I disagree they are fundamentally at odds. The design I'm exploring with capabilities means that if you want you can do all of those things, but you can also scope them. An actor can create another actor and pass the capability or restrict it further. Imagine something like codemode with capabilities, where you want your agent to be able to shop for you. You ask your OS agent, it creates a couple different actors, one maybe manages your money, with limits you can set. Only that actor can do that. Another gets a restricted HTTP client only for those shops you whitelist.
Then a third is an agentic actor that gets access to those other two. That one then has access to two things:
* HTTP requests to specific websites * A limited way to use money
Since you can compose the primitives to limit the impact of any agent doing stupid shit you can trust it more to shop for you or book travel for you.
Of course it's more friction, but you can also choose how involved are you. You can potentially trust your coding agent to do most of it and once done everything that can be deterministic is deterministic, and only agents come in for the non-determinism and adaptability.
As the system evolve you have a library of actors that act as restricted capabilities, and an agent cannot create them out of thin air.