Skip to content

Connectors & capabilities

A capability is an operation an agent or workspace can use with the appropriate context and authority. Depending on the build and workspace, the category may include file operations, browser control, document or artifact operations, local computation, or domain-specific tools. This is a conceptual taxonomy, not a complete tool inventory.

File access is scoped to the workspace’s authorized resources. Document and Office-style operations can work on structured objects such as pages, rows and cells instead of reducing everything to a text prompt. Generated artifacts remain work products with a separate rendering boundary. Python and shell execution on macOS use an isolated guest rather than unrestricted host execution.

A connector links a workflow to an external service. It does not move the entire Aleph runtime into the cloud. A connector’s authorization, network calls and provider-side data handling form an explicit external boundary. Browser control and web access are separate capabilities with destination policy; they are not automatically granted by the presence of a model.

BYOK model credentials and OAuth account authorization are separate configuration paths. The available adapters and providers are release-dependent, so this page does not advertise an unverified integration list. See the security model for the public trust-boundary description.