ROTE PLAYOFFS / FIELD KIT

150 STARTING POINTS

Find work worth teaching.

Research-backed Play ideas that connect APIs, browsers, and local commands to produce a useful result.

Start with a repeated decision, reconciliation, or investigation. Filter by the systems you can reach, then give the exploration prompt to your agent.

EXPLORE 150 IDEAS ↓
FOR AGENTS · COMPLETE CATALOG

Give this list to your agent.

Use the readable brief for exploration or the versioned feed for structured selection.

STARTER PROMPTRead https://www.modiqo.ai/play-ideas.md. Shortlist three Play ideas that fit the systems I can access. For each, explain the repeated result, required access, safety boundary, and why it is worth teaching. Do not run anything yet.
THE IDEA INDEX

Choose a useful result.

Complexity describes the join, not the quality. Start with work you understand well enough to correct.

150 IDEAS
FIELD
REACH
001 · CLOUD-001COMPLEXITY 5 / 5

Software and cloud operations

Release causality window

For every production release, align the deploy, flag changes, error onset, and monitor movement on one clock. Produce the smallest evidence-backed change set that could explain the regression.

GitHub DeploymentsSentry ReleasesLaunchDarklyDatadog
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Build a release causality window for the latest production regression from GitHub Deployments, Sentry, LaunchDarkly, and Datadog. Align all evidence by time and propose the smallest plausible change set. Do not modify production.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
002 · CLOUD-002COMPLEXITY 4 / 5

Software and cloud operations

Feature-flag ghost town

Find flags with no recent evaluations, no live code references, and no owner activity. Separate safe retirement candidates from dormant emergency controls.

LaunchDarklyGitHubLinear
REACH
APISHELL
ACCESS
Required
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Find feature flags with no recent evaluations and no live code references. Use LaunchDarkly, repository search, and Linear ownership to produce a review-only retirement queue, preserving emergency controls.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
003 · CLOUD-003COMPLEXITY 5 / 5

Software and cloud operations

Unowned public endpoint

Join public DNS, cloud accounts, repository ownership, and current worker records to find internet-facing names whose responsible team no longer exists.

Cloudflare DNSAWS OrganizationsGitHubRippling
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map every public DNS name to its AWS account, repository owner, and current team in Rippling. Flag endpoints whose owning team or maintainer no longer exists. Make no changes.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
004 · CLOUD-004COMPLEXITY 5 / 5

Software and cloud operations

Infrastructure reality split

Compare declared Terraform, saved state, recent CloudTrail changes, and the current pull request. Explain each unmanaged or out-of-band difference and identify its likely author and purpose.

TerraformAWS CloudTrailGitHub
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Compare Terraform configuration and state with recent AWS CloudTrail changes and the open pull request. Explain every reality split, identify likely ownership, and stop before apply.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
005 · CLOUD-005COMPLEXITY 4 / 5

Software and cloud operations

Shadow scheduler map

Discover recurring work hidden across CI schedules, pipeline schedules, cloud event rules, and machine crontabs. Group jobs by effect instead of by scheduler name to expose duplicates.

GitHub ActionsGitLab CIAWSlocal crontab
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Inventory recurring jobs across GitHub Actions, GitLab pipelines, AWS scheduling configuration, and local crontabs. Group jobs by actual effect and flag duplicates or conflicting schedules. Do not disable anything.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
006 · CLOUD-006COMPLEXITY 5 / 5

Software and cloud operations

Rollback route rehearsal

Trace the exact reversible path from a bad deploy through the previous artifact, feature flags, aliases, and health checks. Rehearse commands against dry-run or read-only endpoints.

GitHub DeploymentsVercelLaunchDarklySentry
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Rehearse the rollback route for the current production release using GitHub Deployments, Vercel, LaunchDarkly, and Sentry. Resolve the last known good state and verify commands without executing production writes.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
007 · CLOUD-007COMPLEXITY 4 / 5

Software and cloud operations

Error budget by change batch

Attribute reliability loss to change batches rather than individuals by joining deploy windows, monitor state, and incident timing. Reveal risky combinations of changes that look harmless in isolation.

GitHub DeploymentsDatadogPagerDuty
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Explain error-budget loss by deploy batch using GitHub Deployments, Datadog monitors, and PagerDuty incidents. Find combinations of changes and conditions, not people to blame.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
008 · CLOUD-008COMPLEXITY 5 / 5

Software and cloud operations

Support-to-release regression graph

Connect first customer symptom, error fingerprint, affected release, and fixing commit. Preserve cases where support noticed a regression before observability did.

ZendeskSentryGitHubLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Connect recent Zendesk symptom reports to Sentry fingerprints, GitHub releases, and Linear fixes. Show which regressions customers detected before monitors and keep customer text private.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
009 · CLOUD-009COMPLEXITY 4 / 5

Software and cloud operations

Green pipeline, broken data

Detect pipelines that pass while their promised output is stale, empty, or statistically implausible. Compare job artifacts with downstream dashboards and prior successful output.

GitLab CIGitHub Actions artifactsGrafanashell
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Find pipelines that report success while their output is stale, empty, or implausible. Compare CI artifacts, shell-level output checks, and Grafana downstream signals against prior good runs.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
010 · CLOUD-010COMPLEXITY 3 / 5

Software and cloud operations

Runbook command truth test

Extract commands from operational docs, compare them with current CLI help and repository paths, then execute only harmless discovery forms. Report stale flags, renamed services, and missing prerequisites.

Notion or Google Drivelocal CLIsGitHub
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Verify our operational runbooks against current CLI help, repository paths, and read-only discovery commands. Report stale syntax and missing prerequisites without executing destructive steps.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
011 · CLOUD-011COMPLEXITY 5 / 5

Software and cloud operations

Certificate renewal dependency chain

Map every certificate-bearing hostname to its DNS validation records, Terraform ownership, secret references, and renewal calendar. Find renewals that depend on a person or vanished repo.

Cloudflare DNSTerraform1PasswordGoogle Calendar
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map certificate hostnames to Cloudflare validation records, Terraform ownership, 1Password references, and renewal events. Flag any renewal dependent on a person, missing repo, or inaccessible vault. Never reveal secrets.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
012 · CLOUD-012COMPLEXITY 4 / 5

Software and cloud operations

Region asymmetry finder

Compare infrastructure shape, cost mix, and telemetry coverage across nominally identical regions. Explain whether each asymmetry is intentional, drift, or a hidden capacity risk.

AWS Cost ExplorerTerraformDatadog
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare supposedly identical regions using Terraform, AWS cost and usage, and Datadog coverage. Classify asymmetries as intentional, unexplained drift, or capacity risk with evidence.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
013 · CLOUD-013COMPLEXITY 4 / 5

Software and cloud operations

Orphan preview environment

Find preview deployments whose branch, pull request, owner, or DNS alias no longer exists, then estimate ongoing cost and exposure.

VercelGitHubCloudflare DNSAWS Cost Explorer
REACH
APISHELL
ACCESS
Required
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Find preview environments with no live branch, pull request, owner, or expected DNS alias. Estimate cost and exposure, then produce a review-only cleanup list.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
014 · CLOUD-014COMPLEXITY 4 / 5

Software and cloud operations

Shipped but unobservable

For each deployable service, prove the existence of traffic telemetry, a meaningful monitor, an on-call route, and an owner. Surface services that can fail silently.

GitHubDatadogPagerDutyRippling
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For every deployable service, prove there is telemetry, a meaningful monitor, a PagerDuty route, and a current owner. List services that can fail silently and the missing proof.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
015 · CLOUD-015COMPLEXITY 4 / 5

Software and cloud operations

Change-freeze contradiction

Cross-check declared freeze windows against deployments, flag edits, and emergency approvals. Distinguish documented exceptions from unnoticed policy drift.

Google CalendarGitHub DeploymentsLaunchDarkly audit logLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare declared change-freeze windows with GitHub deploys, LaunchDarkly audit events, and Linear exception records. Separate approved exceptions from unexplained contradictions.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
016 · CLOUD-016COMPLEXITY 3 / 5

Software and cloud operations

Hotfix knowledge gap

Identify production hotfixes whose incident context, rationale, or follow-up never reached the issue tracker or durable docs. Build the missing evidence packet from commits and incident timelines.

GitHubPagerDutyLinearNotion
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find recent production hotfixes whose rationale or follow-up never reached Linear or Notion. Reconstruct a draft evidence packet from Git history and PagerDuty timelines for human review.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
017 · CLOUD-017COMPLEXITY 4 / 5

Software and cloud operations

Dependency-change blast radius

For a package upgrade, trace direct and transitive consumers, CI artifacts, deploy targets, and observed errors. Show which services actually exercised the changed path.

npmGitHubGitHub Actions artifactsSentry
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Map the real blast radius of a package change across dependency trees, repository consumers, CI artifacts, deploy targets, and Sentry errors. Show exercised paths, not just declared dependencies.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
018 · CLOUD-018COMPLEXITY 4 / 5

Software and cloud operations

Schema-consumer impact map

Diff an API schema, locate generated and handwritten consumers, identify tests covering changed fields, and open a review list by owning team.

OpenAPI or GraphQL schemaGitHubLinearshell
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Diff the current and proposed API schema, find generated and handwritten consumers, locate tests for changed fields, and produce an owner-grouped impact review. Make no code or ticket changes.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
019 · CLOUD-019COMPLEXITY 5 / 5

Software and cloud operations

Drift owner resolver

For each out-of-band cloud change, connect the CloudTrail actor to the Terraform resource, repository owner, and reason recorded in work tracking. Mark changes with no durable explanation.

AWS CloudTrailTerraformGitHubLinear
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Resolve every recent out-of-band AWS change to its Terraform resource, repository owner, and Linear rationale. Flag changes with no durable explanation and do not revert anything.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
020 · CLOUD-020COMPLEXITY 5 / 5

Software and cloud operations

Cost spike as product event

Explain cloud-cost anomalies through product releases, feature rollouts, and traffic or error changes instead of cost categories alone.

AWS Cost ExplorerGitHub DeploymentsLaunchDarklyDatadog
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Explain the latest AWS cost spike using deploys, feature rollouts, and Datadog traffic or error movement. Rank evidence-backed product causes and label uncertainty explicitly.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
021 · CLOUD-021COMPLEXITY 5 / 5

Software and cloud operations

Data-residency route proof

Trace a representative request from DNS through deployment region and configured data services. Compare the actual route with declared residency policy and repository configuration.

Cloudflare DNSAWS OrganizationsTerraformGitHub
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace a representative customer request from Cloudflare DNS through AWS accounts, regions, and Terraform-managed data services. Compare the actual route with declared residency policy and report contradictions.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
022 · CLOUD-022COMPLEXITY 4 / 5

Software and cloud operations

Secret-expiry launch risk

Before a launch, map referenced secrets to CI jobs, deploy targets, owners, and upcoming expiry or rotation events without retrieving secret values.

1PasswordGitHub ActionsVercelGoogle Calendar
REACH
SHELLAPI
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Before launch, map 1Password secret references to GitHub Actions jobs, Vercel targets, owners, and expiry events. Identify launch risks without retrieving or printing secret values.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
023 · CLOUD-023COMPLEXITY 5 / 5

Software and cloud operations

Dead-service retirement proof

Prove a service is unused by joining DNS, request telemetry, deploy history, repository activity, and residual cost. Preserve counterevidence that blocks retirement.

Cloudflare DNSDatadogGitHub DeploymentsAWS Cost Explorer
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Build retirement proof for a suspected dead service from DNS, traffic, deploy history, repository activity, and residual cost. Preserve counterevidence and make no destructive changes.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
024 · CLOUD-024COMPLEXITY 3 / 5

Software and cloud operations

Monorepo test-gap cartography

Map changed files to ownership, historical failures, workflow selection, and produced artifacts. Find code paths that changed but never reached a relevant test job.

GitHubGitHub ActionsGitHub Actions artifactsGit
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Map this monorepo change to owners, selected workflows, historical failures, and produced test artifacts. Identify changed paths that never reached a relevant test job.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
025 · CLOUD-025COMPLEXITY 3 / 5

Software and cloud operations

License-change release gate

Detect when a dependency or transitive dependency changes license between the locked and proposed versions, then locate the binaries and deployables that absorb it.

npmGitHubshell
REACH
SHELLAPI
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Compare licenses across the locked and proposed dependency trees, including transitive packages. Map changed licenses to shipped binaries and produce a legal-review queue without making legal conclusions.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
026 · AGENT-001COMPLEXITY 3 / 5

Agent operations

Instruction collision map

Resolve every instruction file that can affect a task, apply directory precedence, and show contradictory commands before an agent starts work.

AGENTS.mdCopilot instructionsrepository files
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Resolve all repository and path-specific agent instructions for this task, apply precedence, and show contradictions or unreachable guidance before any work begins.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
027 · AGENT-002COMPLEXITY 4 / 5

Agent operations

Tool-permission shadow diff

Compare tools advertised to an agent with tools it actually invoked, their read/write annotations, and the permissions used. Reveal broad grants that never contributed to the result.

MCP schemasagent tracelocal policy files
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Compare advertised agent tools, MCP annotations, actual calls, and permissions used in this run. Identify unnecessary write or open-world access and propose a review-only least-privilege profile.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
028 · AGENT-003COMPLEXITY 4 / 5

Agent operations

Tool-schema drift impact

Diff MCP or OpenAPI tool schemas across versions, then search prompts, skills, and saved Plays for arguments or outputs that became invalid.

MCP serversOpenAPI specsGitHublocal Play catalog
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Diff current and previous tool schemas, then find prompts, skills, and Plays that depend on removed arguments, changed enums, or output fields. Produce an owner-grouped repair list.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
029 · AGENT-004COMPLEXITY 4 / 5

Agent operations

Replay nondeterminism microscope

Replay the same task against frozen inputs, compare tool-call order and outputs, and isolate whether divergence came from the model, changing external state, or an unstable command.

agent tracesGit worktreeslocal processes
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Replay this agent task against frozen inputs three times. Compare tool order, arguments, outputs, and file diffs to isolate model, external-state, and command nondeterminism.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
030 · AGENT-005COMPLEXITY 3 / 5

Agent operations

Retry-loop fingerprint miner

Cluster repeated failed calls by unchanged error, mutated argument, and eventual recovery. Turn productive recovery sequences into candidate Plays and flag blind retries.

agent tracesMCP tool resultsshell history
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Cluster retries in recent agent traces by error, argument change, and eventual recovery. Separate productive diagnosis from blind repetition and propose reusable recovery candidates.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
031 · AGENT-006COMPLEXITY 3 / 5

Agent operations

Context payload bloat locator

Measure which files, tool outputs, and repeated excerpts enter context but never influence a citation, decision, command, or diff. Preserve required safety instructions even when unused.

agent tracerepository filesMCP resources
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Measure context inputs against later citations, decisions, commands, and diffs. Find repeated or inert payload while preserving safety and policy instructions regardless of apparent use.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
032 · AGENT-007COMPLEXITY 4 / 5

Agent operations

Expert-correction hotspot

Find where experts repeatedly correct the same field, assumption, or tool choice across runs. Rank the corrections whose reuse would prevent the most rework.

agent tracesGit diffsissue comments
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find repeated expert corrections across agent traces, Git diffs, and issue comments. Rank the corrections most likely to prevent future rework and show the evidence for each.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
033 · AGENT-008COMPLEXITY 4 / 5

Agent operations

Fallback-model divergence

Run a frozen task through the configured primary and fallback paths, then compare tool selection, policy adherence, evidence use, and final diffs rather than prose style.

agent harnessGit worktreestest runner
REACH
SHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Run this frozen task through the configured primary and fallback model paths in isolated worktrees. Compare tool choice, policy adherence, evidence, tests, and diffs rather than writing style.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
034 · AGENT-009COMPLEXITY 3 / 5

Agent operations

Claimed-test verifier

Compare an agent's test claims with shell history, workflow artifacts, exit codes, and changed files. Detect tests that were named but never run or ran before the relevant change.

agent traceshell historyGitHub Actions artifactsGit
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Verify every test claim in this agent run against command history, timestamps, exit codes, artifacts, and the final diff. Flag tests never run or run before the relevant change.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
035 · AGENT-010COMPLEXITY 3 / 5

Agent operations

Invisible side-effect census

Snapshot filesystem, processes, network listeners, package locks, and Git status before and after a run to reveal side effects absent from the final answer.

local filesystemprocess tableGitpackage manager
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Compare pre-run and post-run filesystem, process, listener, package-lock, and Git state. Report side effects that were not disclosed, without cleaning or terminating anything.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
036 · AGENT-011COMPLEXITY 5 / 5

Agent operations

Credential reach versus task need

Map each credential available to a run to the exact endpoint or command that used it. Show credentials whose scope exceeded the task's demonstrated need.

1Password referencesMCP serversagent tracecloud APIs
REACH
SHELLAPI
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map available credential references to actual endpoints and commands used in this run. Identify scope beyond demonstrated need without reading, printing, revoking, or rotating any secret.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
037 · AGENT-012COMPLEXITY 2 / 5

Agent operations

Stale skill versus live CLI

Compare commands embedded in agent skills with current CLI grammar, help, and harmless dry runs. Pinpoint instructions that would fail today.

skill fileslocal CLIsGit
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Audit agent skill commands against installed CLI versions, grammar, help, and harmless dry runs. List stale flags, missing subcommands, and unsafe assumptions without executing writes.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
038 · AGENT-013COMPLEXITY 5 / 5

Agent operations

Prompt-to-write provenance

For each external write, connect the user instruction, intermediate evidence, approval state, tool call, and resulting remote object. Surface writes with no clear authority chain.

agent traceMCP tool resultsGit historyexternal audit logs
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Build a provenance chain for every external write in this run: user authority, evidence, approval, tool call, and resulting object. Flag any write with a missing link.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
039 · AGENT-014COMPLEXITY 4 / 5

Agent operations

Cross-harness result parity

Run the same Play in two supported harnesses with frozen inputs and compare artifacts, writes proposed, citations, and policy outcomes.

two agent harnessesGit worktreestest runner
REACH
SHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Run this Play in two supported harnesses against the same frozen fixture. Compare artifacts, proposed writes, citations, policy outcomes, and final tests in isolated worktrees.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
040 · AGENT-015COMPLEXITY 3 / 5

Agent operations

Missing stop-condition detector

Examine long runs for loops that had no measurable completion state, then infer a verifiable stop condition from the user's requested outcome and successful prior runs.

agent tracestest resultsissue state
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Find agent runs that continued without a measurable completion state. Infer evidence-based stop conditions from the requested outcome, tests, and comparable successful runs.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
041 · AGENT-016COMPLEXITY 3 / 5

Agent operations

Tool-argument instability map

Compare repeated calls to the same tool and identify arguments the agent guesses inconsistently, especially IDs, time windows, pagination, and destructive flags.

agent tracesMCP schemasAPI logs
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Compare repeated calls to the same tools and identify unstable guessed arguments, especially identifiers, time windows, pagination, and write flags. Suggest parameters that should be resolved once and referenced.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
042 · AGENT-017COMPLEXITY 4 / 5

Agent operations

Shared-state contamination test

Run a task in a clean profile and the normal profile, then identify outputs caused by stale browser sessions, cached files, environment variables, or prior tool state.

agent harnessbrowser profilelocal filesystemGit
REACH
BROWSERSHELL
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Run this task once in a clean profile and once in the normal profile. Compare outcomes to locate stale browser, cache, file, environment, or tool state without revealing secrets.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
043 · AGENT-018COMPLEXITY 2 / 5

Agent operations

Public canary for tool honesty

Use stable no-auth public endpoints to test whether a harness actually performs calls, preserves citations, handles pagination, and reports rate limits rather than fabricating results.

OSVWorld Bank IndicatorsUSGSagent harness
REACH
API
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Build a no-auth harness canary using OSV, World Bank, and USGS. Verify real calls, pagination, citations, error handling, and rate-limit reporting with small read-only queries.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
044 · AGENT-019COMPLEXITY 5 / 5

Agent operations

Approval-boundary proof

Inject representative read, reversible-write, and irreversible-write requests into a sandbox and prove where the harness pauses, asks, or proceeds.

agent harnesssandbox APIGit worktree
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Prove this harness's approval boundaries with sandboxed read, reversible-write, and irreversible-write cases. Record where it pauses, asks, or proceeds; never target real systems.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
045 · AGENT-020COMPLEXITY 4 / 5

Agent operations

Self-modifying instruction watch

Detect when a run changes an instruction, skill, hook, or policy file that will govern its own later behavior. Explain the before-and-after authority implications.

Gitagent instruction filesskill fileshooks
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Detect any changes this run makes to instructions, skills, hooks, or policy files that will govern later behavior. Explain the authority change and require human review.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
046 · AGENT-021COMPLEXITY 3 / 5

Agent operations

Agent dependency expansion audit

Compare requested work with every package, binary, browser extension, and MCP server added or activated. Find expansions that were unnecessary or persisted beyond the task.

npmlocal package managerMCP configurationGit
REACH
SHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Compare the requested task with packages, binaries, extensions, and MCP servers added or activated during the run. Flag unnecessary or persistent expansion without removing anything.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
047 · AGENT-022COMPLEXITY 3 / 5

Agent operations

Ungrounded identifier detector

Collect every repository, ticket, deployment, user, and incident identifier asserted by the agent and prove it came from a tool result or user input.

agent traceGitHubLinearPagerDuty
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Audit every repository, issue, deploy, user, and incident identifier in this run. Prove each came from user input or a tool result and mark every ungrounded identifier.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
048 · AGENT-023COMPLEXITY 4 / 5

Agent operations

Rate-limit recovery rehearsal

Simulate throttling against fixtures and verify that the agent respects retry headers, preserves pagination state, and avoids duplicate writes after recovery.

mock APIagent harnessMCP tool schema
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Rehearse API throttling with fixtures. Verify retry headers, backoff, pagination continuity, and duplicate-write prevention without intentionally rate-limiting a production service.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
049 · AGENT-024COMPLEXITY 4 / 5

Agent operations

Judgment per compute cycle

Measure useful verified outcomes per model call by linking each reasoning segment to evidence gathered, corrections avoided, tests passed, and durable artifacts produced.

agent tracestest runnerGitissue tracker
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Measure useful verified outcomes per model call for recent runs using evidence gathered, corrections avoided, tests passed, and durable artifacts. Diagnose workflow waste without ranking people.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
050 · AGENT-025COMPLEXITY 4 / 5

Agent operations

Repeated-trace Play candidate ranker

Find recurring successful trace shapes across different tasks, quantify shared steps and expert corrections, and rank the highest-value methods to crystallize as Plays.

agent tracesGitissue tracker
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find recurring successful trace shapes across recent work. Rank methods to crystallize as Plays by repeated steps, expert corrections avoided, frequency, and outcome value.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
051 · SECURITY-001COMPLEXITY 5 / 5

Security and compliance

Dormant admin, live token

Find administrators with no recent interactive use but active API tokens or automation attributed to them. Separate legitimate service ownership from forgotten human credentials.

OktaOkta System LogGitHub1Password
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find dormant administrator accounts that still have active tokens or automation. Separate legitimate service ownership from forgotten human credentials using Okta events, repository evidence, and secret references. Make no access changes.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
052 · SECURITY-002COMPLEXITY 5 / 5

Security and compliance

Former-employee deploy lineage

Trace deploy keys, signed commits, CI jobs, and recent production changes back to workers who have left or changed roles. Identify durable machine ownership before proposing cleanup.

RipplingGitHub ActionsGitAWS CloudTrail
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace deploy keys, CI jobs, signed commits, and production changes to workers who left or changed roles. Resolve current machine ownership and produce a review-only cleanup plan.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
053 · SECURITY-003COMPLEXITY 5 / 5

Security and compliance

SSO-bypass path graph

Compare the intended identity provider path with direct passwords, API tokens, break-glass accounts, and local application users. Show every route that reaches a protected system without the expected SSO policy.

OktaGoogle AdminSaaS user directoriesaudit logs
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map every documented route into protected SaaS systems and identify accounts, tokens, or local users that do not traverse the intended SSO policy. Use directory and audit evidence only; do not attempt access.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
054 · SECURITY-004COMPLEXITY 4 / 5

Security and compliance

Ownerless machine identity

Link service accounts, bot users, API tokens, and scheduled jobs to a current team, repository, and business purpose. Surface identities whose last human owner has vanished.

OktaGoogle AdminGitHub ActionsRippling
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map service accounts, bot users, tokens, and scheduled jobs to current teams, repositories, and business purpose. Flag machine identities whose human owner or purpose can no longer be proven.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
055 · SECURITY-005COMPLEXITY 5 / 5

Security and compliance

Secret-rotation blast radius

Before rotating a secret, enumerate every reference, CI job, deployment target, fallback credential, and known owner. Prove which consumers can be tested independently.

1PasswordGitHub ActionsVercelTerraform
REACH
SHELLAPI
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Map the blast radius of rotating a named secret across 1Password references, CI jobs, Vercel targets, and Terraform. Identify independently testable consumers without reading or changing the secret.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
056 · SECURITY-006COMPLEXITY 5 / 5

Security and compliance

Role entropy after job changes

Compare recent promotions, transfers, and manager changes with current group membership and actual application use. Find additive access that accumulated while old duties disappeared.

RipplingOktaOkta System Log
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare recent role changes in Rippling with Okta groups and actual application use. Find additive access that outlived prior duties and prepare an owner-confirmed review queue.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
057 · SECURITY-007COMPLEXITY 5 / 5

Security and compliance

Session outlives employment

Detect browser or SaaS sessions active after a worker's termination or suspension time by aligning HR state with authentication events and application logs.

RipplingOkta System LogGoogle Admin Reports
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Align worker termination and suspension times with Okta and Google Workspace authentication events. Flag sessions or activity that continued afterward and preserve an incident-ready evidence timeline.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
058 · SECURITY-008COMPLEXITY 5 / 5

Security and compliance

API-key privilege versus observed use

Compare an API token's allowed scopes with the endpoints it actually called over a representative period. Produce the narrowest observed permission set plus exceptions that need owner confirmation.

SaaS audit logsOkta1Password referencesagent traces
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare each selected API token's allowed scopes with endpoints actually used over the review period. Propose the narrowest observed scope and list unproven future needs for owner confirmation.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
059 · SECURITY-009COMPLEXITY 4 / 5

Security and compliance

Dormant webhook still delivering

Find integrations whose source object is inactive but whose webhook endpoint still receives data. Resolve the endpoint owner, payload sensitivity, and last confirmed consumer.

Linear webhooksGitHubCloudflare DNSapplication logs
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find webhooks attached to inactive projects or integrations that still deliver data. Resolve endpoint ownership, payload sensitivity, and last confirmed consumer without disabling anything.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
060 · SECURITY-010COMPLEXITY 5 / 5

Security and compliance

Audit-log silence detector

Model the events a control should generate, then flag systems where expected activity continued but audit events stopped, changed shape, or arrived late.

Okta System LogGoogle Admin ReportsLaunchDarkly audit logAWS CloudTrail
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Define expected audit events for selected controls, then detect where business activity continued but Okta, Google, LaunchDarkly, or CloudTrail evidence stopped or changed shape. Label uncertainty.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
061 · SECURITY-011COMPLEXITY 5 / 5

Security and compliance

Production data in development artifacts

Inspect CI artifacts, test fixtures, screenshots, and error samples for identifiers that also appear in production-only records. Establish provenance without copying sensitive values into the report.

GitHub Actions artifactsSentryGitshell
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Check CI artifacts, fixtures, screenshots, and error samples for hashed indicators of production-only data. Establish provenance and affected artifacts without reproducing sensitive values.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
062 · SECURITY-012COMPLEXITY 5 / 5

Security and compliance

Expired exception, missing control

Join security exception records with current configuration and recent system use. Find exceptions that expired while the risky state remained and no compensating control appeared.

LinearNotionOktaAWS CloudTrail
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare expired security exceptions with current configuration and recent use. Flag risky states that remained after expiry without a documented compensating control, preserving the original approval context.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
063 · SECURITY-013COMPLEXITY 5 / 5

Security and compliance

Running exploitability, not CVE volume

Join a local SBOM with OSV and CISA KEV, then prove whether affected versions are present in currently deployed artifacts and reachable services. Prioritize known exploitation on running paths.

local SBOM toolsOSVCISA KEVGitHub Deployments
REACH
SHELLAPI
ACCESS
Mixed
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Join the current SBOM with OSV and CISA KEV, then map affected versions to deployed artifacts and reachable services. Prioritize known exploitation on running paths and label unproven reachability.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
064 · SECURITY-014COMPLEXITY 5 / 5

Security and compliance

Vulnerable but unreachable proof

For a known vulnerable package, trace imports, build inclusion, runtime entry points, network exposure, and feature flags to assemble evidence that the vulnerable path is or is not reachable.

OSVGitbuild toolsLaunchDarkly
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [For this vulnerable package, trace imports, build inclusion, runtime entry points, exposure, and feature flags. Assemble evidence for reachable or unreachable status and state uncertainty explicitly.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
065 · SECURITY-015COMPLEXITY 4 / 5

Security and compliance

Signing-material policy drift

Inventory certificate and signing-key metadata, then compare algorithms, age, intended use, repository verification settings, and rotation records with current policy.

1PasswordGitGitHub ActionsNotion
REACH
SHELLAPI
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Inventory signing and certificate metadata without exporting private material. Compare algorithms, age, intended use, repository verification, and rotation records with current policy.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
066 · SECURITY-016COMPLEXITY 5 / 5

Security and compliance

CI artifact secret residue

Scan build artifacts and logs for high-confidence secret structure, then trace the generating step and retention window. Verify findings against secret names without revealing values.

GitHub Actions artifactsGitLab CI1Passwordshell
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Scan selected CI artifacts and logs for high-confidence secret residue. Trace the generating step and retention window, verify only against secret names, and redact every value.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
067 · SECURITY-017COMPLEXITY 5 / 5

Security and compliance

Privileged change outside the window

Align privileged configuration changes with maintenance windows, incident declarations, and approver availability. Distinguish emergency action from unexplained timing.

AWS CloudTrailOkta System LogGoogle CalendarPagerDuty
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Align privileged AWS and identity changes with maintenance windows, incidents, and approver availability. Separate emergency actions from unexplained timing without inferring intent.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
068 · SECURITY-018COMPLEXITY 4 / 5

Security and compliance

Shared-mailbox shadow administrator

Find operational accounts controlled through shared inboxes, aliases, or delegated mail, then map who can reset or approve access through that mailbox.

GmailGoogle AdminOkta
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find operational accounts whose recovery or approval path depends on shared mailboxes, aliases, or delegation. Map who can control those paths using only necessary metadata.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
069 · SECURITY-019COMPLEXITY 5 / 5

Security and compliance

Public link to private incident

Locate broadly shared Drive files referenced from support or incident records, then determine whether customer identifiers, credentials, or internal topology are exposed beyond intended responders.

Google DriveZendeskPagerDuty
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find broadly shared Drive files linked from Zendesk or PagerDuty records. Classify exposure of customer data, credentials, or internal topology without echoing content or changing permissions.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
070 · SECURITY-020COMPLEXITY 5 / 5

Security and compliance

Break-glass readiness proof

Verify that emergency accounts exist, are excluded from ordinary use, have recent controlled tests, reachable owners, and documented recovery material without signing in as them.

OktaGoogle Admin1PasswordGoogle Calendar
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Verify break-glass accounts, ownership, isolation from daily use, controlled-test evidence, and recovery-material references without signing in as those accounts or reading secrets.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
071 · SECURITY-021COMPLEXITY 4 / 5

Security and compliance

Dangling-domain takeover candidate

Find DNS records pointing at deleted deployments, missing repositories, or unclaimed service identifiers. Confirm dangling state from control-plane evidence rather than attempting to claim the resource.

Cloudflare DNSVercelGitHubshell DNS tools
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Find DNS records pointing to deleted deployments, missing repositories, or unclaimed service identifiers. Confirm dangling state from read-only control-plane evidence and never attempt to claim a resource.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
072 · SECURITY-022COMPLEXITY 5 / 5

Security and compliance

Subprocessor reality mismatch

Compare vendors declared in legal and security documents with domains contacted by production, dependencies shipped in code, and current SaaS integrations. Explain additions and vanished vendors.

Google DriveCloudflareGitHubOkta
REACH
APISHELLBROWSER
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare declared subprocessors with production domains, shipped dependencies, and active SaaS integrations. Explain additions and vanished vendors and prepare a legal-security review queue.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
073 · SECURITY-023COMPLEXITY 5 / 5

Security and compliance

Auth event to sensitive change

For high-risk authentication events, inspect the narrow subsequent window for repository, identity, feature-flag, and cloud changes attributable to the same principal.

Okta System LogGitLaunchDarkly audit logAWS CloudTrail
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For selected high-risk authentication events, inspect the following time window for repository, flag, identity, and AWS changes by the same principal. Preserve evidence and label attribution uncertainty.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
074 · SECURITY-024COMPLEXITY 5 / 5

Security and compliance

Identity geography contradiction

Compare authentication geography and device signals with working location, approved travel, and subsequent sensitive actions. Focus on contradictions that survive timezone and VPN normalization.

Okta System LogGoogle CalendarGoogle Admin ReportsAWS CloudTrail
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare authentication geography and device signals with working location, approved travel, and sensitive actions. Normalize timezones and VPNs, then report only contradictions that remain.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
075 · SECURITY-025COMPLEXITY 5 / 5

Security and compliance

Control evidence chain completeness

For a named control, prove that policy, configuration, execution, exception handling, and review evidence all refer to the same systems and time period. Surface broken links rather than collecting screenshots.

Notion or Google DriveOktaAWS CloudTrailLinear
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For this control, connect policy, live configuration, execution evidence, exceptions, and review records for the same systems and period. Show broken links and do not issue a compliance conclusion.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
076 · FINANCE-001COMPLEXITY 5 / 5

Finance, revenue, and commerce

Webhook-to-cash completeness

Start with every paid-order event and prove its path through webhook delivery, fulfillment, processor balance movement, bank settlement, and accounting entry. Surface economic events that vanished between systems.

Stripe WebhooksShopifyStripe Balance TransactionsMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace each selected paid-order event through Stripe webhook delivery, Shopify fulfillment, Stripe balance movement, Mercury settlement, and Xero posting. Find missing economic events without resending or writing entries.]
DOCUMENTED CAPABILITIES · 6 SOURCES +
077 · FINANCE-002COMPLEXITY 5 / 5

Finance, revenue, and commerce

Settlement-delay causality

Explain why cash arrived later than the customer payment by joining processor availability dates, dispute holds, settlement batches, bank credits, and weekends or holidays.

Stripe or RazorpayMercuryXeroGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Explain delayed cash arrival by joining processor availability, disputes, settlement batches, bank credits, and calendar boundaries. Produce an evidence timeline and label unresolved banking assumptions.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
078 · FINANCE-003COMPLEXITY 5 / 5

Finance, revenue, and commerce

Duplicate economic event detector

Match payments, refunds, transfers, and journal entries by economic meaning rather than ID. Detect one customer event represented twice after retries, processor migration, or manual correction.

StripeRazorpayMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Detect duplicate economic events across Stripe, Razorpay, Mercury, and Xero using amount, currency, customer, timing, and source lineage rather than IDs alone. Make no reversals.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
079 · FINANCE-004COMPLEXITY 5 / 5

Finance, revenue, and commerce

Refund promised, money absent

Find support conversations where a refund was promised, then prove whether it was created, settled back to the customer, and reflected in accounting. Distinguish pending, failed, and never initiated.

ZendeskStripeMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find refund promises in Zendesk and verify creation, processor settlement, bank movement, and accounting treatment. Classify pending, failed, and never initiated refunds without issuing one.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
080 · FINANCE-005COMPLEXITY 5 / 5

Finance, revenue, and commerce

Dispute evidence assembler

For each dispute, assemble the order, delivery proof, customer communication, access logs, refund history, and evidence deadline into a review-ready packet.

Stripe or RazorpayShopifyZendeskapplication logsGoogle Drive
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Assemble a review-ready dispute packet from processor data, Shopify fulfillment, Zendesk communication, access logs, and permitted Drive documents. Include the deadline and do not submit evidence.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
081 · FINANCE-006COMPLEXITY 5 / 5

Finance, revenue, and commerce

Negative-margin order autopsy

Calculate realized margin after discounts, processor fees, shipping, refunds, support credits, and currency conversion. Explain the policy or exception that produced each loss-making order.

ShopifyStripeXeroZendesk
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find orders with negative realized margin after discounts, fees, fulfillment, refunds, support credits, and FX. Explain each loss using source evidence and configurable accounting mappings.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
082 · FINANCE-007COMPLEXITY 5 / 5

Finance, revenue, and commerce

Entitlement-billing contradiction

Compare invoice and subscription state with product entitlements and observed use. Find customers paying without access, consuming without payment, or holding incompatible plan features.

Stripe Subscriptionsapplication entitlement storeproduct logsZendesk
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare Stripe subscription and invoice state with product entitlements, observed use, and support history. Find paid-without-access and access-without-payment contradictions without changing either side.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
083 · FINANCE-008COMPLEXITY 4 / 5

Finance, revenue, and commerce

Dormant subscription, live consumption

Find canceled, paused, or unpaid subscriptions whose API keys, seats, storage, or compute still generate usage and cost.

Stripe Subscriptionsproduct usage logsAWS Cost ExplorerHubSpot
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find canceled, paused, or unpaid subscriptions that still generate product usage or cloud cost. Reconcile customer and contract context, then produce an owner-reviewed action list.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
084 · FINANCE-009COMPLEXITY 5 / 5

Finance, revenue, and commerce

Payroll funding readiness

Before payroll cutoff, reconcile active workers, expected payroll amount, available bank balance, pending transfers, and exceptional compensation changes.

RipplingMercuryGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Before the payroll cutoff, reconcile active workers, expected funding, available Mercury balance, pending transfers, and exceptional compensation changes. Report funding risk without initiating money movement.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
085 · FINANCE-010COMPLEXITY 5 / 5

Finance, revenue, and commerce

Payroll-to-ledger population mismatch

Compare worker and payroll populations with bank debits and accounting payroll entries. Find missing workers, duplicate groups, and payments posted to the wrong entity or period.

RipplingMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Reconcile payroll populations across Rippling, Mercury debits, and Xero entries. Find missing workers, duplicate groups, and wrong entity or period postings while protecting compensation data.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
086 · FINANCE-011COMPLEXITY 5 / 5

Finance, revenue, and commerce

Contractor in employee clothing

Find people paid through accounts payable who also hold employee-only access, schedules, or benefits-like entitlements. Assemble classification evidence for qualified review.

XeroRipplingOktaGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find contractors paid through accounts payable who also hold employee-only access, schedules, or entitlements. Assemble evidence for HR and legal review without making a classification decision.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
087 · FINANCE-012COMPLEXITY 5 / 5

Finance, revenue, and commerce

Changed-bank-detail payment proof

Before paying a changed beneficiary, connect the invoice, vendor history, bank-recipient change, approval conversation, and independent contact path. Surface circular approval evidence.

XeroMercurySlackGoogle Drive
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For a vendor with changed bank details, connect the invoice, prior payments, recipient change, approval trail, and independent contact path. Flag circular evidence and do not send money.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
088 · FINANCE-013COMPLEXITY 5 / 5

Finance, revenue, and commerce

Revenue-recognition exception finder

Compare invoice timing, payment, subscription service period, credits, and accounting entry period to find revenue recognized before or after the underlying obligation.

Stripe InvoicesStripe SubscriptionsXeroGoogle Drive
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare Stripe invoice, payment, subscription service period, credits, contract evidence, and Xero posting period. Produce revenue-recognition review cases without posting adjustments.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
089 · FINANCE-014COMPLEXITY 4 / 5

Finance, revenue, and commerce

Credit-note plus refund double relief

Find cases where a customer received both a processor refund and accounting credit relief without the intended linkage, leaving receivables or revenue understated.

StripeXeroZendesk
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find customer events that produced both a processor refund and an unlinked accounting credit. Reconcile support intent and quantify possible double relief without changing records.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
090 · FINANCE-015COMPLEXITY 5 / 5

Finance, revenue, and commerce

Foreign-exchange fee leak

Trace original charge currency, processor conversion, settlement currency, bank conversion, and ledger rate. Identify avoidable double conversion and silent margin loss.

Stripe or RazorpayMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace original charge, processor conversion, settlement, bank conversion, and ledger rate for cross-currency transactions. Find double conversion and quantify observed fee leakage.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
091 · FINANCE-016COMPLEXITY 4 / 5

Finance, revenue, and commerce

Gift-card liability drift

Reconcile issued, redeemed, refunded, expired, and transferred gift-card value with accounting liability and order adjustments. Preserve jurisdiction-dependent expiry rules as configuration.

ShopifyXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Reconcile issued, redeemed, refunded, expired, and transferred gift-card value between Shopify and Xero. Show liability drift while treating expiry and breakage rules as reviewed configuration.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
092 · FINANCE-017COMPLEXITY 4 / 5

Finance, revenue, and commerce

Inventory cash trap

Find products tying up cash by joining inventory aging, sales velocity, refunds, supplier payments, and gross margin. Distinguish deliberate strategic stock from unnoticed stagnation.

ShopifyXeroMercury
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find inventory tying up cash using Shopify aging and velocity, refunds, Xero costs, and Mercury supplier payments. Separate strategic stock from unexplained stagnation.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
093 · FINANCE-018COMPLEXITY 5 / 5

Finance, revenue, and commerce

Discount leakage after a product change

Explain unexpected discounting through coupon configuration, feature rollout, checkout code, sales promises, and invoice results. Find discounts surviving after their intended campaign or segment ended.

Stripe InvoicesLaunchDarklyGitHubHubSpot
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Explain unexpected discounting through Stripe invoices, feature rollout history, checkout code, and HubSpot deal promises. Find discounts that survived their intended campaign without changing pricing.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
094 · FINANCE-019COMPLEXITY 5 / 5

Finance, revenue, and commerce

Dispute spike after release

Correlate dispute categories and purchase cohorts with checkout releases, fulfillment changes, support symptoms, and error fingerprints to find product-caused chargebacks.

Stripe DisputesGitHub DeploymentsShopifyZendeskSentry
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Test whether a dispute spike aligns with checkout releases, fulfillment changes, support symptoms, or Sentry errors. Segment by purchase cohort and label causal uncertainty.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
095 · FINANCE-020COMPLEXITY 5 / 5

Finance, revenue, and commerce

Nexus evidence without the spreadsheet chase

Aggregate order destinations, employee work locations, inventory presence, and entity records into a time-bounded evidence pack for tax advisers.

ShopifyRipplingXeroGoogle Drive
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Assemble a time-bounded nexus evidence pack from order destinations, worker locations, inventory presence, entity records, and accounting data. Do not make a tax determination.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
096 · FINANCE-021COMPLEXITY 5 / 5

Finance, revenue, and commerce

Cross-border payroll conversion leak

Compare compensation currency, payroll debit, bank conversion, worker receipt evidence, and ledger rate to identify repeated spread or routing losses.

RipplingMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare compensation currency, payroll debits, bank conversion, and ledger rates across cross-border payroll. Quantify repeated spread or routing loss while protecting employee data.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
097 · FINANCE-022COMPLEXITY 5 / 5

Finance, revenue, and commerce

Runway versus commitments

Rebuild runway from bank balances, recurring payments, open bills, payroll timing, and signed contractual commitments rather than budget categories alone.

MercuryXeroRipplingGoogle DriveGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Rebuild runway from current bank balances, recurring payments, open bills, payroll timing, and signed commitments. Show scenarios and assumptions without giving financial advice.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
098 · FINANCE-023COMPLEXITY 5 / 5

Finance, revenue, and commerce

Customer entitlement ghost

Find entitlements attached to deleted, merged, or duplicate CRM and billing identities. Resolve the real customer relationship and the revenue attached to each ghost.

Stripe SubscriptionsHubSpot or Salesforceapplication databaseZendesk
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find product entitlements attached to deleted, merged, or duplicate billing and CRM identities. Resolve likely customer lineage and revenue impact without merging or changing access.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
099 · FINANCE-024COMPLEXITY 4 / 5

Finance, revenue, and commerce

Failed dunning, continued fulfillment

Detect customers whose invoice retries exhausted or subscription became unpaid while physical or digital fulfillment continued. Account for grace periods and contractual exceptions.

Stripe InvoicesStripe SubscriptionsShopify FulfillmentHubSpot
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find customers whose invoice collection failed or subscription became unpaid while fulfillment continued. Apply configured grace periods and contract exceptions, then produce a review queue.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
100 · FINANCE-025COMPLEXITY 5 / 5

Finance, revenue, and commerce

Processor-routing anomaly

Compare similar transactions routed through different processors by geography, method, fee, failure rate, settlement lag, and dispute outcome. Reveal routing rules that cost more without improving success.

StripeRazorpayMercuryXero
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare similar transactions routed through Stripe and Razorpay by geography, method, fee, failure, settlement lag, and dispute outcome. Identify costly routing anomalies without changing routing.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
101 · PEOPLE-001COMPLEXITY 5 / 5

Customers, people, and governance

Promised-feature debt

Extract customer promises from deal notes, email, and Slack, then prove whether each became a scoped issue, shipped behavior, or an aging unowned commitment.

HubSpotGmailSlackLinearGitHub Deployments
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find product promises in CRM notes, email, and Slack. Prove whether each became a Linear issue, shipped release, or aging unowned commitment, and preserve uncertainty about contractual force.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
102 · PEOPLE-002COMPLEXITY 5 / 5

Customers, people, and governance

SLA clock disagreement

Reconstruct the same customer event using support, incident, and service timestamps. Explain where acknowledgment, impact, pause, and resolution clocks disagree.

Zendesk Ticket AuditsPagerDutyDatadog IncidentsGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Reconstruct selected customer incidents across Zendesk, PagerDuty, and Datadog. Explain disagreements in acknowledgment, impact, pause, and resolution clocks using configured SLA definitions.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
103 · PEOPLE-003COMPLEXITY 4 / 5

Customers, people, and governance

Workaround retirement proof

Find customer workarounds documented in tickets and docs, connect them to the fixing release, and prove whether affected customers still rely on the old path.

ZendeskNotionGitHub DeploymentsSentry
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find documented customer workarounds, connect each to its intended fixing release, and verify whether affected customers still rely on the old path. Produce retirement candidates only.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
104 · PEOPLE-004COMPLEXITY 4 / 5

Customers, people, and governance

Knowledge article versus shipped truth

Turn support documentation examples into browser and API checks against the current product. Flag steps, labels, fields, and permissions that no longer match reality.

Zendesk Guide or Notionproduct browserOpenAPI schemaGitHub
REACH
BROWSERSHELLAPI
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Verify support documentation examples against the current product UI, API schema, and repository. Flag stale labels, fields, steps, and permissions using test accounts only.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
105 · PEOPLE-005COMPLEXITY 5 / 5

Customers, people, and governance

Churn intent before the CRM

Detect repeated cancellation language, escalation patterns, and declining engagement that appear in support and permitted communication before a churn risk reaches the CRM.

ZendeskGmail or SlackHubSpotproduct usage logs
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find churn signals in authorized support and customer communication that predate CRM risk status. Join them with usage evidence and produce account-owner review cases, not automated outreach.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
106 · PEOPLE-006COMPLEXITY 4 / 5

Customers, people, and governance

Renewal owner disappeared

Before a renewal window, prove that the internal owner, customer contacts, open blockers, and decision meetings still exist. Detect renewals inherited by nobody after team changes.

HubSpotRipplingGoogle CalendarLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For upcoming renewals, verify the internal owner is current, customer contacts are active, blockers are owned, and decision meetings exist. Flag renewals inherited by nobody.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
107 · PEOPLE-007COMPLEXITY 5 / 5

Customers, people, and governance

Customer flag without a customer

Find feature targeting rules tied to deleted, merged, churned, or renamed customer identities. Resolve whether each flag is a live obligation, a forgotten workaround, or dead configuration.

LaunchDarklyHubSpotStripe SubscriptionsGitHub
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find feature-flag targets tied to deleted, merged, churned, or renamed customer identities. Resolve live obligations versus forgotten workarounds and produce a review queue.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
108 · PEOPLE-008COMPLEXITY 5 / 5

Customers, people, and governance

Bug impact priced in pipeline

Connect an error fingerprint to affected accounts, open opportunities, renewals, and support severity so engineering sees commercial exposure without guessing from ticket volume.

SentryHubSpotZendeskLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Connect this Sentry issue to affected customer accounts, support severity, renewals, and open opportunities. Quantify commercial exposure while preserving non-revenue severity factors.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
109 · PEOPLE-009COMPLEXITY 4 / 5

Customers, people, and governance

Sales-demo environment drift

Before a demo, compare the promised scenario with current preview deployment, feature flags, seeded data, user permissions, and last successful rehearsal.

Google CalendarHubSpotVercelLaunchDarklybrowser
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Before the next demo, compare the CRM promise and calendar agenda with the demo deployment, flags, seeded data, permissions, and last rehearsal. Use demo accounts only.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
110 · PEOPLE-010COMPLEXITY 5 / 5

Customers, people, and governance

Contract clause to operating control

Extract an approved obligation, connect it to owners, system configuration, recurring evidence, and review dates, then reveal clauses that exist only in the signed document.

Google DriveLinearNotionGoogle Calendarsystem APIs
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For an approved contract, connect each selected obligation to an owner, live system control, recurring evidence, and review date. Flag clauses that exist only on paper and route ambiguity to legal review.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
111 · PEOPLE-011COMPLEXITY 5 / 5

Customers, people, and governance

Deletion request proof chain

Trace a verified deletion request through CRM, support, billing, files, and product records. Produce proof of completion and explicitly list systems where legal retention overrides deletion.

ZendeskHubSpotStripeGoogle Driveapplication database
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace a verified data-deletion request across support, CRM, billing, Drive, and product records. Produce a reviewable proof chain and list approved retention exceptions without deleting anything.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
112 · PEOPLE-012COMPLEXITY 5 / 5

Customers, people, and governance

Operational drift after contract redline

Compare the signed revision with earlier drafts and find operational controls, pricing rules, data routes, or service terms that still implement superseded language.

Google Drive revisionsGitHubLaunchDarklyStripeLinear
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Diff the signed contract against prior revisions and locate code, flags, billing, or work items that still implement superseded language. Produce evidence for legal and operational review.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
113 · PEOPLE-013COMPLEXITY 4 / 5

Customers, people, and governance

Scorecard written after the decision

Compare interview end times, scorecard submission times, debrief meetings, and stage changes to find assessments written after group influence or hiring decisions.

GreenhouseGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare interview end, scorecard submission, debrief, and stage-change times. Find assessments written after group influence or decisions, and report process evidence without judging candidates.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
114 · PEOPLE-014COMPLEXITY 4 / 5

Customers, people, and governance

Interview load collides with on-call

Find interview panels assigned during incident rotations, known release windows, or concentrated operational load, then propose evidence-backed rescheduling options.

GreenhouseGoogle CalendarPagerDutyGitHub Deployments
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find interview panels that collide with on-call rotations, release windows, or incident load. Propose alternatives that preserve candidate speed without editing calendars.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
115 · PEOPLE-015COMPLEXITY 5 / 5

Customers, people, and governance

Offer promise versus day-one reality

Compare approved offer details and recruiting notes with HR title, manager, location, equipment, and access prepared for day one. Find promise gaps before the worker starts.

GreenhouseRipplingOktaGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Before start date, compare the approved offer and recruiting commitments with Rippling title, manager, location, Okta access, and onboarding schedule. Flag promise gaps privately.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
116 · PEOPLE-016COMPLEXITY 5 / 5

Customers, people, and governance

Role changed, work pattern did not

After a transfer or promotion, compare the new responsibility with actual application use, repository activity, meetings, and unresolved work. Find duties that never moved with the org chart.

RipplingOkta System LogGitGoogle CalendarLinear
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [After selected role changes, compare intended responsibility with application use, repository activity, meetings, and unresolved work. Find duties that never moved without scoring employee performance.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
117 · PEOPLE-017COMPLEXITY 4 / 5

Customers, people, and governance

Leave creates an ownership hole

Before planned leave, map the person's on-call shifts, CODEOWNERS paths, approvals, customer commitments, and recurring meetings to concrete temporary owners.

RipplingPagerDutyGitHubHubSpotGoogle Calendar
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Before planned leave, map on-call shifts, code ownership, approvals, customer commitments, and recurring meetings to temporary owners. Limit leave details to authorized planning.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
118 · PEOPLE-018COMPLEXITY 5 / 5

Customers, people, and governance

New manager inherits invisible commitments

When management changes, assemble the team's unresolved decisions, promised dates, recurring approvals, customer obligations, and operational rotations into a handoff ledger.

RipplingLinearGoogle CalendarGmailPagerDuty
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For a manager transition, assemble unresolved decisions, promised dates, recurring approvals, customer obligations, and on-call rotations into a private handoff ledger.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
119 · PEOPLE-019COMPLEXITY 4 / 5

Customers, people, and governance

Decision made, record missing

Find meetings and Slack threads that contain a clear decision or exception but no durable record, owner, or follow-up in the designated system of record.

SlackGoogle CalendarNotionLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find clear decisions or exceptions in authorized meetings and Slack threads that lack a durable record, owner, or follow-up. Draft confirmation packets for the designated system of record.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
120 · PEOPLE-020COMPLEXITY 3 / 5

Customers, people, and governance

Meeting without durable output

For recurring meetings, compare agendas and attendance with decisions, tasks, document changes, and issue movement. Find expensive rituals that produce no inspectable output.

Google CalendarGoogle DriveGoogle TasksLinear
REACH
API
ACCESS
Required
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [For recurring meetings, connect agendas and attendance to decisions, tasks, document revisions, and issue movement. Find sessions with no durable output and preserve known exceptions.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
121 · PEOPLE-021COMPLEXITY 4 / 5

Customers, people, and governance

Customer escalation arrived through the wrong door

Find urgent customer issues first raised in sales or executive channels instead of support, then reconstruct why normal routing failed and which evidence was lost.

GmailSlackHubSpotZendesk
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find urgent customer issues first raised through authorized sales or executive channels rather than support. Reconstruct routing failure and lost evidence without exposing private correspondence.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
122 · PEOPLE-022COMPLEXITY 5 / 5

Customers, people, and governance

One-customer configuration tax

For customer-specific flags, branches, scripts, and support procedures, calculate the maintenance surface and identify custom behavior with no current commercial or contractual owner.

LaunchDarklyGitHubZendeskHubSpotStripe
REACH
APISHELL
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Inventory customer-specific flags, code, scripts, and support procedures. Quantify maintenance surface and identify customization with no current commercial or contractual owner.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
123 · PEOPLE-023COMPLEXITY 5 / 5

Customers, people, and governance

Sales exception survived the deal

Find temporary pricing, permission, or product exceptions created to close a deal that remain active after the promised end, renewal, or customer change.

HubSpotStripeLaunchDarklyOktaGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find temporary sales exceptions in pricing, permissions, or features that survived their promised end, renewal, or account change. Resolve owner and evidence without changing customer state.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
124 · PEOPLE-024COMPLEXITY 5 / 5

Customers, people, and governance

Customer-success claim provenance

For status updates sent to a customer, prove each claimed fix, date, metric, and next step against deploy, issue, telemetry, and calendar evidence.

GmailZendeskGitHub DeploymentsDatadogLinear
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Verify each fix, date, metric, and next step in selected customer updates against deploy, issue, telemetry, and calendar evidence. Draft discrepancies for owner review without sending mail.]
DOCUMENTED CAPABILITIES · 5 SOURCES +
125 · PEOPLE-025COMPLEXITY 4 / 5

Customers, people, and governance

Vendor roadmap promise aging

Track promises made by a critical vendor across email, public changelogs, support tickets, and internal plans. Detect architecture or launch commitments still waiting on an unshipped dependency.

Gmailvendor changelogZendeskLinearGoogle Calendar
REACH
APIBROWSER
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Track critical vendor promises across authorized email, public changelogs, support tickets, and internal plans. Flag aged dependencies blocking architecture or launch commitments with dated evidence.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
126 · PUBLIC-001COMPLEXITY 3 / 5

Public intelligence and personal operations

Package-abandonment early signal

Combine release cadence, maintainer changes, issue response, dependency freshness, and bus factor to identify a public package becoming operationally unsafe before it is officially abandoned.

npm public registryGitHub public repositories
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Assess whether selected public packages show early abandonment risk using releases, maintainer changes, issue response, dependency freshness, and bus factor. Preserve uncertainty and cite public evidence.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
127 · PUBLIC-002COMPLEXITY 4 / 5

Public intelligence and personal operations

Maintainer-transfer blast radius

Detect package ownership or publishing changes, then map the transferred package into local lockfiles, public dependent repositories, and recent releases. Surface trust changes hidden behind an unchanged package name.

npm public registryGitHub public repositorieslocal lockfiles
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Detect recent maintainer or publisher changes for dependencies, then map affected packages into local lockfiles and public dependents. Report trust changes without alleging compromise.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
128 · PUBLIC-003COMPLEXITY 4 / 5

Public intelligence and personal operations

Silent breaking-release detector

Compare package behavior, exported types, command help, and repository diff across versions with the published release notes. Find breaking changes that the changelog did not disclose.

npm public registryGitHub public repositorieslocal test runner
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Compare two public package versions by exports, types, CLI help, repository diff, and sandbox tests. Identify observed breaking behavior absent from release notes and preserve uncertainty.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
129 · PUBLIC-004COMPLEXITY 3 / 5

Public intelligence and personal operations

Public API contract drift

Snapshot a public API's machine-readable schema and representative responses, then detect removed fields, enum growth, pagination changes, and documentation lag before downstream code fails.

public OpenAPI or discovery documentbrowserGit
REACH
APIBROWSERSHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Snapshot this public API's schema, documentation, and small representative responses. Detect field, enum, pagination, and documentation drift, then produce a downstream impact note.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
130 · PUBLIC-005COMPLEXITY 5 / 5

Public intelligence and personal operations

Research correction reaches product claim

Follow corrections, retractions, and post-publication updates from a cited paper into company docs, product claims, model cards, and repository comments that still rely on the original result.

CrossrefPubMedOpenAlexGitHub public repositories
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Track corrections, retractions, and post-publication updates for cited research into public product docs, claims, model cards, and repository comments. State only what the sources support.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
131 · PUBLIC-006COMPLEXITY 4 / 5

Public intelligence and personal operations

Prior-art watch for a live implementation

Monitor new papers around a technical claim, then compare methods and constraints with a public repository's current implementation. Highlight newly published approaches that invalidate an assumption or simplify the design.

arXivOpenAlexGitHub public repositories
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Monitor new public research around this implementation's core claim. Compare methods and constraints with the repository and flag assumptions newly challenged or simplified. Do not assess patentability.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
132 · PUBLIC-007COMPLEXITY 5 / 5

Public intelligence and personal operations

Reproducibility input pack

Given a paper and public code, resolve exact versions, datasets, licenses, citations, commands, and missing inputs into an executable evidence pack. Preserve every unresolved dependency.

CrossrefPubMed or arXivGitHub public repositorieslocal shell
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [For this paper and public code, resolve exact versions, datasets, licenses, citations, commands, and missing inputs into a reproducibility pack. Do not claim success unless outputs match stated criteria.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
133 · PUBLIC-008COMPLEXITY 4 / 5

Public intelligence and personal operations

Filing-to-homepage contradiction

Compare a company's latest SEC disclosures with current homepage, product, hiring, and developer claims. Surface dated contradictions in markets, dependencies, risk, and operating scale.

SEC EDGARpublic websiteGitHub public repositories
REACH
APIBROWSERSHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Compare the latest SEC disclosures with current public website and repository claims. Surface dated contradictions in markets, dependencies, risk, or operating scale without making investment or fraud conclusions.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
134 · PUBLIC-009COMPLEXITY 4 / 5

Public intelligence and personal operations

Known-exploit response lag

For open-source products in CISA KEV, measure the path from public exploitation status to maintainer acknowledgment, patch, package release, downstream adoption, and documentation update.

CISA KEVOSVnpm public registryGitHub public repositories
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Measure response lag for selected CISA KEV entries from known exploitation to maintainer acknowledgment, patch, package release, downstream adoption, and docs update. Do not include exploit steps.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
135 · PUBLIC-010COMPLEXITY 4 / 5

Public intelligence and personal operations

Typosquat neighborhood watch

Generate visually and keyboard-similar names around dependencies, query the public registry, and compare publication age, maintainers, contents, and install behavior. Focus on names adjacent to actual lockfiles.

npm public registrylocal lockfilessandbox shell
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Check the typo-neighborhood around packages in this lockfile. Compare public package age, maintainers, contents, and install scripts, using metadata first and an isolated sandbox only when necessary.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
136 · PUBLIC-011COMPLEXITY 4 / 5

Public intelligence and personal operations

Dataset-definition drift

Track changes in an indicator's definition, source organization, frequency, country coverage, and footnotes, then locate analyses and charts that still compare incompatible periods.

World Bank Indicatorslocal notebooksGit
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Track definition, source, frequency, coverage, and footnote changes for these public indicators. Find notebooks and charts comparing incompatible periods and propose explicit repairs.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
137 · PUBLIC-012COMPLEXITY 4 / 5

Public intelligence and personal operations

Research funding concentration risk

Map a technical field's papers, institutions, funders, citations, and shared datasets to reveal when apparently independent evidence rests on one funding or data source.

CrossrefOpenAlex
REACH
API
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Map papers, institutions, funders, citations, and shared datasets for this technical claim. Reveal concentration and dependencies without implying research misconduct.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
138 · PUBLIC-013COMPLEXITY 4 / 5

Public intelligence and personal operations

Climate shock meets supplier geography

Join public weather alerts and forecasts with a declared supplier or facility list, then rank operational exposure by lead time, transport dependency, and available alternatives.

National Weather Servicepublic supplier-location fileWorld Bank Indicators
REACH
APISHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Join current NWS alerts and forecasts with this public supplier or facility list. Rank operational exposure by lead time, transport dependency, and alternatives, stating geographic uncertainty.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
139 · PUBLIC-014COMPLEXITY 3 / 5

Public intelligence and personal operations

Earthquake facility first-look

Turn a new earthquake event into a radius- and intensity-aware list of public facilities, routes, and dependencies that warrant human checks, while preserving uncertainty in early event data.

USGS Earthquake Catalogpublic facility filepublic maps browser
REACH
APIBROWSERSHELL
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [For the latest relevant USGS event, identify listed facilities, routes, and dependencies that warrant human checks using conservative distance and magnitude rules. Do not infer structural safety.]
DOCUMENTED CAPABILITIES · 1 SOURCE +
140 · PUBLIC-015COMPLEXITY 3 / 5

Public intelligence and personal operations

Community hazard action brief

Combine current weather alerts, earthquake events, and public local-service pages into a concise, source-linked action brief with only official instructions and expiry times.

National Weather ServiceUSGSpublic local-government browser pages
REACH
APIBROWSER
ACCESS
None
BEST HOME
Public
EXPLORE IN YOUR HARNESS$play explore [Create a source-linked community hazard brief from current NWS alerts, USGS events, and official local-service pages. Include issue and expiry times and add no unsupported safety advice.]
DOCUMENTED CAPABILITIES · 2 SOURCES +
141 · PERSONAL-001COMPLEXITY 4 / 5

Public intelligence and personal operations

Itinerary shock absorber

Before and during travel, join itinerary email, calendar, destination weather, connection time, and meeting commitments. Prepare ranked contingencies before a disruption becomes a missed obligation.

GmailGoogle CalendarNational Weather ServiceGoogle Tasks
REACH
API
ACCESS
Mixed
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Join my authorized itinerary email and calendar with current destination weather and commitments. Prepare ranked contingency options for likely disruptions without booking or canceling anything.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
142 · PERSONAL-002COMPLEXITY 4 / 5

Public intelligence and personal operations

Commitment with no next action

Find promises made in authorized email and Slack that contain a deliverable or date but never became a task or calendar block. Preserve commitments that were later withdrawn.

GmailSlackGoogle TasksGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Find commitments I made in authorized email and Slack that specify a deliverable or date but have no task or calendar block. Exclude withdrawn promises and draft next actions for review.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
143 · PERSONAL-003COMPLEXITY 4 / 5

Public intelligence and personal operations

Decision decay after meetings

Compare meeting notes and follow-up mail with later tasks, document revisions, and calendar events. Surface decisions that lost an owner, date, or exact wording as they propagated.

Google CalendarGoogle DriveGmailGoogle Tasks
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Trace selected meeting decisions into follow-up email, tasks, document revisions, and later calendar events. Surface where owner, date, or wording decayed and draft a confirmation note.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
144 · PERSONAL-004COMPLEXITY 4 / 5

Public intelligence and personal operations

Promise-capacity collision

Compare dated commitments made in messages with actual calendar capacity, travel, focus time, and existing due tasks. Detect impossible weeks before deadlines arrive.

GmailSlackGoogle CalendarGoogle Tasks
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare my dated commitments in authorized messages with calendar capacity, travel, focus time, and due tasks. Find impossible weeks and propose tradeoffs without changing anything.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
145 · PERSONAL-005COMPLEXITY 3 / 5

Public intelligence and personal operations

Quiet-hours reality check

Measure when work communication and meetings actually cross declared focus, leave, and quiet hours. Separate self-scheduled work from pressure created by others and recurring system noise.

SlackGmailGoogle Calendar
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare my authorized work messages and meetings with declared focus, leave, and quiet hours. Separate self-scheduled activity, outside pressure, and system noise without scoring people.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
146 · PERSONAL-006COMPLEXITY 4 / 5

Public intelligence and personal operations

Document-expiry readiness

Locate personal document metadata and renewal instructions, then work backward from expiry through appointment availability, processing time, travel, and dependent bookings.

Google DriveGmailGoogle Calendarbrowser
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [For selected personal documents, work backward from expiry through official renewal steps, appointment timing, travel, and dependent bookings. Keep document numbers private and submit nothing.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
147 · PERSONAL-007COMPLEXITY 3 / 5

Public intelligence and personal operations

Family logistics handoff

Turn the next seven days of shared events, school or care messages, travel time, and tasks into explicit handoffs with owner, cutoff, and required item. Reveal assumptions where two people expect the other to act.

GmailGoogle CalendarGoogle Tasks
REACH
API
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Turn the next seven days of consented family messages, shared calendar events, travel time, and tasks into explicit handoffs. Flag conflicting assumptions and create no tasks without review.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
148 · PERSONAL-008COMPLEXITY 3 / 5

Public intelligence and personal operations

Volunteer coverage before the gap

Compare upcoming volunteer shifts with confirmations, calendar conflicts, required skills, and prior no-shows. Identify coverage gaps early and draft the smallest outreach set.

Google CalendarGmail or SlackGoogle Drive roster
REACH
API
ACCESS
Required
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Compare upcoming volunteer shifts with confirmations, calendar conflicts, required skills, and prior attendance. Identify coverage gaps and draft the smallest outreach set without sending messages.]
DOCUMENTED CAPABILITIES · 4 SOURCES +
149 · PERSONAL-009COMPLEXITY 4 / 5

Public intelligence and personal operations

Job-application narrative consistency

Across applications, resumes, cover letters, interviews, and public profile, find factual dates, titles, metrics, and claims that drifted. Build a private source-of-truth record before the next interview.

GmailGoogle DriveGoogle Calendarbrowser
REACH
APIBROWSER
ACCESS
Required
BEST HOME
Private
EXPLORE IN YOUR HARNESS$play explore [Compare my authorized applications, resume versions, interview notes, and public profile for factual drift in dates, titles, metrics, and claims. Build a private source-of-truth record.]
DOCUMENTED CAPABILITIES · 3 SOURCES +
150 · PERSONAL-010COMPLEXITY 4 / 5

Public intelligence and personal operations

Learning plan that notices the field moved

Compare a learning syllabus and saved exercises with new package releases, current documentation, and recent research. Replace obsolete lessons with changes that affect the learner's actual projects.

Google DriveGoogle Tasksnpm public registryarXivGitHub public repositories
REACH
APISHELL
ACCESS
Mixed
BEST HOME
Either
EXPLORE IN YOUR HARNESS$play explore [Compare my learning syllabus and exercises with current package releases, official docs, recent research, and my actual projects. Propose focused updates without deleting notes or tasks.]
DOCUMENTED CAPABILITIES · 5 SOURCES +