Read the columns in CAPACIDADES.md
In module 1.3, you discovered each system’s path. The capability map is where that discovery is written down in a format the agent reads before acting. The AGENTS.md says: use only systems listed there, through the specified method.
Each line has six columns. Each column answers a question you would ask before letting someone use your system.
How to read the diagram: read from left to right as a sentence: "system X, through path Y, at level N, is called this, with this policy, and was tested on this date". The green box carries the most weight: without it, the line doesn't count.
| Column | Question | Where it comes from |
|---|---|---|
| System | Which tool do you use for your work? | you |
| Via | How does the agent reach it? | the ladder (1.3) |
| Level | Where does this path sit on the ladder? | table of LEIA-ME.md |
| How the agent calls it | With what command or path? | the test that worked |
| Policy | Does it act on its own or ask first? | POLITICA.md (read, change, send…) |
| Tested in | When did someone check? | the test date, or "pending" |
What to look for in the table: only the first column depends solely on you. The others come from the ladder, the policy, and a test that was run.
what the agent can use
come from the ladder
comes from POLITICA.md
or "pending"
Understand the two lines that are already ready to use
The file isn't empty. It includes two lines that have already been tested: the agents themselves. One can call the other, and the map needs to explain how.
Use these two as good row template: clear path, ladder level, exact command, policy, and date.
| Sistema | Via | Nível | Como o agente chama | Política | Testado em | |---|---|---|---|---|---| | Codex CLI | CLI | 3 | `runtime/pontes/codex-exec.sh` | ler (N4) | 2026-10-05 ok | | Claude Code | CLI | 3 | `claude -p --permission-mode plan` | ler (N4) | 2026-10-05 ok |
🆕 New here? Bridge and planning mode
Bridge is what turns a route into something the agent can call. The codex-exec.sh is a bridge: it wraps the codex exec with the kit's rules (module 2.1). Planning mode (--permission-mode plan) is the way to run Claude Code where it only reads and plans, without changing anything. That’s why the Claude line fits under “read.”
On the Codex side, Claude asks for a second opinion through the bridge; changing files through Codex is a separate policy, which you enable only when you ask (recipe R1). On the Claude side, it’s called without opening the screen, in planning mode: it reads and responds without changing anything.
✓ What makes them a good model
- ✓ Exact command you can copy
- ✓ Level checked against the ladder
- ✓ Read-only policy
- ✓ Date with “ok” from a real test
✗ What a bad row would have
- ✗ “Use Codex” without saying how
- ✗ Guessed level
- ✗ “Everything allowed” policy
- ✗ No date
CLI, high stability
without asking, without changing anything
codex-exec.sh
2026-10-05 ok
Use the examples to copy
Below the table, the file has a section called "Examples to copy": four lines for common cases. Look at the last column in each one: pending.
Pending means the line describes the plan, but no one has tested it on your machine yet. Starting with an example similar to your case saves half the work.
| Planilha de estoque (.xlsx) | Ponte local (arquivo) | 6 | ler ~/estoque/estoque.xlsx | ler (N4) | pendente | | ERP sem API | Exportação CSV diária | 6 | ler ~/erp/export/*.csv | ler (N4) | pendente | | Agenda da clínica (planilha) | Ponte local (arquivo) | 6 | ler/escrever agenda.csv | alterar (N2) | pendente | | Site do fornecedor | Uso do computador | 5 | navegador automatizado | enviar (N2) | pendente |
| Example | Who has this case | Where the course tests |
|---|---|---|
| Inventory spreadsheet | store, warehouse | 2.3 (your system’s bridge) |
| ERP without an API | Sônia | 2.2 and 2.3 (R3 recipe) |
| Clinic schedule | Clara | 2.2 (R3 recipe) |
| Vendor’s website | who buys through the portal | 2.4 (R5 recipe) |
What to look for in the table: three examples stop at step 6 and one at 5. The website one stays at 5 because vendor websites usually don’t have an export option, and its policy is "send" (N2), because filling out a form sends data outside.
💡 The policy matches the riskiest action
Inventory and ERP are read-only: N4. The calendar reads and writes: use the higher level, "change" (N2). The website can send: "send" (N2). When copying a line, ask "what’s the worst thing the agent could do here?" and adjust the policy.
plan without a test
three of the four
the site only
modifying and sending require
Fill in the map with the agent
The agent knows the ladder; you know your work. Together, you can map it out in minutes. The README includes the ready-to-use request, the same one you used in module 1.2.
O LEIA-ME.md gives a hint on how to guide it: ask the agent to fill in "with me, level by level". It's a guided interview, with you approving each line.
Open claude in the kit folder and paste:
Read runtime/LEIA-ME.md and help me fill out CAPACIDADES.md for my work.
If it tries to do everything at once, add:
Fill it in with me, level by level: one system at a time, one question at a time. Use the examples in CAPACIDADES.md as a guide and mark every row we haven't tested yet as "pending".
runtime/CAPACIDADES.md. The new line has all six columns filled in, and the last one says “pending” or gives a date and the result of a test you watched run.You name the system
In your own words: “the scheduling spreadsheet,” “the ERP that exports sales.”
The agent moves up the ladder
Ask and test one level at a time, as in module 1.3, until you find the most stable route.
He proposes the line
Via, level, how to call it and policy, with "pending" at the end.
You review and approve
Check the policy especially. When in doubt, choose the most restrictive one.
💡 Sônia in ten minutes
Sônia says, “the distributor’s ERP, it only exports sales CSVs.” The agent goes through the ladder, stops at step 6, and proposes a row based on the “ERP without an API” example, with the path to her export folder and the policy “read (N4).” She approves it. It stays “pending” until the bridge runs, in module 2.3.
agent-guided
system and question
starting point
you approve
Only let tested rows in
The file opens and closes with the same rule. At the top: "only add a row with test done". At the end: "system with no line here no is used by the agent".
Works like a allowlist: anything not on the list is excluded. This prevents the agent from inventing access to a system no one has checked.
How to read the diagram: there are two gates in sequence. Only those who pass through both reach the green box. The red boxes aren’t errors: they show the agent following the rule and returning the decision to you.
✓ Line that can be added
- ✓ Six completed columns
- ✓ Exact command or path in "how to call it"
- ✓ Policy checked in the
POLITICA.md - ✓ Date of a test you watched run
✗ Row that is left out (or pending)
- ✗ “I think there’s an API” without testing
- ✗ Command no one has run
- ✗ Blank policy
- ✗ Date copied from another row
⚠️ The agent doesn't test itself by keyword
If the agent writes "tested" on the line, ask to see the command and output. The date on the map is for a test that actually happened on screen, not one it "thinks" would pass. It's the same proof idea as in the recipes: command → expected output.
out of the list, out
shown on screen
when it passed
doesn't use it yet
Look at the software before saying it’s impossible
Before marking a system as "no path", observe what the program already provides. A lot of exports are hidden in a menu no one opens. A lot of integrations are on a forgotten settings page.
The good side of reverse engineering is that you discover the path by observing, without connecting any improvised wires. And if there’s no path after you look, that gets recorded too.
Export menus and reports
Look for "Export", "Save As", "Reports". A CSV is already a local bridge (step 6).
Settings and integrations
Screens with "Integrations," "API," "Developers," or "Webhooks" point to levels 1 to 3.
Manufacturer help and website
Documentation usually lists what the program exchanges with other systems. Show it to the agent and ask it to test.
Couldn't find it? Make a note in LIMITES.md
What you tried, what blocked you, and the workaround. This record prevents repeating the search and shows what to ask the vendor.
| data | o que tentei | o que barrou | contorno | status | |---|---|---|---|---|
POLITICA.md also asks you to log every reverse engineering experiment here, for lab purposes only (module 4.4).💡 Clara looked first
She thought the schedule "didn’t connect to anything." Looking at her own spreadsheet, she saw she could save it as CSV, in the same format as the agenda.csv from the kit. Done: step 6, no hacks.
Quick test (optional): the agent wants to read a system that has a row in CAPACIDADES.md, but the last column says "pending." What happens?
what already exists
forgotten menu
settings screen
what blocked it
🎓 Module summary
Next learning path:
Track 2 — Connect: the map becomes a bridge, starting with Claude using Codex (2.1).