Capabilities (distribute Skills / Agents)
Capabilities is the most central governance page in Console: a unified Skill/Agent catalog plus an authorization-and-distribution hub. Here you decide which capabilities the organization has and which departments they go to; employees then automatically inherit the available capabilities based on the department they belong to.
1 · Overview
“Capabilities” covers both Skills and Agents. Capabilities lets you pick suitable capabilities from a master catalog, add them to the organization’s tenant library, and then assign them down by department — avoiding each employee installing their own with inconsistent standards, and letting the enterprise manage everything centrally.
2 · Distribution model
Capability distribution follows a clear multi-level model:
- Master catalog — all selectable capabilities, filterable by industry, occupation, and type.
- Add to tenant library — grant the selected capabilities to the current organization.
- Assign departments — assign capabilities from the tenant library to one or more departments (revocable at any time).
- Member inheritance — members automatically get the corresponding capabilities through the departments they belong to; the system computes each person’s effective capabilities from this.
Effective capabilities = the organization’s tenant library ∩ the capabilities assigned to the departments the member belongs to. Employees never get capabilities they weren’t granted.
〔Figure: the distribution flow from catalog → tenant library → department assignment〕
3 · Page overview
- Capability catalog — filter by type (Skill / Agent), organization status (Enabled / Disabled / Removed / Not in tenant library), industry, occupation, and keyword, with pagination.
- Tenant library — the list of capabilities added to this organization.
- Department targets panel — view the capabilities currently assigned to a department.
- Member effective capabilities — a read-only check of which capabilities each member ultimately gets.
4 · How to distribute capabilities
- In the catalog, filter for suitable capabilities by industry/occupation/type.
- Select them and Add to tenant library (bulk grant).
- Select capabilities from the tenant library × select several departments, and assign in bulk.
- When you need to take them back, bulk revoke is supported the same way.
〔Figure: the bulk assign/revoke of capabilities × departments〕
5 · Capability configuration
Open a single capability to configure it further:
- Skill — view/edit the packaged files (such as
SKILL.md). - Agent — view/edit the Agent’s prompt and upload an avatar; view its packaged dependencies and their authorization status in the organization; set “whether it can be opened to employees” (opening is blocked when a dependency isn’t authorized).
- Version pinning and rollback — preview the version source (organization-pinned version / latest published package), with support for rolling back to a specific version.
6 · Check a member’s effective capabilities
In “Member effective capabilities,” you can see each member’s current departments and every capability they inherit, annotated with its source: default capability / department inheritance / organization grant — handy for verifying “why this person can/can’t use a given capability.”
7 · Important notes
Important notes
- Grants follow the tenant library: dependencies and permissions are resolved solely from the tenant library, and the client’s self-reported claims are not trusted — employees cannot escalate their own privileges.
- The assignment dimension is the department: industry/occupation are labels used to filter for suitable capabilities; the actual grant/assignment is bound to the department.
- Revocation takes effect immediately: after a capability is revoked from a department, the relevant members lose it accordingly.
- Change trail: capability grant and configuration changes are best reviewed together with Agent audit.
Last updated · July 2026 | Next: Knowledge spaces →
