AI Capabilities by Permission Basis

The Registry records the permission or identity basis under which an AI capability operates where public evidence establishes it. This view groups current capability records by that permission basis. It distinguishes capabilities operating through a user’s permissions from those using separate permissions, a dedicated agent identity, multiple documented mechanisms, or cases where the runtime authority is not publicly established.

Permission basis describes runtime authority. Administrative control over whether an AI feature can be enabled or configured does not by itself establish the permissions used when the capability operates.

How the Registry records permission basisView capabilities that can take actionsView capabilities by human confirmation

Recorded permission basis

User permissions
29
Dedicated agent identity
9
Separate permissions
8
Mixed
23
Not established
41

110 capabilities currently recorded.

What each category records

User permissions
The documented runtime access or actions follow the invoking user's existing permissions.
Dedicated agent identity
The AI operates using a distinct documented non-human identity or security principal.
Separate permissions
The AI uses a permission mechanism distinct from the user's normal permissions, without evidence requiring classification as a dedicated agent identity.
Mixed
Two or more distinct runtime permission or identity mechanisms are documented for the capability.
Not established
The public evidence reviewed by the Registry does not establish the runtime permission or identity basis.

Administrative ability to enable, disable, configure or deploy an AI feature does not by itself qualify as an admin role. Plan entitlement does not establish runtime permission basis, and authentication does not by itself establish runtime permission basis.

Permission basis does not by itself establish what actions the capability can take, whether a human must confirm those actions, whether it can act outside its immediate product, whether it is enabled by default, or whether the permission model is appropriate for a particular organisation. Those properties remain separate Registry fields. “Not established” does not mean the capability has no permissions; it means the reviewed public evidence does not establish the runtime basis.

Showing 110 of 110 capability records.

User permissions 29 records

Dedicated agent identity 9 records

Separate permissions 8 records

Mixed 23 records

Not established 41 records