Omniscio documentation
Browse all documentation
  1. Getting Started13
  2. Sessions & Agents121
  3. Inbox & Notifications65
  4. Projects & Tasks95
  5. Automation & Scheduling82
  6. Knowledge & Memory26
  7. AI Features66
  8. Integrations101
  9. Plugins & Marketplace34
  10. Cloud & Teams57
  11. Settings & Customization62
  12. Account & Billing28
  13. Troubleshooting86
  14. CLI & API Reference24
  15. Legal & Policies4
  16. Uncategorised17

Toolchain, provenance and platform tools

These six things are separate tools rather than one feature, but together they are the machinery under the app: the external command-line tools Omniscio installs and drives, the trace from any inbox action back to the session that did it, your own workspaces, a functional check of a web app an agent built, encryption for your local database, and a prompt to clear out share links nobody has opened. Each is documented in full on its own page; this page is the map.

What it is

  • Tools view — the catalogue of external CLIs Omniscio can drive (29–31 of them across ten categories): what is installed, what is missing, and an Install button for each. Closely paired with Toolchain updates, which covers keeping them current.
  • Session provenance — every inbox row an agent raised and every session an agent spawned carries a line naming its origin ("Generated by …" / a pinned "Spawned by …"), so any action can be walked back up the chain to where it started.
  • User management — the self-serve workspaces layer: the workspace list and switcher, so you can create a workspace and move between the ones you belong to.
  • Web-app verification — Obscura, the tool that functionally checks a web app an agent just built: it loads the app, confirms the elements are there, and reports console errors.
  • Database encryption — encrypting your live local database at rest, in two tiers: a transparent one that seals the key in your operating system's keychain, and a zero-knowledge passphrase. Off by default.
  • Shares view — the shares list, including the Smart Share Reaper: an opt-in sweep that finds share links over a year old that were never viewed and gives each a grace expiry rather than deleting it.

Where to find it

  • Settings → Tools (and the Tools view) for the CLI catalogue and its install state.
  • A session's or an inbox row's own page for provenance — the "Generated by" line sits with the item, not in a separate panel.
  • Settings → Users & Workspaces for the self-serve workspace list and switcher.
  • The verification tool's own entry point when an agent builds a web app, and Settings → Database for encryption.
  • The Shares panel for the reaper's Keep / let-expire card when it has something to ask about.

How it behaves

Nothing here acts silently on your data. The two that touch things you cannot easily recreate are the careful ones: encryption is off until you turn it on and hands you a one-time recovery code it insists you keep, and the reaper never deletes — it asks, with a Keep button that clears the expiry and returns the link to permanent.

They work on demand, not in the background. The toolchain is a catalogue you install from, verification runs when an agent has built something to check, and provenance is a label on the work as it happens. Only the share sweep and (once enabled) database encryption run on their own.

Each is complete on its own page. This page deliberately does not restate them: follow the link for the behaviour, the settings and the troubleshooting of whichever one you came for.

For agents

Aggregate subject: the roadmap id cat-toolchain-provenance-platform is an inventory grouping over six independent areas, and zero pages carried it before this one. Each bullet above is covered in full elsewhere — do not fold their content in here; keep this page a map. The toolchain half lives in src/main/services/toolchain/toolchain-registry.ts (TOOL_DEFINITIONS, TOOLCHAIN_INSTALL_TOOL) and is documented by tools-view.md + toolchain-update-v3.md; provenance by session-provenance.md (cat-backend-session-spawn); workspaces by user-management.md (cat-self-serve-workspaces); verification by web-app-verification.md (cat-web-app-verification-obscura); encryption by database-encryption.md (cat-database-encryption); the reaper by shares-view.md (setting smartShareReaperEnabled, shipped default off).

Related

Last verified 2026-10-06