Capability matrix · v3.25.0

What NAVIG operates today
Every row is real.

The full operating surface — grounded in the shipped CLI, the runtime contracts, and the gateway. Each capability carries its proof: the command you run or the surface you open. No roadmap items dressed as features.

Shipped28Preview2

Infrastructure operations

SSH hosts, remote execution, containers, databases, files, deploys, updates.

  • Host management

    Shipped

    Add, switch, and test SSH hosts — with per-project context that remembers which server each repo talks to.

    navig host add · navig host use <name> · navig host test
  • Remote execution

    Shipped

    Run any command on the active host, stream the output back.

    navig run "systemctl status nginx"
  • Docker operations

    Shipped

    Containers on the active host at a glance.

    navig docker ps
  • Databases & backups

    Shipped

    List databases, dump them, back them all up in one pass.

    navig db list · navig backup run --db-all
  • Remote files

    Shipped

    Inspect, edit, and upload files on remote hosts without opening a shell.

    navig file show /var/log/syslog --tail --lines 20
  • Deploys with rollback

    Shipped

    Repeatable deploy workflows with history and a rollback path.

    navig deploy run · navig deploy rollback · navig deploy status
  • System updates

    Shipped

    Preview updates before applying them; roll back when one goes wrong.

    navig update check · navig update run · navig update rollback

Missions & runtime

Typed contracts, a strict mission state machine, receipts, and mission control in the Deck.

  • Typed runtime contracts

    Shipped

    Node, Mission, and ExecutionReceipt are versioned, schema-pinned contracts — not loose JSON.

    Published JSON Schemas · serialize→parse→serialize is byte-stable
  • Mission state machine

    Shipped

    queued → running → succeeded / failed / cancelled / timed out. Only legal transitions are accepted; failed and timed-out missions can retry. State survives a daemon restart.

    Enforced by the runtime — illegal transitions are rejected
  • Runtime API

    Shipped

    REST on your local gateway: register nodes, create and advance missions, read receipts.

    GET/POST /runtime/nodes · /runtime/missions · /runtime/receipts
  • MCP runtime resources

    Shipped

    Any MCP-speaking agent can read the runtime state — nodes, missions, receipts.

    navig://runtime/nodes · missions · receipts
  • Mission control in the Deck

    Shipped

    Queue view, per-state timeline, start / cancel / retry, and receipt inspection — the full lifecycle without CLI fallback.

    Deck → Mesh Explorer → Missions
  • Execution receipts

    Shipped

    Every mission that reaches a terminal state records a receipt: outcome, duration, error.

    Deck → Missions → Receipts · GET /runtime/receipts
  • Agentic executor missions from the Deck

    Preview

    Launching AI-executor missions directly from the Deck (today the Deck operates runtime lifecycle records).

    Follow-up on the public roadmap
  • LAN mesh discovery

    Preview

    Flux Mesh Phase 1 — peers discover each other on your LAN over UDP multicast. LAN only, by design.

    GET /mesh/peers — cross-network validation still open

Safety, audit & undo

Approval gates that fail closed, a tamper-evident ledger, honest reversibility, and undo.

  • Approval gate — fails closed

    Shipped

    Privileged gateway actions pass a policy gate: allow / require-approval / deny per action pattern. Timeout, error, or no approval channel means denied — never silently allowed.

    gateway.policy rules · approve from Deck, Telegram, or the API
  • Structured audit log

    Shipped

    Every policy decision is recorded — who, what, when, decision, matched rule. Inputs stored as hashes, never verbatim.

    GET /audit?limit=50
  • Hash-chained operations ledger

    Shipped

    Every recorded operation is chained to the previous one. Delete, edit, or reorder a line and verification fails. Tamper-evident, not tamper-proof — worded honestly.

    navig ledger verify
  • Reversibility labels & undo

    Shipped

    Every operation is labeled green (undoable), yellow (compensable), or red (irreversible) — unknown defaults to red. Undo replays the last green operation with drift detection and double-undo protection.

    navig undo --list · navig undo
  • Ledger inspection

    Shipped

    Recent operations with chain state, reversibility label, and undone markers. Secrets are redacted before display.

    navig ledger show --tail 50
  • Dangerous-command detection

    Shipped

    Destructive patterns are blocked or require confirmation; safe mode limits sudo and concurrency.

    Built into the execution path — configurable patterns
  • Self-diagnosis & self-heal

    Shipped

    One command checks the whole install; safe fixes can run automatically, disruptive ones are prescribed, never auto-executed.

    navig doctor · navig doctor --heal --dry-run

Comms & reachability

Your operator, reachable from anywhere — on your own infrastructure.

  • Telegram channel

    Shipped

    Operate from your phone: run status checks, receive alerts, approve gated actions.

    Approvals resolve from Telegram · Deck Inbox · the API
  • Lighthouse edge — no tunnel

    Shipped

    One browser login deploys a tiny edge worker to YOUR Cloudflare account. The brain dials out over a single WebSocket — no tunnel, no open ports, no domain.

    navig lighthouse login · navig lighthouse url
  • Deck as a Telegram Mini App

    Shipped

    Publish your own Deck UI and wire it up as your bot’s Mini App button — one command.

    navig miniapp deploy
  • Local Deck cockpit

    Shipped

    The operator cockpit in your browser, served by your local gateway.

    navig deck open

Skills, personas, spaces & blocks

The four things you install — knowledge, personality, workshops, and verifiable outcomes.

  • Skills

    Shipped

    Knowledge the agent pulls in — teaches it how to do a kind of task. SKILL.md format, Claude Code-compatible. Always free.

    navig skills list
  • Personas

    Shipped

    A personality — the voice and manner the agent speaks in. Free.

    Install from Harbor Bay
  • Spaces

    Shipped

    A whole workshop — a folder with skills, agents, plans, and memory.

    navig space init · navig space install <source>
  • Blocks

    Shipped

    Installable, executable, verifiable outcomes — apply an outcome, proven by a verified receipt.

    navig apply <id>

Proof beats promises.

Install NAVIG and run any row on this page against your own infrastructure — or start with the guided first mission.