Capabilities tied to a published release

Features with their limits in view

Explore implemented capabilities by the work they support, with maturity, applicability, prerequisites, and operating limits kept beside exact release evidence.

Two independent signals

How release channels and capability maturity differ

BUILD / CHANNEL

Stable, Beta, or Nightly

Describes how a complete build is distributed. This inventory names one exact published Nightly; capabilities listed for that Nightly are not presented as Stable capabilities.

ROW / MATURITY

Stable maturity, beta maturity, or Experimental

Describes one capability inside the named Nightly build. Capability maturity is not a release channel, security certification, or promise that every surface behaves identically.

Shareable server filters

Filter capabilities in this Nightly release

76 of 76 capabilities shown

Current view: All capabilities.

Reader groups are descriptive navigation labels derived from the registry area. They do not grant permissions or replace the capability's approval rules.

01

Models

5 matching capabilities

  1. agent.adaptive-routing

    Transparent adaptive model routing

    An opt-in deterministic router chooses eligible models by task role, capability, privacy, reliability, latency, cost, cache opportunity, and explicit preference while preserving manual pins.

    Open the Transparent adaptive model routing guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Routing metadata and price estimates are operator/provider inputs, unknown cost or latency becomes ineligible only when a corresponding hard ceiling is configured, and invocation recovery remains the separate failover subsystem.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Local-only and local-to-cloud rules are hard gates; retained decisions are content-free, aggregate outcome learning is off until consented, and all routing telemetry can be reset.
    Approval
    Enabling adaptive routing, changing policy, allowing local-to-cloud movement, and opting into aggregate learning are explicit operator settings actions.
    Inspect exact public release evidence
  2. agent.provider-conformance

    Model/protocol conformance records

    Exact model/adapter conformance records keep declared capability, an offline transcript round-trip matrix, and opt-in bounded live evidence separate, invalidate evidence when the adapter or model identity changes, and refuse effort values outside the protocol contract with an actionable explanation.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Synthetic verdicts prove the adapter contract against scripted fixtures, not live provider behavior; live evidence expires after thirty days and is dropped when the adapter code changes; the provider-reported model string is not captured yet.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Records and benchmark reports hold verdicts, reason codes, digests, timestamps, and exact model identities only; opaque native reasoning and signature material is replayed under its provider contract and is never stored as evidence or telemetry.
    Approval
    Live probes run only with an explicit model and request budget on the command line; offline probes and record refreshes from Settings send fixed synthetic prompts to no provider.
    Inspect exact public release evidence
  3. agent.provider-resilience

    Safe provider recovery and circuit breaking

    An opt-in provider-neutral coordinator applies normalized failure policy, bounded pre-response retries, eligible-model failover, partial-output retention, and durable single-probe circuit breakers without replaying consequential tools.

    Open the Safe provider recovery and circuit breaking guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Automatic recovery is prohibited after visible output, cancellation, a safety refusal, invalid/auth/unknown failures, or consequential tool results; live provider behavior, billing, and registry metadata remain provider/operator inputs.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Circuit and attempt state is content-free and bounded; prompts, responses, tool arguments/results, credentials, and provider error bodies are excluded and diagnostics can be reset.
    Approval
    Recovery is disabled by default; enabling it, changing fallback/action policy, allowing fallback from a pinned model, and resetting circuits/traces are explicit operator settings actions.
    Inspect exact public release evidence
  4. agent.structured-outputs

    Schema-constrained model outputs

    Versioned JSON Schema contracts provide provider-native enforcement when available, canonical local validation, bounded repair, typed failures, privacy-safe evidence, and accessible result rendering.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Schema compliance does not prove factual correctness; native keyword support and limits vary by provider, while unsupported models require the bounded prompt fallback unless native enforcement is mandatory.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Unvalidated response text is buffered; traces retain contract identity, validation state, usage, known cost, and hashes without raw candidate content by default.
    Approval
    Structured output does not bypass tool, connector, workflow, or artifact approval policy.
    Inspect exact public release evidence
  5. models.image-generation

    Image generation

    Image-capable configured providers can generate raster artifacts through a typed tool path.

    Open the Image generation guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop
    Prerequisites
    A configured image-capable model

    Operating limit

    Supported sizes, formats, edits, pricing, and safety policy are provider-specific.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Prompts and reference images are sent to the selected image provider.
    Approval
    Provider calls follow the active tool policy.
    Inspect exact public release evidence

02

Core agent

10 matching capabilities

  1. agent.context-continuity

    Inspectable long-task context continuity

    A bounded continuity record carries the objective, authoritative owner constraints, accepted decisions, unresolved work, artifact revisions, and remaining verification across repeated compactions, a restart, and a smaller-model switch, with retrievable references to omitted tool output and an inspectable context budget.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    The default compaction strategy is unchanged pending the packaged offline comparison; retained output is capped per session and by size, a truncated body keeps a whole-output digest, and the budget's cache figures come from the segment planner's estimates rather than measured provider billing.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    The record, its references, and the retained tool output stay in the host's local state directory, field-encrypted under the installation's own state-encryption boundary when one is configured; a reference stores a digest of the bytes it stands for, never a copy that outlives its retention cap.
    Approval
    Resolving a reference passes the same principal and scope the original action ran under, so recovering historical output can never widen a grant; owner constraints are authoritative and a model-authored summary cannot alter them.
    Inspect exact public release evidence
  2. agent.durable-goals

    Durable bounded goals

    Versioned goals continue through the ordinary host boundary with leases, multidimensional budgets, explicit authority, evidence-driven completion, and conservative restart recovery.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Persistent Holaryn host for autonomous continuation

    Operating limit

    Prepared attempts resume exactly once, but a non-journaled attempt interrupted after dispatch is paused as uncertain and must be reviewed.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Goal metadata, budget ledgers, evidence, blockers, and decisions persist locally; redacted export is the default.
    Approval
    Scope, budget, workspace, continuation, and authority expansion requires a named reviewer; underlying tools retain normal approval policy.
    Inspect exact public release evidence
  3. agent.local-model-lifecycle

    Local model lifecycle and hardware manager

    Holaryn can assess local hardware, import or adopt models, supervise Ollama and llama.cpp endpoints, benchmark them, and route them through the ordinary provider registry.

    Open the Local model lifecycle and hardware manager guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Ollama or llama.cpp for managed serving, Enough disk and memory for the selected model

    Operating limit

    Hardware fit is advisory, built-in catalog entries do not guess mutable artifact URLs, and Holaryn cannot safely stop processes it did not launch in the current host process.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Hardware inventory, model metadata, roles, health, and benchmark metrics stay local; only an explicit HTTPS download or adopted non-loopback provider can use the network.
    Approval
    Downloads, endpoint scans, launches, benchmarks, role changes, and owned-file removal are explicit operator actions; removal requires confirmation.
    Inspect exact public release evidence
  4. agent.loop

    Durable agent loop

    Typed streaming turns, crash-safe checkpoints, cursor reattachment, fenced host recovery, tool outcomes, cancellation, steering, and terminal trace export share one event model.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    A configured model is required for model-backed turns; an external side effect interrupted before its durable outcome requires explicit operator review unless the external system proves idempotency.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Prompts and responses stay local except when sent to the selected model provider; durable events, checkpoints, tool evidence, artifacts, and trace exports are redacted and use optional state encryption.
    Approval
    Tool calls pass through the configured consequence-aware approval policy.
    Inspect exact public release evidence
  5. agent.onboarding

    Resumable first-success onboarding

    Desktop, CLI, Compose, source, and offline activation paths share versioned recovery, provider setup, model roles, a safe posture, streamed verification, and an approval-gated reversible demo.

    Open the Resumable first-success onboarding guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    The demo writes only beneath the generated onboarding state sandbox; external moderated-usability evidence is tracked separately.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Milestones exclude credentials, prompts, responses, outputs, and user paths.
    Approval
    The generated-file demo always requires an explicit decision.
    Inspect exact public release evidence
  6. agent.prompt-cache

    Prompt caching and deterministic prefix optimization

    Opt-in provider prefix caching uses canonical segments, provider-aware boundaries, complete authorization isolation, content-free diagnostics, and paired quality/cost/latency evidence.

    Open the Prompt caching and deterministic prefix optimization guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Provider minimums, TTLs, reporting, prices, data policies, and cache availability vary by model and account; unknown metrics remain unknown.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Caching is off by default; provider retention requires explicit consent, restricted data stops the prefix, and local diagnostics contain only hashes, sizes, ids, token aggregates, latency, and estimates.
    Approval
    Changing cache mode or accepting provider retention is an operator model-settings action.
    Inspect exact public release evidence
  7. agent.provider-capacity

    Provider credential pools and fair capacity

    Authorized compatible connections share durable quota, rate, health, priority, and weighted-fair scheduling with sticky-account and drain/revoke controls.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Pools coordinate one Holaryn state directory and compatible provider wire adapters; configured forecast accuracy bounds token and spend reservation accuracy.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Pool state stores opaque connection ids, safe aliases, content-free scope hashes, and aggregate usage only; raw credentials never enter the pool database or diagnostics.
    Approval
    Creating or changing a pool is an operator settings action; revocation requires a destructive confirmation and discards late results from cancelled leases.
    Inspect exact public release evidence
  8. agent.providers

    Provider and model registry

    Curated API, subscription, aggregator, local, and custom connections feed capability-aware model routing.

    Open the Provider and model registry guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Available models and terms remain controlled by each provider.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Credentials use the write-only secret store or explicit environment variables.
    Approval
    Connection creation and sign-in are operator actions.
    Inspect exact public release evidence
  9. agent.trajectory-export

    Privacy-reviewed training-data exports

    Operator-selected successful runs become deterministic OpenAI chat, ShareGPT, or versioned Holaryn episode JSONL through a stale-safe preview, redaction report, exact consent boundary, and digest-bound local provenance.

    Open the Privacy-reviewed training-data exports guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    A durable completed run owned by the local operator, Explicit review of the privacy preview and exact export consent

    Operating limit

    Export does not upload data, start fine-tuning, promote memory, or change routing; images are reduced to available alt text, historical compacted runs fail closed, and pattern redaction cannot replace operator review.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    System messages, context, and tool results are omitted by default; registered secrets, secret-like values, common PII, private paths, metadata, and operator-supplied exact private values are redacted without persisting match values. Hidden chain-of-thought is never collected or exported.
    Approval
    Preview has no side effect; export recomputes and binds the exact source, options, redaction report, and private-value fingerprints before accepting the exact consent phrase. Digest-safe deletion has a separate force confirmation for changed files.
    Inspect exact public release evidence
  10. agent.workflows

    Reusable declarative workflows and runbooks

    Immutable typed workflow versions provide safe branching, bounded fan-out, approvals, waits, retries, durable restart recovery, triggers, imports, curated recipes, artifacts, and audited supervision.

    Open the Reusable declarative workflows and runbooks guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Persistent Holaryn host for scheduled, event-driven, and restart-resilient execution, Configured models, tools, connectors, and secret handles required by a selected recipe

    Operating limit

    Expressions are a small non-executable language, loops and budgets are bounded, interrupted non-idempotent side effects require manual recovery, and irreversible third-party compensation cannot be guaranteed.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Definitions and durable step state remain local; secret values are opaque handles, imported programs are disabled pending review, and dry-run performs no model, tool, connector, or artifact action.
    Approval
    Every consequential step still traverses canonical policy and approval; imports expose permission, dependency, secret, network, risk, trigger, and consequence changes before enablement.
    Inspect exact public release evidence

03

Automation

7 matching capabilities

  1. automation.batch-datasets

    Durable batch and dataset runner

    Versioned CSV, TSV, and JSONL datasets feed bounded, isolated per-row agent runs with preflight estimates, durable attempts, filtered retry, linked exports, and aggregate reports.

    Open the Durable batch and dataset runner guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Persistent Holaryn host for unattended batch execution

    Operating limit

    Inputs are local materialized files in this release. Parquet-ready export writes linked JSONL plus a schema sidecar rather than a binary Parquet file.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Dataset rows, prompts, outputs, item errors, and usage are stored locally; selected providers receive each rendered row prompt, and cross-row memory is disabled by default.
    Approval
    Tools are unavailable unless explicitly allowlisted; every allowed tool still follows ordinary unattended approval and consequence policy.
    Inspect exact public release evidence
  2. automation.browser

    First-party browser agent

    A host-owned Chromium engine provides isolated or opt-in persistent sessions, semantic-first navigation and forms, bounded research, supervised takeover, quarantined downloads, and redacted traces without requiring Node or npx.

    Open the First-party browser agent guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Chromium is the shipping engine; Firefox and WebKit can implement the engine contract later. CAPTCHAs, anti-bot bypass, and control of a user's existing browser are excluded.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Ephemeral profiles are the default; persistent cookies are opt-in, page content is untrusted, credentials are never traced, and downloads remain quarantined artifacts.
    Approval
    Typing, uploads, final submission, browser control, and other interactions pass through consequence-aware approval; direct API actions require an explicit approval field.
    Inspect exact public release evidence
  3. automation.computer-use

    Accessibility-native computer use

    A crash-isolated Windows UI Automation helper exposes bounded semantic application trees, expiring element identities, supervised controls, selected-window screenshots, approval-gated fallback, and redacted action traces.

    Open the Accessibility-native computer use guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows
    Surfaces
    CLI, Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Windows UI Automation ships first. macOS AX and Linux AT-SPI can implement the conformance-tested platform contract later. Elevated/secure desktops, credential managers, games, DRM, and anti-automation bypass are excluded.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Only the explicitly selected application window is observed; credential values and sensitive titles are redacted, whole-desktop continuous capture is disabled, and secure desktop is never automated.
    Approval
    Application launch, value entry, keyboard input, sensitive controls, close operations, and every visual fallback pass through consequence-aware approval.
    Inspect exact public release evidence
  4. automation.event-sources

    Durable proactive event sources

    Webhooks, folder changes, timers, and connector deltas share cursors, deduplication, filtering, source-local circuits, and replayable delivery traces.

    Open the Durable proactive event sources guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    Persistent Holaryn host for polling and unattended execution

    Operating limit

    Connector adapters must supply their delta events; uncertain crash outcomes require operator review before replay.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Events store bounded provenance metadata and payload references; folder events never store file content.
    Approval
    Detection never grants authority; every triggered run follows its profile, policy, budget, and ordinary approvals.
    Inspect exact public release evidence
  5. automation.lifecycle-hooks

    Secure lifecycle hooks

    Versioned blocking and observational hooks add deterministic policy, formatting, tests, notifications, webhooks, and audit automation at agent lifecycle boundaries.

    Open the Secure lifecycle hooks guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Explicit trust for project hook files

    Operating limit

    Project hook trust is bound to the exact file digest; changed files stop executing until reviewed and trusted again.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Handlers receive a bounded, redacted event payload and a minimal environment; project process hooks require an isolated execution backend.
    Approval
    Hooks may deny, mutate explicitly allowlisted fields, or request ordinary approval, but every resulting action is revalidated by normal tool, path, governance, and approval policy.
    Inspect exact public release evidence
  6. automation.scheduler

    Durable scheduler

    Cron, interval, one-shot, and natural-language schedules survive host restarts and support profiles and team posts.

    Open the Durable scheduler guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    Persistent Holaryn host for unattended execution

    Operating limit

    The host must be running when a schedule becomes due.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Schedule definitions are local; a run follows the selected provider and tool privacy rules.
    Approval
    Unattended actions that need approval park in the operator inbox.
    Inspect exact public release evidence
  7. automation.webhooks

    Authenticated webhook triggers

    Stable webhook events enter a durable deduplicated trigger lifecycle; legacy scheduled-job firing remains compatible.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    Explicit listener exposure, Configured webhook token

    Operating limit

    No public relay or managed ingress is included; keep the dedicated token behind HTTPS.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    Bounded metadata and a payload reference are stored locally; raw payloads and credentials are not stored in the event database.
    Approval
    Webhook runs use unattended approval rules and park sensitive actions.
    Inspect exact public release evidence

04

Coding

1 matching capability

  1. coding.validation

    Evidence-driven code validation

    Deterministic discovery builds tiered lint, format, type, test, and package plans; execution records revision-bound diagnostics, honest unverified states, and bounded repair attempts.

    Open the Evidence-driven code validation guide

    Beta maturity

    Reader groups
    Developers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Validation proves only the recorded gates for one exact workspace state; it does not prove complete program correctness.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Validation runs only in the selected workspace with a minimal environment; secret-like variables are withheld and persisted output is redacted.
    Approval
    Fixed checks may run under validation policy; repository-provided commands show their exact argv, cwd, and provenance and require explicit project-command trust.
    Inspect exact public release evidence

05

Collaboration

7 matching capabilities

  1. collaboration.device-nodes

    Secure mobile and edge device capabilities

    A paired phone or edge node advertises narrow OS-mediated capabilities with independent permissions and grants, exact approval-bound invocations, expiring nonces, provenance, and resumable integrity-checked artifacts.

    Open the Secure mobile and edge device capabilities guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Mobile, API, Service
    Prerequisites
    Mobile supervision enabled and the device explicitly paired, HTTPS outside loopback and a trusted private network path, A supported device/browser capability and its local OS permission

    Operating limit

    The reference PWA provides camera, location, notification, and selected-file capabilities; it is not an agent runtime and cannot execute arbitrary tools.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    The server journals bounded invocation/provenance metadata; camera, location, notification, and selected-file content move only after an exact device-side confirmation.
    Approval
    The canonical invoke tool uses ordinary approval policy bound to the exact device, capability, parameters, data movement, and expiry; an ask server grant requires the owner's approval for every invocation under any posture except attended Unrestricted. OS permission and server grant remain independent.
    Inspect exact public release evidence
  2. collaboration.mobile-supervision

    Mobile supervision pocket console

    A paired installable PWA monitors active and recent work, presents exact approval evidence, answers questions, controls runs, opens artifacts, and delivers privacy-safe Web Push alerts.

    Open the Mobile supervision pocket console guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, Mobile, API, Service
    Prerequisites
    Persistent Holaryn host with mobile supervision explicitly enabled, HTTPS outside loopback and a trusted private network path, A browser with IndexedDB; Web Push support is optional

    Operating limit

    No public tunnel, native background service, arbitrary phone tool execution, mobile terminal/editor, or mobile high-impact approval is included; narrow device capabilities have a separate boundary.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    Device credentials and cached summaries are encrypted in browser-local non-extractable storage; lock-screen previews hide sensitive content by default.
    Approval
    Decisions are bound to the exact request digest and an idempotency key; high-impact categories remain desktop-only until verified step-up authentication is available.
    Inspect exact public release evidence
  3. collaboration.peers

    Paired peer agents

    LAN discovery, authenticated pairing, enable/disable controls, remote targets, and ask/send bridge agents across machines.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Reachable peer host, Explicit pairing

    Operating limit

    Discovery is LAN-scoped; internet routing is user-managed.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    Only addressed peer traffic crosses the authenticated link.
    Approval
    Pairing and re-enabling a peer are explicit operator actions.
    Inspect exact public release evidence
  4. collaboration.subagents

    Delegated subagents

    Child runs support live progress, questions, steering, cancellation, and bounded budgets.

    Open the Delegated subagents guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Parallel capacity depends on provider and host limits.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Each child shares only the context and workspace explicitly assigned to it.
    Approval
    Child tools remain subject to policy; questions return to the operator.
    Inspect exact public release evidence
  5. collaboration.task-graphs

    Durable multi-agent task graphs

    Typed DAGs coordinate ready-only parallel work, joins, retries, recovery, evidence, and explicit integration across Agent Teams.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    Persistent Holaryn host, An active Agent Team

    Operating limit

    Cross-host peer members are not eligible until a durable remote completion and lease protocol ships.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Graph state and evidence persist locally; assigned work follows the selected team member's provider policy.
    Approval
    Graph expansion and uncertain-attempt recovery require explicit operator decisions; member tools retain normal approval policy.
    Inspect exact public release evidence
  6. collaboration.task-packages

    Shareable reproducible task packages

    Versioned template, snapshot, and diagnostic packages preserve immutable provenance while supporting reviewed redaction, deterministic archives, signatures, clean-profile dependency planning, local remaps, registries, and sandbox evidence reruns.

    Open the Shareable reproducible task packages guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Explicit review of every export scan finding, Local dependency and permission resolution before activation

    Operating limit

    A valid signature proves integrity and publisher-key identity, not package safety; model prose is not expected to be byte-identical, filesystem registry sharing is local, and organization governance remains deployment-specific.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Raw secrets and account credentials are prohibited; export canaries are supplied by environment-variable name, findings show only redacted samples, and local model/path/account/SecretRef mappings stay outside the immutable package.
    Approval
    Export requires per-finding decisions; imported bundles default to dry-run and sandbox, cannot silently install executable dependencies, and reference reruns require an exact digest confirmation.
    Inspect exact public release evidence
  7. collaboration.teams

    Agent Teams

    Named local, coding-CLI, and remote members coordinate through routing, contracts, budgets, and shared team memory.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Cross-machine members require explicit peer pairing.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Team messages are persisted locally and cross a peer/provider boundary only when routed there.
    Approval
    Members retain their configured approval and contract boundaries.
    Inspect exact public release evidence

06

Extensions

4 matching capabilities

  1. extensions.commands

    Extensible slash commands

    Built-ins, TOML prompts, macro sequences, gated scripts, packs, skills, and MCP prompts share one command surface.

    Open the Extensible slash commands guide

    Stable maturity

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Telegram
    Prerequisites
    None listed in the registry

    Operating limit

    Control-plane commands are intentionally unavailable on untrusted channel surfaces.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Prompt commands stay local until invoked; their resulting model request follows provider policy.
    Approval
    Script commands and nested tools remain approval-gated.
    Inspect exact public release evidence
  2. extensions.mcp

    Model Context Protocol client

    Negotiated stdio and HTTP/SSE sessions contribute policy-filtered tools, prompts, resources, roots, logging, bounded sampling, and typed elicitation with conformance diagnostics.

    Open the Model Context Protocol client guide

    Stable maturity

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    A compatible MCP server

    Operating limit

    Server quality and schemas are controlled by the MCP provider; interactive OAuth refresh remains separate roadmap work.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Data is disclosed only to configured servers under explicit capability and item policy; sampling cannot import Holaryn context or tools.
    Approval
    New server capabilities remain pending; tools, sampling, elicitation, roots, and resources retain independent policy boundaries.
    Inspect exact public release evidence
  3. extensions.mcp-apps

    Sandboxed MCP Apps

    Compatible MCP tools can attach an interactive app that loads on demand in a double-iframe, isolated-origin sandbox with pinned resources, explicit authority, and an accessible structured fallback.

    Open the Sandboxed MCP Apps guide

    Beta maturity

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop
    Prerequisites
    A server implementing the MCP Apps 2026-01-26 extension, The server's apps capability explicitly approved in Settings

    Operating limit

    Apps run only on the local web/desktop host; arbitrary external networking, ambient credentials, top-level navigation, and direct filesystem access are denied.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Tool input, structured results, and approved host actions are shared only with the selected app; pinned HTML and integrity metadata persist with the local chat.
    Approval
    App tool calls and host actions re-enter the canonical approval gate; declared CSP domains and permissions grant no authority by themselves.
    Inspect exact public release evidence
  4. extensions.skills-plugins

    Skills 2.0 and plugins

    Portable SKILL.md packages use exact immutable lifecycle, policy, evaluation, reviewed imports, accessible supervision, and privacy-safe receipts; plugin capabilities remain separately reviewed.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop
    Prerequisites
    Explicit review for install, publication, activation, trust, and authority

    Operating limit

    Offline fixtures do not prove live-host, provider, tool, or executable equivalence; scanning and evaluation do not prove arbitrary third-party content safe.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Packages and protected evidence are local by default; public projections redact private content but exact digests can remain identifying. External sources and integrations use only explicit reviewed requests.
    Approval
    Skill text, metadata, scans, signatures, and trust never grant authority. Consequential lifecycle and typed execution require exact policy and attended review.
    Inspect exact public release evidence

07

Interfaces

12 matching capabilities

  1. interfaces.annotations

    Versioned inline review annotations

    Reviewers can anchor threaded notes to exact messages, plan steps, diff ranges, and artifact regions, then assign, resolve, remap, export, or queue scoped agent work.

    Open the Versioned inline review annotations guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Conservative remapping can leave an annotation visibly orphaned when the selected target cannot be identified uniquely.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Annotation visibility and target visibility are enforced independently; annotation text remains untrusted review content.
    Approval
    Agent actions created from annotations enter the normal context, policy, and approval boundaries.
    Inspect exact public release evidence
  2. interfaces.artifact-workspace

    Professional document and artifact workspace

    Chat, code, canvas, desktop, WebUI, and public API share immutable, previewed, validated, comparable DOCX, XLSX, PPTX, and PDF artifacts.

    Open the Professional document and artifact workspace guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API
    Prerequisites
    Document adapters (bundled in desktop and official Compose builds)

    Operating limit

    Deterministic semantic previews are not every Office or PDF viewer; arbitrary macro-enabled or external-linked templates are not imported.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Artifact content and previews remain local after model generation and use optional state encryption; identifiers, formats, sizes, timestamps, status, and digests can remain visible.
    Approval
    Create and revise are reversible artifact writes governed by normal tool policy; exact base versions prevent silent overwrite.
    Inspect exact public release evidence
  3. interfaces.canvas

    Accessible live canvas

    Agents can render updating dashboards, boards, and tables beside a conversation with semantic screen-reader output.

    Open the Accessible live canvas guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    The supported schema is intentionally smaller than arbitrary web content.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Canvas state is local and follows transcript retention rules.
    Approval
    Canvas rendering does not bypass tool approval.
    Inspect exact public release evidence
  4. interfaces.code

    Screen-reader-first coding workspace

    Plan/build sessions share chat and approvals while durable isolated worktrees separate files, checkpoints, terminals, indexes, validation evidence, and reviewed integration.

    Open the Screen-reader-first coding workspace guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, CLI
    Prerequisites
    A selected workspace

    Operating limit

    Interactive terminals are local PTY/ConPTY sessions; remote attachment and replay across a host restart are not yet supported.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Repository source, worktree metadata, and disposable revision-keyed indexes remain local except excerpts explicitly included in model or coding-CLI requests; untracked secrets are not copied into new worktrees.
    Approval
    Index reads and rebuildable cache maintenance are reversible; target-branch integration requires exact-plan review and approval, while writes, shell commands, cancellation, and checkpoint reversal retain explicit safety controls.
    Inspect exact public release evidence
  5. interfaces.connected-apps

    Connected Apps and first-party productivity connectors

    Versioned connector contracts normalize scoped accounts, external resources, pagination, subscriptions, health, safe action previews, idempotent results, and final-boundary credential leases across first-party and remote capability sources.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    Encrypted scoped-secret storage for live accounts, Provider OAuth client configuration for live accounts

    Operating limit

    The bundled release supplies Gmail, Google Calendar, and Google Drive through one Google Workspace transport, not every SaaS provider; live provider OAuth client registration remains deployment configuration.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    OAuth values remain behind opaque encrypted-secret references; search/fetch results are lazy, bounded, provenance-labeled, and untrusted; activity excludes resource content.
    Approval
    Read scopes are separate from write, send, share, delete, and admin scopes; every consequential tool shows its exact account, tenant, recipients or resource, content or permission, consequence, scopes, and idempotency identity.
    Inspect exact public release evidence
  6. interfaces.desktop-web

    Accessible web and native desktop app

    One responsive React application provides chat, settings, approvals, operators, help, tray integration, native menus, and updates.

    Open the Accessible web and native desktop app guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Desktop packaging and updater support vary by operating-system signing availability.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    The UI is served locally by default; remote listening requires explicit configuration and authentication.
    Approval
    All surfaces share the same approval broker and policy.
    Inspect exact public release evidence
  7. interfaces.ide-acp

    ACP v1 IDE integration

    A stable ACP v1 adapter and reference Visual Studio Code extension create, reattach, steer, cancel, and stream durable Holaryn coding sessions without the Web UI.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Editor
    Prerequisites
    A configured Holaryn chat model for prompts, Visual Studio Code 1.96 or newer for the reference client

    Operating limit

    Stable ACP v1 uses local stdio. The optional Holaryn TCP transport is non-standard, requires TLS 1.3 and mutual TLS, and requires explicit opt-in for non-loopback listening.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    The reference editor sends bounded, redacted workspace context to the local Holaryn process; only the selected provider receives context used in a model turn, and provider credentials never enter the extension.
    Approval
    File, tool, and terminal consequences remain server-owned and use one-shot keyboard-accessible editor prompts; the client cannot widen path policy or forge a lower consequence.
    Inspect exact public release evidence
  8. interfaces.localization

    Internationalized and RTL-ready interfaces

    Versioned ICU-compatible message catalogs, reviewed Spanish and French core translations, deterministic regional formats, and expansion/RTL pseudo-locales span the web, desktop, CLI, channels, and exports.

    Open the Internationalized and RTL-ready interfaces guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Spanish and French cover the reviewed core flows in this release; untranslated legacy surfaces use English while the no-new-raw-string policy drives incremental extraction.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Locale preferences contain language identifiers only; translated content follows the privacy boundary of its original message.
    Approval
    Safety-critical translations are version-reviewed and fall back to reviewed English whenever review metadata is missing or stale.
    Inspect exact public release evidence
  9. interfaces.messaging-channels

    Multi-channel conversation ecosystem

    Channel API 1.0 normalizes identity, threads, edits, attachments, approvals, policy, health, and retry-safe delivery across Telegram, Slack, and Discord reference adapters.

    Open the Multi-channel conversation ecosystem guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Telegram, Slack, Discord, Web, Desktop, API, Service
    Prerequisites
    Explicit external workspace/channel/user binding, A credential-bearing provider transport for live Slack or Discord

    Operating limit

    Telegram retains its bundled live polling service. Slack and Discord ship as authenticated Channel API reference adapters and require an explicitly attached host or executable-extension transport.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Provider messages and attachment metadata are untrusted; the durable store keeps identity metadata and digests, not credentials or attachment bytes.
    Approval
    Bindings carry explicit Holaryn authority; approvals preserve exact consequences and explicit decisions or a visible fallback; revoke and emergency stop require typed confirmation.
    Inspect exact public release evidence
  10. interfaces.public-api

    Versioned public automation API and official SDKs

    A tenant-scoped API, Python sync/async SDK, and TypeScript promise client automate sessions, runs, durable events, approvals, artifacts, discovery, webhooks, and administration.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, API, Service
    Prerequisites
    Explicitly enable the public API and create a scoped service credential

    Operating limit

    Remote access requires an operator-managed TLS reverse proxy; secret-bearing administration responses are shown once and cannot be replayed.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Bearer credentials are header-only, API keys are stored as digests, resource access is tenant-bound, and audit/webhook records omit prompt and credential content.
    Approval
    Automated clients answer the same durable approval requests as interactive surfaces and cannot bypass application-service scope checks.
    Inspect exact public release evidence
  11. interfaces.telegram

    Telegram channel

    A long-polling Telegram bot supports per-chat allowlists, conversations, coding notifications, and team escalation.

    Open the Telegram channel guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Telegram, Service, Web, Desktop
    Prerequisites
    Telegram bot token, Allowed chat identifiers

    Operating limit

    Telegram remains the bundled live third-party channel; Slack and Discord Channel API reference adapters require an explicitly attached transport.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    Messages cross Telegram and the configured model provider when a model turn runs.
    Approval
    Unattended sensitive actions park for operator review.
    Inspect exact public release evidence
  12. interfaces.voice

    Real-time local voice conversations

    Ordered local STT, live captions, automatic/wake/continuous turn modes, privacy-bounded incremental speech, barge-in, recovery, and replay-safe decisions wrap the canonical agent loop.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop
    Prerequisites
    Optional speech engine extra, Microphone permission

    Operating limit

    Browser/OS/hardware determine latency and voice/device quality; no phone, cloud STT, biometric identity, native speech-to-speech, or background OS wake service.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Raw audio is discarded by default; opt-in audio requires bounded expiry, exports omit bytes, captions/text-only are independent, and narration omits raw arguments/output.
    Approval
    Capture starts explicitly; deny binds to the exact pending request, low-impact approval is opt-in and two-step, and high-impact approval requires visual review.
    Inspect exact public release evidence

08

Memory

1 matching capability

  1. memory.hybrid

    Hybrid local memory

    Versioned scoped memory combines relational, full-text, and optional vector recall with explainable decisions, provenance, citations, review, and verified controls.

    Open the Hybrid local memory guide

    Stable maturity

    Reader groups
    Operators, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    Optional embedder or external vector/database backend for non-default modes

    Operating limit

    Semantic quality depends on the selected embedder and model. Feedback weighting and automatic consolidation are deferred; prior exported copies and deployment backups are outside live-store deletion.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    The default store is local; external database, vector, or embedding endpoints receive configured memory data.
    Approval
    Learning can be automatic, paused, or review-gated by scope/category/source; edits, lifecycle controls, source forget, export, and external backend setup are explicit operator actions.
    Inspect exact public release evidence

09

Personalization

3 matching capabilities

  1. personalization.agent-builder

    Versioned custom agents and Agent Builder

    Typed content-only manifests move through draft, validation, profile-bound HolarynBench smoke, immutable publication, capability-scoped specialist routing, typed handoffs, version pinning, rollback, and secret-safe import/export.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Marketplace distribution, hosted organization authoring, executable manifest code, and dependency installation are deferred; unavailable declared dependencies block publication. Automated accessibility evidence is not a WCAG, legal, or manual JAWS conformance claim.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Definitions and validation evidence are local; exports preserve secret references but reject secret values. Retained specialist routing and handoff activity contains bounded identifiers, counts, and digests rather than task or payload content.
    Approval
    Organization policy is a non-bypassable compiler ceiling; overlays and routed specialists can narrow permissions and autonomy but cannot widen them. New permissions and local-to-cloud changes require explicit publication review.
    Inspect exact public release evidence
  2. personalization.profile-library

    Installable Profile Library and coordinated sets

    A local searchable catalog installs exact immutable specialist profiles individually or as ownership-safe Accessibility and Software Development sets, including optional reviewed DevOps planning.

    Open the Installable Profile Library and coordinated sets guide

    Beta maturity

    Reader groups
    Operators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    The initial catalog is built in and local; remote catalog distribution is deferred. Set workflows require every member to be installed and enabled.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Catalog and installation metadata remain local; exact definitions and prior run evidence are retained after uninstall without storing credentials or task content in the ledger.
    Approval
    Every lifecycle mutation requires a state-bound consequence preview. Installation declares capabilities but grants no credentials, accounts, network access, autonomy, integration, deployment, or policy exception.
    Inspect exact public release evidence
  3. personalization.profiles

    Profiles and versioned Persona 2.0

    Named profiles and agents can bind exact immutable Persona 2.0 Markdown versions; deterministic layers, per-chat communication styles, attended proposals, rollback, import/export, and subagent inheritance preserve identity without widening authority.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service, Telegram
    Prerequisites
    None listed in the registry

    Operating limit

    Profile/persona replacement applies at a run boundary, and a per-chat style selected during a response applies to the next turn. Model-backed PersonaBench evaluation is optional and must be reported separately from deterministic coverage.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Persona definitions, versions, proposals, and active selection are stored locally. The effective persona is included in model context; journals record its encrypted snapshot while ordinary events expose content-free identifiers and digests.
    Approval
    Publication, activation, rollback, import confirmation, and proposal acceptance are explicit operator actions. Persona content cannot grant tools, permissions, secrets, autonomy, approvals, policy exceptions, or execution authority.
    Inspect exact public release evidence

10

Quality

2 matching capabilities

  1. quality.benchmarks

    HolarynBench and extended quality gates

    Versioned no-network capability scenarios, parser properties, critical browser flows, fault soaks, and noise-aware performance workloads produce reproducible release evidence.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Developers, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI
    Prerequisites
    Docker only for live shell benchmark scenarios

    Operating limit

    Offline results measure runtime behavior, not competitor or live-model quality; manual assistive-technology sign-off still supplements automated accessibility checks.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Deterministic suites use synthetic fixtures and omit prompts, outputs, secrets, and user paths from private reports.
    Approval
    Benchmark manifests declare and bound every tool and approval decision.
    Inspect exact public release evidence
  2. quality.capability-matrix

    Living capability and documentation contract

    One versioned registry drives deterministic JSON, user documentation, CLI diagnostics, and in-product About data while CI rejects drift and contradictions.

    Open the Living capability and documentation contract guide

    Stable maturity

    Reader groups
    Developers, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API
    Prerequisites
    None listed in the registry

    Operating limit

    Maturity describes the Holaryn integration and does not certify third-party services or security compliance.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Capability diagnostics contain product metadata only and never inspect credentials, prompts, outputs, account identifiers, or user paths.
    Approval
    Reading or generating capability metadata is non-mutating; artifact updates remain reviewed source changes.
    Inspect exact public release evidence

11

Runtime/deployment

14 matching capabilities

  1. platform.hacp

    Optional HACP platform connection

    The standalone core can attach to Holaryn Space through the open HACP boundary without importing Platform code.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    HACP endpoint and credentials

    Operating limit

    The standalone agent does not bundle or require Holaryn Space.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    Only configured HACP messages and requested capabilities cross the platform boundary.
    Approval
    Platform-contributed capabilities register through the same local policy seams.
    Inspect exact public release evidence
  2. runtime.attachments

    Format-aware attachment ingestion and citations

    Hostile files become immutable structured blocks with page, slide, sheet/cell, section, line, image, and archive-path citations; bounded search selects only relevant evidence.

    Open the Format-aware attachment ingestion and citations guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    The documents extra for Office, PDF rendering, image decoding, and OCR

    Operating limit

    The source limit is 5 MiB; perfect OCR and format fidelity are not claimed; legacy binary Office files and executable attachments are unsupported.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Originals, reports, jobs, and derived blocks use local authenticated state encryption; one-time decryption values are never stored and URL credentials/query data are not retained.
    Approval
    Attachment reads are chat-authorized and never grant action authority; extracted content is always untrusted and prompt-injection indicators remain visible.
    Inspect exact public release evidence
  3. runtime.compose-deployment

    Production Docker Compose self-host deployment

    A hardened one-command stack provides authenticated first-run onboarding, pinned non-root containers, durable named volumes, optional database/vector/model/worker/proxy/observability profiles, diagnostics, encrypted backup, tested upgrade, and rollback.

    Open the Production Docker Compose self-host deployment guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Service
    Prerequisites
    A supported Docker Engine with the Compose v2 plugin, DNS plus inbound TCP 80/443 for automatic public TLS, Operator-managed backup storage and recovery material

    Operating limit

    The reference production topology targets one Linux host; external databases, orchestrators, high availability, enterprise identity, off-host backup retention, and capacity scaling remain operator-owned.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    The minimal profile runs locally with a loopback-only application port; production exposes only the TLS proxy. Secrets use mounted files, support bundles redact values, and deployment status reports metadata and configuration shape only.
    Approval
    Bootstrap, production exposure, profile enablement, upgrades, backup, restore, rollback, and secret changes are explicit operator actions.
    Inspect exact public release evidence
  4. runtime.context

    Typed contextual references and provenance

    Versioned references resolve files, attachments, artifacts, URLs, memory, prior work, and canvases at send time with freshness, trust, taint, budgets, and validated citations.

    Open the Typed contextual references and provenance guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Diagnostics, git objects, model/profile, and peer kinds are schema-reserved but need a concrete resolver before their content can be included.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    External URLs drop credentials and query data before persistence; source content remains bounded and labeled in the local transcript.
    Approval
    References never grant authority; current workspace, chat, store, and connector permissions are rechecked on every resolution.
    Inspect exact public release evidence
  5. runtime.dynamic-tools

    Dynamic tool discovery and bounded code mode

    A versioned policy-aware catalog exposes only a bounded discovery core, loads exact schemas after inspection, and can optionally compose approved capability handles in a no-eval restricted runtime.

    Open the Dynamic tool discovery and bounded code mode guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    The restricted language supports sequential call assignments and literals, not arbitrary Python/JavaScript, loops, packages, imports, ambient filesystem/network access, or automatic tool installation.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Catalog metadata is sanitized and bounded; discovery audit events omit tool arguments, outputs, prompts, credentials, and secret values.
    Approval
    Search and schema loading never grant permission; direct, alias, handle, script, and bounded-code invocation all recheck the canonical registry and normal approval path.
    Inspect exact public release evidence
  6. runtime.encrypted-state

    Encrypted local state and recovery backups

    Versioned per-domain envelope encryption protects classified local records, files, and path-independent recovery archives with fail-closed key handling, resumable migration, rotation, and restore validation.

    Open the Encrypted local state and recovery backups guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    OS credential vault or operator-held recovery material, Stopped host for enablement, migration, key maintenance, backup, and restore

    Operating limit

    It does not protect an authorized running process, uncovered control-plane/workspace content, external stores, OS swap or crash dumps; losing both key-provider access and recovery material can make data unrecoverable.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Covered secrets, journal and memory fields, chat/device artifacts, and backup payloads use authenticated encryption; ids, timestamps, states, sizes, digests, embeddings, excluded stores, and explicit exports can remain visible as documented.
    Approval
    Encryption is opt-in pending independent review; key mutations and recovery are explicit stopped-host CLI operations and recovery material is never accepted as a command argument.
    Inspect exact public release evidence
  7. runtime.execution

    Durable local, Docker, and SSH execution

    Workspace-confined one-shot tools and opt-in durable sessions share typed policy, replay, cancellation, artifact, and recovery contracts across local, persistent Docker, and pinned-host SSH backends.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    Docker only when persistent container execution is selected, A pinned SSH profile and remote Holaryn worker for strong remote replay

    Operating limit

    Managed serverless execution is not bundled; raw SSH remains a documented degraded mode without strong remote process identity.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Filesystem access is root-confined, journals are redacted and encrypted when state encryption is configured, and backend network authority is explicit.
    Approval
    Every command is admitted against an immutable session policy before provisioning or launching a side effect.
    Inspect exact public release evidence
  8. runtime.governance

    Enterprise identity, governance, audit, and policy

    Provider-neutral tenant scopes, revocable identity sessions, RBAC, deny-overrides organization policy, legal-hold-aware retention, and tamper-evident audit protect consequential actions.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    An injected governance service and authenticated authorization context, Deployment-owned identity, directory, key custody, audit archive, and deletion adapters as applicable

    Operating limit

    Ordinary standalone hosts remain explicitly unattached; this foundation supplies adapter contracts rather than a bundled live IdP, KMS/HSM, WORM archive, compliance certification, or remote resource deleters.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Audit details are minimized and sensitive-looking values are redacted; exports are tenant-filtered and written beneath a trusted host directory.
    Approval
    Organization deny is non-overridable, review forces one-action approval, and allow never weakens local autonomy or information-flow policy.
    Inspect exact public release evidence
  9. runtime.migration

    Agent migration

    A reviewable importer brings supported skills, memory, and persona data from OpenClaw or Hermes into local Holaryn state.

    Matching public documentation is not available for this release.

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI
    Prerequisites
    Readable source-agent directory

    Operating limit

    Only documented portable data shapes are imported; source-specific runtime state is not.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Migration is local and supports dry-run before writes.
    Approval
    The importer previews and confirms changes unless --yes is explicit.
    Inspect exact public release evidence
  10. runtime.observability

    Privacy-safe usage diagnostics

    Canonical run/model/tool/approval traces, normalized usage, optional cost, bounded OTLP export, Prometheus metrics, and provisioned dashboards support local and fleet diagnosis.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    The optional otel dependency when network export is enabled

    Operating limit

    Token and cost fields may be unavailable when a provider does not report them; exporter buffering is deliberately bounded and may drop signals under backpressure.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Usage records and OTLP signals exclude prompts, responses, thinking, tool arguments/output, paths, URLs, recipients, exception messages, and secrets; exporter destinations are explicitly allowlisted.
    Approval
    Viewing diagnostics is read-only; network export, insecure private transport, authentication secret changes, and external destinations require explicit operator configuration.
    Inspect exact public release evidence
  11. runtime.policy

    Autonomy policy and staged plans

    Ask, selective, allow-all, and unrestricted postures combine with consequence rules and reviewable dry-run plans.

    Open the Autonomy policy and staged plans guide

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Policy cannot eliminate risk from an intentionally approved external action.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Policy evaluation is local and content-free audit metadata is retained.
    Approval
    Unattended runs never auto-approve held actions; unrestricted is always explicit.
    Inspect exact public release evidence
  12. runtime.secret-broker

    Scoped secret broker and just-in-time credential delivery

    Opaque references resolve through exact, expiring, use-bounded leases only inside trusted provider, connector, signing, request, or process adapters, with encrypted metadata, rotation, revocation, audit, and transformed-form redaction.

    Open the Scoped secret broker and just-in-time credential delivery guide

    Beta maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Encrypted local state initialized, An authorized usage policy with exact principal, run, tool, destination, purpose, and injection mode

    Operating limit

    Local metadata reveals opaque ids, states, version/count/timestamp fields, backend ids, and SQLite size. Provider adapters may retain a credential for their bounded runtime after lease consumption; arbitrary third-party code is never a trusted injection adapter.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Values stay in the selected secure backend and trusted injection boundary; authenticated metadata views expose aliases, scopes, versions, policy bindings, and usage timestamps. Redaction is defence-in-depth and cannot undo arbitrary exfiltration after disclosure.
    Approval
    Default deny; policies can require review, break-glass requires a distinct reviewer and exact confirmation, and permanent deletion requires prior revocation plus alias confirmation.
    Inspect exact public release evidence
  13. runtime.security

    Secret storage and layered injection defense

    Write-only secrets, typed provenance/taint, versioned detectors, and information-flow policy protect trust and action boundaries.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service, Telegram
    Prerequisites
    None listed in the registry

    Operating limit

    Detection and provenance reduce risk but cannot prove content is safe; managed DLP classifiers and their content-handling contracts remain deployment responsibilities.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Secrets are redacted; findings retain bounded plain-text evidence, and offline evaluation reports omit evaluated content.
    Approval
    Keywordless untrusted-to-action flows require review; suspected injection and tainted secret egress are non-overridable blocks.
    Inspect exact public release evidence
  14. runtime.service-install

    Cross-platform host service and installation

    CLI, per-user install, persistent host, systemd, launchd, Windows service, desktop packages, and channel-aware updates share release metadata.

    Matching public documentation is not available for this release.

    Stable maturity

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Desktop, Service
    Prerequisites
    Platform service permissions when installing a service

    Operating limit

    Windows tags require Authenticode credentials and run the automated NSIS lifecycle plus atomic checksum, CycloneDX, attestation, and clean-runner verification; native package execution on macOS and Linux remains platform-dependent.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Update checks disclose only ordinary release request metadata to the configured release host.
    Approval
    Install, uninstall, service registration, and update actions are explicit operator actions.
    Inspect exact public release evidence

12

Experimental capabilities

Experimental capabilities require explicit opt-in and have named exclusions. They remain separate from the ordinary inventory even when filters are active.

  1. agent.independent-review

    Independent specialist review with bounded authority

    A reviewer child with read and verify tools only checks a fingerprinted candidate against named criteria, reports findings as data, and rechecks fixes within one shared rounds, attempts, tokens and wall-time budget; approval comes only from host validation of the exact candidate, and a changed candidate invalidates earlier approvals.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, API
    Prerequisites
    HOLARYN_REVIEW_WORKFLOW_ENABLED=true to start reviews or request rounds

    Operating limit

    Off by default until the live reviewer-versus-single-agent comparison (pending the owner's budget decision) justifies it; the offline comparison replays scripted turns and makes no capability claim. Only the owner starts a review (holaryn review start or POST /api/review on the running host, which dispatches the reviewer child in the background); no agent tool or schedule starts one, a fingerprint-only candidate is never approved because the host cannot validate it, and the /reviews web page lands with a later frontend step.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Review records (claims, evidence, notes, dispositions) are field-encrypted in the local state directory; canonical review events carry only ids, state and role words, round numbers and counts.
    Approval
    The reviewer can never publish, record a disposition, approve its own or anyone's change, or widen a grant; its verify tools are kept from the parent's own set and still pass the central approval gate, only the owner accepts a limitation, and nothing the coordinator does approves an action.
    Inspect exact public release evidence
  2. agent.maintenance-proposals

    Owner-enabled maintenance proposals

    An opt-in scheduler job turns exact duplicate and superseded memory records into inactive, quarantined review proposals with lineage, an offline candidate-versus-baseline result, and a reversible disposition.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, API, Service
    Prerequisites
    HOLARYN_MAINTENANCE_ENABLED=true (off by default), Persistent Holaryn host for scheduled runs, Self-improvement collection enabled

    Operating limit

    Only exact normalized duplicates and superseded records with an equal-or-stronger active successor are enabled. Contradiction, skill-drift, and repetition classes stay retain-experimental. A run sees at most 1000 active records. The Improve page lists maintenance proposals with defer and reject; a maintenance status view is deferred to SA-505.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Reads memory metadata locally and stores only memory ids, versions, digests, and aggregate metrics; no model call, no tokens, and no memory content leaves the process. Pinned, held, expired, and non-active records are excluded, and private sessions leave no repetition observation.
    Approval
    The job cannot change grants, activate skills, or edit memory; proposals start quarantined, can only be deferred or rejected by an attended reviewer, and any archive stays a separate operator action.
    Inspect exact public release evidence
  3. agent.safe-self-improvement

    Evidence-gated self-improvement

    Privacy-safe outcome clusters become complete hypotheses, isolated patches, reproducible gates, independent reviews, and deterministic bounded rollouts with automatic rollback.

    Open the Evidence-gated self-improvement guide

    Experimental

    Reader groups
    Operators, Developers, Administrators, Maintainers
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    Git worktree support for patch preparation, Independent reviewer for promotion authorization

    Operating limit

    Promotion records an authorization artifact only. Patch application, production deployment, online experimentation, and unsupervised control-plane mutation are not included.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Signals contain stable references and cluster keys rather than prompts or outputs; collection can be disabled and retained proposal data explicitly deleted.
    Approval
    Ordinary authority cannot mutate the active install or protected controls; protected, high-risk, and evaluation-control changes need two distinct elevated reviewers.
    Inspect exact public release evidence
  4. extensions.executable

    Sandboxed executable extensions

    A versioned language-neutral protocol and Python SDK add reviewed tools and settings schemas through crash-isolated, default-deny Docker processes without importing third-party code into Holaryn core.

    Open the Sandboxed executable extensions guide

    Experimental

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    Docker with an independently reviewed extension image available locally, HOLARYN_EXTENSIONS_ENABLED=true after package and permission review

    Operating limit

    The initial production vertical integrates tools and generic settings; other versioned extension-point descriptors remain catalog-only until their host adapters ship. Docker is required and images are never pulled automatically.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    The extension sees only its read-only package, bounded scratch space, call input/config, and exact resources mediated by declared file, HTTPS, SecretRef, or canonical-tool permissions.
    Approval
    Install is disabled by default; enablement and every permission expansion require explicit operator review and consent.
    Inspect exact public release evidence
  5. extensions.marketplace

    Trusted capability marketplace

    Signed public, private, mirrored, and offline registries distribute skills, content plugins, command and MCP bundles, connectors, themes, assets, and isolated executable extensions through transparent trust tiers.

    Open the Trusted capability marketplace guide

    Experimental

    Reader groups
    Developers, Administrators, Extension authors
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, Service
    Prerequisites
    An organization marketplace policy with pinned registry and publisher trust roots, HOLARYN_MARKETPLACE_ENABLED=true for remote refresh and download

    Operating limit

    Review, signatures, popularity, and sandboxing are separate signals and none proves safety. The first release supplies a local registry/client and publication vertical slice rather than a hosted billing or revenue-sharing service.

    Inspect network, privacy, approval, and evidence
    Network
    optional
    Privacy
    Catalog browsing uses signed cached metadata; remote refresh/download contacts only organization-approved registry locations. Reports remain queued locally until explicitly submitted.
    Approval
    Every package is inspected before install; activation and permission expansion require explicit review. Locked organization allowlists cannot be bypassed locally.
    Inspect exact public release evidence
  6. interfaces.agent-a2a

    A2A agent interoperability

    Explicitly paired external A2A 1.0 agents can advertise approved skills and exchange authenticated, policy-bounded tasks, progress, cancellation, and untrusted artifacts.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, API, Service
    Prerequisites
    An operator-reviewed HTTPS Agent Card trust binding, Transport authentication and outbound-data policy, A host-supplied Agent Card signature verifier when signatures are required

    Operating limit

    Private preview supports the A2A 1.0 HTTP+JSON binding. Push notifications are not enabled, URL artifacts are not fetched automatically, and the standalone server adapter is not mounted unless explicitly configured.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    The outbound policy authorizes the exact redacted message; credentials remain transport-only, and diagnostics omit messages, artifact content, prompts, credentials, and signing material.
    Approval
    Pairing, Agent Card verification, approved skill policy, session authorization, and consequence approval remain independent deny-by-default gates; card metadata never grants authority.
    Inspect exact public release evidence
  7. runtime.advanced-reasoning

    Selectable experimental advanced reasoning

    A host-wide Experimental Features control can opt subsequent Chat turns into a bounded typed plan-search preflight while Standard reasoning remains the default.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    Web, Desktop, API, Service
    Prerequisites
    Unlocked encrypted local state for Advanced reasoning, A configured model provider for model-backed turns

    Operating limit

    Experimental, opt-in, and not a production-readiness claim. The SA-434 four-arm offline comparison records retain-experimental: bounded beam did not beat plan-execute-verify, and only a funded live held-out run meeting decision rule sa434-promote-v1 can promote it. The deterministic benchmarks do not establish live-model quality, classifier accuracy, current provider cost, or latency; live observations remain disabled.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    Candidate state is encrypted locally; events and the Chat presence line remain content-free, and private chain-of-thought is neither requested nor retained.
    Approval
    Selecting Advanced reasoning grants no authority; branch generation, evaluation, and losing branches are charged to the run's shared parent budget, and the selected plan is refused if the workspace or any cited source drifted before it re-enters the canonical tool, permission, approval, workspace, budget, and completion boundaries.
    Inspect exact public release evidence
  8. runtime.advanced-workflows

    Sandboxed advanced capability workflows

    An explicitly enabled typed interpreter composes authorized capability handles with bounded parallel maps, conditions, retries, reductions, schemas, evidence, checkpoints, and inspectable approval pauses.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Private preview and disabled by default. Workflows use declarative calls, maps, conditions, and reductions only; no arbitrary code, ambient filesystem/network/process access, package installation, recursion, or unbounded fan-out.

    Inspect network, privacy, approval, and evidence
    Network
    provider-dependent
    Privacy
    The interpreter has no ambient host access; checkpoints retain bounded structured results and evidence, while traces omit arguments, outputs, prompts, credentials, and private chain-of-thought.
    Approval
    Consequential or approval-required calls pause before dispatch; every prepared and resumed call re-enters current Capability Fabric authorization and the canonical host executor.
    Inspect exact public release evidence
  9. runtime.capability-center

    Capability Center and effective authority projection

    One canonical live projection explains catalog, source/account, policy/model, runtime, and approval state across Web, API, and CLI surfaces.

    Open the Capability Center and effective authority projection guide

    Experimental

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    None listed in the registry

    Operating limit

    Private preview and disabled by default; the previous stable runtime remains the execution and approval authority, and the documented readiness gaps must close before public beta.

    Inspect network, privacy, approval, and evidence
    Network
    none
    Privacy
    Responses contain bounded capability metadata and authority digests; they omit prompts, tool arguments and outputs, credential values, account subjects, and principal identifiers.
    Approval
    Search, inspection, explanation, and schema loading grant no authority; source actions require current authorization, catalog revision checks, permission-diff review, and confirmation when consequential.
    Inspect exact public release evidence
  10. runtime.web-retrieval

    Browser-independent web search, fetch, and citations

    Stable model-facing search and safe page/PDF extraction work across verified tool-calling models without Chrome or provider-specific prompts.

    Matching public documentation is not available for this release.

    Experimental

    Reader groups
    Operators, Developers, Administrators
    Platforms
    Windows, macOS, Linux
    Surfaces
    CLI, Web, Desktop, API, Service
    Prerequisites
    A configured search backend for web_search; direct HTTPS fetch needs no browser

    Operating limit

    Public static HTML, text, and PDFs are supported; use browser automation for authenticated, interactive, rendered, download, or user-takeover flows. Live tests remain opt-in.

    Inspect network, privacy, approval, and evidence
    Network
    required
    Privacy
    URLs are normalized without credentials or fragments; authorization headers, cookies, local paths, unrelated context, and backend exception details never enter results.
    Approval
    Every request is admitted by HTTPS/domain/network policy and Capability Fabric authorization; discovery, fetched instructions, and citations never grant tool authority.
    Inspect exact public release evidence

Read before choosing a build

Current product limitations

One Nightly baseline, not a channel comparison

Every row above is bound to v0.12.6.dev0+g563af09 at source 563af099deba52fa028e46d19b6b0544bd3eda48. The website does not infer a Stable capability set from this Nightly registry.

Capability support is not packaging support

A listed platform describes that capability's registry support. Installer formats, architectures, and availability remain release-asset facts.

Providers and networks remain conditional

Configured providers, external services, credentials, and network modes still govern whether a model-backed or connected capability can run.

Accessibility evidence has open coverage

Semantic and keyboard-oriented implementation does not establish broad assistive-technology compatibility or formal conformance.