opbox

The kernel registry defines 899 verbs across 116 domains (138 are always-on Core verbs; the rest unlock on demand or are admin-only). Every action in Opbox - from the agent, the CLI, or the front end - is one of these verbs, entering through the one front door where it is capability-checked, permission-checked and audited (INV-1). For a plain-language tour by area, start with Capabilities; this page is the exhaustive per-verb detail.

Each verb carries a capability (the permission it needs), a risk class (Read / Write / Sensitive / Money / Destructive - which fixes the minimum autonomy level), a minimum permission tier (Member / Admin / Owner / External), an availability tier (Core / on-demand / vertical / admin-only), and an egress class (none for the great majority - they never leave the box). Money-moving verbs additionally require an MFA step-up, and consequential verbs are put behind a human four-eyes gate in orgs that declare themselves high-risk.

DomainVerbsPrefix
Equity & cap table64equity.*
Documents62doc.*
Matters45matter.*
Tables44tables.*
Files & storage39file.*
Client portals36portal.*
Corporate services (CSP)33csp.*
Organisation30org.*
Billing & invoicing26bill.*
Agent tasks19agenttask.*
Integration connections17connection.*
Integrations17integration.*
Agent governance16agent.*
Boards & templates16board.*
Signing envelopes16envelope.*
Vertical setup13setup.*
Workflow runs13workflow.*
Parties12party.*
Workspaces12workspace.*
Submissions11submission.*
Tenancy11tenant.*
Audit log10audit.*
Extraction & OCR10extraction.*
Forms10form.*
Review queue9review.*
Signing (client)9sign.*
Conversations8conversation.*
Knowledge base8knowledge.*
Policy & rules8policy.*
Stakeholders8stakeholder.*
Matter steps8step.*
Actors (people)7actor.*
Change requests7change-request.*
Teams7team.*
Table columns6column.*
Credentials6credential.*
Engagement presence6engagement.*
Form envelopes6form-envelope.*
Form templates6form-template.*
Approval gates6gate.*
Oversight6oversight.*
Table rows6row.*
Runs (workflow)6run.*
Tokens6token.*
Triggers6trigger.*
Users6user.*
Regulator returns5regulator.*
Research5research.*
Scheduled tasks5scheduledtask.*
Stored files5stored_file.*
Tables (legacy)5table.*
Consent records4consent.*
Cross-workspace tasks4cross-workspace-task.*
Embeddings4embed.*
Fundamental-rights impact (FRIA)4fria.*
Helpdesk4helpdesk.*
Time tracking4time.*
Verification4verification.*
Versions4version.*
Access control3acl.*
Compliance exceptions3compliance.*
AI cost & budget3cost.*
Domain profiles3domainProfile.*
Escalations3escalation.*
Facts3fact.*
Identity3identity.*
Inbox & notifications3inbox.*
Invoices3invoice.*
Links3link.*
Org add-ons3orgAddon.*
Preferences3pref.*
Saved queries3savedquery.*
Sessions3session.*
Step types3steptype.*
Watchers3watch.*
Billing profiles2billing.*
Evidence capture2capture.*
Table cells2cell.*
Charges (company registers)2charge.*
Configuration2config.*
Disaster recovery2dr.*
Entity edges2edge.*
Entities2entity.*
Flow events2flow.*
Import console2import.*
Multi-factor auth2mfa.*
Notifications2notify.*
Org membership2orgmember.*
Profiles2profile.*
Registry2registry.*
Task lists2tasklist.*
Transcripts2transcript.*
Web capture2webcapture.*
Webhooks2webhook.*
Workspace membership2workspacemember.*
AcroForm fill1acroform.*
Authentication1auth.*
Exhibit bundles1bundle.*
Capability manifest1capability.*
Cross-jurisdiction transfers1cross-jurisdiction-transfer.*
Cutover1cutover.*
Data-plane audit1data.*
Egress policy1egress.*
Event feed1event.*
Generated documents1generated.*
Host operations1host.*
Incidents1incident.*
Field mapping1mapping.*
Migration1migration.*
Objects1object.*
Registry coverage1registryCoverage.*
Render export1render.*
Search1search.*
Secrets1secret.*
Signing provenance1signing.*
System1system.*