Part 8 of 16
Capabilities
What the Crux Daemon gives you: 119 capabilities across 14 families, each with what it does, why it works that way, and what it deliberately does not do.
- What the daemon gives youThe explanation set for the Crux Daemon: what each capability is for, why it works that way, what changes once it is on, and what it deliberately does not do.
- Memory that persistsWhy the daemon stores agent memory as plain appended facts, what private-by-default and tenant scoping actually protect, how content is really deleted, and what none of it promises.
- Memory that stays trueWhy the daemon demotes stale facts instead of hiding them, what as_of really answers, how contradictions are surfaced without being resolved, and why consolidation can always be undone.
- Finding thingsWhy recall is budgeted rather than unbounded, what each of the two retrieval lanes is good at, why overflow becomes pointers instead of being dropped, and why the default embedder is not semantic.
- ContinuityWhy the daemon keeps sessions, precedents, handoffs, decisions and constraints, what each one changes for the agent and the operator, and exactly where each one stops.
- Running a fleetWhy the daemon has a work board, ExecPlan projection, approval gates, presence, path leases, orchestrators and projects, what each changes for a fleet lead, and where each stops short of enforcing.
- EvidenceWhat receipts, observation chains, verification and audit bundles actually establish, why each is built the way it is, and the precise point at which each one stops being proof.
- Who is callingWhy the daemon separates naming an actor from proving one, what each of the ten identity and access controls actually stops, and the three places where a reasonable reading of the word "identity" will
- What it costsWhy the daemon measures tokens and never money, what the cost lens can and cannot attribute, and which of the six cost, quota and metering capabilities are actually running on a stock install.
- LeavingWhat you can actually take with you, what the export deliberately leaves behind, why the custody scorecard is a statement about the architecture rather than a measurement of your daemon, and where era
- Bringing your own systemsWhy the daemon reaches out to your repositories, notes and peers rather than asking you to upload them, what each connector is gated on, and the one endpoint that answers "what would leave this box if
- Making it do moreWhy the daemon's extension model looks the way it does: declarative packs that run no code in-process, capability grants, signed distribution, outbound HTTPS tools, the WASM sandbox, the typed substra
- Operating itWhy each operating capability exists and what it refuses to do: a lifecycle that aborts rather than half-starts, configuration precedence and its nine truthiness dialects, ingress caps, the nine readi
- Reaching itWhich surfaces actually work and which do not: the HTTP API, the MCP server and its four JSON-RPC methods, tool-surface shaping, the gRPC plane that returns unimplemented on every RPC, the operator CL
- Trusting the buildWhy you can believe the artefact you installed: a CI-asserted no-phone-home guarantee, eleven required checks behind a merge queue, unsafe code forbidden workspace-wide, cosign-signed releases with a
- Status appendixEvery one of the 119 daemon capabilities in one table: family, status, the flag that gates it and its default, the surface it is reached through, and a link to its explainer.

