A user's capability is controlled by two things, authorizations and CMS configuration rights.
Authorizations control what tools a user can run on the managed node.
Authorizations = user + toolbox + system.