{"updated":"2026-09-15","statuses":{"working":"Working now","partial":"Partial / session-dependent","planned":"Planned","blocked":"Blocked"},"capabilities":[{"id":"web-research","name":"Live web research","category":"Research","description":"Search the current web, open sources, compare claims, and cite what changed recently.","status":"working","permission":"Automatic","access":"Web search + browser","verified":"2026-09-08"},{"id":"deep-research","name":"Source synthesis","category":"Research","description":"Turn many sources into concise research, comparisons, recommendations, and decision support.","status":"working","permission":"Automatic","access":"Web + reasoning","verified":"2026-09-08"},{"id":"visual-reference","name":"Image and visual reference search","category":"Research","description":"Find useful visual references when people, places, products, or physical context matter.","status":"working","permission":"Automatic","access":"Web image search","verified":"2026-09-08"},{"id":"gmail","name":"Gmail","category":"Connected accounts","description":"Search and read mail, inspect threads and attachments, draft replies, and perform explicit mail actions.","status":"working","permission":"Approval for messages to known people","access":"Connected Gmail","verified":"2026-09-08","showInAccess":true,"operatorRule":"Use the connected Gmail connector first. Do not say Gmail is unavailable until the connector path has actually been checked.","healthCheck":"Run a harmless mailbox/search read through the connected Gmail path.","fallback":"Use the private 3DVR mail/control path only when that account is explicitly configured there."},{"id":"calendar","name":"Google Calendar","category":"Connected accounts","description":"Read schedules, check availability, create or update events, and reconcile plans.","status":"working","permission":"Automatic for calendar work","access":"Connected Google Calendar","verified":"2026-09-08","operatorRule":"Use the connected Google Calendar path before browser automation.","healthCheck":"Run a read-only calendar lookup.","fallback":"Use browser automation only for calendar surfaces not covered by the connector."},{"id":"contacts","name":"Google Contacts","category":"Connected accounts","description":"Resolve people, email addresses, phone numbers, organizations, and attendee details.","status":"working","permission":"Read / resolve automatically","access":"Connected Google Contacts","verified":"2026-09-08","operatorRule":"Resolve people through Google Contacts before guessing or asking Thomas to repeat saved details.","healthCheck":"Run a read-only contact lookup.","fallback":"Use CRM or the relevant communication thread when the contact is not in Google Contacts."},{"id":"drive","name":"Google Drive / Docs / Sheets / Slides","category":"Connected accounts","description":"Find, read, organize, create, and edit connected Drive content and office files.","status":"working","permission":"Automatic when requested","access":"Connected Google Drive","verified":"2026-09-08","operatorRule":"Use the connected Drive/Docs/Sheets/Slides path before browser automation.","healthCheck":"Run a read-only file search or metadata lookup.","fallback":"Use the portal/library path only when the file is intentionally stored there."},{"id":"outlook","name":"Outlook email","category":"Connected accounts","description":"Search and reference Microsoft Outlook mail; some write paths still depend on the connected surface.","status":"partial","permission":"Approval for sends","access":"Connected Outlook","verified":"2026-09-08","showInAccess":true,"operatorRule":"Check the connected Outlook surface before treating Outlook mail as unavailable.","healthCheck":"Run a harmless search/read operation.","fallback":"Use the authenticated browser path only if the connector cannot perform the required operation."},{"id":"finances","name":"Personal finance analysis","category":"Connected accounts","description":"Analyze linked accounts, spending, cash flow, liabilities, recurring bills, and investments when accounts are synced.","status":"partial","permission":"Read / analyze automatically","access":"Finances connector","verified":"2026-09-08"},{"id":"stripe","name":"Stripe business operations","category":"Connected accounts","description":"Inspect and manage supported payment, product, pricing, and payment-link workflows.","status":"partial","permission":"Explicit business action","access":"Connected Stripe","verified":"2026-09-08"},{"id":"github","name":"GitHub repositories","category":"Code & infrastructure","description":"Search code, inspect repositories, issues and pull requests, and update authenticated repos through the server workflow.","status":"working","permission":"Automatic for authorized project work","access":"GitHub + authenticated Git","verified":"2026-09-08","showInAccess":true,"operatorRule":"Use the connected GitHub integration first; authenticated git on a worker is the execution fallback.","healthCheck":"Read repository metadata or the latest commit.","fallback":"Use authenticated git on an authorized 3DVR worker when repository execution or local tests are needed."},{"id":"vercel","name":"Vercel projects and deployments","category":"Code & infrastructure","description":"Inspect projects, deployments, logs, domains and configuration, and deploy supported projects.","status":"working","permission":"Automatic for authorized project work","access":"Connected Vercel","verified":"2026-09-08"},{"id":"remote-linux","name":"Remote Linux computer control","category":"Code & infrastructure","description":"Run commands, inspect files, edit code, test systems, and coordinate work across authorized Linux machines.","status":"working","permission":"Automatic within authorized systems","access":"Remote Desktop Commander","verified":"2026-09-13","showInAccess":true,"operatorRule":"Enumerate Desktop Commander devices and test a real command before declaring remote machine access unavailable.","healthCheck":"Require both device reachability and a harmless command such as hostname/uptime; a ping alone is not operational proof.","fallback":"Use the private 3DVR MCP/server mesh or authenticated SSH aliases where already configured."},{"id":"digitalocean","name":"DigitalOcean infrastructure","category":"Code & infrastructure","description":"Provision and manage supported cloud resources; current project-specific paths are still being consolidated.","status":"partial","permission":"Explicit infrastructure action","access":"Connected DigitalOcean","verified":"2026-09-08"},{"id":"repo-work","name":"Repository editing and testing","category":"Code & infrastructure","description":"Clone clean working copies, edit code, run tests, inspect diffs, commit, and push changes.","status":"working","permission":"Automatic for authorized repos","access":"Git + remote shell","verified":"2026-09-08"},{"id":"browser-automation","name":"Logged-in browser automation","category":"Code & infrastructure","description":"Use persistent authenticated browser sessions for sites without direct APIs. Browser-changing work is kept single-writer to prevent agents fighting over one profile.","status":"partial","permission":"Depends on site and action","access":"Persistent Chromium on control node","verified":"2026-09-14","showInAccess":true,"operatorRule":"Use the named persistent browser/session lane and respect single-writer identity leases.","healthCheck":"Open the target site and verify the expected signed-in state; process/service health alone is insufficient.","fallback":"Use an isolated browser lane for non-identity work; require human re-pair/login only when the authenticated session is actually lost."},{"id":"bitwarden-vault","name":"Bitwarden password manager","category":"Connected accounts","description":"Use approved Bitwarden/browser paths for saved login material without exposing password values in chat or the public registry.","status":"partial","permission":"Owner-gated / workflow-specific","access":"Bitwarden Password Manager + approved browser/UI path","verified":"2026-09-13","showInAccess":true,"operatorRule":"Treat Bitwarden as the credential source of record where configured. Never request a raw password in chat merely because an automated path forgot how to reach the vault.","healthCheck":"Verify the approved Bitwarden/browser integration can open the vault or satisfy the intended login flow without revealing the secret.","fallback":"Use the 3DVR Secrets Broker for machine credentials; use a human checkpoint for owner-only vault unlocks."},{"id":"recovery-vault","name":"Owner recovery vault","category":"Agent system","description":"Passkey-protected break-glass recovery for owner root credentials. Agents may guide the ceremony but must never receive decrypted recovery material.","status":"planned","permission":"Owner-only local ceremony","access":"WebAuthn PRF + local authenticated encryption + encrypted backup bundle","verified":"2026-09-14","showInAccess":true,"operatorRule":"Agents may launch the Recovery Vault UI and verify encrypted backup health, but must never request, read, log, remember, or persist decrypted owner root credentials.","healthCheck":"Verify the canonical recovery route and encrypted-bundle metadata without performing decryption.","fallback":"Use Bitwarden device/passkey login and documented emergency access until the local recovery client passes production security review."},{"id":"secret-broker","name":"Scoped secrets broker","category":"Code & infrastructure","description":"Approval-based, scoped, auditable secret access with Bitwarden as a backend is under active construction.","status":"partial","permission":"Scoped approval","access":"3DVR control plane + Bitwarden","verified":"2026-09-14","showInAccess":true,"operatorRule":"Use the signed /access/ owner path; never ask for or store raw secrets in chat or the public registry.","healthCheck":"Verify OVH broker status, Bitwarden backend readiness, audit chain, and scoped agent identities.","fallback":"Stop at the approval boundary if the broker is unavailable; do not bypass it with copied credentials."},{"id":"n8n","name":"n8n workflow automation","category":"Code & infrastructure","description":"Build and run automation workflows for repeatable business and agent tasks; reliability is still being hardened.","status":"partial","permission":"Workflow-specific","access":"Server-hosted automation","verified":"2026-09-08"},{"id":"drafting","name":"Messages, emails, proposals and follow-ups","category":"Communication","description":"Draft polished communication using the relevant thread, project, or relationship context.","status":"working","permission":"Draft automatically","access":"Chat + connected context","verified":"2026-09-08"},{"id":"send-known","name":"Send to known contacts","category":"Communication","description":"Send supported email or message actions after approval when communicating with people Thomas knows personally or professionally.","status":"working","permission":"Approval required","access":"Connected mail / messaging paths","verified":"2026-09-08"},{"id":"server-mail","name":"3dvr.tech server email","category":"Communication","description":"Use the server-side 3dvr.tech mail path for business outreach and operations where configured.","status":"partial","permission":"Outreach policy dependent","access":"Server mail + browser","verified":"2026-09-08","showInAccess":true,"operatorRule":"Use the configured 3dvr.tech server-mail path for fresh business outreach when policy allows it.","healthCheck":"Perform a non-sending account/session or mailbox health check.","fallback":"Use the approved connected mailbox/browser route for the same sender identity when configured."},{"id":"whatsapp","name":"WhatsApp Web","category":"Communication","description":"Read and operate the paired WhatsApp Web session when the browser session remains healthy.","status":"partial","permission":"Approval for known contacts","access":"Persistent browser session","verified":"2026-09-14","showInAccess":true,"operatorRule":"Check the paired persistent WhatsApp Web session before saying WhatsApp is unavailable.","healthCheck":"Verify the browser lane is alive, WhatsApp loads, and the paired session is still authenticated.","fallback":"If the session is logged out, surface a re-pair checkpoint instead of repeatedly rediscovering the setup."},{"id":"sms","name":"Google Messages / SMS","category":"Communication","description":"Use the paired web messaging path when the browser session remains healthy.","status":"partial","permission":"Approval for known contacts","access":"Persistent browser session","verified":"2026-09-14","showInAccess":true,"operatorRule":"Check the paired Google Messages/SMS web session before saying texts are unavailable.","healthCheck":"Verify the browser lane is alive, Messages loads, and the paired session is authenticated.","fallback":"If pairing is lost, surface a phone re-pair checkpoint and preserve the documented browser lane."},{"id":"reminders","name":"One-time reminders","category":"Automation","description":"Schedule reminders relative to now or at a specific date and time.","status":"working","permission":"Automatic when requested","access":"ChatGPT automations","verified":"2026-09-08"},{"id":"recurring","name":"Recurring briefings and tasks","category":"Automation","description":"Run daily, weekly, or custom recurring prompts for summaries, reviews, and follow-up work.","status":"working","permission":"Automatic when requested","access":"ChatGPT automations","verified":"2026-09-08"},{"id":"condition-watch","name":"Condition watches","category":"Automation","description":"Check changing conditions on a schedule and only notify when the requested condition becomes true.","status":"working","permission":"Automatic when requested","access":"ChatGPT automations","verified":"2026-09-08"},{"id":"iatse-member-portal","name":"IATSE Local 122 member portal","category":"Work & life ops","description":"Use the persistent OVH browser and scoped Bitwarden-backed login path for Local 122 member availability and portal workflows.","status":"working","permission":"Routine login automatic; requested portal actions per workflow","access":"OVH general browser lane + 3DVR Secrets Broker","verified":"2026-09-15","showInAccess":true,"operatorRule":"Use `3dvr-browser-login iatse`, then verify an authenticated member route such as `/avail`; never ask for the saved password in chat.","healthCheck":"Verify the general lane, broker, and live member UI on `member.iatse.io`.","fallback":"Recover the same OVH profile and mirrored Bitwarden login; request a human step only for provider-enforced verification."},{"id":"encore-ukg","name":"Encore UKG / UltiPro","category":"Work & life ops","description":"Use the dedicated persistent Encore browser lane for UKG schedules, employee workflows, and request-off work.","status":"working","permission":"Routine login automatic; requested employer actions per workflow","access":"OVH encore browser lane + 3DVR Secrets Broker","verified":"2026-09-15","showInAccess":true,"operatorRule":"Use `3dvr-browser-login ukg` and verify `/default.aspx`. Treat `PostLogout.aspx` as expired, never authenticated. Do not substitute the TouchBase time clock for request-off work.","healthCheck":"Verify the Encore lane and the signed-in UKG home page, not merely a reachable CDP target.","fallback":"Return from PostLogout/Login.aspx through the broker-backed login and preserve the same profile."},{"id":"encore-sharepoint","name":"Encore SharePoint / Connect","category":"Work & life ops","description":"Maintain the Encore Microsoft tenant session through SharePoint/Connect; this is also the reliable SSO bootstrap for Lighthouse.","status":"working","permission":"Routine session reuse automatic; Microsoft MFA requires owner approval","access":"OVH general browser lane + Microsoft/Encore SSO","verified":"2026-09-15","showInAccess":true,"operatorRule":"Use the secured corporate Microsoft Login ID when Microsoft asks for identity; keep the persistent browser signed in after owner-approved MFA. Never publish the Login ID or onboarding secrets.","healthCheck":"Verify the signed-in Connect home at `psav.sharepoint.com/sites/encore-connect`.","fallback":"Restart the same general profile; if Microsoft requires Authenticator number matching, surface only that one human checkpoint."},{"id":"encore-lighthouse","name":"Encore Lighthouse","category":"Work & life ops","description":"Use Lighthouse through the persistent general browser profile with Encore Microsoft SSO; SharePoint-first is the canonical recovery path.","status":"working","permission":"Routine session reuse automatic; Microsoft MFA requires owner approval","access":"OVH general browser lane + SharePoint-first SSO","verified":"2026-09-15","showInAccess":true,"operatorRule":"Establish the Encore SharePoint/Microsoft session first, then open Lighthouse in the same profile and verify a flowsheet route. Do not reuse the UKG password on Microsoft SSO screens.","healthCheck":"Verify a signed-in Lighthouse `/flowsheets/` route with live flowsheet content.","fallback":"Recover SharePoint/Microsoft SSO in the same general profile, then retry Lighthouse; direct Lighthouse identity prompts are not the preferred recovery path."},{"id":"workforce-clock","name":"Workforce time-clock workflows","category":"Work & life ops","description":"Operate the authorized time-clock flow, including transfers and history checks, without publishing employee identifiers here.","status":"working","permission":"User-requested action","access":"Authenticated browser workflow","verified":"2026-09-08"},{"id":"freelance-portals","name":"Freelance and union portal operations","category":"Work & life ops","description":"Review bookings, availability, portals, and work opportunities; exact automation depends on each site's session and forms.","status":"partial","permission":"Job-search policy dependent","access":"Browser + email + calendar","verified":"2026-09-08"},{"id":"job-search","name":"Job discovery and applications","category":"Work & life ops","description":"Find strong-fit roles, prepare application materials, and move into applications when authorized; CAPTCHAs, attestations, and identity checks can still require Thomas.","status":"partial","permission":"Authorized applications","access":"Web + browser + files","verified":"2026-09-08"},{"id":"calendar-reconcile","name":"Cross-system schedule reconciliation","category":"Work & life ops","description":"Compare email, calendars, work portals, and appointments to keep the practical schedule aligned.","status":"partial","permission":"Automatic reads; writes per workflow","access":"Calendar + mail + browser","verified":"2026-09-14"},{"id":"artifacts","name":"Documents, PDFs, slides and spreadsheets","category":"Creation","description":"Create finished office artifacts, reports, resumes, presentations, budgets, dashboards, and exports.","status":"working","permission":"Automatic","access":"Artifact tools","verified":"2026-09-08"},{"id":"images","name":"Image generation and editing","category":"Creation","description":"Generate new visuals and transform or edit supplied images when requested.","status":"working","permission":"Automatic","access":"Image generation","verified":"2026-09-08"},{"id":"data-analysis","name":"Data analysis, tables and charts","category":"Creation","description":"Analyze datasets, compute results, build charts, and create spreadsheet-ready outputs.","status":"working","permission":"Automatic","access":"Python + spreadsheet tools","verified":"2026-09-08"},{"id":"memory","name":"Persistent operating context","category":"Agent system","description":"Carry durable preferences, workflows, project context, and operating rules across conversations when memory is enabled.","status":"working","permission":"User-controlled memory","access":"ChatGPT memory + personal context","verified":"2026-09-08"},{"id":"capability-registry","name":"Living capability registry","category":"Agent system","description":"Keep this machine-readable inventory of abilities, status, access path, permissions, and verification dates inside the 3DVR control plane.","status":"working","permission":"Automatic maintenance during agent work","access":"3DVR Portal + Git","verified":"2026-09-08"},{"id":"phone-bridge","name":"Phone-linked access bridge","category":"Agent system","description":"Reach phone-linked services through paired web sessions, companion/browser bridges, and authorized remote paths even though full native Android control is not complete.","status":"partial","permission":"Device/session authorization required","access":"Paired web sessions + 3DVR companion/remote bridges","verified":"2026-09-13","showInAccess":true,"operatorRule":"Use the existing phone-linked bridge paths for SMS, WhatsApp, browser workflows, and companion actions before concluding that phone access is absent.","healthCheck":"Verify the specific bridge needed by the task; phone-linked access is capability-specific rather than one global on/off state.","fallback":"Surface the smallest required re-pair or device checkpoint instead of rebuilding the whole phone integration."},{"id":"android-control","name":"Full Android device control","category":"Agent system","description":"Deeper phone control remains incomplete; browser, server, and connected-app paths currently cover more than native Android control.","status":"planned","permission":"Device authorization required","access":"Future device agent","verified":"2026-09-08","operatorRule":"Do not confuse incomplete full Android control with loss of all phone-linked capabilities; check phone-bridge, SMS, WhatsApp, and browser paths separately.","healthCheck":"Native device-agent check once implemented.","fallback":"Use the existing phone-linked bridge capabilities while native control remains incomplete."},{"id":"unified-inbox","name":"Unified autonomous communications inbox","category":"Agent system","description":"One reliable layer spanning Gmail, 3dvr.tech mail, Outlook, WhatsApp, and SMS with consistent approvals and audit history.","status":"planned","permission":"Scoped approval model","access":"Future 3DVR agent layer","verified":"2026-09-08"},{"id":"self-verify","name":"Automatic capability health checks","category":"Agent system","description":"Read-only access health checks now cover persistent browser lanes, the CDP bridge, secrets broker, and writer leases; automated repair and registry reconciliation are still being hardened.","status":"partial","permission":"Read-only checks by default","access":"3DVR access continuity health check + existing MCP/device health","verified":"2026-09-14","showInAccess":true,"operatorRule":"Treat health as layered: configured \u2192 reachable \u2192 operational \u2192 authenticated session. Never promote a ping into proof that the workflow works.","healthCheck":"Run the least-invasive real operation appropriate to each capability and record evidence privately.","fallback":"When automatic verification is unavailable, use the documented runbook and mark the result stale/unknown rather than guessing."},{"id":"access-continuity","name":"Persistent access continuity","category":"Agent system","description":"Reuse documented connectors, browser profiles, scoped secrets, health checks, and recovery paths before requesting a human reconnect or re-pair.","status":"partial","permission":"Read-only recovery checks automatically; writes per target workflow","access":"3DVR Portal + OVH persistent sessions + secrets broker","verified":"2026-09-14","showInAccess":true,"operatorRule":"Reuse \u2192 health-check \u2192 recover \u2192 fallback \u2192 human checkpoint. A new chat or dead browser process is not proof that authentication was lost.","healthCheck":"Run the least-invasive real check for the connector/session, then classify configured, reachable, operational, and authenticated state separately.","fallback":"Recover the documented persistent session or connector first; require re-login, MFA, CAPTCHA, or device pairing only when the provider actually invalidated authentication."}],"healthLevels":{"configured":"Known to the control plane with a documented access path.","reachable":"The underlying connector, device, or service answers a lightweight probe.","operational":"A real read-only operation succeeds, not just a ping.","session":"The authenticated app/session is usable for the requested workflow."}}
