Product capabilities

Governed autonomy,
end to end.

Neutron joins agent execution, operational controls, durable memory, automation, and integrations in one self-hosted product. The chapters below separate shipped mechanisms from provider, adapter, and deployment boundaries.

01 / Operate

Operate durable agents across adapters and providers

Each named agent keeps an explicit persona, provider, capability set, workspace grants, safety posture, and visibility. Change the operating identity without forking the core image.

AGENTS · ADAPTERS · PROVIDERS

Responsibility and model access stay separate

The provider control plane manages subscriptions, named API-key credentials, catalog providers, and custom endpoints without redeploying. The Neutron Core agent engine normalizes output and usage from its Claude Agent SDK adapter and OpenCode SDK adapter while retaining their different governance boundaries.

  • GPT-5.6 Sol, Terra, and Luna are selectable through the OpenCode SDK adapter when provider access permits
  • Per-message reasoning effort runs from Low to Max on models that support it
  • Credential scope and rotation are available for compatible API-key backends
  • Conversation activity, token usage, elapsed time, and cost stay attributed to the acting agent
Settings · agents
Neutron agent roster showing core and Research agents, approval posture, models, and default timeout
Core and named agents retain separate operating identities while sharing one deployed product image.Pan horizontally for full-size detail.
Composer · model and effort
Neutron composer with GPT-5.6 Terra selected and reasoning effort choices from Auto through Max
Model availability and effort levels remain dependent on provider access and model support.Pan horizontally for full-size detail.
02 / Govern

Govern the action, identity, and recorded outcome

Turns using the Claude Agent SDK adapter resolve safety mode and per-tool policy before an operation runs. A gated action carries the exact request into a persisted decision and activity trace; the OpenCode SDK adapter remains a separately stated enforcement boundary.

ALLOW · GATE · DENY

Controls operators can inspect

readonly, approval-gated, and readwrite set the default posture. Per-tool rules refine it, and optional role or named-user routing supports two-person approval where policy requires it.

  • The OpenCode SDK adapter currently does not yet enforce Neutron's per-tool policy or tool approval path
  • Headless and repository-channel turns deny gated actions without a live approval bridge
  • Persistent per-agent worktrees isolate repository state; per-repository read-only enforcement remains roadmap
  • PR/MR creation remains separate and requires host CLI authentication
Agent · permissions
Neutron core agent permissions showing approval-gated safety mode, timeout, and admin-only access
The UI proves configuration state; enforcement and persisted decisions remain adapter- and turn-specific.Pan horizontally for full-size detail.
03 / Remember

Remember context without pooling user identity

Neutron keeps per-agent, per-user memory alongside the agent's own working memory. A user can inspect, edit, or clear what an agent remembers about them.

AGENT MEMORY

Durable operating context

Agent memory carries reusable context for one operating identity rather than silently merging every agent's history.

USER MEMORY

A separate slice for each user

Each user gets a bounded memory slice per agent, with visible controls to review or remove it.

THREADS

Conversation continuity stays explicit

Saved web, repository, and linked-message threads retain their own activity and usage context.

Settings · messaging and memory
Neutron Messaging settings with Telegram, Discord, and Slack links and separate agent memory slices
Fixture handles make the linked-channel and per-agent memory boundaries visible without using customer data.Pan horizontally for full-size detail.
04 / Learn

Learn reusable procedures behind a human review gate

The capability registry stores MCP servers, CLI tools, and skills once, then grants only the selected capabilities to each agent.

MCP · TOOL · SKILL

Proposals cannot equip themselves

Agents can submit skill proposals after difficult work. Every proposal remains inert until an admin reviews the full SKILL.md and approves it.

  • Pending skills do not materialize into an agent's runtime
  • OAuth-aware MCP servers connect through a browser flow
  • .mcpb bundles import as reviewable drafts
  • Secret headers and environment values remain secret:// references
Settings · capability review
Neutron capability review showing a pending agent-proposed skill, full SKILL.md, and Approve and Reject controls
The proposed procedure remains pending and inert while an administrator reviews its complete source.Pan horizontally for full-size detail.
05 / Automate

Automate recurring work without automating interruption

Create recurring schedules from Settings → Schedules, then inspect recent runs, status, and errors. Execution and operator attention remain separate policy decisions.

SCHEDULES · INBOX · QUIET HOURS

Run on a clock, notify by policy

A schedule stores cron, timezone, agent, and prompt in the bundled assay-engine. Each fire creates a durable headless turn, then records the result in its schedule thread.

  • Recent run status and errors stay visible in Settings
  • The interrupt governor applies timezone-aware quiet hours to notifications
  • Priority breakthrough can surface urgent results while routine cards arrive silently
  • Headless gated actions are denied rather than waiting for an unavailable approver
Settings · schedules
Neutron schedule with cron, completed and failed runs, quiet hours, and priority breakthrough
Synthetic outcomes expose recent-run and notification policy states without implying a live execution.Pan horizontally for full-size detail.
06 / Connect

Connect the work without erasing its principal

Repository, messaging, computer, secret, and peer-core connections keep their acting identity and deployment boundary visible.

LINKED MESSAGING

Telegram, Discord, and Slack, linked to one agent

Link a Telegram chat, Discord DM, or Slack DM or channel to a selected agent. Messages run as the link owner with channel-specific thread and memory. A linked Slack channel has one link owner; it does not assign each participant a separate principal. Approve or deny gated actions inline in chat. Slack uses Socket Mode with admin-configured app and bot tokens, so it needs no public webhook.

COMPUTERS

Provision a browser desktop when the work needs one

On Kubernetes deployments with computer provisioning enabled and the required RBAC, admins can create a browser desktop from Settings → Computers. Provisioned desktops use Neutron's authenticated proxy without per-computer ingress; existing external noVNC URLs remain supported.

The optional computers connector lets operators allow, gate, or deny agent requests to provision and remove desktops. Driving one still requires a separately granted computer-use capability.

CONSTELLATION

A network of cores

Constellation is a network of cores: a control core registers scoped peer tokens, checks health, delegates chat, or invokes peer administration. The retained fleet configuration identifier keeps existing deployments compatible.

WORKSPACES · SHARED SERVICES

Git hosts, vault, search, and administration

GitHub and GitLab workspaces combine scoped connections with persistent per-agent worktrees. The encrypted vault, OpenBao backend, self-hosted search, REST API, and admin MCP remain opt-in services.

Settings · computers
Neutron Computers settings with a registered desktop and conditional provisioning form
This surface proves registration and provisioning controls, not successful provisioning or a live desktop session.Pan horizontally for full-size detail.