress\u2026",
   "reaches": "github.com and its API, package registries (PyPI, npm), the sgit.ai estate, and other hosts the proxy policy admits"
  },
  "egress-allow|container|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n2: outbound HTTPS, through a mandatory egress proxy",
   "tier": "boundary",
   "measured": "2026-08-26",
   "label": "outbound HTTPS, through a mandatory egress\u2026",
   "reaches": "github.com and its API, package registries (PyPI, npm), the sgit.ai estate, and other hosts the proxy policy admits"
  },
  "egress-allow|runner|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n3: outbound network access",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "outbound network access",
   "reaches": "hosts reachable: github.com 200, pypi.org 200, example.com 200 \u2014 UNRESTRICTED"
  },
  "egress-allow|runner|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n3: outbound network access",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "outbound network access",
   "reaches": "hosts reachable: github.com 200, pypi.org 200, example.com 200 \u2014 UNRESTRICTED"
  },
  "egress-deny|container|v1": {
   "verdict": "UNKNOWN",
   "tool": "",
   "by": "measurement was refused here \u2014 the honest outcome is unknown, not no",
   "grant": "n9: reach non-allowlisted external hosts",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "reach non-allowlisted external hosts",
   "reaches": "UNKNOWN \u2014 the egress policy's exact perimeter was not probed after the classifier refused the host-sweep"
  },
  "egress-deny|container|v2": {
   "verdict": "UNKNOWN",
   "tool": "",
   "by": "measurement was refused here \u2014 the honest outcome is unknown, not no",
   "grant": "n9: reach non-allowlisted external hosts",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "reach non-allowlisted external hosts",
   "reaches": "UNKNOWN \u2014 the egress policy's exact perimeter was not probed after the classifier refused the host-sweep"
  },
  "egress-deny|runner|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n3: outbound network access",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "outbound network access",
   "reaches": "hosts reachable: github.com 200, pypi.org 200, example.com 200 \u2014 UNRESTRICTED"
  },
  "egress-deny|runner|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n3: outbound network access",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "outbound network access",
   "reaches": "hosts reachable: github.com 200, pypi.org 200, example.com 200 \u2014 UNRESTRICTED"
  },
  "exec|container|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n5: execute arbitrary programs and install software",
   "tier": "setting",
   "measured": "2026-08-26",
   "label": "execute arbitrary programs and install\u2026",
   "reaches": "anything installable from reachable registries \u2014 this session installed a CLI (sgit-ai) and used a pre-installed browser"
  },
  "exec|container|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n5: execute arbitrary programs and install software",
   "tier": "setting",
   "measured": "2026-08-26",
   "label": "execute arbitrary programs and install\u2026",
   "reaches": "anything installable from reachable registries \u2014 this session installed a CLI (sgit-ai) and used a pre-installed browser"
  },
  "exec|runner|v1": {
   "verdict": "ABSENT",
   "tool": "",
   "by": "the twin has no node for this capability in this world",
   "grant": "\u2014",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "",
   "reaches": ""
  },
  "exec|runner|v2": {
   "verdict": "ABSENT",
   "tool": "",
   "by": "the twin has no node for this capability in this world",
   "grant": "\u2014",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "",
   "reaches": ""
  },
  "recall|container|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n6: read and write the session's own accumulated record",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "read and write the session's own accumulated\u2026",
   "reaches": "the transcript, persisted tool outputs, and uploaded files for this session \u2014 a superset of every file the session read "
  },
  "recall|container|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n6: read and write the session's own accumulated record",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "read and write the session's own accumulated\u2026",
   "reaches": "the transcript, persisted tool outputs, and uploaded files for this session \u2014 a superset of every file the session read "
  },
  "recall|runner|v1": {
   "verdict": "UNKNOWN",
   "tool": "",
   "by": "measurement was refused here \u2014 the honest outcome is unknown, not no",
   "grant": "n6: read this environment's accumulated session record",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "read this environment's accumulated session\u2026",
   "reaches": "no retained session record found at the usual paths"
  },
  "recall|runner|v2": {
   "verdict": "UNKNOWN",
   "tool": "",
   "by": "measurement was refused here \u2014 the honest outcome is unknown, not no",
   "grant": "n6: read this environment's accumulated session record",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "read this environment's accumulated session\u2026",
   "reaches": "no retained session record found at the usual paths"
  },
  "escalate|container|v1": {
   "verdict": "ABSENT",
   "tool": "",
   "by": "the twin has no node for this capability in this world",
   "grant": "\u2014",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "",
   "reaches": ""
  },
  "escalate|container|v2": {
   "verdict": "ABSENT",
   "tool": "",
   "by": "the twin has no node for this capability in this world",
   "grant": "\u2014",
   "tier": "unknown",
   "measured": "2026-08-26",
   "label": "",
   "reaches": ""
  },
  "escalate|runner|v1": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n1a: escalate to administrator",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "escalate to administrator",
   "reaches": "everything, without a further credential"
  },
  "escalate|runner|v2": {
   "verdict": "HAPPENS",
   "tool": "",
   "by": "observed on the twin, 2026-08-26",
   "grant": "n1a: escalate to administrator",
   "tier": "none",
   "measured": "2026-08-26",
   "label": "escalate to administrator",
   "reaches": "everything, without a further credential"
  }
 }
}
