The kernel registry defines 899 verbs across 116 domains (138 are always-on Core verbs; the rest unlock on demand or are admin-only). Every action in Opbox - from the agent, the CLI, or the front end - is one of these verbs, entering through the one front door where it is capability-checked, permission-checked and audited (INV-1). For a plain-language tour by area, start with Capabilities; this page is the exhaustive per-verb detail.
Each verb carries a capability (the permission it needs), a risk class (Read / Write / Sensitive / Money / Destructive - which fixes the minimum autonomy level), a minimum permission tier (Member / Admin / Owner / External), an availability tier (Core / on-demand / vertical / admin-only), and an egress class (none for the great majority - they never leave the box). Money-moving verbs additionally require an MFA step-up, and consequential verbs are put behind a human four-eyes gate in orgs that declare themselves high-risk.