Implemented Versus Planned Behavior
ISA Warden extension docs must distinguish active runtime behavior from planned marketplace or host features.
The general command catalog includes native host behavior. Browser availability is the permission-filtered command list returned for the current verified launch, rather than every command appearing in these chapters.
Browser parity implementation snapshot
| Area | Implemented source and validation boundary |
|---|---|
Device-local storage_* | Origin/account/extension-scoped host storage; real Chromium and Firefox tests cover reload, isolation, quota/denial and account reset. It is not shared project persistence. |
| Group folders, reads and projects | Existing authenticated launch gateway operations with immutable workspace/group/extension scope and current resource checks. |
| Upload/delete/atomic writes | Online adapters reuse dashboard workspace-file/artifact routes; no offline browser success. The launch list includes these commands when the manifest permits them, after the server suite and local authorization-guard test passed. Live two-user visibility, multipart/CAS and cleanup-failure proof remains required. |
| Connection-bound chat, extension threads and direct tools | Shared host/server adapters exist; launch capabilities, current resource access and executor health decide availability. These do not provide durable detached execution. |
| Images and host integration | Verified-package icon resolution, browser clipboard/link handling and supported chat image payloads use host boundaries. Browser filesystem paths, native windows/mods/binaries, audio and cross-root grants remain unavailable. |
The cloud/native features plan owns full functional acceptance. Passing local persistence and adapter tests does not prove every live gateway, provider, mail or artifact workflow.
Native and shared runtime catalog
Implemented runtime behavior documented here:
- Host command invocation through
window.isaExtensionBridge.invoke(...). - Extension app info and capability discovery.
- Extension-owned key/value storage commands.
- Host-mediated local file picking through
open_file_dialog. - Group-folder extension storage through
filesystem_ensure_group_folder. - User-mediated workspace file and folder grants through
filesystem_open_workspace_fileandfilesystem_open_workspace_folder. - Canonical workspace-file commands using the
filesystem_*names. - Active-group shared project discovery, idempotent creation, and reversible soft archive through
projects_list,projects_create, andprojects_set_archived. Project identities remain stable across archive and restore and are reusable across extensions. - Syncable extension files under the returned group folder, with host-managed durable offline queueing, restart-safe reads and lists, reconnect replay for replacements and new files, and dashboard-confirmed conflict handling. The folder and read-write grant must already have been provisioned online.
- Desktop microphone capture as opaque host-owned WAV recordings, including pause/resume, restart recovery, a global stop control, revocable grants, and local TTL cleanup.
- Batch transcription through exact-group
speechToTextmodels, using local Whisper or a host-confirmed OpenAI-compatible provider. - Version 1 model recommendations in dashboard extension manifests, including add-flow validation, exact workspace matching, administrator review, and workspace-only creation through the existing model API.
- Optional speaker-aware segments from configured diarization-capable remote providers. Support is advertised per transcription model; speaker identities remain opaque until an extension or user maps them explicitly.
- Host-managed first-use download checks for local transcription models. A model may be listed before its asset is ready, and the extension retries the documented download sentinel; download progress is not exposed yet.
- Safe scoped audio, transcription, and filesystem-sync bridge events.
- Explicit
modmanifests with a separate validatedmodEntry, trusted dashboard distribution cross-checks, interactive host activation warnings, synchronous self-registration, named main-shell mount points, and tracked cleanup for host styles, roots, and listeners.
Planned or intentionally absent behavior:
- Large read-only local download for non-syncable files.
- Extension-owned offline sync queues for files already marked syncable.
- Automatic extension workspace folders at launch.
- Runtime access to arbitrary group-visible files without a local user grant.
- Marketplace policy automation beyond the currently implemented host checks.
- Recommendation bundles for tools, agents, servers, groups, or files.
- Runtime lookup by recommendation key, automatic group linking, automatic recommendation processing on extension update, and model cleanup on extension uninstall.
- System/loopback audio, live transcription, local speaker diarization, and shared raw audio.
- Durable or unattended approval for host-realm mod execution; automatically installed mods remain inactive until acknowledged in the current session.
Restart recovery means recovering persisted recording/job state through query commands. Active capture is stopped during host shutdown, and unfinished transcription becomes interrupted; inference is not resumed automatically.
When extending this specification:
- Label implemented runtime APIs as implemented.
- Label broader ecosystem ideas as planned or policy guidance.
- Do not present future MCP/server invocation behavior as available unless it is backed by implemented source.