A connected client receives search and call, plus query when the person may search Standards. The long tail of Tindre actions remains behind a permission-filtered capability catalog.
search
Find permitted capability ids using short domain terms.
schema
Re-run search with include_schemas once the choice is narrowed.
call
Re-check permission and validate the input.
result
Return data, a proposal, or a typed refusal.
Search before calling
Search matches text, not meaning. Use several short queries and include schemas only after narrowing the choice. Permission filtering happens before names or schemas are disclosed.
Read the capability controls
effect describes what changes, control says whether a person gates it, and execution says how the result returns. These fields are independent; an autonomous action is not necessarily harmless.
Human-only work stays absent
Deleting content, changing access or people, credentials, organization settings, sign-in policy, and audit access are not automatable. No flag or broader credential reveals a hidden capability.
Connector tools resolve at call time
An external tool can be disabled, autonomous, confirmation-required, or human-only according to its annotations and attachment policy. Treat tool_unavailable as policy or configuration, not as an invitation to bypass it.