Why Capabilities exist
Most advice jumps straight to a tool: "use this app," "turn on this setting." DEFEND asks a different question first — what outcome are we actually trying to achieve or maintain? That outcome is the Capability. A Control (see the next page) is how you actually realize it.
Separating the two matters because tools and providers change constantly, but the outcome — your account can't be taken over, your files stay recoverable, your identity isn't scattered across services that don't need it — stays the same.
What a Capability looks like
The full catalog isn't reproduced here — capability-level language is precise and versioned, and reads better as part of the Control it realizes. These illustrative examples show the shape:
Unauthorized access to an account is prevented, even if a password is stolen.
Stored and shared information stays unreadable to anyone without authorized access.
Your real identity isn’t required for services that don’t need it.
Exposure from a data breach is detected in a timely way, not months later.
Illustrative examples — not the full catalog.
Every Capability maps directly to the Digital Life Domains it's relevant to, and most Capabilities apply across several Domains rather than just one.
See how a Capability turns into something you can actually do on the Controls page →