Getting started

Core concepts

Projects, agents, packages, skills, contributions, roles, features, sources, and sessions.

Neuralis has a small, stable vocabulary, and it is deliberately the vocabulary of an organization: projects and members, roles and grants, agents with workspaces and schedules. Every other page of this documentation builds on the terms below — each entry here is a one-paragraph orientation with a link to the page that explains the concept in full.

Project

The unit of membership and isolation. Users join a project with a role; agents, conversations, filesystem sources, and package enablement are all project-scoped, and a project's data lives in its own directory tree. A user who is not a member of a project cannot see that it has agents, packages, or sources at all. See multi-tenancy.

User and role

A user is an authenticated account; a role is what that user may do within one project. Roles (owner, admin, manager, member, viewer, plus custom roles) are bundles of feature grants, ordered by priority so that nobody can hand out a role stronger than their own. See roles and features.

Feature grant

The atomic permission unit: string keys such as core.execute, drive.read, or platform.config, granted to roles and checked server-side before any data access or mutation. Anything not granted is denied. The prefix tells you the blast radius: a project.* feature acts inside your current project, a platform.* one crosses the project boundary. The owner role holds the '*' wildcard; the admin role holds every project-tier feature explicitly. Packages declare the features they provide and require — see features and access.

Agent

An AI assistant configured inside a project: its model, system prompt, enabled packages, and tool access. Each agent owns its conversations and a per-agent data zone, including identity files it can rewrite to remember who it is and what it has learned. See agent-core.

Package

The unit of capability. Everything beyond identity and routing — chat, files, memory, terminal, admin, machine automation — ships as a package that declares its tools, skills, routes, App surfaces, connectors, and policies in files and a manifest, never in host code. Packages reach the platform along three paths: installed by the admin (the @neuralis/* builtins), dropped into a project's _packages/ directory (WASM-sandboxed), or discovered as source packages inside any synced filesystem source — no install step at all. See the package system.

Contribution

A markdown file a package contributes to the agent's context, organized by category folder: skills/<name>/SKILL.md (a procedure the model can activate, with optional scripts), plus flat .md files under instructions/, rules/, agents/ (subagent personas), and docs/. Contributions are injected into the system prompt subject to package enablement and the caller's feature grants. See contributions and skills.

Tool

A model-callable function declared by a strict JSON schema in a package's tools/*.json, executed by the package's handler. Tool calls pass feature gates, trust ceilings, input validation, and policy evaluation before they run. See tools.

Source and connector

A source is a mounted data location — a project's data folder, an extra host directory, the vector memory, a machine sandbox — identified by a slug and scoped to a project, user, or agent. A connector is the driver behind a source kind (local disk, brain vector memory, webtop machine, host the operator's own machine reached over the host broker). Synced sources are chunked and embedded into the vector index, which makes them semantically searchable and lets their markdown contribute source packages. See sources and connectors.

URI

Every file artifact is addressed as <source>://<path> — for example data://notes/meeting.md. Tools, routes, the UI, and the shell all resolve the same URIs, and per-path access is governed by URI policies evaluated against the caller's role. See brain-core for the vocabulary and URI policies for the protection model.

Workflow

A persistent, per-agent schedule entry that fires an instruction into a normal agent stream — on a timezone-aware cron schedule, at a one-shot time, or on demand. Runs queue, obey concurrency caps, and always execute as the workflow's creator with that person's current rights, never as a system identity. The Calendar widget is the workspace view over the whole project's workflow activity. See workflows.

Session

The single identity carrier for every operation: who is calling (userId), where (projectId, optional agentId), and with what authority (role and granted features). Routes, tools, and skill scripts all authenticate to the same session contract — there are no parallel identity paths. See sessions.

Workspace and widget

The workspace is the browser shell you see after signing in: a dock, tiled panels, and widgets. A widget is a App surface contributed by a package through its manifest — chat, files, terminal, machine, and admin are all package widgets. See the workspace and App surfaces.

On this page