Complete capability list

Everything AI Agent Sync does.

One system, twelve capability areas, 94 capabilities. Six of the governance controls are the subject of pending patent applications. Everything listed here exists in running code with tests, not on a roadmap.

01

Governance and control

Deterministic controls that decide what an agent may do and stop it when it goes wrong. The AI proposes; policy decides; an independent verifier proves.

Live intervention · patent pending

Acts on a running session — interrupt, reground or halt — rather than reporting a failure after the fact.

Continuity through context loss · patent pending

Detects compaction and truncation mid-task and restores the objective, so a long task does not silently become a different one.

Verify-or-Block · patent pending

No state-changing action executes until the evidence gate passes. The gate runs before the action.

Ground-or-Abstain · patent pending

An agent asserting an outcome it cannot evidence is blocked, not believed.

Capability confinement · patent pending

Narrow explicit permissions per agent. Neither the agent nor injected page text can widen them.

Outcome oversight · patent pending

The agent that acted never confirms its own success. A separate read-only verifier decides.

Approval gates

Checkout, payment, identity, credential and DNS changes require a human decision.

Cost, retry and time budgets

Hard ceilings that stop runaway loops before they spend money.

Objective envelope

The task objective is held outside mutable model context so it cannot drift.

Resource conflict locks

Two agents cannot act on the same resource at once.

Operator kill switch

Halts all autonomous action instantly, across every agent, with no deploy.

Checkpoints and rollback

Recovery points so an action can be reversed where technically possible.

02

Detection

Six deterministic detectors run continuously against the live session. No model judgement, no false confidence.

Runaway loop detection

Identifies repeated tool signatures and circular reasoning, with an automatic circuit breaker.

Stall and no-progress supervision

Catches an agent that is running but no longer advancing.

Prompt injection screening

Screens untrusted page content and inter-agent messages for instruction injection and credential exfiltration.

Overconfidence detection

Flags confident success language unsupported by grounding turns.

Unrecognized agent detection

Notices when a new or unidentified agent enters the session.

Context compaction detection

Detects the moment context is lost — the failure that usually goes unnoticed.

03

Live agent observability

Real-time visibility into machine visitors, with observed fact, inferred intent and verified outcome kept as separate evidence classes.

Agents active now

Who is on the site, their operator, family, version and verification status.

Journey stage and inferred intent

Where the agent is in the journey and what it appears to be trying to do.

Movement timeline

Page-by-page and endpoint-by-endpoint path through the session.

Friction and blocker events

The exact point an agent got stuck, with evidence.

Intervention ledger

Every concierge action taken, the policy decision behind it, and the outcome.

Observed · Inferred · Verified

Three distinct evidence classes, never blended into one misleading number.

04

Agent readiness audit

The free public assessment. Compares what a browser receives with what an honestly identified agent receives, then reports the gaps. Read-only.

Discovery probe

Can an agent find the business and its capabilities at all?

Access probe

Is the agent blocked by policy, rendering or bot controls?

Capability probe

Can the agent determine what actions are available?

Commerce probe

Is machine-readable product, price and availability data present?

Identity probe

Can the agent establish who it is dealing with?

Agent-to-agent probe

Delegated intent, trust, handoff and human-protection readiness.

Uncertainty reporting

Explicitly marks what cannot be determined rather than guessing.

Applicability-weighted score

Findings weighted by whether they actually apply to this site.

05

Machine-readable output generation

Generates the artifacts agents need in order to read and act on a site correctly.

Agent card

Publishable capability descriptor for visiting agents.

AI catalog

Structured product and service catalog at a well-known location.

llms.txt

Machine-facing summary of the site for language models.

Robots and access policy

Explicit crawler and agent access rules.

Schema JSON-LD

Structured data an agent can parse reliably.

UCP manifest

Universal Commerce Protocol capability manifest.

06

Protocols and gateway

The interface visiting agents talk to, with merchant policy applied before any disclosure or action.

A2A endpoint

Agent-to-agent messaging with context and task identifiers.

UCP support

Universal Commerce Protocol surface where applicable.

MCP exposure

Model Context Protocol surface where appropriate.

Generic HTTP/JSON

A plain support gateway for agents on no standard protocol.

Capability negotiation

Discovery and negotiation of what the agent may do.

Unknown-agent conservative mode

Unrecognized agents get the most restrictive treatment by default.

Structured friction intake

Visiting agents can report what blocked them, as evidence not authority.

Agent identity detection

User-agent, verified identity and operator family where available.

07

Concierge and resolution

Merchant-side specialist agents that help an authorized visiting agent finish the journey, inside policy.

Real-time friction classification

Identifies what kind of blocker occurred as it happens.

Dynamic specialist routing

Routes to the right concierge — discovery, comparison, cart, checkout, payment, fulfillment, support.

Graded resolution order

Knowledge answer, then runtime route, then permitted action, then persistent fix, then human escalation.

Approved alternate paths

Pre-authorized checkout, auth and fulfillment routes around a blocker.

Policy-governed offers

Discounts and rewards inside margin floors, inventory rules, exclusions and stacking limits.

Product recommendation

Bundles, substitutes, upgrades and in-stock alternatives from intent and cart.

Generated agent team

A specialist team built from your configuration, per industry.

Human escalation

A clean handoff when policy says a person must decide.

08

Knowledge and learning

Grounded answers from your own data, and verified outcomes that become reusable.

Local knowledge ingestion

Catalog, inventory, pricing, policies, FAQs, shipping, returns, loyalty and promotions.

Vector index

Local embeddings or a vector backend you choose.

Grounded answer engine

Answers carry source provenance — no ungrounded assertions.

Compatibility knowledge graph

Agent, intent, friction, root cause, safe resolution and verified outcome, linked.

Resolution library

Verified fixes recorded as structured, reusable cases.

Recipe promotion gate

A case becomes a reusable recipe only after sandbox replay and independent verification.

Emerging behavior detection

Notices new agent behaviour patterns as they appear.

Knowledge freshness and versioning

Tracks staleness so answers do not silently rot.

09

Journeys and regression protection

Synthetic journeys that prove a change helped, and prove it broke nothing else.

Journey authoring

Build discovery-through-fulfillment test journeys.

Agent-family profiles

Test as different agent families behave differently.

Protected human journeys

Human paths are tested alongside agent paths.

Automatic friction reproduction

Replays a live failure in a controlled environment.

Before-and-after reliability scoring

Quantifies whether the fix actually worked.

Cross-agent regression matrix

Blocks a change that fixes agent A but breaks agent B or a human.

10

Analytics and monitoring

Evidence-backed measurement. Nothing is substituted when data is absent.

Journey completion and friction rate

By agent, journey and stage.

Intervention success rate

Did the concierge actually resolve it?

Conversion and recovery

Journeys saved that would otherwise have failed.

Offer performance and margin impact

What promotions cost and returned.

Fix durability

Whether a repair held, or regressed.

Continuous monitoring

Scheduled re-checks with configurable intervals.

Proactive compatibility alerts

Warning before a known change breaks you.

Drift detection

Notices when the live environment moves away from the verified state.

11

Enterprise, deployment and privacy

Built to run inside your boundary, on your terms, with evidence that survives outside scrutiny.

Local-first runtime

Operational data stays in your environment by default.

No mandatory AI vendor

Local model, bring your own key, bring your own model, or your own gateway.

Air-gapped mode

Full operation with no outbound dependency.

Encrypted local secrets

Keychain-backed credential storage.

SSO, SAML and SCIM

Enterprise identity and provisioning.

Role-based access control

Workspace roles and least-privilege membership.

API keys and service accounts

Programmatic access with scoped permissions.

Hash-chained audit export

Verifiable evidence export, including CEF for SIEM.

Property authorization

Ownership verified by token before any private assessment.

Deployment packaging

Bundles for deploying into your own infrastructure.

Retention controls

You decide what is kept and for how long.

Licensing and entitlements

Offline and air-gapped license verification supported.

12

Where it runs

Released software with notarized builds, not a prototype. 229 deterministic self-tests pass on every build of the detection engine.

Agent platforms

ChatGPT, Claude, Claude Code, Cursor, Grok and Xcode, with a host registry that extends.

macOS

Notarized desktop application.

iOS

Native app with widget and Apple Watch companion.

Android

Native application.

Browser extensions

Chrome and Safari.

Self-hosted service

Container-deployable service for your own infrastructure.