PTENES
Skip to content
MODULE 1.4

🗺️ The capabilities map

O runtime/CAPACIDADES.md it’s the list of what the agent can use: one line per system, with access method, level, how to call it, policy, and test date. A system without a line isn’t used.

6
Topics
~35
Minutes
Base
Level
Practical
Type
0 of 60%
1

Read the columns in CAPACIDADES.md

In module 1.3, you discovered each system’s path. The capability map is where that discovery is written down in a format the agent reads before acting. The AGENTS.md says: use only systems listed there, through the specified method.

Each line has six columns. Each column answers a question you would ask before letting someone use your system.

Systemwhat? Viawhich way? Levelwhich step? What it’s calledwhich command? Policycan it do it alone? Tested inwhen? one line = one system the agent can use without a date, it doesn’t count

How to read the diagram: read from left to right as a sentence: "system X, through path Y, at level N, is called this, with this policy, and was tested on this date". The green box carries the most weight: without it, the line doesn't count.

ColumnQuestionWhere it comes from
SystemWhich tool do you use for your work?you
ViaHow does the agent reach it?the ladder (1.3)
LevelWhere does this path sit on the ladder?table of LEIA-ME.md
How the agent calls itWith what command or path?the test that worked
PolicyDoes it act on its own or ask first?POLITICA.md (read, change, send…)
Tested inWhen did someone check?the test date, or "pending"

What to look for in the table: only the first column depends solely on you. The others come from the ladder, the policy, and a test that was run.

🗺️
Map

what the agent can use

🛣️
Via and level

come from the ladder

🚦
Policy

comes from POLITICA.md

📅
Test date

or "pending"

2

Understand the two lines that are already ready to use

The file isn't empty. It includes two lines that have already been tested: the agents themselves. One can call the other, and the map needs to explain how.

Use these two as good row template: clear path, ladder level, exact command, policy, and date.

📄 The runtime/CAPACIDADES.md table (actual kit content)
| Sistema | Via | Nível | Como o agente chama | Política | Testado em |
|---|---|---|---|---|---|
| Codex CLI | CLI | 3 | `runtime/pontes/codex-exec.sh` | ler (N4) | 2026-10-05 ok |
| Claude Code | CLI | 3 | `claude -p --permission-mode plan` | ler (N4) | 2026-10-05 ok |
Notice: both are at level 3 (CLI), with a read policy (N4) and a test date. Neither lets the other agent modify files by default.

🆕 New here? Bridge and planning mode

Bridge is what turns a route into something the agent can call. The codex-exec.sh is a bridge: it wraps the codex exec with the kit's rules (module 2.1). Planning mode (--permission-mode plan) is the way to run Claude Code where it only reads and plans, without changing anything. That’s why the Claude line fits under “read.”

On the Codex side, Claude asks for a second opinion through the bridge; changing files through Codex is a separate policy, which you enable only when you ask (recipe R1). On the Claude side, it’s called without opening the screen, in planning mode: it reads and responds without changing anything.

✓ What makes them a good model

  • ✓ Exact command you can copy
  • ✓ Level checked against the ladder
  • ✓ Read-only policy
  • ✓ Date with “ok” from a real test

✗ What a bad row would have

  • ✗ “Use Codex” without saying how
  • ✗ Guessed level
  • ✗ “Everything allowed” policy
  • ✗ No date
3️⃣
Level 3

CLI, high stability

👁️
read (N4)

without asking, without changing anything

🌉
Bridge

codex-exec.sh

✅
Tested line

2026-10-05 ok

3

Use the examples to copy

Below the table, the file has a section called "Examples to copy": four lines for common cases. Look at the last column in each one: pending.

Pending means the line describes the plan, but no one has tested it on your machine yet. Starting with an example similar to your case saves half the work.

📄 Examples to copy (actual CAPACIDADES.md content)
| Planilha de estoque (.xlsx)  | Ponte local (arquivo)   | 6 | ler ~/estoque/estoque.xlsx      | ler (N4)        | pendente |
| ERP sem API                  | Exportação CSV diária   | 6 | ler ~/erp/export/*.csv          | ler (N4)        | pendente |
| Agenda da clínica (planilha) | Ponte local (arquivo)   | 6 | ler/escrever agenda.csv         | alterar (N2)    | pendente |
| Site do fornecedor           | Uso do computador       | 5 | navegador automatizado          | enviar (N2)     | pendente |
How to use: copy the closest matching row into the table above, replace the name and path with yours, and leave it as "pending" until you test it.
ExampleWho has this caseWhere the course tests
Inventory spreadsheetstore, warehouse2.3 (your system’s bridge)
ERP without an APISônia2.2 and 2.3 (R3 recipe)
Clinic scheduleClara2.2 (R3 recipe)
Vendor’s websitewho buys through the portal2.4 (R5 recipe)

What to look for in the table: three examples stop at step 6 and one at 5. The website one stays at 5 because vendor websites usually don’t have an export option, and its policy is "send" (N2), because filling out a form sends data outside.

💡 The policy matches the riskiest action

Inventory and ERP are read-only: N4. The calendar reads and writes: use the higher level, "change" (N2). The website can send: "send" (N2). When copying a line, ask "what’s the worst thing the agent could do here?" and adjust the policy.

⏳
Pending

plan without a test

🌉
Local bridge

three of the four

🖱️
Computer

the site only

✋
N2

modifying and sending require

4

Fill in the map with the agent

The agent knows the ladder; you know your work. Together, you can map it out in minutes. The README includes the ready-to-use request, the same one you used in module 1.2.

O LEIA-ME.md gives a hint on how to guide it: ask the agent to fill in "with me, level by level". It's a guided interview, with you approving each line.

🎯 Objective: add a new line to CAPACIDADES.md for one of your systems

Open claude in the kit folder and paste:

Read runtime/LEIA-ME.md and help me fill out CAPACIDADES.md for my work.

If it tries to do everything at once, add:

Fill it in with me, level by level: one system at a time, one question at a time. Use the examples in CAPACIDADES.md as a guide and mark every row we haven't tested yet as "pending".
How to verify: open the runtime/CAPACIDADES.md. The new line has all six columns filled in, and the last one says “pending” or gives a date and the result of a test you watched run.
1

You name the system

In your own words: “the scheduling spreadsheet,” “the ERP that exports sales.”

2

The agent moves up the ladder

Ask and test one level at a time, as in module 1.3, until you find the most stable route.

3

He proposes the line

Via, level, how to call it and policy, with "pending" at the end.

4

You review and approve

Check the policy especially. When in doubt, choose the most restrictive one.

💡 Sônia in ten minutes

Sônia says, “the distributor’s ERP, it only exports sales CSVs.” The agent goes through the ladder, stops at step 6, and proposes a row based on the “ERP without an API” example, with the path to her export folder and the policy “read (N4).” She approves it. It stays “pending” until the bridge runs, in module 2.3.

🎤
Interview

agent-guided

1️⃣
One at a time

system and question

📎
Example

starting point

👤
Human review

you approve

5

Only let tested rows in

The file opens and closes with the same rule. At the top: "only add a row with test done". At the end: "system with no line here no is used by the agent".

Works like a allowlist: anything not on the list is excluded. This prevents the agent from inventing access to a system no one has checked.

agent wants use a system has a line in CAPACIDADES? no → don’t use it yes has a date test? pending → proposes a test uses via route and policy from the row

How to read the diagram: there are two gates in sequence. Only those who pass through both reach the green box. The red boxes aren’t errors: they show the agent following the rule and returning the decision to you.

✓ Line that can be added

  • ✓ Six completed columns
  • ✓ Exact command or path in "how to call it"
  • ✓ Policy checked in the POLITICA.md
  • ✓ Date of a test you watched run

✗ Row that is left out (or pending)

  • ✗ “I think there’s an API” without testing
  • ✗ Command no one has run
  • ✗ Blank policy
  • ✗ Date copied from another row

⚠️ The agent doesn't test itself by keyword

If the agent writes "tested" on the line, ask to see the command and output. The date on the map is for a test that actually happened on screen, not one it "thinks" would pass. It's the same proof idea as in the recipes: command → expected output.

📋
Allowlist

out of the list, out

🧪
Test

shown on screen

📅
Date

when it passed

⏳
Pending

doesn't use it yet

6

Look at the software before saying it’s impossible

Before marking a system as "no path", observe what the program already provides. A lot of exports are hidden in a menu no one opens. A lot of integrations are on a forgotten settings page.

The good side of reverse engineering is that you discover the path by observing, without connecting any improvised wires. And if there’s no path after you look, that gets recorded too.

1

Export menus and reports

Look for "Export", "Save As", "Reports". A CSV is already a local bridge (step 6).

2

Settings and integrations

Screens with "Integrations," "API," "Developers," or "Webhooks" point to levels 1 to 3.

3

Manufacturer help and website

Documentation usually lists what the program exchanges with other systems. Show it to the agent and ask it to test.

4

Couldn't find it? Make a note in LIMITES.md

What you tried, what blocked you, and the workaround. This record prevents repeating the search and shows what to ask the vendor.

📄 The runtime/LIMITES.md columns (actual kit content)
| data | o que tentei | o que barrou | contorno | status |
|---|---|---|---|---|
Notice: the file arrives empty. The first line is yours. The POLITICA.md also asks you to log every reverse engineering experiment here, for lab purposes only (module 4.4).

💡 Clara looked first

She thought the schedule "didn’t connect to anything." Looking at her own spreadsheet, she saw she could save it as CSV, in the same format as the agenda.csv from the kit. Done: step 6, no hacks.

Quick test (optional): the agent wants to read a system that has a row in CAPACIDADES.md, but the last column says "pending." What happens?

👀
Observe

what already exists

📤
Export

forgotten menu

🔗
Integration

settings screen

🧱
LIMITES.md

what blocked it

🎓 Module summary

✓
Six columns, one sentence — system, method, level, how to invoke it, policy, date.
✓
Two ready-to-use lines — Codex and Claude, level 3, read (N4).
✓
Examples start as pending — copy the closest match and adjust it.
✓
No entry, no use — and a line without a test remains pending.
✓
Look before calling it “impossible” — and note in LIMITES.md what blocked you.

Next learning path:

Track 2 — Connect: the map becomes a bridge, starting with Claude using Codex (2.1).