Every capability an app can be granted, by group and worker. Grants are named Group.Worker:Capability. Calendar is live today (real capabilities); the rest currently expose a placeholder Ping and list their intended curated surface, drawn from each class's public methods.
Proven at runtime. Login → 27 workers launched in parallel → post-quantum handshake → a granted call ran in the Calendar worker, an ungranted one was refused by XRUIOS.Permission. The catalog below is what fills out from there.
Worker
Capabilities
Calendar (live)
GetEvents(day) · AddEvent(day, summary) · DeleteEvent(uid) (privileged)
Alarm
AddAlarm · ListAlarms · UpdateAlarm · DeleteAlarm
Timer
StartTimer · AddTime · CancelTimer
Stopwatch
CreateStopwatch · Lap · Stop · Export
Chrono
GetTime · GetDate · SetTimezone · AddWorldTime · GetWorldTimes
Worker
Capabilities
Songs
AddSongDirectory · GetSongs · Search · AddToFavorites · AddToPlayHistory
MusicPlayer
GetCurrentlyPlaying · SetCurrentlyPlaying · Queue · Reorder
MediaAlbum
AddAlbum · GetAlbums · Update · Favorites
Creator
CreateCreator · GetCreator · AddFile · Favorites
MediaTagger
TagCreator · GetCreatorFiles
RecentlyRecorded
GetRecent · AddRecent · Clear
Worker
Capabilities
AreaManager
AddWorldPoint · GetWorldPoints · UpdateWorldPoint · DeleteWorldPoint
WorldEvents
AddWorldEvent · GetWorldEvents · DeleteWorldEvent · Clear
DataManager
AddSession · AddDataSlot · Get · Update · Favorites
Geo
GetExactCoordinates · GetRelative · AddVirtualPoint · History
DeviceManager
AddDevice · GetDevices · Update · Delete
Worker
Capabilities
Volume
GetCurrent · SetCurrent · AddPreset · ListPresets
SoundEQ
GetCurrentEQ · SetEQ · AddProfile · SetDefault
ExperimentalVolume
GetSettings · SetSettings · MasterVolume
Worker
Capabilities
Theme
SaveTheme · GetThemes · SetTheme · Delete
Notification
AddNotification · GetNotifications · Remove · ClearAll
Clipboard
Add · Get · Remove (per group)
Note
SaveJournal · GetJournals · GetCategory · Favorites · History
Worker
Capabilities
Identity
CreateUser (privileged) · Login · UpdateAccount · EraseAccount (privileged)
Worker
Capabilities
SystemInfo
GetSpecs
App
AddApp · GetApps · Update · Favorites
Processes
GetProcesses · Snapshot · KillProcess (privileged)
Grants are two lines in the Manager - register the app (mints its own password), then grant each capability:
var app = apps. Register ( "weather" ) ;
await permissions. GrantAsync ( app. AppId, "Time.Calendar:GetEvents" ) ;