Application and service control must be explicit, bounded, and auditable.
The software bootstrap may inventory applications and services, but it must not activate them.
Read-only discovery may include:
It must not:
Natural-language intents such as:
open firefox
start libreoffice
show ssh status
restart nginx
stop this service
must be routed through dedicated connectors with explicit capabilities and policy. Discovery alone is not permission to act.
Service start, stop, restart, package install, package removal, and process termination are write actions. They require explicit user intent, connector policy, and audit records.
Software inventory is private host shape. It must stay under:
md-os/ops/local/software/
It must remain cleanable with:
cortex software clean
The portable MD-OS package should include the software model and connector code, not the private list of applications and services installed on a user’s machine.