Vianordis
--:--:-- UTCVianordis / ED. 02 / 2026
§ 07 — App support

Skills

Give agents the right skills, then let customers build the next ones.

Skills combines a curated catalog of predefined agent capabilities with a marketplace where customers can create, publish, and sell specialized custom skills. The GSC Skill Server executes those skills through authenticated MCP requests, permission checks, executor routing, approvals, and audit records.

01Problem

Agents are only useful when their capabilities are controlled and discoverable.

Organizations want agents to handle mail, calendars, contacts, infrastructure, documentation, monitoring, and business workflows. Without a governed skills layer, every team wires capabilities differently, customers cannot package domain expertise, and administrators lose visibility into what agents can actually do.

  • Reusable agent capabilities are scattered across custom integrations, prompts, service credentials, and one-off scripts.
  • Customers and partners have no clean route to package specialized skills, publish them, or sell them to other tenants.
  • Administrators need to see requested permissions, executor type, data access, approval requirements, and runtime history before trusting a skill.
  • Agents need a consistent way to list available tools, call a tool, and receive structured results without bypassing identity or tenant controls.
  • High-impact actions such as sending mail, creating calendar events, provisioning users, or changing infrastructure need approval gates and audit records.
02Solution

Skills turns agent capability into a governed product surface.

The marketplace presents skills as installable, permissioned products while the GSC Skill Server executes them through a hardened MCP plane. Agents discover the assigned catalog, call a skill through JSON-RPC, and receive a structured result while authentication, permission checks, executor routing, approvals, and ledger records stay behind the service boundary.

  • A curated catalog provides predefined operational, collaboration, documentation, monitoring, infrastructure, mail, calendar, and contact skills.
  • A marketplace model lets customers create, publish, and monetize custom skills for tenant-specific workflows or reusable vertical expertise.
  • The execution plane supports Keycloak JWT, CallerContext service-token authentication, role and tenant checks, rate limits, and approval-aware execution.
03Benefits

Make agent capability reusable without making it uncontrolled.

Skills gives administrators, builders, customers, and agents a common place to manage what can be done, by whom, under which identity, and with which evidence.

Start with predefined capabilities

Ship agents with approved skills for mail, calendar, contacts, DNS, certificates, users, SSO, databases, secrets, documentation, communication, and monitoring.

Create a customer marketplace

Let customers package domain workflows as custom skills, publish them privately or commercially, and sell specialized capabilities to other organizations.

Keep execution governed

Every call passes through authenticated MCP handling, permission checks, executor-specific auth, rate limits, and execution records.

Expose clear install decisions

Marketplace listings can show provider, requested permissions, required integrations, data access, approvals, executor type, and operational limits.

Separate authors from operators

Skill creators define capability packages while tenant administrators decide installation, scopes, credentials, agent assignment, and rollout.

Support rich agent results

Agents can list tools, call tools, and render structured skill output while failures, approvals, and execution metadata remain visible.

04How it works

From marketplace listing to audited agent execution.

  1. 01

    Publish or select a skill

    A predefined, partner, or customer-built skill is described with metadata, permissions, executor configuration, approval needs, provider information, and optional commercial terms.

  2. 02

    Install and assign it

    Tenant administrators review the listing, approve scopes, configure credentials or service tokens, and assign the skill to selected workspaces or agents.

  3. 03

    Execute through the Skill Server

    An agent calls the MCP endpoint, the service authenticates the caller, checks roles and tenant policy, routes the request to the selected executor, records the result, and returns structured output.

05Features

What the Skills marketplace provides.

Curated skill catalog

Predefined skills can cover collaboration, gatekeeper mail and calendar operations, contacts, infrastructure, documentation, user management, databases, secrets, and monitoring.

Custom skill publishing

Customers can create specialized skill packages, publish them for their own tenant or the wider marketplace, and sell domain-specific automation.

Agent assignment

Skills can be installed into approved workspaces or assigned to specific agents so the available tool list matches each agent's mandate.

Permission and approval model

Listings and runtime checks can enforce role, tenant, scope, integration, and human-approval requirements before a skill executes.

Multiple executor types

The execution plane supports internal services, infrastructure MCP, ops API calls, external webhooks, n8n workflows, and GraphQL endpoints.

Execution ledger

Skill calls record success, failure, duration, approval state, caller identity, tenant context, and result metadata for operational review.

06Architecture

Architecture and operating model.

Skills separates marketplace lifecycle from runtime execution. The marketplace handles discovery, packaging, installation, assignment, commercial publishing, and governance metadata. The GSC Skill Server handles live MCP requests, authentication, permission checks, executor routing, and audit recording.

  • Agent clients use MCP JSON-RPC methods such as tools/list, tools/call, and resources/read to discover and execute assigned skills.
  • The Skill Server authenticates requests with Keycloak JWT or service-token CallerContext headers from trusted agent services.
  • Rate limiting protects the endpoint, with per-user request controls before executor routing.
  • Skill definitions are loaded from the agent portal catalog and cached for fast runtime lookup.
  • Permission checks evaluate role, tenant, approval, and configured skill policy before execution.
  • Executors route calls to internal services, infrastructure MCP over mTLS, gsc-ops-api with mTLS and API key auth, external webhooks, n8n, or GraphQL APIs.
  • Execution records are written back to the agent portal ledger so administrators can inspect outcomes and failures.
07Use cases

Where Skills fits.

Enterprise assistant rollout

Give workplace agents approved capabilities for inbox review, message drafting, calendar availability, event creation, contact search, and controlled sending.

Infrastructure operations

Assign DNS, certificate, database, SSO, user-provisioning, secrets, documentation, and monitoring skills to operations agents with explicit approvals.

Customer-built vertical workflows

Let schools, healthcare teams, manufacturers, financial teams, or public-sector customers publish reusable skills for their own regulated processes.

Partner marketplace

Allow trusted vendors and integrators to package connectors, automations, n8n workflows, and API actions as installable marketplace skills.

Controlled internal automation

Replace one-off scripts with skill definitions that carry owner, permissions, version, executor, logs, and rollout state.

Agent specialization

Create different tool catalogs for service desk, sales, compliance, operations, education, or engineering agents without changing the agent runtime.

08Integrations

Connects agents, marketplace authors, and execution targets.

Skills is designed as the bridge between customer-facing marketplace operations and the runtime systems agents need to act on behalf of users.

GSC Skill Server

Shows how this service fits into the wider Vianordis environment instead of standing alone.

MCP JSON-RPC

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Agent Portal

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Keycloak

Keeps access tied to organization accounts, roles, and sign-in policy.

CallerContext headers

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Sovereign Sign approvals

Makes actions reviewable before work is executed or escalated.

gsc-ops-api

Lets approved systems connect without ad hoc exports or manual copy-paste.

Infrastructure MCP

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Internal services

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Webhook targets

Shows how this service fits into the wider Vianordis environment instead of standing alone.

n8n

Shows how this service fits into the wider Vianordis environment instead of standing alone.

GraphQL APIs

Lets approved systems connect without ad hoc exports or manual copy-paste.

Mail

Connects communication records so messages can be used in the governed workflow.

Calendar

Connects scheduling data so time, meetings, and availability stay part of the workflow.

Contacts

Connects address-book data so people and organizations remain visible in context.

DNS

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Certificates

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Monitoring

Shows how this service fits into the wider Vianordis environment instead of standing alone.

09Trust

Governance controls for executable marketplace content.

A skill can do real work, so marketplace governance must be stronger than ordinary app discovery. Skills makes identity, tenant context, permission policy, approvals, executor auth, and execution records part of the product surface.

Caller identity

Requests authenticate with Keycloak JWT or trusted service tokens plus X-Caller headers carrying user and tenant context.

Tenant control

Skill definitions, installation, assignment, credentials, and execution policy can be scoped to the tenant and agent.

Executor isolation

Different executor types keep internal services, infrastructure tools, ops APIs, workflow engines, webhooks, and GraphQL targets explicit.

Approval gates

High-impact skills such as sending mail or creating events can require approval before execution completes.

Rate limits

Runtime calls are rate-limited per user to protect shared execution infrastructure.

Audit evidence

Execution history records success, failure, duration, caller, tenant, approval state, and result metadata for review.

10 — Pricing

Use published marketplace pricing or scope a private catalog.

Skills can be priced as platform marketplace access, tenant-private skill publishing, paid third-party skills, or custom build support. A demo is the fastest way to review agent scope, approval rules, customer publishing needs, and marketplace commercial terms.

11FAQ

Questions technical buyers usually ask.

What is a skill?

A skill is an executable capability that an agent can discover and call through the governed MCP execution plane. It can wrap an internal service, infrastructure tool, ops API endpoint, webhook, workflow, or GraphQL operation.

Are skills only provided by Vianordis?

No. The platform can include predefined Vianordis skills and marketplace skills created by customers, partners, or internal teams.

Can customers sell custom skills?

Yes. The marketplace model is designed so customers can create, publish, and sell specialized custom skills where commercial publishing is enabled.

How do agents know which skills they can use?

Agents call the catalog through MCP, and the available tools reflect installation, tenant policy, user roles, permissions, and assigned agent configuration.

How are risky actions controlled?

Runtime checks can require roles, tenant permissions, scoped credentials, approval workflows, and explicit executor configuration before the action is performed.

What happens when a skill fails?

Failures are returned as structured execution results and recorded in the ledger so operators can inspect authentication, permission, executor, integration, approval, or runtime errors.

12 — Next step

Turn agent capability into a marketplace customers can extend.

See how Skills can ship approved capabilities to every agent while opening a governed path for customer-built skills, commercial publishing, and audited execution.