HOTL Host Capability Matrix
July 6, 2026 ยท View on GitHub
Generated from
runtime/capabilities/catalog.json(schema v1); claims verified 2026-07-05. Do not edit this table by hand.
This matrix separates three different claims:
- Provider maturity describes what the provider documents.
- Local detection is reported by
scripts/hotl-capabilities.sh probeand can remainunknowneven when a host is installed. - HOTL support describes whether HOTL has a conformant implementation, only a candidate native integration, or a fallback.
The Phase 1 catalog is descriptive. It does not select an execution driver or change permissions.
| Host | Capability | Category | Provider maturity | HOTL support | Minimum version | Observability | Availability conditions | Security boundary | Fallback | Verified | Sources |
|---|---|---|---|---|---|---|---|---|---|---|---|
| claude-code | Agent view | automation | research preview | candidate | 2.1.139 | partial | Agent view available in the active Claude Code distribution | Background sessions continue without a terminal and may use isolated worktrees; agent-view row state is scheduling telemetry, not HOTL completion evidence. | hotl-fallback:workflow-execution | 2026-07-05 | source 1 |
| claude-code | Worktree-isolated sessions | isolation | stable | candidate | not specified | partial | Git repository | Filesystem and command permissions continue to apply inside the isolated checkout. | hotl-fallback:worktree-isolation | 2026-06-29 | source 1 |
| claude-code | Lifecycle hooks | lifecycle | stable | candidate | not specified | full | Hooks not disabled by user or managed settings | Hooks execute with the trust level of the local Claude Code process and must be reviewed as code. | hotl-fallback:durable-state | 2026-06-29 | source 1 |
| claude-code | Plugin background monitors | lifecycle | stable | candidate | 2.1.105 | full | Interactive CLI with Monitor tool availability Plugin enabled | Monitors run unsandboxed at hook trust level and require careful command review. | hotl-fallback:durable-state | 2026-06-29 | source 1 |
| claude-code | Agent teams | orchestration | experimental | candidate | 2.1.32 | partial | Experimental agent teams enabled Task can be partitioned without conflicting shared-file edits | Each teammate is an independent Claude Code session with team coordination tools. | hotl-fallback:workflow-execution | 2026-06-29 | source 1 |
| claude-code | Background subagents | orchestration | stable | candidate | 2.1.198 | partial | Claude Code session with Agent tool availability Background tasks not disabled by configuration | Subagents run in the background by default but their completion notification is not verification or HOTL completion evidence. | hotl-fallback:workflow-execution | 2026-07-05 | source 1 source 2 |
| claude-code | Dynamic workflows | orchestration | research preview | candidate | 2.1.154 | partial | Paid plan or supported API/provider Dynamic workflows enabled where required | Spawned agents inherit the workflow tool allowlist and use accept-edits behavior for file changes. | hotl-fallback:workflow-execution | 2026-06-29 | source 1 |
| claude-code | Goal and loop continuation | orchestration | stable | candidate | 2.1.139 | partial | Claude Code distribution exposing /goal and /loop Hooks and managed policy permit the selected continuation path | Goal and loop commands continue host turns but do not replace HOTL iteration bounds, gates, ownership, or receipts. | hotl-fallback:workflow-execution | 2026-07-05 | source 1 |
| claude-code | Subagents | orchestration | stable | candidate | not specified | partial | Claude Code session with the Agent tool available | Subagent tools, model, permissions, and MCP access are scoped by the agent definition and parent session. | hotl-fallback:workflow-execution | 2026-06-29 | source 1 |
| claude-code | Auto permission mode | security | research preview | candidate | 2.1.83 | partial | Eligible plan and supported model/provider Workspace admin enablement when required | A classifier reviews actions after hard permission rules; auto mode is not a substitute for sensitive-operation review. | hotl-fallback:human-gates | 2026-06-29 | source 1 |
| codex | Automations | automation | stable | candidate | not specified | partial | Codex app Automation availability for the active account and workspace | Automation runs use the configured project permissions and workspace policy. | hotl-fallback:workflow-execution | 2026-06-29 | source 1 |
| codex | Remote connections | automation | stable | candidate | not specified | partial | Codex Remote available for the active account Authenticated paired host and supported mobile or desktop client | Remote control uses the connected host's project, credentials, permissions, and approval boundary; remote UI status is not a HOTL receipt. | hotl-fallback:workflow-execution | 2026-07-05 | source 1 source 2 |
| codex | Browser Developer mode | browser | stable | candidate | not specified | full | Codex app Browser or Chrome integration Full CDP access enabled and allowed by workspace policy | Full CDP inspection requires explicit approval and can be disabled by managed policy. | hotl-fallback:typed-verification | 2026-06-29 | source 1 |
| codex | Managed worktrees | isolation | stable | candidate | not specified | partial | Git repository Codex app or supported local surface | Filesystem access remains bounded by the active Codex permissions. | hotl-fallback:worktree-isolation | 2026-06-29 | source 1 |
| codex | Lifecycle hooks | lifecycle | stable | candidate | not specified | full | Hooks feature enabled Non-managed hook definition reviewed and trusted | Non-managed command hooks require hash-based user trust before execution. | hotl-fallback:durable-state | 2026-06-29 | source 1 |
| codex | Local, worktree, and remote thread handoff | lifecycle | stable | candidate | Codex app 26.616 | partial | Matching project available on the destination host Connected and trusted local or remote host | Handoff moves host execution context but does not transfer HOTL controller ownership until the new controller explicitly claims or takes over the run. | hotl-fallback:durable-state | 2026-07-05 | source 1 source 2 |
| codex | Memories | memory | stable | candidate | not specified | partial | Memories available for the active account Memory use or generation enabled | Memory use follows account, workspace, and per-thread controls. | none | 2026-06-29 | source 1 |
| codex | Goal mode | orchestration | stable | candidate | not specified | partial | Codex app, CLI, or IDE extension Goal mode available on the active surface | Goal mode can continue for hours or days but remains inside the active Codex sandbox and approval policy; it is not HOTL completion evidence. | hotl-fallback:workflow-execution | 2026-07-05 | source 1 |
| codex | Subagents | orchestration | stable | candidate | not specified | partial | Enabled by default in current Codex releases Spawned only after an explicit user request | Subagents inherit parent sandbox and live approval overrides. | hotl-fallback:workflow-execution | 2026-06-29 | source 1 |
| codex | Native code review | review | stable | candidate | not specified | partial | Git repository with a reviewable diff, commit, or base branch | Review is read-oriented unless the user separately authorizes fixes. | hotl-fallback:reporting | 2026-06-29 | source 1 |
| hotl-fallback | HOTL worktree isolation | isolation | stable | conformant | 2.18.0 | full | Git repository with at least one commit | Protected branches, dirty worktrees, and branch collisions stop according to HOTL preflight rules. | none | 2026-06-29 | source 1 |
| hotl-fallback | HOTL workflow execution | orchestration | stable | conformant | 2.18.0 | full | HOTL runtime or inline executor available | Uses the active host's shell sandbox and approval boundary while HOTL enforces controller ownership, workflow order, retry limits, aggregate budgets, gates, and effect evidence. | none | 2026-07-05 | source 1 |
| hotl-fallback | Durable run state | persistence | stable | conformant | 2.18.0 | full | jq installed | Serialized, revisioned state remains local under the execution root and is gitignored by default; explicit leased controller ownership prevents concurrent mutation and age alone never permits takeover. | none | 2026-07-05 | source 1 |
| hotl-fallback | Durable execution reporting | review | stable | conformant | 2.18.0 | full | jq installed for state-managed reporting | Reports default to concise successful output and captured failure evidence; missing reports are reconstructed from authoritative state and completion remains false until disposition is recorded. | none | 2026-07-05 | source 1 |
| hotl-fallback | Risk-sensitive human gates | security | stable | conformant | 2.18.0 | full | Interactive controller available for human gates | High-risk human gates cannot be auto-approved. | none | 2026-06-29 | source 1 |
| hotl-fallback | Typed verification | verification | stable | conformant | 2.18.0 | full | HOTL runtime available Required verifier capability available or human fallback accepted | Verification commands run inside the active host shell boundary. | none | 2026-06-29 | source 1 |
HOTL support states
candidate: provider capability identified for a future native adapter; no HOTL conformance claim yet.experimental: a HOTL integration exists but is opt-in and not yet conformant.conformant: deterministic HOTL contract scenarios pass for the implementation.fallback_only: HOTL deliberately uses a generic fallback rather than a native integration.unsupported: HOTL has no safe native or fallback path for the capability.deprecated: the integration remains visible only for migration.
Interpretation rules
- An installed executable does not prove plan entitlement, rollout availability, administrator enablement, or usable permissions.
- Preview and experimental capabilities remain opt-in even when locally detected.
unknownis an evidence-preserving result, not an error and not a synonym for unavailable.- Host security controls remain authoritative when they are stricter than HOTL policy.
- Relevant catalog rows must be refreshed from official sources when a driver or support claim changes.