Pick which capabilities to compile into the agent APK. Anything left unchecked is fully absent from the build — no permission requested, no code path. To add it later you'd rebuild and reinstall. Anything checked here can still be turned on/off remotely, per device, from that device's page — no rebuild needed for that.
docker compose run --rm apk-builder