When a tool menu becomes infrastructure, who gains control?
A runtime that filters plugin suggestions, gates tool registration through configuration, and performs background capability discovery could be building a safer capability market. The same mechanisms could become a centrally managed distribution layer that determines which capabilities users may discover.
The evidence does not choose the future for us. The reporting task is to define competing scenarios, identify mechanisms that move each scenario forward, and publish observations that would prove the forecast wrong.
What changed since the first Atlas draft
Capability markets get more concrete when API specs become tools.
different-ai/openwork OpenWork Makes Team Memory A Governed Agent SurfaceGoverned memory points toward organizational agent infrastructure.
Scopewalker Builder Work: Scopewalker Gives Agents A Complexity GaugeBuilder Work shows agents using MCP-style read-only measures before editing.
Forecasts need kill switches
A credible forecast names the evidence that would invalidate it. Without that discipline, every tool registry, policy layer, or subagent feature can be presented as proof that a preferred future is arriving.
The useful unit is a source-visible sequence: a mechanism appears, spreads into runtime state, gains tests and operator controls, and survives real failure cases. A scenario weakens when those mechanisms disappear, remain experimental, or become impossible to inspect.
Scenario one: supervised software organizations
In this future, agents become teams, but supervision improves faster than delegation complexity. Stable correlation IDs, run-specific errors, provenance, visible client identity, explicit lineage, and recoverable work let humans identify which worker acted and where its result belongs.
The scenario strengthens if these identities become consistent across tools, approvals, subagents, surfaces, and external effects. It weakens if parallel work grows while ownership remains session-wide and humans must reconstruct responsibility from raw logs.
Scenario two: governed capability markets
In this future, tool menus become dynamic but inspectable contracts. Runtimes filter suggestions against installed context, gate registration through settings, discover capabilities without blocking startup, and distinguish availability checks from authentication.
The market becomes governable if users can inspect provenance, permissions, schemas, and activation requirements before granting access. It becomes chaotic if discovery outpaces review or marketplaces hide why a capability was suggested.
Scenario three: managed but opaque stacks
In this future, policy, entitlements, and capability selection move upstream into delivered bundles and managed gateways faster than public inspection improves. These systems may produce safer defaults while making local behavior depend on remote configuration and account state.
The decisive question is whether managed control remains attributable. If operators can inspect layer identity, precedence, entitlement coverage, and effective behavior, management can strengthen assurance. If the client becomes only a shell around undisclosed decisions, the stack becomes harder to audit.
Signals that would strengthen each future
Supervised software organizations
Delegation grows useful only if ownership, lineage, recovery, and approvals remain legible.
Governed capability markets
Dynamic tools create value only when discovery, activation, provenance, and permissions remain understandable.
Managed but opaque stacks
Delivered policy and entitlements move important decisions away from local files.
The evidence feeding the forecast
-
Supervised organizations
accountable workers and recoverable work
-
Governed capability markets
inspectable discovery and activation
-
Managed opaque stacks
stronger control, weaker local audit
What would prove each forecast wrong
- Falsify supervised organizations if parallel execution expands while correlation, lineage, and recovery remain optional.
- Falsify governed capability markets if discovery converges on opaque activation without inspectable provenance and permissions.
- Falsify managed opacity if managed systems consistently expose effective configuration, enforcement logic, and auditable provenance.