Fleet
fleet.list_devicesdevices.readFilters tenant devices by status and location. Returns health, hardware, platform, runtime and last heartbeat without device credentials.
fleet.get_devicedevices.readReturns one device from the authenticated tenant partition. Cross-tenant device IDs resolve as not found.
fleet.get_summarydevices.read + status.readSummarizes device, OTA, active-alert and outbound-delivery health without claiming a physical action.
Releases and models
release.list_approvedreleases.readLists checksum-published metadata. It never issues private download URLs.
model.list_provenancemodels.readReturns model name, version, source, runtime, SHA-256 and device-reported verification state.
IoT integrations
integration.listintegrations.readiot.list_devicesiot.readiot.list_recent_eventsiot.readThese tools exclude integration credentials and enforce tenant ownership before reading recent events.
Monitoring and determinations
monitor.liststatus.readalert.list_recentstatus.readdetermination.list_recentmodels.readThese tools separate current alert state from retained transitions and expose bounded VLM/VLA evidence.
Outbound delivery
webhook.list_outboundintegrations.readwebhook.list_deliveriesintegrations.readSigning secrets, event payloads and URL query values are never returned.
Status and documentation
status.get_hosted_servicesstatus.readdocs.get_pageoddessy.readTool safety annotations
Every v0.2 tool advertises readOnlyHint: true, destructiveHint: false and idempotentHint: true. Tool calls are audit logged with tenant, actor, scopes, request hash, result code, region, trace and latency.
Explicitly unavailable
raw PLC writes
arbitrary shell execution
arbitrary customer-network proxying
secret retrieval
safety-interlock override
device enrolment
release deployment or rollback
approval decisions