8.0Marketplace
Install a specialist, with its reach on the label
Agents other operators have already built, arriving with their tools declared. You approve what it may touch before it runs, and it is an ordinary editable agent afterwards.
Capabilities
Open any capability. Nothing installs until you have seen what it asks for.
An installed item works inside your workspace's own permissions and the ceiling you set on it. It does not arrive carrying rights from whoever published it.
Installing
Nothing arrives trusted
A marketplace item is a configuration, not a licence. Installing one shows you what it reads, what it writes and what it may never do on its own — before it runs once, not after something goes wrong.
Capabilities
Open any capability. Nothing installs until you have seen what it asks for.
- 8.1Scoped on arrivalThe permissions step is the install. You see the connectors it wants and the actions it claims, and you approve that set rather than the idea of the agent.
- 8.2Declared, not discoveredWhat an item may touch is declared in its manifest and enforced by the runtime. It cannot reach a connector it did not ask for, whatever its prompt says.
- 8.3Yours after installAn installed agent is an ordinary agent. Its prompt, model, connectors and limits are all yours to read and change; nothing about it stays sealed.
- 8.4Built by whomItems say whether Hawi built them or another operator did. Community items carry the same restrictions as ours and get no additional trust for being popular.
What it cannot do
The restrictions travel with the item
An installed agent inherits the workspace's rules rather than bringing its own. There is no marketplace item — ours or anyone's — that can release a held decision or move money, because that is not a permission the platform grants to agents at all.
- 8.5Money is never includedEvery item that touches an amount produces a proposal. Refunds, purchases and payments stop at the gate exactly as they would from an agent you built yourself.
- 8.6Revocable in one moveRemoving an item removes its access immediately. Work it already did stays in the history, attributed to it — uninstalling is not a way to edit the past.
- 8.7Scoped to one workspaceInstalling into one workspace grants nothing in another. An agency running a workspace per client installs per client, deliberately.
- 8.8Updates are not silentA new version that asks for more than the installed one requires approving the new set. Widening reach is always a decision, never an update.
The rest of the system
- 1.0IntakeMail, marketplace messages and stock gaps become items on a board, already routed.
- 2.0WatchCover counted against what is selling, so a line that runs out is flagged early.
- 3.0ActNamed agents work the item and hand it between themselves with the evidence attached.
- 4.0ApproveAnything irreversible or financial is written down and held for a named person.
- 5.0MonitorWhat moved, what is stuck, and what is waiting on you — with the numbers behind it.
- 9.0LimitsA ceiling on what runs unattended, and the actions no ceiling ever covers.
- 10.0BoardsOne board held by people and agents alike, where the column follows the owner.
- 11.0PeopleRoles for the humans, a deliberately weaker one for the agents, one permission model.
- 12.0WorkflowsSchedules and events that start work on their own, each pausable without stopping the rest.
Start with one agent and one job.