"Publish" looks like the safest button in software. A text box, a preview, maybe a schedule picker. Low stakes.
Then an agent starts pressing it for you, and the illusion breaks. A published post reaches an audience, speaks in your name, and can't be recalled. That's not UI — it's an action with consequences, and it belongs in the same category as deploying code or reading a customer record.
Capability Host Protocol treats it that way. "Publish this to LinkedIn" and "commit this article to the blog" are capability invocations — no different in kind from "read this file." Each has to answer the questions that make an action accountable: who invoked it (which agent, under whose authority), was it allowed (anything that publishes crosses a human-held approval gate), what actually went out (the exact text and destination, as signed evidence), and can you prove it later (a receipt that outlives the moment).
Most tools can schedule your content. The difference is what you're left holding afterward: accountability by construction — the same denial-aware, signed trail you'd expect for a production change, applied to the ordinary act of hitting publish.
Because the actions that burn you are rarely the ones that look dangerous. Sometimes it's just a post. (This one went out through exactly that path — proposed by an agent, approved by a human, committed with a receipt.)