A feature list is easy to write and impossible to check. This page does the opposite: it says what the agent executes today, under what contract the set is the same in any channel, and what it refuses, which is the part that decides whether you bring the answer into a meeting.
The set is one
What the agent exposes is a subset of what the API exposes, and that holds as a contract
There is an internal rule the house treats as a contract: the set of operations exposed to the agent is a subset of what the programming interface exposes. Nothing exists in the agent without existing in the API. In practice your team automates from outside everything a person does by talking, and a new capability does not appear in one channel and vanish in the other.
The rule also holds in the direction nobody asks about and that matters more: nothing the agent does escapes the record the API already keeps. The same authorization, the same metering, the same lineage. Talking is not a shortcut around the control, it is another door into it.
What it does
Read, measure, compare, translate, and point to the source of every answer
It opens what came in: each document in its format’s unit, with the text, the origin, the speaker notes, the comments and the hidden ones, which is what is in your documents. It answers from what the engine measured, without reprocessing anything, and brings the address with it. It compares two versions and returns a number instead of an impression. It walks the neural network of your vault node by node, entering through one document and following the links, instead of swallowing the whole folder. And when the question turns into a request, it triggers the operation: translate is the first of them, with a receipt.
Every answer carries that address, and it is what separates an impression from a fact: what the agent states, you reopen and check.
What it refuses
When it is not in your documents, it says so
When something is not in your documents, the agent says it is not there. It does not fill in, does not summarize what it did not read, does not fill the silence with a plausible fiction. For someone answering to an auditor, it is not in the material is a feature, not a failure: it is the answer you repeat in the meeting without fear, because it carries the same backing as the others.
And the refusal is not a behavior instruction we asked of the model, it is a property of the arrangement. The agent does not have your file in front of it to guess from: it has what the engine recorded, and the record either holds the information or it does not. The reason for this is in the conversation is with the AI.
The limit, stated before the test. The agent reads the corpus, never the file. What was not extracted on entry does not exist for it, and the honest answer in that case is the refusal. The text sent to the model follows the provider's retention terms, and the agent's own first line already says so.
How a capability lands on this page
Three questions before the sentence is published
Every capability passes through three questions before it becomes a served sentence: is there a written decision that decides it, was it measured, and can anyone reproduce the measurement. What passes all three we call a receipt. What passes only the first two stays declared as a practice, with no present-tense verb and no number.
A page that presents seven capabilities where three are a receipt is weaker than one that presents four and backs all four, and choosing which of the two to write is the one thing this house does before writing. Where the coverage ends, and why the boundary is stated by us before it is discovered by you, is in trust; the whole of the platform that supports all of this is in platform.
This is the set. Where it reaches you is in interfaces, and the design that separates the conversation from the execution is in the conversation is with the AI.