Capability Catalog¶
Authority: Portfolio-Registry.yaml (Engineering-Standard/authority/) Scope: Outcomes the organization or platform can perform. Excludes the tools/technologies that implement them (see tools.md, technologies.md). Status: Authoritative Last verified: 2026-08-29
Purpose¶
The canonical inventory of capabilities provided across the Bluefly portfolio. Lifecycle state machine: see standards/architecture/capability-convergence.md.
Catalog¶
| Capability | Owner | Status | Lifecycle State | Reason | LOC Removable | Evidence |
|---|---|---|---|---|---|---|
| CAP-HUB-001 Agent Platform Hub | ContextControl | Not established | NOT_REVIEWED | OBSERVED 2026-08-19: GitLab project search metadata for blueflyio/contextcontrol.ai/contextcontrol-ai describes it as "ContextControl.ai... shared, governed contextual memory layer," but its README.md on main is entirely the Wasteland (wl) federation-CLI tool documentation — content does not match the project's stated purpose. Flagging the mismatch rather than building a capability conclusion on ambiguous evidence; not resolving further here (would require the actual project owner, not a docs-registry read). | TBD | gitlab.com/blueflyio/contextcontrol.ai/contextcontrol-ai README.md, main branch (fetched 2026-08-19) — contradicts project description metadata from the same fetch |
| CAP-GOV-001 Governance Portal | ContractPlane | Planned | PLANNED | OBSERVED 2026-08-19 (GitLab README, main branch): this Drupal 11 site explicitly owns Governance control primitives (PolicyDecision, TrustPosture, CompatibilityProfile, ReleaseGate, DeployGate, Attestation, EvidenceEnvelope, Lease, Registration) as UI/display surfaces fed by drupal/contractplane (the sole API boundary to contractplane-sdk). Not yet built: the repo's own ordered backlog item 9 is "Wire trust/evidence/policy displays to integration layer" — still pending. This is Bluefly's own product surface, not an upstream capability question; no duplication concern. | n/a (product surface, not removal candidate) | gitlab.com/blueflyio/contractplane.ai/contractplane.ai-website README.md, main branch (fetched 2026-08-19) |
| CAP-INT-001 OSSA Adapter | OpenClaw | Operating | RETAINED | Intentional thin composition over OpenClaw SDK | n/a | SDK Parity Doc |
| CAP-WT-001 Worktree lifecycle | blu-cli (blu worktree) | Operating | RETAINED | gt worktree/polecat sandboxes operate only within Gas City's own ~/gt/ |
n/a (no upstream candidate covers this domain) | gt worktree --help, gt polecat --help, blu-cli/src/commands/blu-worktree.ts (2026-07-13) |
| CAP-MON-001 Runtime monitoring | blu-cli (blu monitor) | Partial | UPSTREAM_INSUFFICIENT | Capability decomposes. (a) Machine-resource daemon (Mac disk/cache thresholds + cleanup) — gt monitors agents/town, not workstation resources; no upstream contract. (b) snapshot + gt-cost.ts already correctly CONSUME gt health/cost contracts. Gap closes when execution leaves workstations; re-review then. | 0 today | bead hq-58wi (2026-07-13) |
| CAP-OBS-001 Observability (metrics/logs/dashboards) | laptop OrbStack K3s (Prometheus, Grafana, Langfuse) | Partial | UPSTREAM_EQUIVALENT | gascityhall/gascity-otel is Gas City's own published, pre-configured observability stack (VictoriaMetrics + VictoriaLogs + Grafana, docker-compose, OTLP push/insert endpoints) explicitly wired for gc/bd/Claude-Code telemetry with pre-built Grafana dashboards. Bluefly currently runs a hand-assembled, laptop-only equivalent (Prometheus + Grafana + Langfuse in OrbStack K3s) already flagged as a migration risk in Engineering-Standard/authority/Platform-Inventory.md ("Entire observability stack... run in laptop K3s"). Direct overlap; not yet migrated. | TBD (docker-compose + K3s manifests, not yet measured) | gh api repos/gascityhall/gascity-otel/readme (2026-07-19); Platform-Inventory.md 'Services: Laptop-Only' |
| CAP-DASH-001 Convoy/fleet activity dashboard | — | Not established | NOT_REVIEWED | gascityhall/overwatch ("Gas City Convoys") is a real-time WebSocket dashboard for convoy operations (completion rate, polecat/crew counts) already published upstream. OBSERVED 2026-08-19 (docs.gascityhall.ai/reference/): the current live dashboard entry point is gt convoy list / gt convoy status, not gt feed as previously assumed here — correcting the tool name only, the overwatch-vs-Bluefly-duplicate question is unchanged. No confirmed Bluefly-side duplicate found yet — needs a check in the Bluefly-repo-audit pass (blueflyio-6xe.5) before this can move past NOT_REVIEWED. |
TBD | gh api repos/gascityhall/overwatch/readme (2026-07-19); docs.gascityhall.ai/reference/ (fetched 2026-08-19): gt convoy list/status is the live dashboard entry point |
| CAP-ESC-001 Escalation of blocked work | — | Retired | REMOVED | gt escalate --help verified live on Oracle — severity P0-P3, bead-tracked (gt:escalation), tiered routing. UPSTREAM_EQUIVALENT. Blu owned no code, only behavior: chat/ad-hoc blocked-reporting retired as the escalation channel wherever a town exists. | 0 (process replacement) | bead hq-58wi (2026-07-13) |
| CAP-GUARD-001 Canonical-repo protection | — | Retired | REMOVED | gt tap guard (PreToolUse, exit 2) is the upstream owner; blu-cli's parallel pre-commit mechanism (commit 27f7457, chore/hq-k7eq-execution-boundary) was a duplicate, verified live and deleted (local + origin) 2026-07-13. | -15 (branch deleted 2026-07-13, local + origin) | bead hq-58wi, bead hq-k7eq, gt tap --help (2026-07-13) |
| CAP-QUEUE-001 Work readiness/queue | blu work surfaces | Partial | UPSTREAM_EQUIVALENT | bd ready remains the Beads graph primitive for unblocked work. Bluefly workers do not browse fleet-wide bd ready as session start; they pull routed work via gc hook then bd update --claim (see operating-model/beads-work-ownership-contract.md). Whether "blu work surfaces" is a thin consumer of bd ready/work_query or duplicates it is NOT_ESTABLISHED — blu-cli source is not in this repo. |
NOT_ESTABLISHED | beads-work-ownership-contract.md; docs.gascity.com how-gas-city-works; bd ready is graph primitive, gc hook is worker discovery |
| CAP-MERGE-001 Merge queue | — | Partial | UPSTREAM_EQUIVALENT | Current Gas City docs confirm Refinery (the Rig's main-branch worktree) runs a continuous mol-refinery-patrol wisp that "processes the merge queue and reviews MRs" — Refinery is current terminology, not stale. Registry already records owner=null (no Bluefly merge-queue implementation) — this is consistent with current evidence and requires no change; Bluefly should remain a consumer of Refinery, not build a parallel queue. |
n/a (no Bluefly implementation exists to remove) | docs.gascityhall.ai/reference/ (fetched 2026-08-19): Refinery patrol processes merge queue, reviews MRs |
| CAP-PATROL-001 Periodic automation/patrols | blu slop, Node jobs | Partial | UPSTREAM_EQUIVALENT | Current Gas City docs confirm Deacon, Witness, and Refinery each run continuous patrol loops via wisps (mol-deacon-patrol: agent lifecycle/ plugin execution/health checks; mol-witness-patrol: nudge stuck polecats) — this is current upstream behavior, not historical. Distinct from Gas City scheduled orders, which are a separate City-level concept not yet evidenced in this registry pass. Whether "blu slop, Node jobs" duplicates Deacon/Witness patrol scope or covers a domain neither patrols (e.g. workstation-only jobs) is NOT_ESTABLISHED without a read of the actual blu slop / Node job definitions. | NOT_ESTABLISHED | docs.gascityhall.ai/reference/ (fetched 2026-08-19): Deacon/Witness/Refinery run continuous patrol loops via wisps |
| CAP-SEC-001 Secrets orchestration | blu secure / blu op / blu 1p | Operating | RETAINED | Enterprise policy layer over 1Password/gitleaks; no upstream candidate found in inspected docs | n/a | 2026-07-13 read of Gas City docs |
| CAP-GITLAB-001 GitLab surface | blu gitlab | Operating | RETAINED | Integration adapter; GitLab API is the upstream | n/a | GitLab API is the published contract |
| CAP-GTBD-001 gt/bd consumption | blu gascity, blu work | Operating | RETAINED | Thin consumers, correct shape (self-described wrappers, OBSERVED) | n/a | gt CLI, Oracle bd |
| CAP-SEC-002 Config/sync credential value-shape detection | Formula (Proposed) | Planned | PLANNED | Genuine new capability. Detects config/sync credentials by value shape (e.g. >=16 chars, hex, base64) rather than key name, avoiding blind spots. | 0 | bc-m25y; detected live Google API key on bc-yn6l |
| CAP-DRU-010 Estate inventory with coverage declaration | Formula (Proposed) | Planned | PLANNED | Genuine new capability. Enumerates estate and tests coverage against a baseline, stating tested-vs-enumerated rather than absolute counts. | 0 | bc-m25y candidate 1 |
| CAP-VER-001 Rendered-effect proof standard | Policy (Proposed) | Planned | PLANNED | Genuine new capability. Acceptance standard requiring RENDERED_EFFECT_PROVEN=YES and BEFORE_STATE_ESTABLISHED=YES. | 0 | bc-m25y candidate 2 |
| CAP-DRU-011 | -discard error suppression scan | Formula (mol-drupal-site-maintain) | Partial | UPSTREAM_EQUIVALENT | Already covered by an existing Formula (mol-drupal-site-maintain) which scans for 2>/dev/null and | |
| CAP-VER-002 Action-shaped acceptance criteria | Policy (Section 10 of the directive) | Partial | UPSTREAM_EQUIVALENT | Already covered by existing Policy (Section 10 of the directive). | 0 | bc-m25y candidate 4 |
| CAP-VER-003 Rotate when corrections turn inward | Policy (Proposed) | Planned | PLANNED | Genuine new capability (Factory Practice). Policy to stop/rotate when corrections surface errors in own prior work rather than estate. | 0 | bc-m25y candidate 5 |
Relationships¶
Capabilities are exposed by Products (products.md) and built on Technologies (technologies.md) via Tools (tools.md). ARCH-001: Bluefly owns composition, not the upstream runtime/CMS/gateway/ledger/identity systems a capability may depend on.