Capabilities tied to a published release
Features with their limits in view
Explore implemented capabilities by the work they support, with maturity, applicability, prerequisites, and operating limits kept beside exact release evidence.
Two independent signals
How release channels and capability maturity differ
BUILD / CHANNEL
Stable, Beta, or Nightly
Describes how a complete build is distributed. This inventory names one exact published Nightly; capabilities listed for that Nightly are not presented as Stable capabilities.
ROW / MATURITY
Stable maturity, beta maturity, or Experimental
Describes one capability inside the named Nightly build. Capability maturity is not a release channel, security certification, or promise that every surface behaves identically.
01
Models
5 matching capabilities
-
agent.adaptive-routing
Transparent adaptive model routing
An opt-in deterministic router chooses eligible models by task role, capability, privacy, reliability, latency, cost, cache opportunity, and explicit preference while preserving manual pins.
Open the Transparent adaptive model routing guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Routing metadata and price estimates are operator/provider inputs, unknown cost or latency becomes ineligible only when a corresponding hard ceiling is configured, and invocation recovery remains the separate failover subsystem.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Local-only and local-to-cloud rules are hard gates; retained decisions are content-free, aggregate outcome learning is off until consented, and all routing telemetry can be reset.
- Approval
- Enabling adaptive routing, changing policy, allowing local-to-cloud movement, and opting into aggregate learning are explicit operator settings actions.
-
agent.provider-conformance
Model/protocol conformance records
Exact model/adapter conformance records keep declared capability, an offline transcript round-trip matrix, and opt-in bounded live evidence separate, invalidate evidence when the adapter or model identity changes, and refuse effort values outside the protocol contract with an actionable explanation.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Synthetic verdicts prove the adapter contract against scripted fixtures, not live provider behavior; live evidence expires after thirty days and is dropped when the adapter code changes; the provider-reported model string is not captured yet.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Records and benchmark reports hold verdicts, reason codes, digests, timestamps, and exact model identities only; opaque native reasoning and signature material is replayed under its provider contract and is never stored as evidence or telemetry.
- Approval
- Live probes run only with an explicit model and request budget on the command line; offline probes and record refreshes from Settings send fixed synthetic prompts to no provider.
-
agent.provider-resilience
Safe provider recovery and circuit breaking
An opt-in provider-neutral coordinator applies normalized failure policy, bounded pre-response retries, eligible-model failover, partial-output retention, and durable single-probe circuit breakers without replaying consequential tools.
Open the Safe provider recovery and circuit breaking guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Automatic recovery is prohibited after visible output, cancellation, a safety refusal, invalid/auth/unknown failures, or consequential tool results; live provider behavior, billing, and registry metadata remain provider/operator inputs.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Circuit and attempt state is content-free and bounded; prompts, responses, tool arguments/results, credentials, and provider error bodies are excluded and diagnostics can be reset.
- Approval
- Recovery is disabled by default; enabling it, changing fallback/action policy, allowing fallback from a pinned model, and resetting circuits/traces are explicit operator settings actions.
-
agent.structured-outputs
Schema-constrained model outputs
Versioned JSON Schema contracts provide provider-native enforcement when available, canonical local validation, bounded repair, typed failures, privacy-safe evidence, and accessible result rendering.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Schema compliance does not prove factual correctness; native keyword support and limits vary by provider, while unsupported models require the bounded prompt fallback unless native enforcement is mandatory.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Unvalidated response text is buffered; traces retain contract identity, validation state, usage, known cost, and hashes without raw candidate content by default.
- Approval
- Structured output does not bypass tool, connector, workflow, or artifact approval policy.
-
models.image-generation
Image generation
Image-capable configured providers can generate raster artifacts through a typed tool path.
Open the Image generation guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop
- Prerequisites
- A configured image-capable model
Operating limit
Supported sizes, formats, edits, pricing, and safety policy are provider-specific.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Prompts and reference images are sent to the selected image provider.
- Approval
- Provider calls follow the active tool policy.
02
Core agent
10 matching capabilities
-
agent.context-continuity
Inspectable long-task context continuity
A bounded continuity record carries the objective, authoritative owner constraints, accepted decisions, unresolved work, artifact revisions, and remaining verification across repeated compactions, a restart, and a smaller-model switch, with retrievable references to omitted tool output and an inspectable context budget.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, API, Service
- Prerequisites
- None listed in the registry
Operating limit
The default compaction strategy is unchanged pending the packaged offline comparison; retained output is capped per session and by size, a truncated body keeps a whole-output digest, and the budget's cache figures come from the segment planner's estimates rather than measured provider billing.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- The record, its references, and the retained tool output stay in the host's local state directory, field-encrypted under the installation's own state-encryption boundary when one is configured; a reference stores a digest of the bytes it stands for, never a copy that outlives its retention cap.
- Approval
- Resolving a reference passes the same principal and scope the original action ran under, so recovering historical output can never widen a grant; owner constraints are authoritative and a model-authored summary cannot alter them.
-
agent.durable-goals
Durable bounded goals
Versioned goals continue through the ordinary host boundary with leases, multidimensional budgets, explicit authority, evidence-driven completion, and conservative restart recovery.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Persistent Holaryn host for autonomous continuation
Operating limit
Prepared attempts resume exactly once, but a non-journaled attempt interrupted after dispatch is paused as uncertain and must be reviewed.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Goal metadata, budget ledgers, evidence, blockers, and decisions persist locally; redacted export is the default.
- Approval
- Scope, budget, workspace, continuation, and authority expansion requires a named reviewer; underlying tools retain normal approval policy.
-
agent.local-model-lifecycle
Local model lifecycle and hardware manager
Holaryn can assess local hardware, import or adopt models, supervise Ollama and llama.cpp endpoints, benchmark them, and route them through the ordinary provider registry.
Open the Local model lifecycle and hardware manager guideBeta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Ollama or llama.cpp for managed serving, Enough disk and memory for the selected model
Operating limit
Hardware fit is advisory, built-in catalog entries do not guess mutable artifact URLs, and Holaryn cannot safely stop processes it did not launch in the current host process.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Hardware inventory, model metadata, roles, health, and benchmark metrics stay local; only an explicit HTTPS download or adopted non-loopback provider can use the network.
- Approval
- Downloads, endpoint scans, launches, benchmarks, role changes, and owned-file removal are explicit operator actions; removal requires confirmation.
-
agent.loop
Durable agent loop
Typed streaming turns, crash-safe checkpoints, cursor reattachment, fenced host recovery, tool outcomes, cancellation, steering, and terminal trace export share one event model.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
A configured model is required for model-backed turns; an external side effect interrupted before its durable outcome requires explicit operator review unless the external system proves idempotency.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Prompts and responses stay local except when sent to the selected model provider; durable events, checkpoints, tool evidence, artifacts, and trace exports are redacted and use optional state encryption.
- Approval
- Tool calls pass through the configured consequence-aware approval policy.
-
agent.onboarding
Resumable first-success onboarding
Desktop, CLI, Compose, source, and offline activation paths share versioned recovery, provider setup, model roles, a safe posture, streamed verification, and an approval-gated reversible demo.
Open the Resumable first-success onboarding guideStable maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
The demo writes only beneath the generated onboarding state sandbox; external moderated-usability evidence is tracked separately.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Milestones exclude credentials, prompts, responses, outputs, and user paths.
- Approval
- The generated-file demo always requires an explicit decision.
-
agent.prompt-cache
Prompt caching and deterministic prefix optimization
Opt-in provider prefix caching uses canonical segments, provider-aware boundaries, complete authorization isolation, content-free diagnostics, and paired quality/cost/latency evidence.
Open the Prompt caching and deterministic prefix optimization guideBeta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Provider minimums, TTLs, reporting, prices, data policies, and cache availability vary by model and account; unknown metrics remain unknown.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Caching is off by default; provider retention requires explicit consent, restricted data stops the prefix, and local diagnostics contain only hashes, sizes, ids, token aggregates, latency, and estimates.
- Approval
- Changing cache mode or accepting provider retention is an operator model-settings action.
-
agent.provider-capacity
Provider credential pools and fair capacity
Authorized compatible connections share durable quota, rate, health, priority, and weighted-fair scheduling with sticky-account and drain/revoke controls.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Pools coordinate one Holaryn state directory and compatible provider wire adapters; configured forecast accuracy bounds token and spend reservation accuracy.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Pool state stores opaque connection ids, safe aliases, content-free scope hashes, and aggregate usage only; raw credentials never enter the pool database or diagnostics.
- Approval
- Creating or changing a pool is an operator settings action; revocation requires a destructive confirmation and discards late results from cancelled leases.
-
agent.providers
Provider and model registry
Curated API, subscription, aggregator, local, and custom connections feed capability-aware model routing.
Open the Provider and model registry guideStable maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Available models and terms remain controlled by each provider.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Credentials use the write-only secret store or explicit environment variables.
- Approval
- Connection creation and sign-in are operator actions.
-
agent.trajectory-export
Privacy-reviewed training-data exports
Operator-selected successful runs become deterministic OpenAI chat, ShareGPT, or versioned Holaryn episode JSONL through a stale-safe preview, redaction report, exact consent boundary, and digest-bound local provenance.
Open the Privacy-reviewed training-data exports guideBeta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- A durable completed run owned by the local operator, Explicit review of the privacy preview and exact export consent
Operating limit
Export does not upload data, start fine-tuning, promote memory, or change routing; images are reduced to available alt text, historical compacted runs fail closed, and pattern redaction cannot replace operator review.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- System messages, context, and tool results are omitted by default; registered secrets, secret-like values, common PII, private paths, metadata, and operator-supplied exact private values are redacted without persisting match values. Hidden chain-of-thought is never collected or exported.
- Approval
- Preview has no side effect; export recomputes and binds the exact source, options, redaction report, and private-value fingerprints before accepting the exact consent phrase. Digest-safe deletion has a separate force confirmation for changed files.
-
agent.workflows
Reusable declarative workflows and runbooks
Immutable typed workflow versions provide safe branching, bounded fan-out, approvals, waits, retries, durable restart recovery, triggers, imports, curated recipes, artifacts, and audited supervision.
Open the Reusable declarative workflows and runbooks guideBeta maturity
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Persistent Holaryn host for scheduled, event-driven, and restart-resilient execution, Configured models, tools, connectors, and secret handles required by a selected recipe
Operating limit
Expressions are a small non-executable language, loops and budgets are bounded, interrupted non-idempotent side effects require manual recovery, and irreversible third-party compensation cannot be guaranteed.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Definitions and durable step state remain local; secret values are opaque handles, imported programs are disabled pending review, and dry-run performs no model, tool, connector, or artifact action.
- Approval
- Every consequential step still traverses canonical policy and approval; imports expose permission, dependency, secret, network, risk, trigger, and consequence changes before enablement.
03
Automation
7 matching capabilities
-
automation.batch-datasets
Durable batch and dataset runner
Versioned CSV, TSV, and JSONL datasets feed bounded, isolated per-row agent runs with preflight estimates, durable attempts, filtered retry, linked exports, and aggregate reports.
Open the Durable batch and dataset runner guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Persistent Holaryn host for unattended batch execution
Operating limit
Inputs are local materialized files in this release. Parquet-ready export writes linked JSONL plus a schema sidecar rather than a binary Parquet file.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Dataset rows, prompts, outputs, item errors, and usage are stored locally; selected providers receive each rendered row prompt, and cross-row memory is disabled by default.
- Approval
- Tools are unavailable unless explicitly allowlisted; every allowed tool still follows ordinary unattended approval and consequence policy.
-
automation.browser
First-party browser agent
A host-owned Chromium engine provides isolated or opt-in persistent sessions, semantic-first navigation and forms, bounded research, supervised takeover, quarantined downloads, and redacted traces without requiring Node or npx.
Open the First-party browser agent guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Chromium is the shipping engine; Firefox and WebKit can implement the engine contract later. CAPTCHAs, anti-bot bypass, and control of a user's existing browser are excluded.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Ephemeral profiles are the default; persistent cookies are opt-in, page content is untrusted, credentials are never traced, and downloads remain quarantined artifacts.
- Approval
- Typing, uploads, final submission, browser control, and other interactions pass through consequence-aware approval; direct API actions require an explicit approval field.
-
automation.computer-use
Accessibility-native computer use
A crash-isolated Windows UI Automation helper exposes bounded semantic application trees, expiring element identities, supervised controls, selected-window screenshots, approval-gated fallback, and redacted action traces.
Open the Accessibility-native computer use guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows
- Surfaces
- CLI, Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Windows UI Automation ships first. macOS AX and Linux AT-SPI can implement the conformance-tested platform contract later. Elevated/secure desktops, credential managers, games, DRM, and anti-automation bypass are excluded.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Only the explicitly selected application window is observed; credential values and sensitive titles are redacted, whole-desktop continuous capture is disabled, and secure desktop is never automated.
- Approval
- Application launch, value entry, keyboard input, sensitive controls, close operations, and every visual fallback pass through consequence-aware approval.
-
automation.event-sources
Durable proactive event sources
Webhooks, folder changes, timers, and connector deltas share cursors, deduplication, filtering, source-local circuits, and replayable delivery traces.
Open the Durable proactive event sources guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- Persistent Holaryn host for polling and unattended execution
Operating limit
Connector adapters must supply their delta events; uncertain crash outcomes require operator review before replay.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Events store bounded provenance metadata and payload references; folder events never store file content.
- Approval
- Detection never grants authority; every triggered run follows its profile, policy, budget, and ordinary approvals.
-
automation.lifecycle-hooks
Secure lifecycle hooks
Versioned blocking and observational hooks add deterministic policy, formatting, tests, notifications, webhooks, and audit automation at agent lifecycle boundaries.
Open the Secure lifecycle hooks guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Explicit trust for project hook files
Operating limit
Project hook trust is bound to the exact file digest; changed files stop executing until reviewed and trusted again.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Handlers receive a bounded, redacted event payload and a minimal environment; project process hooks require an isolated execution backend.
- Approval
- Hooks may deny, mutate explicitly allowlisted fields, or request ordinary approval, but every resulting action is revalidated by normal tool, path, governance, and approval policy.
-
automation.scheduler
Durable scheduler
Cron, interval, one-shot, and natural-language schedules survive host restarts and support profiles and team posts.
Open the Durable scheduler guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- Persistent Holaryn host for unattended execution
Operating limit
The host must be running when a schedule becomes due.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Schedule definitions are local; a run follows the selected provider and tool privacy rules.
- Approval
- Unattended actions that need approval park in the operator inbox.
-
automation.webhooks
Authenticated webhook triggers
Stable webhook events enter a durable deduplicated trigger lifecycle; legacy scheduled-job firing remains compatible.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- Explicit listener exposure, Configured webhook token
Operating limit
No public relay or managed ingress is included; keep the dedicated token behind HTTPS.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- Bounded metadata and a payload reference are stored locally; raw payloads and credentials are not stored in the event database.
- Approval
- Webhook runs use unattended approval rules and park sensitive actions.
04
Coding
1 matching capability
-
coding.validation
Evidence-driven code validation
Deterministic discovery builds tiered lint, format, type, test, and package plans; execution records revision-bound diagnostics, honest unverified states, and bounded repair attempts.
Open the Evidence-driven code validation guideBeta maturity
- Reader groups
- Developers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Validation proves only the recorded gates for one exact workspace state; it does not prove complete program correctness.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Validation runs only in the selected workspace with a minimal environment; secret-like variables are withheld and persisted output is redacted.
- Approval
- Fixed checks may run under validation policy; repository-provided commands show their exact argv, cwd, and provenance and require explicit project-command trust.
05
Collaboration
7 matching capabilities
-
collaboration.device-nodes
Secure mobile and edge device capabilities
A paired phone or edge node advertises narrow OS-mediated capabilities with independent permissions and grants, exact approval-bound invocations, expiring nonces, provenance, and resumable integrity-checked artifacts.
Open the Secure mobile and edge device capabilities guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Mobile, API, Service
- Prerequisites
- Mobile supervision enabled and the device explicitly paired, HTTPS outside loopback and a trusted private network path, A supported device/browser capability and its local OS permission
Operating limit
The reference PWA provides camera, location, notification, and selected-file capabilities; it is not an agent runtime and cannot execute arbitrary tools.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- The server journals bounded invocation/provenance metadata; camera, location, notification, and selected-file content move only after an exact device-side confirmation.
- Approval
- The canonical invoke tool uses ordinary approval policy bound to the exact device, capability, parameters, data movement, and expiry; an ask server grant requires the owner's approval for every invocation under any posture except attended Unrestricted. OS permission and server grant remain independent.
-
collaboration.mobile-supervision
Mobile supervision pocket console
A paired installable PWA monitors active and recent work, presents exact approval evidence, answers questions, controls runs, opens artifacts, and delivers privacy-safe Web Push alerts.
Open the Mobile supervision pocket console guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, Mobile, API, Service
- Prerequisites
- Persistent Holaryn host with mobile supervision explicitly enabled, HTTPS outside loopback and a trusted private network path, A browser with IndexedDB; Web Push support is optional
Operating limit
No public tunnel, native background service, arbitrary phone tool execution, mobile terminal/editor, or mobile high-impact approval is included; narrow device capabilities have a separate boundary.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- Device credentials and cached summaries are encrypted in browser-local non-extractable storage; lock-screen previews hide sensitive content by default.
- Approval
- Decisions are bound to the exact request digest and an idempotency key; high-impact categories remain desktop-only until verified step-up authentication is available.
-
collaboration.peers
Paired peer agents
LAN discovery, authenticated pairing, enable/disable controls, remote targets, and ask/send bridge agents across machines.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Reachable peer host, Explicit pairing
Operating limit
Discovery is LAN-scoped; internet routing is user-managed.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- Only addressed peer traffic crosses the authenticated link.
- Approval
- Pairing and re-enabling a peer are explicit operator actions.
-
collaboration.subagents
Delegated subagents
Child runs support live progress, questions, steering, cancellation, and bounded budgets.
Open the Delegated subagents guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Parallel capacity depends on provider and host limits.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Each child shares only the context and workspace explicitly assigned to it.
- Approval
- Child tools remain subject to policy; questions return to the operator.
-
collaboration.task-graphs
Durable multi-agent task graphs
Typed DAGs coordinate ready-only parallel work, joins, retries, recovery, evidence, and explicit integration across Agent Teams.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- Persistent Holaryn host, An active Agent Team
Operating limit
Cross-host peer members are not eligible until a durable remote completion and lease protocol ships.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Graph state and evidence persist locally; assigned work follows the selected team member's provider policy.
- Approval
- Graph expansion and uncertain-attempt recovery require explicit operator decisions; member tools retain normal approval policy.
-
collaboration.task-packages
Shareable reproducible task packages
Versioned template, snapshot, and diagnostic packages preserve immutable provenance while supporting reviewed redaction, deterministic archives, signatures, clean-profile dependency planning, local remaps, registries, and sandbox evidence reruns.
Open the Shareable reproducible task packages guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Explicit review of every export scan finding, Local dependency and permission resolution before activation
Operating limit
A valid signature proves integrity and publisher-key identity, not package safety; model prose is not expected to be byte-identical, filesystem registry sharing is local, and organization governance remains deployment-specific.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Raw secrets and account credentials are prohibited; export canaries are supplied by environment-variable name, findings show only redacted samples, and local model/path/account/SecretRef mappings stay outside the immutable package.
- Approval
- Export requires per-finding decisions; imported bundles default to dry-run and sandbox, cannot silently install executable dependencies, and reference reruns require an exact digest confirmation.
-
collaboration.teams
Agent Teams
Named local, coding-CLI, and remote members coordinate through routing, contracts, budgets, and shared team memory.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Cross-machine members require explicit peer pairing.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Team messages are persisted locally and cross a peer/provider boundary only when routed there.
- Approval
- Members retain their configured approval and contract boundaries.
06
Extensions
4 matching capabilities
-
extensions.commands
Extensible slash commands
Built-ins, TOML prompts, macro sequences, gated scripts, packs, skills, and MCP prompts share one command surface.
Open the Extensible slash commands guideStable maturity
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Telegram
- Prerequisites
- None listed in the registry
Operating limit
Control-plane commands are intentionally unavailable on untrusted channel surfaces.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Prompt commands stay local until invoked; their resulting model request follows provider policy.
- Approval
- Script commands and nested tools remain approval-gated.
-
extensions.mcp
Model Context Protocol client
Negotiated stdio and HTTP/SSE sessions contribute policy-filtered tools, prompts, resources, roots, logging, bounded sampling, and typed elicitation with conformance diagnostics.
Open the Model Context Protocol client guideStable maturity
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- A compatible MCP server
Operating limit
Server quality and schemas are controlled by the MCP provider; interactive OAuth refresh remains separate roadmap work.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Data is disclosed only to configured servers under explicit capability and item policy; sampling cannot import Holaryn context or tools.
- Approval
- New server capabilities remain pending; tools, sampling, elicitation, roots, and resources retain independent policy boundaries.
-
extensions.mcp-apps
Sandboxed MCP Apps
Compatible MCP tools can attach an interactive app that loads on demand in a double-iframe, isolated-origin sandbox with pinned resources, explicit authority, and an accessible structured fallback.
Open the Sandboxed MCP Apps guideBeta maturity
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop
- Prerequisites
- A server implementing the MCP Apps 2026-01-26 extension, The server's apps capability explicitly approved in Settings
Operating limit
Apps run only on the local web/desktop host; arbitrary external networking, ambient credentials, top-level navigation, and direct filesystem access are denied.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Tool input, structured results, and approved host actions are shared only with the selected app; pinned HTML and integrity metadata persist with the local chat.
- Approval
- App tool calls and host actions re-enter the canonical approval gate; declared CSP domains and permissions grant no authority by themselves.
-
extensions.skills-plugins
Skills 2.0 and plugins
Portable SKILL.md packages use exact immutable lifecycle, policy, evaluation, reviewed imports, accessible supervision, and privacy-safe receipts; plugin capabilities remain separately reviewed.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop
- Prerequisites
- Explicit review for install, publication, activation, trust, and authority
Operating limit
Offline fixtures do not prove live-host, provider, tool, or executable equivalence; scanning and evaluation do not prove arbitrary third-party content safe.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Packages and protected evidence are local by default; public projections redact private content but exact digests can remain identifying. External sources and integrations use only explicit reviewed requests.
- Approval
- Skill text, metadata, scans, signatures, and trust never grant authority. Consequential lifecycle and typed execution require exact policy and attended review.
07
Interfaces
12 matching capabilities
-
interfaces.annotations
Versioned inline review annotations
Reviewers can anchor threaded notes to exact messages, plan steps, diff ranges, and artifact regions, then assign, resolve, remap, export, or queue scoped agent work.
Open the Versioned inline review annotations guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Conservative remapping can leave an annotation visibly orphaned when the selected target cannot be identified uniquely.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Annotation visibility and target visibility are enforced independently; annotation text remains untrusted review content.
- Approval
- Agent actions created from annotations enter the normal context, policy, and approval boundaries.
-
interfaces.artifact-workspace
Professional document and artifact workspace
Chat, code, canvas, desktop, WebUI, and public API share immutable, previewed, validated, comparable DOCX, XLSX, PPTX, and PDF artifacts.
Open the Professional document and artifact workspace guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API
- Prerequisites
- Document adapters (bundled in desktop and official Compose builds)
Operating limit
Deterministic semantic previews are not every Office or PDF viewer; arbitrary macro-enabled or external-linked templates are not imported.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Artifact content and previews remain local after model generation and use optional state encryption; identifiers, formats, sizes, timestamps, status, and digests can remain visible.
- Approval
- Create and revise are reversible artifact writes governed by normal tool policy; exact base versions prevent silent overwrite.
-
interfaces.canvas
Accessible live canvas
Agents can render updating dashboards, boards, and tables beside a conversation with semantic screen-reader output.
Open the Accessible live canvas guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
The supported schema is intentionally smaller than arbitrary web content.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Canvas state is local and follows transcript retention rules.
- Approval
- Canvas rendering does not bypass tool approval.
-
interfaces.code
Screen-reader-first coding workspace
Plan/build sessions share chat and approvals while durable isolated worktrees separate files, checkpoints, terminals, indexes, validation evidence, and reviewed integration.
Open the Screen-reader-first coding workspace guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, CLI
- Prerequisites
- A selected workspace
Operating limit
Interactive terminals are local PTY/ConPTY sessions; remote attachment and replay across a host restart are not yet supported.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Repository source, worktree metadata, and disposable revision-keyed indexes remain local except excerpts explicitly included in model or coding-CLI requests; untracked secrets are not copied into new worktrees.
- Approval
- Index reads and rebuildable cache maintenance are reversible; target-branch integration requires exact-plan review and approval, while writes, shell commands, cancellation, and checkpoint reversal retain explicit safety controls.
-
interfaces.connected-apps
Connected Apps and first-party productivity connectors
Versioned connector contracts normalize scoped accounts, external resources, pagination, subscriptions, health, safe action previews, idempotent results, and final-boundary credential leases across first-party and remote capability sources.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- Encrypted scoped-secret storage for live accounts, Provider OAuth client configuration for live accounts
Operating limit
The bundled release supplies Gmail, Google Calendar, and Google Drive through one Google Workspace transport, not every SaaS provider; live provider OAuth client registration remains deployment configuration.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- OAuth values remain behind opaque encrypted-secret references; search/fetch results are lazy, bounded, provenance-labeled, and untrusted; activity excludes resource content.
- Approval
- Read scopes are separate from write, send, share, delete, and admin scopes; every consequential tool shows its exact account, tenant, recipients or resource, content or permission, consequence, scopes, and idempotency identity.
-
interfaces.desktop-web
Accessible web and native desktop app
One responsive React application provides chat, settings, approvals, operators, help, tray integration, native menus, and updates.
Open the Accessible web and native desktop app guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Desktop packaging and updater support vary by operating-system signing availability.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- The UI is served locally by default; remote listening requires explicit configuration and authentication.
- Approval
- All surfaces share the same approval broker and policy.
-
interfaces.ide-acp
ACP v1 IDE integration
A stable ACP v1 adapter and reference Visual Studio Code extension create, reattach, steer, cancel, and stream durable Holaryn coding sessions without the Web UI.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Editor
- Prerequisites
- A configured Holaryn chat model for prompts, Visual Studio Code 1.96 or newer for the reference client
Operating limit
Stable ACP v1 uses local stdio. The optional Holaryn TCP transport is non-standard, requires TLS 1.3 and mutual TLS, and requires explicit opt-in for non-loopback listening.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- The reference editor sends bounded, redacted workspace context to the local Holaryn process; only the selected provider receives context used in a model turn, and provider credentials never enter the extension.
- Approval
- File, tool, and terminal consequences remain server-owned and use one-shot keyboard-accessible editor prompts; the client cannot widen path policy or forge a lower consequence.
-
interfaces.localization
Internationalized and RTL-ready interfaces
Versioned ICU-compatible message catalogs, reviewed Spanish and French core translations, deterministic regional formats, and expansion/RTL pseudo-locales span the web, desktop, CLI, channels, and exports.
Open the Internationalized and RTL-ready interfaces guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Spanish and French cover the reviewed core flows in this release; untranslated legacy surfaces use English while the no-new-raw-string policy drives incremental extraction.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Locale preferences contain language identifiers only; translated content follows the privacy boundary of its original message.
- Approval
- Safety-critical translations are version-reviewed and fall back to reviewed English whenever review metadata is missing or stale.
-
interfaces.messaging-channels
Multi-channel conversation ecosystem
Channel API 1.0 normalizes identity, threads, edits, attachments, approvals, policy, health, and retry-safe delivery across Telegram, Slack, and Discord reference adapters.
Open the Multi-channel conversation ecosystem guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Telegram, Slack, Discord, Web, Desktop, API, Service
- Prerequisites
- Explicit external workspace/channel/user binding, A credential-bearing provider transport for live Slack or Discord
Operating limit
Telegram retains its bundled live polling service. Slack and Discord ship as authenticated Channel API reference adapters and require an explicitly attached host or executable-extension transport.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Provider messages and attachment metadata are untrusted; the durable store keeps identity metadata and digests, not credentials or attachment bytes.
- Approval
- Bindings carry explicit Holaryn authority; approvals preserve exact consequences and explicit decisions or a visible fallback; revoke and emergency stop require typed confirmation.
-
interfaces.public-api
Versioned public automation API and official SDKs
A tenant-scoped API, Python sync/async SDK, and TypeScript promise client automate sessions, runs, durable events, approvals, artifacts, discovery, webhooks, and administration.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, API, Service
- Prerequisites
- Explicitly enable the public API and create a scoped service credential
Operating limit
Remote access requires an operator-managed TLS reverse proxy; secret-bearing administration responses are shown once and cannot be replayed.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Bearer credentials are header-only, API keys are stored as digests, resource access is tenant-bound, and audit/webhook records omit prompt and credential content.
- Approval
- Automated clients answer the same durable approval requests as interactive surfaces and cannot bypass application-service scope checks.
-
interfaces.telegram
Telegram channel
A long-polling Telegram bot supports per-chat allowlists, conversations, coding notifications, and team escalation.
Open the Telegram channel guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Telegram, Service, Web, Desktop
- Prerequisites
- Telegram bot token, Allowed chat identifiers
Operating limit
Telegram remains the bundled live third-party channel; Slack and Discord Channel API reference adapters require an explicitly attached transport.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- Messages cross Telegram and the configured model provider when a model turn runs.
- Approval
- Unattended sensitive actions park for operator review.
-
interfaces.voice
Real-time local voice conversations
Ordered local STT, live captions, automatic/wake/continuous turn modes, privacy-bounded incremental speech, barge-in, recovery, and replay-safe decisions wrap the canonical agent loop.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop
- Prerequisites
- Optional speech engine extra, Microphone permission
Operating limit
Browser/OS/hardware determine latency and voice/device quality; no phone, cloud STT, biometric identity, native speech-to-speech, or background OS wake service.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Raw audio is discarded by default; opt-in audio requires bounded expiry, exports omit bytes, captions/text-only are independent, and narration omits raw arguments/output.
- Approval
- Capture starts explicitly; deny binds to the exact pending request, low-impact approval is opt-in and two-step, and high-impact approval requires visual review.
08
Memory
1 matching capability
-
memory.hybrid
Hybrid local memory
Versioned scoped memory combines relational, full-text, and optional vector recall with explainable decisions, provenance, citations, review, and verified controls.
Open the Hybrid local memory guideStable maturity
- Reader groups
- Operators, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- Optional embedder or external vector/database backend for non-default modes
Operating limit
Semantic quality depends on the selected embedder and model. Feedback weighting and automatic consolidation are deferred; prior exported copies and deployment backups are outside live-store deletion.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- The default store is local; external database, vector, or embedding endpoints receive configured memory data.
- Approval
- Learning can be automatic, paused, or review-gated by scope/category/source; edits, lifecycle controls, source forget, export, and external backend setup are explicit operator actions.
09
Personalization
3 matching capabilities
-
personalization.agent-builder
Versioned custom agents and Agent Builder
Typed content-only manifests move through draft, validation, profile-bound HolarynBench smoke, immutable publication, capability-scoped specialist routing, typed handoffs, version pinning, rollback, and secret-safe import/export.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Marketplace distribution, hosted organization authoring, executable manifest code, and dependency installation are deferred; unavailable declared dependencies block publication. Automated accessibility evidence is not a WCAG, legal, or manual JAWS conformance claim.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Definitions and validation evidence are local; exports preserve secret references but reject secret values. Retained specialist routing and handoff activity contains bounded identifiers, counts, and digests rather than task or payload content.
- Approval
- Organization policy is a non-bypassable compiler ceiling; overlays and routed specialists can narrow permissions and autonomy but cannot widen them. New permissions and local-to-cloud changes require explicit publication review.
-
personalization.profile-library
Installable Profile Library and coordinated sets
A local searchable catalog installs exact immutable specialist profiles individually or as ownership-safe Accessibility and Software Development sets, including optional reviewed DevOps planning.
Open the Installable Profile Library and coordinated sets guideBeta maturity
- Reader groups
- Operators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
The initial catalog is built in and local; remote catalog distribution is deferred. Set workflows require every member to be installed and enabled.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Catalog and installation metadata remain local; exact definitions and prior run evidence are retained after uninstall without storing credentials or task content in the ledger.
- Approval
- Every lifecycle mutation requires a state-bound consequence preview. Installation declares capabilities but grants no credentials, accounts, network access, autonomy, integration, deployment, or policy exception.
-
personalization.profiles
Profiles and versioned Persona 2.0
Named profiles and agents can bind exact immutable Persona 2.0 Markdown versions; deterministic layers, per-chat communication styles, attended proposals, rollback, import/export, and subagent inheritance preserve identity without widening authority.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service, Telegram
- Prerequisites
- None listed in the registry
Operating limit
Profile/persona replacement applies at a run boundary, and a per-chat style selected during a response applies to the next turn. Model-backed PersonaBench evaluation is optional and must be reported separately from deterministic coverage.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Persona definitions, versions, proposals, and active selection are stored locally. The effective persona is included in model context; journals record its encrypted snapshot while ordinary events expose content-free identifiers and digests.
- Approval
- Publication, activation, rollback, import confirmation, and proposal acceptance are explicit operator actions. Persona content cannot grant tools, permissions, secrets, autonomy, approvals, policy exceptions, or execution authority.
10
Quality
2 matching capabilities
-
quality.benchmarks
HolarynBench and extended quality gates
Versioned no-network capability scenarios, parser properties, critical browser flows, fault soaks, and noise-aware performance workloads produce reproducible release evidence.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Developers, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI
- Prerequisites
- Docker only for live shell benchmark scenarios
Operating limit
Offline results measure runtime behavior, not competitor or live-model quality; manual assistive-technology sign-off still supplements automated accessibility checks.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Deterministic suites use synthetic fixtures and omit prompts, outputs, secrets, and user paths from private reports.
- Approval
- Benchmark manifests declare and bound every tool and approval decision.
-
quality.capability-matrix
Living capability and documentation contract
One versioned registry drives deterministic JSON, user documentation, CLI diagnostics, and in-product About data while CI rejects drift and contradictions.
Open the Living capability and documentation contract guideStable maturity
- Reader groups
- Developers, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API
- Prerequisites
- None listed in the registry
Operating limit
Maturity describes the Holaryn integration and does not certify third-party services or security compliance.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Capability diagnostics contain product metadata only and never inspect credentials, prompts, outputs, account identifiers, or user paths.
- Approval
- Reading or generating capability metadata is non-mutating; artifact updates remain reviewed source changes.
11
Runtime/deployment
14 matching capabilities
-
platform.hacp
Optional HACP platform connection
The standalone core can attach to Holaryn Space through the open HACP boundary without importing Platform code.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- HACP endpoint and credentials
Operating limit
The standalone agent does not bundle or require Holaryn Space.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- Only configured HACP messages and requested capabilities cross the platform boundary.
- Approval
- Platform-contributed capabilities register through the same local policy seams.
-
runtime.attachments
Format-aware attachment ingestion and citations
Hostile files become immutable structured blocks with page, slide, sheet/cell, section, line, image, and archive-path citations; bounded search selects only relevant evidence.
Open the Format-aware attachment ingestion and citations guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- The documents extra for Office, PDF rendering, image decoding, and OCR
Operating limit
The source limit is 5 MiB; perfect OCR and format fidelity are not claimed; legacy binary Office files and executable attachments are unsupported.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Originals, reports, jobs, and derived blocks use local authenticated state encryption; one-time decryption values are never stored and URL credentials/query data are not retained.
- Approval
- Attachment reads are chat-authorized and never grant action authority; extracted content is always untrusted and prompt-injection indicators remain visible.
-
runtime.compose-deployment
Production Docker Compose self-host deployment
A hardened one-command stack provides authenticated first-run onboarding, pinned non-root containers, durable named volumes, optional database/vector/model/worker/proxy/observability profiles, diagnostics, encrypted backup, tested upgrade, and rollback.
Open the Production Docker Compose self-host deployment guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Service
- Prerequisites
- A supported Docker Engine with the Compose v2 plugin, DNS plus inbound TCP 80/443 for automatic public TLS, Operator-managed backup storage and recovery material
Operating limit
The reference production topology targets one Linux host; external databases, orchestrators, high availability, enterprise identity, off-host backup retention, and capacity scaling remain operator-owned.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- The minimal profile runs locally with a loopback-only application port; production exposes only the TLS proxy. Secrets use mounted files, support bundles redact values, and deployment status reports metadata and configuration shape only.
- Approval
- Bootstrap, production exposure, profile enablement, upgrades, backup, restore, rollback, and secret changes are explicit operator actions.
-
runtime.context
Typed contextual references and provenance
Versioned references resolve files, attachments, artifacts, URLs, memory, prior work, and canvases at send time with freshness, trust, taint, budgets, and validated citations.
Open the Typed contextual references and provenance guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Diagnostics, git objects, model/profile, and peer kinds are schema-reserved but need a concrete resolver before their content can be included.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- External URLs drop credentials and query data before persistence; source content remains bounded and labeled in the local transcript.
- Approval
- References never grant authority; current workspace, chat, store, and connector permissions are rechecked on every resolution.
-
runtime.dynamic-tools
Dynamic tool discovery and bounded code mode
A versioned policy-aware catalog exposes only a bounded discovery core, loads exact schemas after inspection, and can optionally compose approved capability handles in a no-eval restricted runtime.
Open the Dynamic tool discovery and bounded code mode guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
The restricted language supports sequential call assignments and literals, not arbitrary Python/JavaScript, loops, packages, imports, ambient filesystem/network access, or automatic tool installation.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Catalog metadata is sanitized and bounded; discovery audit events omit tool arguments, outputs, prompts, credentials, and secret values.
- Approval
- Search and schema loading never grant permission; direct, alias, handle, script, and bounded-code invocation all recheck the canonical registry and normal approval path.
-
runtime.encrypted-state
Encrypted local state and recovery backups
Versioned per-domain envelope encryption protects classified local records, files, and path-independent recovery archives with fail-closed key handling, resumable migration, rotation, and restore validation.
Open the Encrypted local state and recovery backups guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- OS credential vault or operator-held recovery material, Stopped host for enablement, migration, key maintenance, backup, and restore
Operating limit
It does not protect an authorized running process, uncovered control-plane/workspace content, external stores, OS swap or crash dumps; losing both key-provider access and recovery material can make data unrecoverable.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Covered secrets, journal and memory fields, chat/device artifacts, and backup payloads use authenticated encryption; ids, timestamps, states, sizes, digests, embeddings, excluded stores, and explicit exports can remain visible as documented.
- Approval
- Encryption is opt-in pending independent review; key mutations and recovery are explicit stopped-host CLI operations and recovery material is never accepted as a command argument.
-
runtime.execution
Durable local, Docker, and SSH execution
Workspace-confined one-shot tools and opt-in durable sessions share typed policy, replay, cancellation, artifact, and recovery contracts across local, persistent Docker, and pinned-host SSH backends.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- Docker only when persistent container execution is selected, A pinned SSH profile and remote Holaryn worker for strong remote replay
Operating limit
Managed serverless execution is not bundled; raw SSH remains a documented degraded mode without strong remote process identity.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Filesystem access is root-confined, journals are redacted and encrypted when state encryption is configured, and backend network authority is explicit.
- Approval
- Every command is admitted against an immutable session policy before provisioning or launching a side effect.
-
runtime.governance
Enterprise identity, governance, audit, and policy
Provider-neutral tenant scopes, revocable identity sessions, RBAC, deny-overrides organization policy, legal-hold-aware retention, and tamper-evident audit protect consequential actions.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- An injected governance service and authenticated authorization context, Deployment-owned identity, directory, key custody, audit archive, and deletion adapters as applicable
Operating limit
Ordinary standalone hosts remain explicitly unattached; this foundation supplies adapter contracts rather than a bundled live IdP, KMS/HSM, WORM archive, compliance certification, or remote resource deleters.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Audit details are minimized and sensitive-looking values are redacted; exports are tenant-filtered and written beneath a trusted host directory.
- Approval
- Organization deny is non-overridable, review forces one-action approval, and allow never weakens local autonomy or information-flow policy.
-
runtime.migration
Agent migration
A reviewable importer brings supported skills, memory, and persona data from OpenClaw or Hermes into local Holaryn state.
Matching public documentation is not available for this release.
Beta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI
- Prerequisites
- Readable source-agent directory
Operating limit
Only documented portable data shapes are imported; source-specific runtime state is not.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Migration is local and supports dry-run before writes.
- Approval
- The importer previews and confirms changes unless --yes is explicit.
-
runtime.observability
Privacy-safe usage diagnostics
Canonical run/model/tool/approval traces, normalized usage, optional cost, bounded OTLP export, Prometheus metrics, and provisioned dashboards support local and fleet diagnosis.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- The optional otel dependency when network export is enabled
Operating limit
Token and cost fields may be unavailable when a provider does not report them; exporter buffering is deliberately bounded and may drop signals under backpressure.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Usage records and OTLP signals exclude prompts, responses, thinking, tool arguments/output, paths, URLs, recipients, exception messages, and secrets; exporter destinations are explicitly allowlisted.
- Approval
- Viewing diagnostics is read-only; network export, insecure private transport, authentication secret changes, and external destinations require explicit operator configuration.
-
runtime.policy
Autonomy policy and staged plans
Ask, selective, allow-all, and unrestricted postures combine with consequence rules and reviewable dry-run plans.
Open the Autonomy policy and staged plans guideStable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Policy cannot eliminate risk from an intentionally approved external action.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Policy evaluation is local and content-free audit metadata is retained.
- Approval
- Unattended runs never auto-approve held actions; unrestricted is always explicit.
-
runtime.secret-broker
Scoped secret broker and just-in-time credential delivery
Opaque references resolve through exact, expiring, use-bounded leases only inside trusted provider, connector, signing, request, or process adapters, with encrypted metadata, rotation, revocation, audit, and transformed-form redaction.
Open the Scoped secret broker and just-in-time credential delivery guideBeta maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Encrypted local state initialized, An authorized usage policy with exact principal, run, tool, destination, purpose, and injection mode
Operating limit
Local metadata reveals opaque ids, states, version/count/timestamp fields, backend ids, and SQLite size. Provider adapters may retain a credential for their bounded runtime after lease consumption; arbitrary third-party code is never a trusted injection adapter.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Values stay in the selected secure backend and trusted injection boundary; authenticated metadata views expose aliases, scopes, versions, policy bindings, and usage timestamps. Redaction is defence-in-depth and cannot undo arbitrary exfiltration after disclosure.
- Approval
- Default deny; policies can require review, break-glass requires a distinct reviewer and exact confirmation, and permanent deletion requires prior revocation plus alias confirmation.
-
runtime.security
Secret storage and layered injection defense
Write-only secrets, typed provenance/taint, versioned detectors, and information-flow policy protect trust and action boundaries.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service, Telegram
- Prerequisites
- None listed in the registry
Operating limit
Detection and provenance reduce risk but cannot prove content is safe; managed DLP classifiers and their content-handling contracts remain deployment responsibilities.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Secrets are redacted; findings retain bounded plain-text evidence, and offline evaluation reports omit evaluated content.
- Approval
- Keywordless untrusted-to-action flows require review; suspected injection and tainted secret egress are non-overridable blocks.
-
runtime.service-install
Cross-platform host service and installation
CLI, per-user install, persistent host, systemd, launchd, Windows service, desktop packages, and channel-aware updates share release metadata.
Matching public documentation is not available for this release.
Stable maturity
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Desktop, Service
- Prerequisites
- Platform service permissions when installing a service
Operating limit
Windows tags require Authenticode credentials and run the automated NSIS lifecycle plus atomic checksum, CycloneDX, attestation, and clean-runner verification; native package execution on macOS and Linux remains platform-dependent.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Update checks disclose only ordinary release request metadata to the configured release host.
- Approval
- Install, uninstall, service registration, and update actions are explicit operator actions.
12
Experimental capabilities
Experimental capabilities require explicit opt-in and have named exclusions. They remain separate from the ordinary inventory even when filters are active.
-
agent.independent-review
Independent specialist review with bounded authority
A reviewer child with read and verify tools only checks a fingerprinted candidate against named criteria, reports findings as data, and rechecks fixes within one shared rounds, attempts, tokens and wall-time budget; approval comes only from host validation of the exact candidate, and a changed candidate invalidates earlier approvals.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, API
- Prerequisites
- HOLARYN_REVIEW_WORKFLOW_ENABLED=true to start reviews or request rounds
Operating limit
Off by default until the live reviewer-versus-single-agent comparison (pending the owner's budget decision) justifies it; the offline comparison replays scripted turns and makes no capability claim. Only the owner starts a review (holaryn review start or POST /api/review on the running host, which dispatches the reviewer child in the background); no agent tool or schedule starts one, a fingerprint-only candidate is never approved because the host cannot validate it, and the /reviews web page lands with a later frontend step.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Review records (claims, evidence, notes, dispositions) are field-encrypted in the local state directory; canonical review events carry only ids, state and role words, round numbers and counts.
- Approval
- The reviewer can never publish, record a disposition, approve its own or anyone's change, or widen a grant; its verify tools are kept from the parent's own set and still pass the central approval gate, only the owner accepts a limitation, and nothing the coordinator does approves an action.
-
agent.maintenance-proposals
Owner-enabled maintenance proposals
An opt-in scheduler job turns exact duplicate and superseded memory records into inactive, quarantined review proposals with lineage, an offline candidate-versus-baseline result, and a reversible disposition.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, API, Service
- Prerequisites
- HOLARYN_MAINTENANCE_ENABLED=true (off by default), Persistent Holaryn host for scheduled runs, Self-improvement collection enabled
Operating limit
Only exact normalized duplicates and superseded records with an equal-or-stronger active successor are enabled. Contradiction, skill-drift, and repetition classes stay retain-experimental. A run sees at most 1000 active records. The Improve page lists maintenance proposals with defer and reject; a maintenance status view is deferred to SA-505.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Reads memory metadata locally and stores only memory ids, versions, digests, and aggregate metrics; no model call, no tokens, and no memory content leaves the process. Pinned, held, expired, and non-active records are excluded, and private sessions leave no repetition observation.
- Approval
- The job cannot change grants, activate skills, or edit memory; proposals start quarantined, can only be deferred or rejected by an attended reviewer, and any archive stays a separate operator action.
-
agent.safe-self-improvement
Evidence-gated self-improvement
Privacy-safe outcome clusters become complete hypotheses, isolated patches, reproducible gates, independent reviews, and deterministic bounded rollouts with automatic rollback.
Open the Evidence-gated self-improvement guideExperimental
- Reader groups
- Operators, Developers, Administrators, Maintainers
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- Git worktree support for patch preparation, Independent reviewer for promotion authorization
Operating limit
Promotion records an authorization artifact only. Patch application, production deployment, online experimentation, and unsupervised control-plane mutation are not included.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Signals contain stable references and cluster keys rather than prompts or outputs; collection can be disabled and retained proposal data explicitly deleted.
- Approval
- Ordinary authority cannot mutate the active install or protected controls; protected, high-risk, and evaluation-control changes need two distinct elevated reviewers.
-
extensions.executable
Sandboxed executable extensions
A versioned language-neutral protocol and Python SDK add reviewed tools and settings schemas through crash-isolated, default-deny Docker processes without importing third-party code into Holaryn core.
Open the Sandboxed executable extensions guideExperimental
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- Docker with an independently reviewed extension image available locally, HOLARYN_EXTENSIONS_ENABLED=true after package and permission review
Operating limit
The initial production vertical integrates tools and generic settings; other versioned extension-point descriptors remain catalog-only until their host adapters ship. Docker is required and images are never pulled automatically.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- The extension sees only its read-only package, bounded scratch space, call input/config, and exact resources mediated by declared file, HTTPS, SecretRef, or canonical-tool permissions.
- Approval
- Install is disabled by default; enablement and every permission expansion require explicit operator review and consent.
-
extensions.marketplace
Trusted capability marketplace
Signed public, private, mirrored, and offline registries distribute skills, content plugins, command and MCP bundles, connectors, themes, assets, and isolated executable extensions through transparent trust tiers.
Open the Trusted capability marketplace guideExperimental
- Reader groups
- Developers, Administrators, Extension authors
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, Service
- Prerequisites
- An organization marketplace policy with pinned registry and publisher trust roots, HOLARYN_MARKETPLACE_ENABLED=true for remote refresh and download
Operating limit
Review, signatures, popularity, and sandboxing are separate signals and none proves safety. The first release supplies a local registry/client and publication vertical slice rather than a hosted billing or revenue-sharing service.
Inspect network, privacy, approval, and evidence
- Network
- optional
- Privacy
- Catalog browsing uses signed cached metadata; remote refresh/download contacts only organization-approved registry locations. Reports remain queued locally until explicitly submitted.
- Approval
- Every package is inspected before install; activation and permission expansion require explicit review. Locked organization allowlists cannot be bypassed locally.
-
interfaces.agent-a2a
A2A agent interoperability
Explicitly paired external A2A 1.0 agents can advertise approved skills and exchange authenticated, policy-bounded tasks, progress, cancellation, and untrusted artifacts.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, API, Service
- Prerequisites
- An operator-reviewed HTTPS Agent Card trust binding, Transport authentication and outbound-data policy, A host-supplied Agent Card signature verifier when signatures are required
Operating limit
Private preview supports the A2A 1.0 HTTP+JSON binding. Push notifications are not enabled, URL artifacts are not fetched automatically, and the standalone server adapter is not mounted unless explicitly configured.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- The outbound policy authorizes the exact redacted message; credentials remain transport-only, and diagnostics omit messages, artifact content, prompts, credentials, and signing material.
- Approval
- Pairing, Agent Card verification, approved skill policy, session authorization, and consequence approval remain independent deny-by-default gates; card metadata never grants authority.
-
runtime.advanced-reasoning
Selectable experimental advanced reasoning
A host-wide Experimental Features control can opt subsequent Chat turns into a bounded typed plan-search preflight while Standard reasoning remains the default.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- Web, Desktop, API, Service
- Prerequisites
- Unlocked encrypted local state for Advanced reasoning, A configured model provider for model-backed turns
Operating limit
Experimental, opt-in, and not a production-readiness claim. The SA-434 four-arm offline comparison records retain-experimental: bounded beam did not beat plan-execute-verify, and only a funded live held-out run meeting decision rule sa434-promote-v1 can promote it. The deterministic benchmarks do not establish live-model quality, classifier accuracy, current provider cost, or latency; live observations remain disabled.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- Candidate state is encrypted locally; events and the Chat presence line remain content-free, and private chain-of-thought is neither requested nor retained.
- Approval
- Selecting Advanced reasoning grants no authority; branch generation, evaluation, and losing branches are charged to the run's shared parent budget, and the selected plan is refused if the workspace or any cited source drifted before it re-enters the canonical tool, permission, approval, workspace, budget, and completion boundaries.
-
runtime.advanced-workflows
Sandboxed advanced capability workflows
An explicitly enabled typed interpreter composes authorized capability handles with bounded parallel maps, conditions, retries, reductions, schemas, evidence, checkpoints, and inspectable approval pauses.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Private preview and disabled by default. Workflows use declarative calls, maps, conditions, and reductions only; no arbitrary code, ambient filesystem/network/process access, package installation, recursion, or unbounded fan-out.
Inspect network, privacy, approval, and evidence
- Network
- provider-dependent
- Privacy
- The interpreter has no ambient host access; checkpoints retain bounded structured results and evidence, while traces omit arguments, outputs, prompts, credentials, and private chain-of-thought.
- Approval
- Consequential or approval-required calls pause before dispatch; every prepared and resumed call re-enters current Capability Fabric authorization and the canonical host executor.
-
runtime.capability-center
Capability Center and effective authority projection
One canonical live projection explains catalog, source/account, policy/model, runtime, and approval state across Web, API, and CLI surfaces.
Open the Capability Center and effective authority projection guideExperimental
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- None listed in the registry
Operating limit
Private preview and disabled by default; the previous stable runtime remains the execution and approval authority, and the documented readiness gaps must close before public beta.
Inspect network, privacy, approval, and evidence
- Network
- none
- Privacy
- Responses contain bounded capability metadata and authority digests; they omit prompts, tool arguments and outputs, credential values, account subjects, and principal identifiers.
- Approval
- Search, inspection, explanation, and schema loading grant no authority; source actions require current authorization, catalog revision checks, permission-diff review, and confirmation when consequential.
-
runtime.web-retrieval
Browser-independent web search, fetch, and citations
Stable model-facing search and safe page/PDF extraction work across verified tool-calling models without Chrome or provider-specific prompts.
Matching public documentation is not available for this release.
Experimental
- Reader groups
- Operators, Developers, Administrators
- Platforms
- Windows, macOS, Linux
- Surfaces
- CLI, Web, Desktop, API, Service
- Prerequisites
- A configured search backend for web_search; direct HTTPS fetch needs no browser
Operating limit
Public static HTML, text, and PDFs are supported; use browser automation for authenticated, interactive, rendered, download, or user-takeover flows. Live tests remain opt-in.
Inspect network, privacy, approval, and evidence
- Network
- required
- Privacy
- URLs are normalized without credentials or fragments; authorization headers, cookies, local paths, unrelated context, and backend exception details never enter results.
- Approval
- Every request is admitted by HTTPS/domain/network policy and Capability Fabric authorization; discovery, fetched instructions, and citations never grant tool authority.
Read before choosing a build
Current product limitations
One Nightly baseline, not a channel comparison
Every row above is bound to v0.12.6.dev0+g563af09 at source 563af099deba52fa028e46d19b6b0544bd3eda48. The website does not infer a Stable capability set from this Nightly registry.
Capability support is not packaging support
A listed platform describes that capability's registry support. Installer formats, architectures, and availability remain release-asset facts.
Providers and networks remain conditional
Configured providers, external services, credentials, and network modes still govern whether a model-backed or connected capability can run.
Accessibility evidence has open coverage
Semantic and keyboard-oriented implementation does not establish broad assistive-technology compatibility or formal conformance.