Home / The model / The capabilities

The capability grammar

verb.object.reach. 23 primitives, 10 verbs, 9 object classes and 5 reach classes. This grammar is the action vocabulary for everything else on this site, and it was not invented here.

This site did not author this. The grammar, the 23 primitives and their published glosses come from the capability map. Promoting an ontology means giving it an address, not a new vocabulary, so nothing here is renamed. A new primitive is a new verb, object class or reach, and it needs a probe; a specific path, host or mailbox is an instance of a primitive, never a new one.

The reach classes

ReachWhat it means
selfthe agent's own process, sandbox or turn
projectthe working tree or workspace it was pointed at
hostthe machine, container or account it runs as
tenantthe organisation's accounts, repositories and services
worldanything on the internet

What host, tenant and world mean is the deployment's to say, not the grammar's. For an agent in a vendor's container, host is the container and tenant is a scoped token: not your machine and not your accounts. Every example page states its own reach names for this reason.

The 23 primitives

PrimitivePublished glossReachUndoIn how many shapes
read.file.projectRead the project it is working onprojectyes7 of 9
write.file.projectChange the project it is working onprojectwith-effort5 of 9
read.file.hostRead any file the account can reachhostno7 of 9
write.file.hostChange any file the account can reachhostwith-effort6 of 9
delete.file.hostDelete files anywhere the account can reachhostno4 of 9
read.record.historyRead a retained record: shell history, past sessionshostno4 of 9
execute.process.hostRun programs as the accounthostwith-effort6 of 9
execute.process.selfRun programs inside its own sandbox onlyselfyes0 of 9
send.endpoint.allowedReach a permitted list of hoststenantno1 of 9
send.endpoint.worldReach any host on the internetworldno6 of 9
read.credential.hostRead credentials stored where it runshostno4 of 9
authenticate-as.credential.tenantAct in accounts with the credentials it holdstenantno7 of 9
grant.credential.selfChange its own permission settingsselfyes3 of 9
send.message.worldSend a message to anyoneworldno0 of 9
read.message.tenantRead mail or chat it is connected totenantno1 of 9
write.repository.projectCommit to the repository it was pointed atprojectwith-effort4 of 9
write.repository.tenantPush to a code host (any branch it can reach)tenantwith-effort4 of 9
authenticate-as.credential.signingSign commits with the key it holdstenantno3 of 9
create.record.worldPublish packages, images or pages under the name it holdsworldno2 of 9
write.budget.tenantSpend money or tokens against an account it holdstenantno1 of 9
create.schedule.hostCreate something that outlives the turn where it runs (a cron, a service)hostyes4 of 9
create.schedule.tenantCreate something that outlives the session, on the platform (a routine, a scheduled trigger, a new session)tenantyes1 of 9
read.record.browsingRead every page you visithostno1 of 9

The rules that come with the set

The capabilities as JSON · The source bytes

Provenance. 21 of 99 capability rows on this page were measured, meaning seen directly on the thing itself. The other 78 were derived from what the deployment architecturally is, or from the vendor's published documentation. Every row traces to the published capability map, retrieved 2026-09-11T13:00:37Z, content hash sha256:d6d4ba40f1fb1f93f66. The source bytes.