diff --git a/.tegami/2026-08-04-assistant-evidence-continuity.md b/.tegami/2026-08-04-assistant-evidence-continuity.md deleted file mode 100644 index d9a12b53..00000000 --- a/.tegami/2026-08-04-assistant-evidence-continuity.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Keep Assistant evidence useful after reload ---- - -## Features - -Assistant citations now survive transcript reload while still rechecking each -user's current access. Source opening starts with the exact governed evidence -excerpt, supports safe Markdown, PDF, image, text, and download-only files, and -shows truthful retrieval and answer-preparation activity before the first token. diff --git a/.tegami/2026-08-04-assistant-interaction-foundation.md b/.tegami/2026-08-04-assistant-interaction-foundation.md deleted file mode 100644 index 7d23e4fd..00000000 --- a/.tegami/2026-08-04-assistant-interaction-foundation.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Improve the Assistant conversation experience ---- - -## Features - -The Assistant now restores in-session conversation drafts, offers -server-curated starting prompts, retries completed answers with fresh governed -retrieval, and lets users save helpful or not-helpful feedback on an answer. diff --git a/.tegami/2026-08-04-assistant-model-picker.md b/.tegami/2026-08-04-assistant-model-picker.md deleted file mode 100644 index d4bb8de0..00000000 --- a/.tegami/2026-08-04-assistant-model-picker.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Choose a governed model in Assistant conversations ---- - -## Features - -Choose an administrator-approved model directly from the Assistant composer. -The selected model stays with the conversation, remains bound to the exact -approved gateway route, and safely falls back to the deployment default when -no explicit choice is made. diff --git a/.tegami/2026-08-05-agentic-skill-beta.md b/.tegami/2026-08-05-agentic-skill-beta.md deleted file mode 100644 index c61aa635..00000000 --- a/.tegami/2026-08-05-agentic-skill-beta.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Use governed Skills in Assistant answers ---- - -## Features - -The Assistant can now discover an authorized Skill, load its exact released -instructions, and read bounded supporting text while preparing a grounded -answer. Skill content never grants tools or permissions, and OrgMemory does not -execute package scripts, binaries, or shell commands. diff --git a/.tegami/2026-08-05-all-employees-space-placement.md b/.tegami/2026-08-05-all-employees-space-placement.md deleted file mode 100644 index 3cb3ff70..00000000 --- a/.tegami/2026-08-05-all-employees-space-placement.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Restore organization-wide document visibility ---- - -## Fixes - -All-employees demo documents now target the organization-wide Company -Knowledge space instead of inheriting a department-only audience. Department -and executive documents retain their existing restricted placement. diff --git a/.tegami/2026-08-05-assistant-answer-behavior.md b/.tegami/2026-08-05-assistant-answer-behavior.md deleted file mode 100644 index e719350e..00000000 --- a/.tegami/2026-08-05-assistant-answer-behavior.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Make Assistant no-answer guidance permission-safe ---- - -## Improvements - -The Assistant now responds in the user's language when accessible documents do -not answer a question, offers one concise next step, labels nearby information -instead of presenting it as the requested answer, and cites every source it -uses without citing unrelated documents. Assistant answers also show a short -reminder that they rely only on documents the user can access. diff --git a/.tegami/2026-08-05-knowledge-graph-parallel-relations.md b/.tegami/2026-08-05-knowledge-graph-parallel-relations.md deleted file mode 100644 index 6242a421..00000000 --- a/.tegami/2026-08-05-knowledge-graph-parallel-relations.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep parallel knowledge graph relations visible ---- - -## Fixes - -The Knowledge graph no longer fails to load when two distinct semantic -relations connect the same directed pair of entities. Parallel relations remain -separate and visible in the graph and entity inspector. diff --git a/.tegami/2026-08-05-knowledge-graph-responsive-layout.md b/.tegami/2026-08-05-knowledge-graph-responsive-layout.md deleted file mode 100644 index 9333e6b5..00000000 --- a/.tegami/2026-08-05-knowledge-graph-responsive-layout.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep Knowledge Graph controls from crushing the page title ---- - -## Improvements - -The Knowledge Graph workspace now keeps its page title readable while the -explorer controls wrap into the remaining desktop width. The same shared header -behavior prevents dense action groups from collapsing page identity elsewhere -in the product. diff --git a/.tegami/2026-08-05-knowledge-operations-graph-inspector.md b/.tegami/2026-08-05-knowledge-operations-graph-inspector.md deleted file mode 100644 index 1664f6b3..00000000 --- a/.tegami/2026-08-05-knowledge-operations-graph-inspector.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Refine Knowledge document operations and graph inspection ---- - -## Improvements - -Documents now use a persistent desktop reader while keeping the list -interactive, show ingestion failures without relying on hover, and guide -quarantined evidence into a corrected upload. The graph inspector now presents -readable entity context, directional connections, and permission-verified -document evidence instead of generic numbered sources. diff --git a/.tegami/2026-08-05-knowledge-workspace-document-reader.md b/.tegami/2026-08-05-knowledge-workspace-document-reader.md deleted file mode 100644 index 1c08deeb..00000000 --- a/.tegami/2026-08-05-knowledge-workspace-document-reader.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Complete the governed document reader ---- - -## Improvements - -The employee workspace is now named Knowledge, with Documents and Knowledge -graph as its two clear surfaces. Documents open in a responsive right-side -reader with safe rendered or raw Markdown, inline PDF and image previews, -plain-text reading, explicit download-only fallbacks, and retry when governed -content cannot be loaded. diff --git a/.tegami/2026-08-05-retrieval-admission-control.md b/.tegami/2026-08-05-retrieval-admission-control.md deleted file mode 100644 index cc7082ee..00000000 --- a/.tegami/2026-08-05-retrieval-admission-control.md +++ /dev/null @@ -1,15 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Faster, fairer assistant retrieval under load ---- - -## Improvements - -Assistant knowledge retrieval now admits snapshot queries through one fair -process-wide limit instead of per-request batches, so concurrent -conversations can no longer exhaust the database connection pool and stall at -the turn timeout. The API connection pool is right-sized for the production -host, retrieval breadth returns to the upstream LightRAG default, and new -payload-free timing stages make the previously unattributed portion of -time-to-first-token observable. diff --git a/.tegami/2026-08-05-retrieval-recall-observations.md b/.tegami/2026-08-05-retrieval-recall-observations.md deleted file mode 100644 index fcc55c55..00000000 --- a/.tegami/2026-08-05-retrieval-recall-observations.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Verify retrieval recall before query cutover ---- - -## Improvements - -Operators can now capture and score authorization-preserving retrieval recall -against an explicitly restored projection copy without generating answers or -touching the live database. The recorded 43-case comparison confirms that the -raw-query bypass stays level with the current keyword-seeded path and preserves -the evidence needed to diagnose shared misses before any query-plane cutover. diff --git a/.tegami/2026-08-05-unified-governed-document-viewer.md b/.tegami/2026-08-05-unified-governed-document-viewer.md deleted file mode 100644 index eec6bc8b..00000000 --- a/.tegami/2026-08-05-unified-governed-document-viewer.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Unify governed document previews ---- - -## Improvements - -Knowledge documents and Assistant citations now open in one centered, -responsive viewer. Long PDF, image, Markdown, and text evidence gets the full -reading surface, inline citations open it directly, and the source sidebar -remains available for comparing cited and discovered evidence. - diff --git a/.tegami/2026-08-06-ai-gateway-image-dependencies.md b/.tegami/2026-08-06-ai-gateway-image-dependencies.md deleted file mode 100644 index 0e67a2e6..00000000 --- a/.tegami/2026-08-06-ai-gateway-image-dependencies.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Rebuild AI gateway consumers for production ---- - -## Fixes - -Production releases now rebuild the API and worker whenever their shared AI -gateway integration changes, so approved Assistant and model-routing fixes are -included in the immutable image set instead of being treated as deployment -no-ops. diff --git a/.tegami/2026-08-06-assistant-chat-reasoning-effort.md b/.tegami/2026-08-06-assistant-chat-reasoning-effort.md deleted file mode 100644 index 3109b97c..00000000 --- a/.tegami/2026-08-06-assistant-chat-reasoning-effort.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep Assistant tool calls compatible with OpenAI ---- - -## Fixes - -Fresh production deployments now set Answer reasoning to `none` so the -Assistant's governed Skill tools work with `gpt-5.6-sol` on OpenAI Chat -Completions without requiring an organization route workaround. diff --git a/.tegami/2026-08-06-assistant-failure-sentences.md b/.tegami/2026-08-06-assistant-failure-sentences.md deleted file mode 100644 index 9318318e..00000000 --- a/.tegami/2026-08-06-assistant-failure-sentences.md +++ /dev/null @@ -1,18 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Tell people what to do when an Assistant turn fails ---- - -## Fixes - -A failed Assistant turn now ends on a sentence naming what the person who hit it -can do next, instead of one generic message for every cause. An expired gateway -key, a rate limit, a model that is no longer offered, a gateway that did not -answer in time, and a busy assistant are now distinguishable and separately -actionable. - -Every message remains a fixed sentence chosen from the failure's category, so a -misconfigured or unusually talkative AI gateway cannot surface its own text, -credentials, or prompt content in the browser. A failure that matches no known -category still ends on the previous generic message. diff --git a/.tegami/2026-08-06-assistant-one-conversation-store.md b/.tegami/2026-08-06-assistant-one-conversation-store.md deleted file mode 100644 index 172663f2..00000000 --- a/.tegami/2026-08-06-assistant-one-conversation-store.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep an Assistant conversation in one place ---- - -## Improvements - -An Assistant conversation is now stored once. The transcript that already served -history, replay, rename, and delete is also what the model reads back as prior -context, replacing a second copy that was kept in a table with no organization, -no owner, and no link to the conversation it belonged to. - -Prior context is now read in whole question-and-answer turns rather than by -counting messages. The question of the turn currently being answered can no -longer be sent to the model twice, a turn that failed before answering no longer -occupies the window, and the window can no longer begin partway through an -exchange. Deleting a conversation removes its context in the same operation -instead of relying on a separate call. diff --git a/.tegami/2026-08-06-assistant-prompt-input-alignment.md b/.tegami/2026-08-06-assistant-prompt-input-alignment.md deleted file mode 100644 index ef5879c1..00000000 --- a/.tegami/2026-08-06-assistant-prompt-input-alignment.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Make Assistant prompt controls consistent and accessible ---- - -## Improvements - -The Assistant composer now uses a consistent Prompt Input control set for its -model picker, status-aware submit behavior, keyboard composition, tooltips, and -future action menus. Text submission, stop controls, and input-method editing -remain predictable without enabling file, screenshot, voice, or source -attachment capabilities. diff --git a/.tegami/2026-08-06-assistant-skill-activity-receipt.md b/.tegami/2026-08-06-assistant-skill-activity-receipt.md deleted file mode 100644 index 0f4d0198..00000000 --- a/.tegami/2026-08-06-assistant-skill-activity-receipt.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Show Assistant Skill activity without a blank wait ---- - -## Improvements - -The Assistant now keeps its progress state visible until answer text appears -and shows a compact, current-turn receipt when it successfully activates a -governed Skill. Skill titles are bounded plain text, denied or failed Skills -remain unnamed, and the receipt clears safely when a turn ends without an -answer. diff --git a/.tegami/2026-08-06-assistant-skill-catalog-discovery.md b/.tegami/2026-08-06-assistant-skill-catalog-discovery.md deleted file mode 100644 index e701a77f..00000000 --- a/.tegami/2026-08-06-assistant-skill-catalog-discovery.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Match Assistant requests against authorized Skills ---- - -## Fixes - -The Assistant now sees the current user's authorized Skill names and -descriptions before choosing a workflow, so natural-language requests can -activate the matching exact release without inventing catalog search terms. -Unavailable Skills remain hidden, and activation still rechecks access. diff --git a/.tegami/2026-08-06-assistant-turn-activity-continuity.md b/.tegami/2026-08-06-assistant-turn-activity-continuity.md deleted file mode 100644 index ccff9f99..00000000 --- a/.tegami/2026-08-06-assistant-turn-activity-continuity.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep Assistant activity visible until the answer appears ---- - -## Fixes - -Assistant thinking and Skill activity now stay in one stable transcript -position until meaningful answer text appears. Skill receipts no longer expose -an empty disclosure when there is no resource detail to show. diff --git a/.tegami/2026-08-06-assistant-turn-completion-race.md b/.tegami/2026-08-06-assistant-turn-completion-race.md deleted file mode 100644 index ddd75c32..00000000 --- a/.tegami/2026-08-06-assistant-turn-completion-race.md +++ /dev/null @@ -1,18 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Stop losing an Assistant answer that was already on screen ---- - -## Fixes - -An Assistant answer could disappear from a conversation after being delivered. -When two turns of the same conversation finished at the same moment, only one of -them was saved; the other was rolled back and was gone on the next reload, even -though the person asking had watched it arrive. Both are now kept. - -Long answers with many sources also render far more cheaply. Each arriving -source used to discard and rebuild the entire answer shown so far, which made a -long, heavily cited reply progressively slower to display and could leave the -page unresponsive while it finished. The answer is now updated in place as its -sources arrive. diff --git a/.tegami/2026-08-06-clearance-separation.md b/.tegami/2026-08-06-clearance-separation.md deleted file mode 100644 index 1a42fb31..00000000 --- a/.tegami/2026-08-06-clearance-separation.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Separate data clearance from user roles ---- - -## Improvements - -The user "role" field is now a data clearance with two values, Standard and -Executive, matching what the system actually enforces: Executive widens -confidential and restricted document access, while action permissions stay -governed by organization roles. Administrators can now assign a user's -department (required for confidential document access), raising someone to -Executive asks for confirmation and states its reach, and every user can see -their own department and clearance in the account menu. Legacy titles such as -Team lead, Manager, Director, and the misleading Admin label are removed; -existing Executive users keep Executive and everyone else becomes Standard. diff --git a/.tegami/2026-08-06-exact-query-embedding-cache.md b/.tegami/2026-08-06-exact-query-embedding-cache.md deleted file mode 100644 index 9936336e..00000000 --- a/.tegami/2026-08-06-exact-query-embedding-cache.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Reuse exact query embeddings across retrieval requests ---- - -## Improvements - -GraphRAG and hybrid knowledge retrieval now reuse exact query embeddings within -an explicit projection namespace. Repeated requests avoid duplicate embedding -provider work while authorization, evidence selection, and citation verification -continue to run normally. Cached vectors remain isolated by embedding profile, -provider version, and dimensions, with bounded PostgreSQL retention and expiry. diff --git a/.tegami/2026-08-06-gitleaks-synthetic-redaction-fixture.md b/.tegami/2026-08-06-gitleaks-synthetic-redaction-fixture.md deleted file mode 100644 index 55fc0e87..00000000 --- a/.tegami/2026-08-06-gitleaks-synthetic-redaction-fixture.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep synthetic redaction fixtures in secret scanning ---- - -## Fixes - -Secret scanning now narrowly recognizes the API-key-shaped value in the -assistant redaction regression as synthetic test data while continuing to scan -all other files and generic API-key findings. diff --git a/.tegami/2026-08-06-graphrag-degree-query-timeout.md b/.tegami/2026-08-06-graphrag-degree-query-timeout.md deleted file mode 100644 index 658c3c1b..00000000 --- a/.tegami/2026-08-06-graphrag-degree-query-timeout.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep GraphRAG degree ranking within its retrieval budget ---- - -## Fixes - -GraphRAG degree ranking now resolves authorized relation visibility once and -uses indexed source and target endpoint lookups. PostgreSQL also cancels an -abnormally slow degree query before the assistant retrieval deadline, avoiding -orphaned database work that could degrade later chat turns. diff --git a/.tegami/2026-08-06-graphrag-load-relations-timeout.md b/.tegami/2026-08-06-graphrag-load-relations-timeout.md deleted file mode 100644 index 7d0068af..00000000 --- a/.tegami/2026-08-06-graphrag-load-relations-timeout.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Bound authorized GraphRAG relation loading ---- - -## Fixes - -GraphRAG now resolves authorized relation candidates with set-based entity and -relation visibility checks instead of repeating correlated ACL work for each -candidate. Relation reads also use the transaction-scoped PostgreSQL timeout so -a retrieval cancellation cannot leave database work running in the background. diff --git a/.tegami/2026-08-06-graphrag-relation-hotpaths.md b/.tegami/2026-08-06-graphrag-relation-hotpaths.md deleted file mode 100644 index d3fc948d..00000000 --- a/.tegami/2026-08-06-graphrag-relation-hotpaths.md +++ /dev/null @@ -1,20 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Restore fast authorized GraphRAG relation scoring ---- - -## Fixes - -GraphRAG now limits relation contribution and relation-weight authorization work -to the requested candidate relations before checking independently visible source -and target entities. These reads also use the transaction-scoped PostgreSQL -budget, preventing an expensive plan from continuing after retrieval is -cancelled. - -## Improvements - -Snapshot retrieval now reports bounded, payload-free timings for each graph -storage operation under the existing retrieval operation identifier, making -future latency regressions attributable without recording prompts, answers, or -evidence identifiers. diff --git a/.tegami/2026-08-06-knowledge-filters.md b/.tegami/2026-08-06-knowledge-filters.md deleted file mode 100644 index c3a4fe58..00000000 --- a/.tegami/2026-08-06-knowledge-filters.md +++ /dev/null @@ -1,16 +0,0 @@ ---- -packages: - orgmemory: minor -subject: Filter and page the Documents list ---- - -## Improvements - -Documents can now be narrowed by Knowledge Space and classification alongside -the existing status tabs, so the Space shown on every row is finally something -you can filter by. Filtering and search run on the server and the list is paged, -so a large library no longer arrives in one response. Status tab counts describe -the whole filtered library rather than the page you happen to be on, and a -document still processing keeps its real status instead of disappearing while it -publishes. The knowledge graph search now runs as you type, matching the -Documents tab instead of waiting for a separate button. diff --git a/.tegami/2026-08-06-knowledge-graph-container-sizing.md b/.tegami/2026-08-06-knowledge-graph-container-sizing.md deleted file mode 100644 index c0bf2e11..00000000 --- a/.tegami/2026-08-06-knowledge-graph-container-sizing.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep the knowledge graph stable while its panel is sizing ---- - -## Fixes - -The knowledge graph now waits for a visible, positively sized canvas before -starting Sigma, and releases the renderer if the panel becomes size-less during -a layout transition. Opening the graph while its tab or flex layout is still -settling no longer crashes the page with a zero-height container error. diff --git a/.tegami/2026-08-06-shared-service-dns.md b/.tegami/2026-08-06-shared-service-dns.md deleted file mode 100644 index 5589d8a8..00000000 --- a/.tegami/2026-08-06-shared-service-dns.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Put production services on one shared Docker DNS fabric ---- - -## Fixes - -OrgMemory, documentation, and observability services now join the same external -Docker DNS network while retaining their existing private and proxy networks. -Cross-stack diagnostics and integrations can use stable service names instead of -container IP addresses without publishing additional host ports. diff --git a/.tegami/2026-08-06-source-provenance-null-department.md b/.tegami/2026-08-06-source-provenance-null-department.md deleted file mode 100644 index 98d3550c..00000000 --- a/.tegami/2026-08-06-source-provenance-null-department.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Keep the document list working for organization-wide sources ---- - -## Fixes - -The Documents list no longer fails when a source belongs to an -organization-wide Knowledge Space. Those sources carry no owning department, -and the provenance lookup rejected the missing identifier. diff --git a/.tegami/2026-08-06-source-provenance-ux.md b/.tegami/2026-08-06-source-provenance-ux.md deleted file mode 100644 index f192e602..00000000 --- a/.tegami/2026-08-06-source-provenance-ux.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Clarify document provenance and content availability ---- - -## Fixes - -The Documents ledger now identifies each document's Knowledge Space, owning -department, and uploader. Published documents outside the current user's -content scope now show honest access guidance instead of being described as -still waiting for publication. diff --git a/.tegami/2026-08-07-assistant-message-length.md b/.tegami/2026-08-07-assistant-message-length.md deleted file mode 100644 index ad3e7df5..00000000 --- a/.tegami/2026-08-07-assistant-message-length.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -packages: - orgmemory: patch -subject: Enforce the supported Assistant question length ---- - -## Fixes - -The Assistant composer now displays and enforces the 1,000-character question -limit before a turn starts. Questions at the boundary remain accepted, while -longer input is blocked instead of opening a stream that later fails. diff --git a/.tegami/publish-lock.yaml b/.tegami/publish-lock.yaml index ac7ef776..071698a9 100644 --- a/.tegami/publish-lock.yaml +++ b/.tegami/publish-lock.yaml @@ -1,281 +1,141 @@ core:changelogs: - - content: "---\nsubject: Route ACL reads through an owned query boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Route ACL reads through an owned query boundary\n\n## Improvements\n\nRetrieval and Graph now read source ACL facts through `SourceAclQuery` and\nimmutable ACL-owned references instead of consuming the ACL repository, JPA\nentity, or a Space-owned projection type. This follows the independently\nreviewed architecture direction to replace direct implementation edges before\nclosing nested modules.\n" - filename: acl-query-boundary.md + - content: "---\nsubject: Keep Assistant evidence useful after reload\npackages:\n orgmemory:\n type: minor\n---\n\n## Features\n\nAssistant citations now survive transcript reload while still rechecking each\nuser's current access. Source opening starts with the exact governed evidence\nexcerpt, supports safe Markdown, PDF, image, text, and download-only files, and\nshows truthful retrieval and answer-preparation activity before the first token.\n" + filename: 2026-08-04-assistant-evidence-continuity.md v: 0.0.0 - - content: "---\nsubject: Remove the ACL-to-Source Ledger dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the ACL-to-Source Ledger dependency\n\n## Improvements\n\nACL heads now consume an ACL-owned source target and preserve stable conflict\nsemantics without importing Source Ledger entities or exceptions.\n" - filename: acl-source-ledger-seam.md + - content: "---\nsubject: Improve the Assistant conversation experience\npackages:\n orgmemory:\n type: minor\n---\n\n## Features\n\nThe Assistant now restores in-session conversation drafts, offers\nserver-curated starting prompts, retries completed answers with fresh governed\nretrieval, and lets users save helpful or not-helpful feedback on an answer.\n" + filename: 2026-08-04-assistant-interaction-foundation.md v: 0.0.0 - - content: "---\nsubject: AI management permission visible in admin, leaner API surface\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe organization permission catalog now includes the AI management permission,\nso admin screens can show and explain who may manage AI gateways. The\nredundant identity endpoint was removed in favor of the session endpoint, and\nrequest handling avoids repeated per-request work in SCIM limits and worker\nscheduling configuration.\n" - filename: admin-permission-and-api-cleanup.md + - content: "---\nsubject: Choose a governed model in Assistant conversations\npackages:\n orgmemory:\n type: minor\n---\n\n## Features\n\nChoose an administrator-approved model directly from the Assistant composer.\nThe selected model stays with the conversation, remains bound to the exact\napproved gateway route, and safely falls back to the deployment default when\nno explicit choice is made.\n" + filename: 2026-08-04-assistant-model-picker.md v: 0.0.0 - - content: "---\nsubject: Repair published graph snapshots after Apache AGE cutover\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nProduction deployment now reconstructs retained relational graph publications\nin Apache AGE through a bounded, verified one-shot before the API and worker\nstart. Graph exploration and Assistant retrieval no longer remain unavailable\nwhen published snapshots predate the AGE topology backend.\n" - filename: apache-age-published-batch-backfill.md + - content: "---\nsubject: Use governed Skills in Assistant answers\npackages:\n orgmemory:\n type: minor\n---\n\n## Features\n\nThe Assistant can now discover an authorized Skill, load its exact released\ninstructions, and read bounded supporting text while preparing a grounded\nanswer. Skill content never grants tools or permissions, and OrgMemory does not\nexecute package scripts, binaries, or shell commands.\n" + filename: 2026-08-05-agentic-skill-beta.md v: 0.0.0 - - content: "---\nsubject: Repair Apache AGE startup for least-privilege roles\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nApache AGE startup now verifies session preload through a bootstrap-owned\nboolean probe instead of requiring the application to read all PostgreSQL\nsettings. Production-shaped conformance tests use a non-superuser role and keep\nthe broader `pg_read_all_settings` privilege denied.\n" - filename: apache-age-runtime-probe.md + - content: "---\nsubject: Restore organization-wide document visibility\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nAll-employees demo documents now target the organization-wide Company\nKnowledge space instead of inheriting a department-only audience. Department\nand executive documents retain their existing restricted placement.\n" + filename: 2026-08-05-all-employees-space-placement.md v: 0.0.0 - - content: "---\nsubject: Refine Asset catalog layout balance\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nTighten the desktop Asset catalog with a compact ownership scope, trailing\nresult and layout controls, and clearer selected states while preserving the\nexisting responsive workflow.\n" - filename: asset-catalog-layout-balance.md + - content: "---\nsubject: Make Assistant no-answer guidance permission-safe\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe Assistant now responds in the user's language when accessible documents do\nnot answer a question, offers one concise next step, labels nearby information\ninstead of presenting it as the requested answer, and cites every source it\nuses without citing unrelated documents. Assistant answers also show a short\nreminder that they rely only on documents the user can access.\n" + filename: 2026-08-05-assistant-answer-behavior.md v: 0.0.0 - - content: "---\nsubject: Move catalog and chunk values to Knowledge Asset\npackages:\n orgmemory:\n type: patch\n---\n\n# Move catalog and chunk values to Knowledge Asset\n\n## Improvements\n\nKnowledge Asset now owns its catalog projection, normalized text-chunk value,\nand PostgreSQL vector encoding, so Retrieval and other consumers depend on the\ndomain that persists and publishes those values.\n" - filename: asset-owned-catalog-chunk-values.md + - content: "---\nsubject: Keep parallel knowledge graph relations visible\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe Knowledge graph no longer fails to load when two distinct semantic\nrelations connect the same directed pair of entities. Parallel relations remain\nseparate and visible in the graph and entity inspector.\n" + filename: 2026-08-05-knowledge-graph-parallel-relations.md v: 0.0.0 - - content: "---\nsubject: Add personal Asset ownership navigation\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nAdd an owner-scoped `My Assets` workspace alongside the authorized shared\ncatalog, with responsive search, scope, type, sort, and layout controls.\n" - filename: asset-ownership-navigation.md + - content: "---\nsubject: Keep Knowledge Graph controls from crushing the page title\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe Knowledge Graph workspace now keeps its page title readable while the\nexplorer controls wrap into the remaining desktop width. The same shared header\nbehavior prevents dense action groups from collapsing page identity elsewhere\nin the product.\n" + filename: 2026-08-05-knowledge-graph-responsive-layout.md v: 0.0.0 - - content: "---\nsubject: Remove the Knowledge Asset dependency on Retrieval\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Knowledge Asset dependency on Retrieval\n\n## Improvements\n\nKnowledge Asset now owns its compact embedding-profile reference and projection\nnamespace identity. Connector and Worker translate richer Retrieval profiles at\nthe orchestration boundary, leaving Asset with no direct Retrieval dependency.\n" - filename: asset-retrieval-boundary.md + - content: "---\nsubject: Refine Knowledge document operations and graph inspection\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nDocuments now use a persistent desktop reader while keeping the list\ninteractive, show ingestion failures without relying on hover, and guide\nquarantined evidence into a corrected upload. The graph inspector now presents\nreadable entity context, directional connections, and permission-verified\ndocument evidence instead of generic numbered sources.\n" + filename: 2026-08-05-knowledge-operations-graph-inspector.md v: 0.0.0 - - content: "---\nsubject: Isolate Asset publication from Source Ledger persistence\npackages:\n orgmemory:\n type: patch\n---\n\n# Isolate Asset publication from Source Ledger persistence\n\n## Improvements\n\nKnowledge Asset promotion now receives validated source facts through public\nSource Ledger contracts, while publication advances the source revision through\nan owner-defined transaction-aware service instead of cross-module repository\naccess.\n" - filename: asset-source-publication-boundary.md + - content: "---\nsubject: Complete the governed document reader\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe employee workspace is now named Knowledge, with Documents and Knowledge\ngraph as its two clear surfaces. Documents open in a responsive right-side\nreader with safe rendered or raw Markdown, inline PDF and image previews,\nplain-text reading, explicit download-only fallbacks, and retry when governed\ncontent cannot be loaded.\n" + filename: 2026-08-05-knowledge-workspace-document-reader.md v: 0.0.0 - - content: "---\nsubject: Unify authorized graph traversal\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nAuthorized graph expansion now follows one deterministic core policy across\nPostgreSQL, Neo4j, and OpenSearch. Exact snapshot validation, permission-scoped\npaging, canonical ordering, and global limits no longer vary by storage\nbackend, and incomplete native traversal prefixes can no longer become public\nquery results.\n" - filename: authorized-graph-traversal.md + - content: "---\nsubject: Faster, fairer assistant retrieval under load\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nAssistant knowledge retrieval now admits snapshot queries through one fair\nprocess-wide limit instead of per-request batches, so concurrent\nconversations can no longer exhaust the database connection pool and stall at\nthe turn timeout. The API connection pool is right-sized for the production\nhost, retrieval breadth returns to the upstream LightRAG default, and new\npayload-free timing stages make the previously unattributed portion of\ntime-to-first-token observable.\n" + filename: 2026-08-05-retrieval-admission-control.md v: 0.0.0 - - content: "---\nsubject: Automate release note navigation\npackages:\n orgmemory:\n type: patch\n---\n\n# Automate release note navigation\n\n## Documentation\n\nGenerate localized release-note navigation and an internal archive from the\nreviewed product changelog so public history remains current without manual\nsidebar edits or repository access.\n" - filename: automated-release-note-navigation.md + - content: "---\nsubject: Verify retrieval recall before query cutover\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nOperators can now capture and score authorization-preserving retrieval recall\nagainst an explicitly restored projection copy without generating answers or\ntouching the live database. The recorded 43-case comparison confirms that the\nraw-query bypass stays level with the current keyword-seeded path and preserves\nthe evidence needed to diagnose shared misses before any query-plane cutover.\n" + filename: 2026-08-05-retrieval-recall-observations.md v: 0.0.0 - - content: "---\nsubject: Author and revise Skill Drafts in the browser\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nCreate a private Skill Draft from scratch, a `SKILL.md`, ZIP, or local folder.\nOrgMemory previews the validated package before creation, and authorized owners\ncan replace the mutable Draft package without changing any immutable Revision\nor Release.\n" - filename: browser-skill-draft-authoring.md + - content: "---\nsubject: Unify governed document previews\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nKnowledge documents and Assistant citations now open in one centered,\nresponsive viewer. Long PDF, image, Markdown, and text evidence gets the full\nreading surface, inline citations open it directly, and the source sidebar\nremains available for comparing cited and discovered evidence.\n" + filename: 2026-08-05-unified-governed-document-viewer.md v: 0.0.0 - - content: "---\nsubject: Create Skill Drafts from the Assets catalog\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nOpen the new Add asset menu from the Assets catalog, choose Skill, and upload a\nvalidated ZIP package into an authorized Knowledge Space. A successful import\ncreates a private Draft and opens its existing Governance workspace.\n" - filename: browser-skill-upload.md + - content: "---\nsubject: Rebuild AI gateway consumers for production\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nProduction releases now rebuild the API and worker whenever their shared AI\ngateway integration changes, so approved Assistant and model-routing fixes are\nincluded in the immutable image set instead of being treated as deployment\nno-ops.\n" + filename: 2026-08-06-ai-gateway-image-dependencies.md v: 0.0.0 - - content: "---\nsubject: Separate Changelog from documentation categories\npackages:\n orgmemory:\n type: patch\n---\n\n# Separate Changelog from documentation categories\n\n## Documentation\n\nKeep Changelog as a standalone global documentation surface with focused,\nautomatically generated release navigation while limiting the documentation\ncategory switcher to the four reader-oriented categories.\n" - filename: changelog-global-surface.md + - content: "---\nsubject: Keep Assistant tool calls compatible with OpenAI\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nFresh production deployments now set Answer reasoning to `none` so the\nAssistant's governed Skill tools work with `gpt-5.6-sol` on OpenAI Chat\nCompletions without requiring an organization route workaround.\n" + filename: 2026-08-06-assistant-chat-reasoning-effort.md v: 0.0.0 - - content: "---\nsubject: Repair existing-version CLI publication verification\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nMake the retry-safe npm publication path parse correctly when the exact CLI\nversion already exists, and prevent indented nested heredoc terminators from\nreaching the workflow again.\n" - filename: cli-publish-existing-version-shell.md + - content: "---\nsubject: Tell people what to do when an Assistant turn fails\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nA failed Assistant turn now ends on a sentence naming what the person who hit it\ncan do next, instead of one generic message for every cause. An expired gateway\nkey, a rate limit, a model that is no longer offered, a gateway that did not\nanswer in time, and a busy assistant are now distinguishable and separately\nactionable.\n\nEvery message remains a fixed sentence chosen from the failure's category, so a\nmisconfigured or unusually talkative AI gateway cannot surface its own text,\ncredentials, or prompt content in the browser. A failure that matches no known\ncategory still ends on the previous generic message.\n" + filename: 2026-08-06-assistant-failure-sentences.md v: 0.0.0 - - content: "---\nsubject: Correct the missing-version npm publication probe\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nAllow a new exact CLI version to reach npm Trusted Publishing while retaining\nthe immutable-integrity comparison for versions that already exist.\n" - filename: cli-publish-missing-version.md + - content: "---\nsubject: Keep an Assistant conversation in one place\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nAn Assistant conversation is now stored once. The transcript that already served\nhistory, replay, rename, and delete is also what the model reads back as prior\ncontext, replacing a second copy that was kept in a table with no organization,\nno owner, and no link to the conversation it belonged to.\n\nPrior context is now read in whole question-and-answer turns rather than by\ncounting messages. The question of the turn currently being answered can no\nlonger be sent to the model twice, a turn that failed before answering no longer\noccupies the window, and the window can no longer begin partway through an\nexchange. Deleting a conversation removes its context in the same operation\ninstead of relying on a separate call.\n" + filename: 2026-08-06-assistant-one-conversation-store.md v: 0.0.0 - - content: "---\nsubject: Make CLI publication verification retry-safe\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nRecover a successful immutable CLI publication when npm provenance propagates\nafter the package manifest, while refusing any existing version whose registry\nintegrity differs from the reviewed tarball.\n" - filename: cli-publish-verification-recovery.md + - content: "---\nsubject: Make Assistant prompt controls consistent and accessible\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe Assistant composer now uses a consistent Prompt Input control set for its\nmodel picker, status-aware submit behavior, keyboard composition, tooltips, and\nfuture action menus. Text submission, stop controls, and input-method editing\nremain predictable without enabling file, screenshot, voice, or source\nattachment capabilities.\n" + filename: 2026-08-06-assistant-prompt-input-alignment.md v: 0.0.0 - - content: "---\nsubject: Close the Knowledge ACL module boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Close the Knowledge ACL module boundary\n\n## Improvements\n\nKnowledge ACL now enforces a closed public API with an explicit dependency\nallowlist limited to `organization`, `permission`, `shared`, and\n`shared::error`. This completes the independently reviewed ACL closure after\nits sibling implementation edges were replaced with owned APIs.\n" - filename: close-acl-module.md + - content: "---\nsubject: Show Assistant Skill activity without a blank wait\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nThe Assistant now keeps its progress state visible until answer text appears\nand shows a compact, current-turn receipt when it successfully activates a\ngoverned Skill. Skill titles are bounded plain text, denied or failed Skills\nremain unnamed, and the receipt clears safely when a turn ends without an\nanswer.\n" + filename: 2026-08-06-assistant-skill-activity-receipt.md v: 0.0.0 - - content: "---\nsubject: Close the Knowledge Connector module boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Close the Knowledge Connector module boundary\n\n## Improvements\n\nKnowledge Connector now enforces a closed Spring Modulith boundary and an exact\noutgoing dependency allowlist after its ACL, Source Ledger, storage, Asset, and\nRetrieval interactions were reduced to intentional public contracts.\n" - filename: close-connector-module.md + - content: "---\nsubject: Match Assistant requests against authorized Skills\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe Assistant now sees the current user's authorized Skill names and\ndescriptions before choosing a workflow, so natural-language requests can\nactivate the matching exact release without inventing catalog search terms.\nUnavailable Skills remain hidden, and activation still rechecks access.\n" + filename: 2026-08-06-assistant-skill-catalog-discovery.md v: 0.0.0 - - content: "---\nsubject: Close the Knowledge Graph module boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Close the Knowledge Graph module boundary\n\n## Improvements\n\nKnowledge Graph now enforces a closed public API and an exact outgoing\ndependency allowlist after Asset, Source Ledger, ACL, Space, and embedding\nprofile persistence access was replaced with owned query and registry\ncontracts. This completes the independently reviewed Graph closure.\n" - filename: close-graph-module.md + - content: "---\nsubject: Keep Assistant activity visible until the answer appears\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nAssistant thinking and Skill activity now stay in one stable transcript\nposition until meaningful answer text appears. Skill receipts no longer expose\nan empty disclosure when there is no resource detail to show.\n" + filename: 2026-08-06-assistant-turn-activity-continuity.md v: 0.0.0 - - content: "---\nsubject: Close the Source Ledger module boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Close the Source Ledger module boundary\n\n## Improvements\n\nSource Ledger now enforces a closed public API and an explicit allowlist for\nits ACL, storage, organization, permission, and shared dependencies.\n\nThis completes the mechanical closure gate required by the independent\narchitecture review.\n" - filename: close-source-ledger-module.md + - content: "---\nsubject: Stop losing an Assistant answer that was already on screen\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nAn Assistant answer could disappear from a conversation after being delivered.\nWhen two turns of the same conversation finished at the same moment, only one of\nthem was saved; the other was rolled back and was gone on the next reload, even\nthough the person asking had watched it arrive. Both are now kept.\n\nLong answers with many sources also render far more cheaply. Each arriving\nsource used to discard and rebuild the entire answer shown so far, which made a\nlong, heavily cited reply progressively slower to display and could leave the\npage unresponsive while it finished. The answer is now updated in place as its\nsources arrive.\n" + filename: 2026-08-06-assistant-turn-completion-race.md v: 0.0.0 - - content: "---\nsubject: Close the Knowledge Space module boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Close the Knowledge Space module boundary\n\n## Improvements\n\nKnowledge Space now enforces a closed public API with an explicit dependency\nallowlist limited to `authorization`, `knowledge.sourceledger`, `organization`,\n`permission`, `shared`, and `shared::error`. This completes the independently\nreviewed Space closure after sibling repository access was replaced with an\nowned query API.\n" - filename: close-space-module.md + - content: "---\nsubject: Separate data clearance from user roles\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nThe user \"role\" field is now a data clearance with two values, Standard and\nExecutive, matching what the system actually enforces: Executive widens\nconfidential and restricted document access, while action permissions stay\ngoverned by organization roles. Administrators can now assign a user's\ndepartment (required for confidential document access), raising someone to\nExecutive asks for confirmation and states its reach, and every user can see\ntheir own department and clearance in the account menu. Legacy titles such as\nTeam lead, Manager, Director, and the misleading Admin label are removed;\nexisting Executive users keep Executive and everyone else becomes Standard.\n" + filename: 2026-08-06-clearance-separation.md v: 0.0.0 - - content: "---\nsubject: Isolate connector read views from Source Ledger persistence\npackages:\n orgmemory:\n type: patch\n---\n\n# Isolate connector read views from Source Ledger persistence\n\n## Improvements\n\nConnector inventory and activity views now use a Source Ledger-owned read\nboundary instead of consuming its repository, entity status, and aggregate\nprojection types directly. The immutable query result preserves active and\narchived counts, latest activity time, and active external object ids.\n" - filename: connector-ledger-read-boundary.md + - content: "---\nsubject: Reuse exact query embeddings across retrieval requests\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nGraphRAG and hybrid knowledge retrieval now reuse exact query embeddings within\nan explicit projection namespace. Repeated requests avoid duplicate embedding\nprovider work while authorization, evidence selection, and citation verification\ncontinue to run normally. Cached vectors remain isolated by embedding profile,\nprovider version, and dimensions, with bounded PostgreSQL retention and expiry.\n" + filename: 2026-08-06-exact-query-embedding-cache.md v: 0.0.0 - - content: "---\nsubject: Make live connector polling consistent and rotation-aware\npackages:\n orgmemory:\n type: patch\n---\n\n# Make live connector polling consistent and rotation-aware\n\n## Improvements\n\nSlack, Google Drive, and GitHub now run through one connector polling driver\nfor connection isolation, content cadence, failure activity, and\ncredential-derived client lifecycle. Clients retain safe token and rate-limit\nstate across polls, rebuild after credential or client-identity changes, and\nretire when a connection disappears. A crawl in which at least half of the\neligible source units cannot be read is reported as `mostly_failed` instead of\nadvancing a broadly degraded checkpoint, while all existing crawl and\ncomponent cursor bytes remain unchanged.\n" - filename: connector-polling-driver.md + - content: "---\nsubject: Keep synthetic redaction fixtures in secret scanning\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nSecret scanning now narrowly recognizes the API-key-shaped value in the\nassistant redaction regression as synthetic test data while continuing to scan\nall other files and generic API-key findings.\n" + filename: 2026-08-06-gitleaks-synthetic-redaction-fixture.md v: 0.0.0 - - content: "---\nsubject: Isolate connector source lifecycle operations\npackages:\n orgmemory:\n type: patch\n---\n\n# Isolate connector source lifecycle operations\n\n## Improvements\n\nConnector reconciliation now resolves source identity, diffs active inventory,\nand retires tombstoned sources through Source Ledger-owned query and lifecycle\nAPIs. Connector no longer consumes the Source Object repository, entity, or\nstatus enum for these flows.\n" - filename: connector-source-lifecycle-boundary.md + - content: "---\nsubject: Keep GraphRAG degree ranking within its retrieval budget\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nGraphRAG degree ranking now resolves authorized relation visibility once and\nuses indexed source and target endpoint lookups. PostgreSQL also cancels an\nabnormally slow degree query before the assistant retrieval deadline, avoiding\norphaned database work that could degrade later chat turns.\n" + filename: 2026-08-06-graphrag-degree-query-timeout.md v: 0.0.0 - - content: "---\nsubject: Isolate connector source revision transactions\npackages:\n orgmemory:\n type: patch\n---\n\n# Isolate connector source revision transactions\n\n## Improvements\n\nSource Ledger now owns connector revision lookup, evidence staging, completion,\nand atomic graph-job scheduling behind revision commands and immutable draft\nfacts. Connector no longer consumes Source Ledger repositories/entities or the\nGraph queue, while independent transaction boundaries remain enforced.\n" - filename: connector-source-revision-boundary.md + - content: "---\nsubject: Bound authorized GraphRAG relation loading\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nGraphRAG now resolves authorized relation candidates with set-based entity and\nrelation visibility checks instead of repeating correlated ACL work for each\ncandidate. Relation reads also use the transaction-scoped PostgreSQL timeout so\na retrieval cancellation cannot leave database work running in the background.\n" + filename: 2026-08-06-graphrag-load-relations-timeout.md v: 0.0.0 - - content: "---\nsubject: Safer, leaner knowledge publication on OpenSearch\npackages:\n orgmemory:\n type: patch\n---\n\n# Safer, leaner knowledge publication on OpenSearch\n\n## Improvements\n\nPublishing a new knowledge generation on OpenSearch now runs through one\ncoordinated copy-forward protocol with durable ownership: a publisher can no\nlonger take over a copy that another process is still performing, failed\ncopies leave an explicit durable failure state and clean up their partial\noutput, and the previous generation streams across in bounded pages instead\nof being loaded into memory whole. Stored documents are preserved\nbyte-for-byte.\n" - filename: copyforward-coordination.md + - content: "---\nsubject: Restore fast authorized GraphRAG relation scoring\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nGraphRAG now limits relation contribution and relation-weight authorization work\nto the requested candidate relations before checking independently visible source\nand target entities. These reads also use the transaction-scoped PostgreSQL\nbudget, preventing an expensive plan from continuing after retrieval is\ncancelled.\n\n## Improvements\n\nSnapshot retrieval now reports bounded, payload-free timings for each graph\nstorage operation under the existing retrieval operation identifier, making\nfuture latency regressions attributable without recording prompts, answers, or\nevidence identifiers.\n" + filename: 2026-08-06-graphrag-relation-hotpaths.md v: 0.0.0 - - content: "---\nsubject: Keep public docs hydration stable\npackages:\n orgmemory:\n type: patch\n---\n\n# Keep public docs hydration stable\n\n## Fixes\n\nThe public documentation now renders its category selector consistently during\nstatic generation and browser hydration. English and Vietnamese documentation\nroutes no longer emit React hydration errors when opened from a fresh page.\n" - filename: docs-hydration-stability.md + - content: "---\nsubject: Filter and page the Documents list\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nDocuments can now be narrowed by Knowledge Space and classification alongside\nthe existing status tabs, so the Space shown on every row is finally something\nyou can filter by. Filtering and search run on the server and the list is paged,\nso a large library no longer arrives in one response. Status tab counts describe\nthe whole filtered library rather than the page you happen to be on, and a\ndocument still processing keeps its real status instead of disappearing while it\npublishes. The knowledge graph search now runs as you type, matching the\nDocuments tab instead of waiting for a separate button.\n" + filename: 2026-08-06-knowledge-filters.md v: 0.0.0 - - content: "---\nsubject: View and retire governed documents\npackages:\n orgmemory:\n type: patch\n---\n\n## Features\n\nLet users inspect document metadata, safely view supported document content,\nand retire eligible manual uploads directly from the Documents workspace while\npreserving governed evidence and access-control checks.\n" - filename: document-view-delete.md + - content: "---\nsubject: Keep the knowledge graph stable while its panel is sizing\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe knowledge graph now waits for a visible, positively sized canvas before\nstarting Sigma, and releases the renderer if the panel becomes size-less during\na layout transition. Opening the graph while its tab or flex layout is still\nsettling no longer crashes the page with a zero-height container error.\n" + filename: 2026-08-06-knowledge-graph-container-sizing.md v: 0.0.0 - - content: "---\nsubject: Recover graph publication safely across worker restarts\npackages:\n orgmemory:\n type: patch\n---\n\n# Recover graph publication safely across worker restarts\n\n## Fixes\n\nGraph indexing now binds each cross-store publication to a durable commit\npermit and claim epoch. Retries resume the exact permitted PostgreSQL and\nOpenSearch attempt after a worker restart, never discard staging whose\nvisibility is uncertain, fence abandoned copy-forward work, invalidate graph\ncaches before completing the job, and require durable proof before cleaning up\na competing attempt.\n" - filename: durable-graph-publication-recovery.md + - content: "---\nsubject: Put production services on one shared Docker DNS fabric\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nOrgMemory, documentation, and observability services now join the same external\nDocker DNS network while retaining their existing private and proxy networks.\nCross-stack diagnostics and integrations can use stable service names instead of\ncontainer IP addresses without publishing additional host ports.\n" + filename: 2026-08-06-shared-service-dns.md v: 0.0.0 - - content: "---\nsubject: Explain effective document access\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nShow administrators the OpenFGA relationship decision and the canonical\ncontent-policy decision separately, while keeping denied resource metadata\nbehind audit-view permission and technical identifiers out of the primary UI.\n" - filename: effective-access-inspector.md + - content: "---\nsubject: Keep the document list working for organization-wide sources\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe Documents list no longer fails when a source belongs to an\norganization-wide Knowledge Space. Those sources carry no owning department,\nand the provenance lookup rejected the missing identifier.\n" + filename: 2026-08-06-source-provenance-null-department.md v: 0.0.0 - - content: "---\nsubject: Activate evaluated production RAG routes\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nProduction now defaults Answer to `gpt-5.6-sol`, Keyword Planning to\n`gpt-5.6-luna` with reasoning disabled, and Graph Extraction to\n`gpt-5.4-mini`, preserving the independently evaluated quality and latency\nsplit across deployments and shared ZM development.\n" - filename: evaluated-rag-production-routes.md + - content: "---\nsubject: Clarify document provenance and content availability\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe Documents ledger now identifies each document's Knowledge Space, owning\ndepartment, and uploader. Published documents outside the current user's\ncontent scope now show honest access guidance instead of being described as\nstill waiting for publication.\n" + filename: 2026-08-06-source-provenance-ux.md v: 0.0.0 - - content: "---\nsubject: Select an explicit Apache AGE topology backend\npackages:\n orgmemory:\n type: patch\n---\n\n## Features\n\nPostgreSQL GraphRAG now selects either Apache AGE or relational topology as an\nexplicit runtime backend. Apache AGE is the production default, fails startup\ninstead of silently falling back, and serves publication-batch-pinned,\nauthorization-filtered topology while PostgreSQL retains canonical evidence.\n" - filename: explicit-apache-age-backend.md - v: 0.0.0 - - content: "---\nsubject: Import governed Skills from GitHub\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nDiscover Skills in a public or administrator-approved private GitHub\nrepository, preview the exact commit and valid packages, then import selected\nSkills as independent governed Drafts. Private access stays server-side through\nan approved GitHub App connection, and every Draft retains immutable source\nprovenance.\n" - filename: github-skill-import.md - v: 0.0.0 - - content: "---\nsubject: Accurate review actions in the governance workspace\npackages:\n orgmemory:\n type: patch\n---\n\n# Accurate review actions in the governance workspace\n\n## Improvements\n\nThe governance workspace now shows exactly the review actions the server\npermits: a revision author can request changes or reject, and only approval\nis withheld, matching the enforcement rule. Action availability comes from\nthe server instead of being derived in the browser, so what you see always\nmatches what you may do. Authorization rechecks behind search, citations,\nand graph answers now share one hardened implementation with their existing\nper-surface behavior preserved.\n" - filename: governance-affordances.md - v: 0.0.0 - - content: "---\nsubject: Remove Graph access to Asset persistence\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove Graph access to Asset persistence\n\n## Improvements\n\nKnowledge Graph indexing and curation now consume immutable Asset-owned query\ncontracts instead of Asset repositories, JPA entities, and the chunk projection\nstore. This follows the independently reviewed architecture direction by\nremoving an implementation edge before the Graph module is closed.\n" - filename: graph-asset-query-boundary.md - v: 0.0.0 - - content: "---\nsubject: Use the LightRAG mini model for graph extraction\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nDefault graph extraction independently to `gpt-5.4-mini` so changing the\nAssistant model no longer changes indexing behavior, while preserving a\ndedicated deployment override and immutable processing profiles.\n" - filename: graph-extraction-model-default.md - v: 0.0.0 - - content: "---\nsubject: Reliable graph indexing recovery and hardened graph export\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nCancelling a graph indexing job while it is processing no longer wedges the\nindexing queue after its lease expires; cancelled jobs settle into a terminal\nstate and the queue keeps flowing. Connector documents whose embedding or\npublication step failed mid-run now retry cleanly instead of leaving a staged\nrevision that references deleted content. Short knowledge queries with an\nempty trusted keyword plan no longer fail with an internal error. Graph CSV\nexports neutralize leading spreadsheet formula characters so exported cells\ncannot execute as formulas when opened in Excel.\n" - filename: graph-indexing-recovery.md - v: 0.0.0 - - content: "---\nsubject: Remove Graph access to embedding profile persistence\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove Graph access to embedding profile persistence\n\n## Improvements\n\nKnowledge Graph indexing now resolves immutable embedding profiles through the\nRetrieval-owned registry instead of consuming the profile repository and JPA\nentity. This follows the independently reviewed architecture direction by\nremoving the final Graph persistence edge before its module-closing cycle.\n" - filename: graph-retrieval-profile-boundary.md - v: 0.0.0 - - content: "---\nsubject: Remove Graph access to Source revision persistence\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove Graph access to Source revision persistence\n\n## Improvements\n\nKnowledge Graph indexing now resolves immutable source-revision state through\na Source Ledger-owned query instead of consuming revision repositories, JPA\nentities, and persistence status directly. This follows the independently\nreviewed architecture direction by removing another implementation edge before\nthe Graph module is closed.\n" - filename: graph-source-query-boundary.md - v: 0.0.0 - - content: "---\nsubject: Faster document ingestion and graph indexing\npackages:\n orgmemory:\n type: patch\n---\n\n# Faster document ingestion and graph indexing\n\n## Improvements\n\nStaged projection writes now travel in bounded batches instead of one\nstatement per row, and the ingestion and graph-indexing workers process a\nbounded burst of queued jobs per cycle instead of a single job, so backlogs\ndrain far sooner while maintenance jobs and the other queue keep running.\nFailure behavior, publication atomicity, and stored data are unchanged.\n" - filename: ingestion-throughput.md - v: 0.0.0 - - content: "---\nsubject: Faster, leaner storage and connector adapters\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nGraph storage adapters now avoid repeated remote round trips on hot paths:\nvector staging verifies each physical index once per batch, entity degrees are\ncomputed in a single pass, and Slack crawls build their member directory once\nper crawl instead of per thread. Duplicate and dead adapter code paths were\nremoved and model-key handling was hardened, with no change to stored data,\ncursors, or fingerprints.\n" - filename: integration-adapter-hardening.md - v: 0.0.0 - - content: "---\nsubject: Bind independent production AI model routes\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nProduction API and worker configuration now bind Keyword Planning independently\nto `gpt-5.6-luna` with reasoning `none` instead of silently inheriting the\nAnswer model from a shared Java default.\n" - filename: keyword-luna-route-binding.md - v: 0.0.0 - - content: "---\nsubject: Break the ACL-to-Connector dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Break the ACL-to-Connector dependency\n\n## Improvements\n\nACL now owns its ingestion commands and membership evidence while Connector\nmaps crawl payloads at the boundary, removing the reciprocal module dependency\nwithout changing connector or source-access behavior.\n" - filename: knowledge-acl-connector-seam.md - v: 0.0.0 - - content: "---\nsubject: Isolate Knowledge Graph lifecycle and processing boundaries\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nKnowledge Graph indexing, processing profiles, lifecycle operations, curation,\nexploration, and export now share an explicit module boundary, reducing coupling\nand making future graph changes safer to verify and release.\n" - filename: knowledge-graph-module.md - v: 0.0.0 - - content: "---\nsubject: Isolate retrieval and embedding contracts\npackages:\n orgmemory:\n type: patch\n---\n\n# Knowledge retrieval contracts\n\n## Improvements\n\nQuery embedding contracts, embedding profiles, and projection namespaces now\nshare an explicit retrieval module boundary, making provider integration and\nfuture retrieval changes easier to verify safely.\n" - filename: knowledge-retrieval-contracts.md - v: 0.0.0 - - content: "---\nsubject: Complete the Knowledge retrieval module move\npackages:\n orgmemory:\n type: patch\n---\n\n# Knowledge retrieval runtime\n\n## Improvements\n\nAuthorized search, evidence and citation assembly, catalog federation, and\nretrieval persistence now share one explicit module boundary, making the\nsecurity-critical retrieval flow easier to inspect and evolve safely.\n" - filename: knowledge-retrieval-runtime.md - v: 0.0.0 - - content: "---\nsubject: Finish Knowledge root-package ownership\npackages:\n orgmemory:\n type: patch\n---\n\n# Knowledge root-package ownership\n\n## Improvements\n\nThe final source identity, group view, and failure-message types now live with\ntheir owning Knowledge modules, leaving the parent package free of domain\ntypes and ready for enforced boundary closing.\n" - filename: knowledge-root-ownership.md - v: 0.0.0 - - content: "---\nsubject: Record the completed production proof for reliable MCP search\npackages:\n orgmemory:\n type: patch\n---\n\n## Documentation\n\nThe engineering roadmap now records MCP search reliability as shipped after\nthe timeout and result-schema repairs were deployed and verified through a\nreal Claude `search_knowledge` call.\n" - filename: mcp-search-production-proof.md - v: 0.0.0 - - content: "---\nsubject: Restore production AI gateway configuration binding\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nProduction API and worker processes now retain the complete configured AI\ngateway when profile-specific credentials are applied, preventing startup\nfailure after adding gateway capability flags.\n" - filename: prod-ai-gateway-binding.md - v: 0.0.0 - - content: "---\nsubject: Publish the product changelog\npackages:\n orgmemory:\n type: patch\n---\n\n## Documentation\n\nPublish a localized product changelog in the documentation, generated from the\nsame reviewed Tegami release history used for GitHub Releases.\n\n## Security\n\nHarden documentation responses with a content security policy, HSTS, explicit\nHTML revalidation, and removal of framework disclosure headers.\n" - filename: public-product-changelog.md - v: 0.0.0 - - content: "---\nsubject: Route RAG workloads by model role\npackages:\n orgmemory:\n type: minor\n---\n\n# Route RAG workloads by model role\n\n## Improvements\n\nAdministrators can now configure independent Answer and Keyword Planning model\nroutes, including an explicitly supported OpenAI reasoning effort. Graph\nExtraction remains visible as a read-only pinned processing route so changing\ninteractive model settings never rewrites existing document graph history.\n" - filename: rag-workload-routing.md - v: 0.0.0 - - content: "---\nsubject: Hand governed Skill work to local coding agents\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nCopy bounded instructions into a local coding agent to validate and upload a\nprivate Skill Draft, or install one exact released Skill into Claude Code or\nCodex. Every handoff shows its confirmation boundary, uses the existing\nOrgMemory CLI and current access, and keeps publication and sharing as separate\ngoverned actions.\n" - filename: skill-agent-handoff.md - v: 0.0.0 - - content: "---\nsubject: Remove empty Skill authoring side cards\npackages:\n orgmemory:\n type: patch\n---\n\n## Improvements\n\nSkill creation, upload, replacement, and GitHub import no longer reserve a\nlarge side card for explanatory text. Package details appear only after a real\ninspection, while the one relevant private-repository note stays beside its\ninput.\n" - filename: skill-authoring-density.md - v: 0.0.0 - - content: "---\nsubject: Deliver the pinned public Skill CLI handoff\npackages:\n orgmemory:\n type: minor\n---\n\n## Features\n\nPin Skill authoring and installation handoffs to `@orgmemory/cli@0.1.1`, keep\nthe CLI's package, OAuth, and MCP identity versions aligned, and document the\nsame exact `npx` lifecycle in English and Vietnamese.\n" - filename: skill-cli-011-handoff.md - v: 0.0.0 - - content: "---\nsubject: Harden the first Skill CLI publication\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nVerify the packed OrgMemory CLI executable before publication and bind npm\nprovenance to the exact repository, so the first public package cannot succeed\nwith a missing `orgmemory` command or an unrelated source identity.\n" - filename: skill-cli-first-publish-hardening.md - v: 0.0.0 - - content: "---\nsubject: Complete the governed Skill CLI lifecycle\npackages:\n orgmemory:\n type: minor\n---\n\n## Improvements\n\nPrepare the OrgMemory CLI for provenance-backed npm distribution and complete\nthe local Skill lifecycle with offline full-tree verification, exact-version\nupdates, verified-only removal, collision-safe target ownership, serialized\nreceipt writes, and crash recovery.\n" - filename: skill-cli-lifecycle.md - v: 0.0.0 - - content: "---\nsubject: Add target-specific Skill installers\npackages:\n orgmemory:\n type: patch\n---\n\n# Add target-specific Skill installers\n\n## Improvements\n\nReleased Skills now offer compact, exact-version installers for Claude Code\nand Codex. The interface distinguishes verified package integrity and supported\ninstallation from runtime behavior that OrgMemory has not certified.\n" - filename: skill-consumer-installers.md - v: 0.0.0 - - content: "---\nsubject: Consistent Skill package metadata validation across surfaces\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nSkill package metadata keys are now validated identically by the CLI and the\nserver, closing a drift where whitespace-only keys could pass one surface and\nfail another. MCP gateway error handling and CLI package safety helpers were\nconsolidated so the same rules live in one place per app.\n" - filename: skill-package-metadata-consistency.md - v: 0.0.0 - - content: "---\nsubject: Route source ingestion through the ACL facade\npackages:\n orgmemory:\n type: patch\n---\n\n# Route source ingestion through the ACL facade\n\n## Improvements\n\nSource ingestion now uses an ACL-owned transactional facade instead of\ncoordinating ACL repositories and persistence entities directly.\n" - filename: source-ledger-acl-facade.md - v: 0.0.0 - - content: "---\nsubject: Remove the Source Ledger-to-Asset dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Source Ledger-to-Asset dependency\n\n## Improvements\n\nSource Ledger now validates source provenance before calling its own asset\npromotion port, while Asset owns promotion persistence and retirement. This\nremoves the reverse module edge without changing ingestion idempotency,\nsecurity lineage, or publication behavior.\n" - filename: source-ledger-asset-seam.md - v: 0.0.0 - - content: "---\nsubject: Remove the Source Ledger-to-Connector dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Source Ledger-to-Connector dependency\n\n## Improvements\n\nThe current source head projection now belongs to Source Ledger, allowing\nConnector reconciliation to consume it without creating a reverse module\ndependency.\n" - filename: source-ledger-connector-seam.md - v: 0.0.0 - - content: "---\nsubject: Remove the Source Ledger-to-Graph dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Source Ledger-to-Graph dependency\n\n## Improvements\n\nSource publication now schedules graph indexing through a Source-Ledger-owned\nport, while Graph keeps target validation, profile selection, idempotency, and\ndurable queue persistence behind its adapter.\n" - filename: source-ledger-graph-seam.md - v: 0.0.0 - - content: "---\nsubject: Remove the Source Ledger-to-Retrieval dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Source Ledger-to-Retrieval dependency\n\n## Improvements\n\nSource Ledger now depends on its own visibility and embedding-profile\ncontracts while Retrieval implements the governed adapters, removing the\nreverse module edge without weakening authorization or ingestion behavior.\n" - filename: source-ledger-retrieval-seam.md - v: 0.0.0 - - content: "---\nsubject: Remove the Source Ledger-to-Space dependency\npackages:\n orgmemory:\n type: patch\n---\n\n# Remove the Source Ledger-to-Space dependency\n\n## Improvements\n\nSource Ledger now uses its own compact Space target port for upload and\npromotion validation, while Space retains authorization and active-directory\npolicy behind the adapter.\n" - filename: source-ledger-space-seam.md - v: 0.0.0 - - content: "---\nsubject: Route Space reads through an owned query boundary\npackages:\n orgmemory:\n type: patch\n---\n\n# Route Space reads through an owned query boundary\n\n## Improvements\n\nGraph and Retrieval now resolve Knowledge Space existence and active status\nthrough the Space-owned `KnowledgeSpaceQuery` API instead of consuming the\nSpace repository directly. This follows the independently reviewed architecture\ndirection to remove implementation edges before closing a nested module.\n" - filename: space-query-boundary.md - v: 0.0.0 - - content: "---\nsubject: Enforce typed Knowledge Space audiences\npackages:\n orgmemory:\n type: patch\n---\n\n## Features\n\nLet administrators choose organization, department, or restricted custom\naudiences for each Knowledge Space. Managed audiences cannot be silently\nwidened, custom viewers fail closed across PostgreSQL and OpenFGA, and the\nadministration UI explains policy drift without exposing internal identifiers.\n" - filename: typed-knowledge-space-audiences.md - v: 0.0.0 - - content: "---\nsubject: Clearer errors, consistent sizes, and a lighter web app\npackages:\n orgmemory:\n type: patch\n---\n\n# Clearer errors, consistent sizes, and a lighter web app\n\n## Improvements\n\nAdmin AI model screens now surface the real error details returned by the\nserver instead of a generic message. File sizes display with one consistent\nunit convention across the app, and Skill upload limits read the same on\nevery surface. Source upload no longer applies the confidential-classification\ndepartment rule to unrelated classifications. The Sources screen loads the\nknowledge-graph viewer only when its tab is opened, the assistant re-renders\nfar less while streaming, and several unused component kits and dependencies\nwere removed for a smaller bundle.\n" - filename: web-consistency-and-performance.md + - content: "---\nsubject: Enforce the supported Assistant question length\npackages:\n orgmemory:\n type: patch\n---\n\n## Fixes\n\nThe Assistant composer now displays and enforces the 1,000-character question\nlimit before a turn starts. Questions at the boundary remain accepted, while\nlonger input is blocked instead of opening a stream that later fails.\n" + filename: 2026-08-07-assistant-message-length.md v: 0.0.0 core:packages: - changelogIds: - - acl-query-boundary.md - - acl-source-ledger-seam.md - - admin-permission-and-api-cleanup.md - - apache-age-published-batch-backfill.md - - apache-age-runtime-probe.md - - asset-catalog-layout-balance.md - - asset-owned-catalog-chunk-values.md - - asset-ownership-navigation.md - - asset-retrieval-boundary.md - - asset-source-publication-boundary.md - - authorized-graph-traversal.md - - automated-release-note-navigation.md - - browser-skill-draft-authoring.md - - browser-skill-upload.md - - changelog-global-surface.md - - cli-publish-existing-version-shell.md - - cli-publish-missing-version.md - - cli-publish-verification-recovery.md - - close-acl-module.md - - close-connector-module.md - - close-graph-module.md - - close-source-ledger-module.md - - close-space-module.md - - connector-ledger-read-boundary.md - - connector-polling-driver.md - - connector-source-lifecycle-boundary.md - - connector-source-revision-boundary.md - - copyforward-coordination.md - - docs-hydration-stability.md - - document-view-delete.md - - durable-graph-publication-recovery.md - - effective-access-inspector.md - - evaluated-rag-production-routes.md - - explicit-apache-age-backend.md - - github-skill-import.md - - governance-affordances.md - - graph-asset-query-boundary.md - - graph-extraction-model-default.md - - graph-indexing-recovery.md - - graph-retrieval-profile-boundary.md - - graph-source-query-boundary.md - - ingestion-throughput.md - - integration-adapter-hardening.md - - keyword-luna-route-binding.md - - knowledge-acl-connector-seam.md - - knowledge-graph-module.md - - knowledge-retrieval-contracts.md - - knowledge-retrieval-runtime.md - - knowledge-root-ownership.md - - mcp-search-production-proof.md - - prod-ai-gateway-binding.md - - public-product-changelog.md - - rag-workload-routing.md - - skill-agent-handoff.md - - skill-authoring-density.md - - skill-cli-011-handoff.md - - skill-cli-first-publish-hardening.md - - skill-cli-lifecycle.md - - skill-consumer-installers.md - - skill-package-metadata-consistency.md - - source-ledger-acl-facade.md - - source-ledger-asset-seam.md - - source-ledger-connector-seam.md - - source-ledger-graph-seam.md - - source-ledger-retrieval-seam.md - - source-ledger-space-seam.md - - space-query-boundary.md - - typed-knowledge-space-audiences.md - - web-consistency-and-performance.md + - 2026-08-04-assistant-evidence-continuity.md + - 2026-08-04-assistant-interaction-foundation.md + - 2026-08-04-assistant-model-picker.md + - 2026-08-05-agentic-skill-beta.md + - 2026-08-05-all-employees-space-placement.md + - 2026-08-05-assistant-answer-behavior.md + - 2026-08-05-knowledge-graph-parallel-relations.md + - 2026-08-05-knowledge-graph-responsive-layout.md + - 2026-08-05-knowledge-operations-graph-inspector.md + - 2026-08-05-knowledge-workspace-document-reader.md + - 2026-08-05-retrieval-admission-control.md + - 2026-08-05-retrieval-recall-observations.md + - 2026-08-05-unified-governed-document-viewer.md + - 2026-08-06-ai-gateway-image-dependencies.md + - 2026-08-06-assistant-chat-reasoning-effort.md + - 2026-08-06-assistant-failure-sentences.md + - 2026-08-06-assistant-one-conversation-store.md + - 2026-08-06-assistant-prompt-input-alignment.md + - 2026-08-06-assistant-skill-activity-receipt.md + - 2026-08-06-assistant-skill-catalog-discovery.md + - 2026-08-06-assistant-turn-activity-continuity.md + - 2026-08-06-assistant-turn-completion-race.md + - 2026-08-06-clearance-separation.md + - 2026-08-06-exact-query-embedding-cache.md + - 2026-08-06-gitleaks-synthetic-redaction-fixture.md + - 2026-08-06-graphrag-degree-query-timeout.md + - 2026-08-06-graphrag-load-relations-timeout.md + - 2026-08-06-graphrag-relation-hotpaths.md + - 2026-08-06-knowledge-filters.md + - 2026-08-06-knowledge-graph-container-sizing.md + - 2026-08-06-shared-service-dns.md + - 2026-08-06-source-provenance-null-department.md + - 2026-08-06-source-provenance-ux.md + - 2026-08-07-assistant-message-length.md id: product:orgmemory updated: true diff --git a/apps/docs/content/docs/changelog/meta.json b/apps/docs/content/docs/changelog/meta.json index ca8286e0..1942e88f 100644 --- a/apps/docs/content/docs/changelog/meta.json +++ b/apps/docs/content/docs/changelog/meta.json @@ -6,6 +6,7 @@ "pagesIndex": "index", "pages": [ "[Latest](/docs/changelog)", + "[v0.3.0](/docs/changelog#organizational-ai-memory-v030)", "[v0.2.0](/docs/changelog#organizational-ai-memory-v020)", "[v0.1.1](/docs/changelog#organizational-ai-memory-v011)", "[v0.1.0](/docs/changelog#organizational-ai-memory-v010)", diff --git a/apps/docs/content/docs/changelog/meta.vi.json b/apps/docs/content/docs/changelog/meta.vi.json index 3f187a70..07e26a06 100644 --- a/apps/docs/content/docs/changelog/meta.vi.json +++ b/apps/docs/content/docs/changelog/meta.vi.json @@ -6,6 +6,7 @@ "pagesIndex": "index", "pages": [ "[Mới nhất](/vi/docs/changelog)", + "[v0.3.0](/vi/docs/changelog#organizational-ai-memory-v030)", "[v0.2.0](/vi/docs/changelog#organizational-ai-memory-v020)", "[v0.1.1](/vi/docs/changelog#organizational-ai-memory-v011)", "[v0.1.0](/vi/docs/changelog#organizational-ai-memory-v010)", diff --git a/apps/docs/content/includes/product-changelog.md b/apps/docs/content/includes/product-changelog.md index e64cb22f..a9d52729 100644 --- a/apps/docs/content/includes/product-changelog.md +++ b/apps/docs/content/includes/product-changelog.md @@ -1,5 +1,351 @@ [//]: # (Generated from release/CHANGELOG.md by Tegami. Do not edit manually.) +## Organizational AI Memory v0.3.0 + +### Keep Assistant evidence useful after reload + +#### Features + +Assistant citations now survive transcript reload while still rechecking each +user's current access. Source opening starts with the exact governed evidence +excerpt, supports safe Markdown, PDF, image, text, and download-only files, and +shows truthful retrieval and answer-preparation activity before the first token. + +### Improve the Assistant conversation experience + +#### Features + +The Assistant now restores in-session conversation drafts, offers +server-curated starting prompts, retries completed answers with fresh governed +retrieval, and lets users save helpful or not-helpful feedback on an answer. + +### Choose a governed model in Assistant conversations + +#### Features + +Choose an administrator-approved model directly from the Assistant composer. +The selected model stays with the conversation, remains bound to the exact +approved gateway route, and safely falls back to the deployment default when +no explicit choice is made. + +### Use governed Skills in Assistant answers + +#### Features + +The Assistant can now discover an authorized Skill, load its exact released +instructions, and read bounded supporting text while preparing a grounded +answer. Skill content never grants tools or permissions, and OrgMemory does not +execute package scripts, binaries, or shell commands. + +### Restore organization-wide document visibility + +#### Fixes + +All-employees demo documents now target the organization-wide Company +Knowledge space instead of inheriting a department-only audience. Department +and executive documents retain their existing restricted placement. + +### Make Assistant no-answer guidance permission-safe + +#### Improvements + +The Assistant now responds in the user's language when accessible documents do +not answer a question, offers one concise next step, labels nearby information +instead of presenting it as the requested answer, and cites every source it +uses without citing unrelated documents. Assistant answers also show a short +reminder that they rely only on documents the user can access. + +### Keep parallel knowledge graph relations visible + +#### Fixes + +The Knowledge graph no longer fails to load when two distinct semantic +relations connect the same directed pair of entities. Parallel relations remain +separate and visible in the graph and entity inspector. + +### Keep Knowledge Graph controls from crushing the page title + +#### Improvements + +The Knowledge Graph workspace now keeps its page title readable while the +explorer controls wrap into the remaining desktop width. The same shared header +behavior prevents dense action groups from collapsing page identity elsewhere +in the product. + +### Refine Knowledge document operations and graph inspection + +#### Improvements + +Documents now use a persistent desktop reader while keeping the list +interactive, show ingestion failures without relying on hover, and guide +quarantined evidence into a corrected upload. The graph inspector now presents +readable entity context, directional connections, and permission-verified +document evidence instead of generic numbered sources. + +### Complete the governed document reader + +#### Improvements + +The employee workspace is now named Knowledge, with Documents and Knowledge +graph as its two clear surfaces. Documents open in a responsive right-side +reader with safe rendered or raw Markdown, inline PDF and image previews, +plain-text reading, explicit download-only fallbacks, and retry when governed +content cannot be loaded. + +### Faster, fairer assistant retrieval under load + +#### Improvements + +Assistant knowledge retrieval now admits snapshot queries through one fair +process-wide limit instead of per-request batches, so concurrent +conversations can no longer exhaust the database connection pool and stall at +the turn timeout. The API connection pool is right-sized for the production +host, retrieval breadth returns to the upstream LightRAG default, and new +payload-free timing stages make the previously unattributed portion of +time-to-first-token observable. + +### Verify retrieval recall before query cutover + +#### Improvements + +Operators can now capture and score authorization-preserving retrieval recall +against an explicitly restored projection copy without generating answers or +touching the live database. The recorded 43-case comparison confirms that the +raw-query bypass stays level with the current keyword-seeded path and preserves +the evidence needed to diagnose shared misses before any query-plane cutover. + +### Unify governed document previews + +#### Improvements + +Knowledge documents and Assistant citations now open in one centered, +responsive viewer. Long PDF, image, Markdown, and text evidence gets the full +reading surface, inline citations open it directly, and the source sidebar +remains available for comparing cited and discovered evidence. + +### Rebuild AI gateway consumers for production + +#### Fixes + +Production releases now rebuild the API and worker whenever their shared AI +gateway integration changes, so approved Assistant and model-routing fixes are +included in the immutable image set instead of being treated as deployment +no-ops. + +### Keep Assistant tool calls compatible with OpenAI + +#### Fixes + +Fresh production deployments now set Answer reasoning to `none` so the +Assistant's governed Skill tools work with `gpt-5.6-sol` on OpenAI Chat +Completions without requiring an organization route workaround. + +### Tell people what to do when an Assistant turn fails + +#### Fixes + +A failed Assistant turn now ends on a sentence naming what the person who hit it +can do next, instead of one generic message for every cause. An expired gateway +key, a rate limit, a model that is no longer offered, a gateway that did not +answer in time, and a busy assistant are now distinguishable and separately +actionable. + +Every message remains a fixed sentence chosen from the failure's category, so a +misconfigured or unusually talkative AI gateway cannot surface its own text, +credentials, or prompt content in the browser. A failure that matches no known +category still ends on the previous generic message. + +### Keep an Assistant conversation in one place + +#### Improvements + +An Assistant conversation is now stored once. The transcript that already served +history, replay, rename, and delete is also what the model reads back as prior +context, replacing a second copy that was kept in a table with no organization, +no owner, and no link to the conversation it belonged to. + +Prior context is now read in whole question-and-answer turns rather than by +counting messages. The question of the turn currently being answered can no +longer be sent to the model twice, a turn that failed before answering no longer +occupies the window, and the window can no longer begin partway through an +exchange. Deleting a conversation removes its context in the same operation +instead of relying on a separate call. + +### Make Assistant prompt controls consistent and accessible + +#### Improvements + +The Assistant composer now uses a consistent Prompt Input control set for its +model picker, status-aware submit behavior, keyboard composition, tooltips, and +future action menus. Text submission, stop controls, and input-method editing +remain predictable without enabling file, screenshot, voice, or source +attachment capabilities. + +### Show Assistant Skill activity without a blank wait + +#### Improvements + +The Assistant now keeps its progress state visible until answer text appears +and shows a compact, current-turn receipt when it successfully activates a +governed Skill. Skill titles are bounded plain text, denied or failed Skills +remain unnamed, and the receipt clears safely when a turn ends without an +answer. + +### Match Assistant requests against authorized Skills + +#### Fixes + +The Assistant now sees the current user's authorized Skill names and +descriptions before choosing a workflow, so natural-language requests can +activate the matching exact release without inventing catalog search terms. +Unavailable Skills remain hidden, and activation still rechecks access. + +### Keep Assistant activity visible until the answer appears + +#### Fixes + +Assistant thinking and Skill activity now stay in one stable transcript +position until meaningful answer text appears. Skill receipts no longer expose +an empty disclosure when there is no resource detail to show. + +### Stop losing an Assistant answer that was already on screen + +#### Fixes + +An Assistant answer could disappear from a conversation after being delivered. +When two turns of the same conversation finished at the same moment, only one of +them was saved; the other was rolled back and was gone on the next reload, even +though the person asking had watched it arrive. Both are now kept. + +Long answers with many sources also render far more cheaply. Each arriving +source used to discard and rebuild the entire answer shown so far, which made a +long, heavily cited reply progressively slower to display and could leave the +page unresponsive while it finished. The answer is now updated in place as its +sources arrive. + +### Separate data clearance from user roles + +#### Improvements + +The user "role" field is now a data clearance with two values, Standard and +Executive, matching what the system actually enforces: Executive widens +confidential and restricted document access, while action permissions stay +governed by organization roles. Administrators can now assign a user's +department (required for confidential document access), raising someone to +Executive asks for confirmation and states its reach, and every user can see +their own department and clearance in the account menu. Legacy titles such as +Team lead, Manager, Director, and the misleading Admin label are removed; +existing Executive users keep Executive and everyone else becomes Standard. + +### Reuse exact query embeddings across retrieval requests + +#### Improvements + +GraphRAG and hybrid knowledge retrieval now reuse exact query embeddings within +an explicit projection namespace. Repeated requests avoid duplicate embedding +provider work while authorization, evidence selection, and citation verification +continue to run normally. Cached vectors remain isolated by embedding profile, +provider version, and dimensions, with bounded PostgreSQL retention and expiry. + +### Keep synthetic redaction fixtures in secret scanning + +#### Fixes + +Secret scanning now narrowly recognizes the API-key-shaped value in the +assistant redaction regression as synthetic test data while continuing to scan +all other files and generic API-key findings. + +### Keep GraphRAG degree ranking within its retrieval budget + +#### Fixes + +GraphRAG degree ranking now resolves authorized relation visibility once and +uses indexed source and target endpoint lookups. PostgreSQL also cancels an +abnormally slow degree query before the assistant retrieval deadline, avoiding +orphaned database work that could degrade later chat turns. + +### Bound authorized GraphRAG relation loading + +#### Fixes + +GraphRAG now resolves authorized relation candidates with set-based entity and +relation visibility checks instead of repeating correlated ACL work for each +candidate. Relation reads also use the transaction-scoped PostgreSQL timeout so +a retrieval cancellation cannot leave database work running in the background. + +### Restore fast authorized GraphRAG relation scoring + +#### Fixes + +GraphRAG now limits relation contribution and relation-weight authorization work +to the requested candidate relations before checking independently visible source +and target entities. These reads also use the transaction-scoped PostgreSQL +budget, preventing an expensive plan from continuing after retrieval is +cancelled. + +#### Improvements + +Snapshot retrieval now reports bounded, payload-free timings for each graph +storage operation under the existing retrieval operation identifier, making +future latency regressions attributable without recording prompts, answers, or +evidence identifiers. + +### Filter and page the Documents list + +#### Improvements + +Documents can now be narrowed by Knowledge Space and classification alongside +the existing status tabs, so the Space shown on every row is finally something +you can filter by. Filtering and search run on the server and the list is paged, +so a large library no longer arrives in one response. Status tab counts describe +the whole filtered library rather than the page you happen to be on, and a +document still processing keeps its real status instead of disappearing while it +publishes. The knowledge graph search now runs as you type, matching the +Documents tab instead of waiting for a separate button. + +### Keep the knowledge graph stable while its panel is sizing + +#### Fixes + +The knowledge graph now waits for a visible, positively sized canvas before +starting Sigma, and releases the renderer if the panel becomes size-less during +a layout transition. Opening the graph while its tab or flex layout is still +settling no longer crashes the page with a zero-height container error. + +### Put production services on one shared Docker DNS fabric + +#### Fixes + +OrgMemory, documentation, and observability services now join the same external +Docker DNS network while retaining their existing private and proxy networks. +Cross-stack diagnostics and integrations can use stable service names instead of +container IP addresses without publishing additional host ports. + +### Keep the document list working for organization-wide sources + +#### Fixes + +The Documents list no longer fails when a source belongs to an +organization-wide Knowledge Space. Those sources carry no owning department, +and the provenance lookup rejected the missing identifier. + +### Clarify document provenance and content availability + +#### Fixes + +The Documents ledger now identifies each document's Knowledge Space, owning +department, and uploader. Published documents outside the current user's +content scope now show honest access guidance instead of being described as +still waiting for publication. + +### Enforce the supported Assistant question length + +#### Fixes + +The Assistant composer now displays and enforces the 1,000-character question +limit before a turn starts. Questions at the boundary remain accepted, while +longer input is blocked instead of opening a stream that later fails. + ## Organizational AI Memory v0.2.0 ### Route ACL reads through an owned query boundary diff --git a/release/CHANGELOG.md b/release/CHANGELOG.md index b1d8b753..a61c74ff 100644 --- a/release/CHANGELOG.md +++ b/release/CHANGELOG.md @@ -2,6 +2,354 @@ Product releases are assembled from reviewed entries under `.tegami/`. +## orgmemory@0.3.0 + +### Keep Assistant evidence useful after reload + +#### Features + +Assistant citations now survive transcript reload while still rechecking each +user's current access. Source opening starts with the exact governed evidence +excerpt, supports safe Markdown, PDF, image, text, and download-only files, and +shows truthful retrieval and answer-preparation activity before the first token. + +### Improve the Assistant conversation experience + +#### Features + +The Assistant now restores in-session conversation drafts, offers +server-curated starting prompts, retries completed answers with fresh governed +retrieval, and lets users save helpful or not-helpful feedback on an answer. + +### Choose a governed model in Assistant conversations + +#### Features + +Choose an administrator-approved model directly from the Assistant composer. +The selected model stays with the conversation, remains bound to the exact +approved gateway route, and safely falls back to the deployment default when +no explicit choice is made. + +### Use governed Skills in Assistant answers + +#### Features + +The Assistant can now discover an authorized Skill, load its exact released +instructions, and read bounded supporting text while preparing a grounded +answer. Skill content never grants tools or permissions, and OrgMemory does not +execute package scripts, binaries, or shell commands. + +### Restore organization-wide document visibility + +#### Fixes + +All-employees demo documents now target the organization-wide Company +Knowledge space instead of inheriting a department-only audience. Department +and executive documents retain their existing restricted placement. + +### Make Assistant no-answer guidance permission-safe + +#### Improvements + +The Assistant now responds in the user's language when accessible documents do +not answer a question, offers one concise next step, labels nearby information +instead of presenting it as the requested answer, and cites every source it +uses without citing unrelated documents. Assistant answers also show a short +reminder that they rely only on documents the user can access. + +### Keep parallel knowledge graph relations visible + +#### Fixes + +The Knowledge graph no longer fails to load when two distinct semantic +relations connect the same directed pair of entities. Parallel relations remain +separate and visible in the graph and entity inspector. + +### Keep Knowledge Graph controls from crushing the page title + +#### Improvements + +The Knowledge Graph workspace now keeps its page title readable while the +explorer controls wrap into the remaining desktop width. The same shared header +behavior prevents dense action groups from collapsing page identity elsewhere +in the product. + +### Refine Knowledge document operations and graph inspection + +#### Improvements + +Documents now use a persistent desktop reader while keeping the list +interactive, show ingestion failures without relying on hover, and guide +quarantined evidence into a corrected upload. The graph inspector now presents +readable entity context, directional connections, and permission-verified +document evidence instead of generic numbered sources. + +### Complete the governed document reader + +#### Improvements + +The employee workspace is now named Knowledge, with Documents and Knowledge +graph as its two clear surfaces. Documents open in a responsive right-side +reader with safe rendered or raw Markdown, inline PDF and image previews, +plain-text reading, explicit download-only fallbacks, and retry when governed +content cannot be loaded. + +### Faster, fairer assistant retrieval under load + +#### Improvements + +Assistant knowledge retrieval now admits snapshot queries through one fair +process-wide limit instead of per-request batches, so concurrent +conversations can no longer exhaust the database connection pool and stall at +the turn timeout. The API connection pool is right-sized for the production +host, retrieval breadth returns to the upstream LightRAG default, and new +payload-free timing stages make the previously unattributed portion of +time-to-first-token observable. + +### Verify retrieval recall before query cutover + +#### Improvements + +Operators can now capture and score authorization-preserving retrieval recall +against an explicitly restored projection copy without generating answers or +touching the live database. The recorded 43-case comparison confirms that the +raw-query bypass stays level with the current keyword-seeded path and preserves +the evidence needed to diagnose shared misses before any query-plane cutover. + +### Unify governed document previews + +#### Improvements + +Knowledge documents and Assistant citations now open in one centered, +responsive viewer. Long PDF, image, Markdown, and text evidence gets the full +reading surface, inline citations open it directly, and the source sidebar +remains available for comparing cited and discovered evidence. + +### Rebuild AI gateway consumers for production + +#### Fixes + +Production releases now rebuild the API and worker whenever their shared AI +gateway integration changes, so approved Assistant and model-routing fixes are +included in the immutable image set instead of being treated as deployment +no-ops. + +### Keep Assistant tool calls compatible with OpenAI + +#### Fixes + +Fresh production deployments now set Answer reasoning to `none` so the +Assistant's governed Skill tools work with `gpt-5.6-sol` on OpenAI Chat +Completions without requiring an organization route workaround. + +### Tell people what to do when an Assistant turn fails + +#### Fixes + +A failed Assistant turn now ends on a sentence naming what the person who hit it +can do next, instead of one generic message for every cause. An expired gateway +key, a rate limit, a model that is no longer offered, a gateway that did not +answer in time, and a busy assistant are now distinguishable and separately +actionable. + +Every message remains a fixed sentence chosen from the failure's category, so a +misconfigured or unusually talkative AI gateway cannot surface its own text, +credentials, or prompt content in the browser. A failure that matches no known +category still ends on the previous generic message. + +### Keep an Assistant conversation in one place + +#### Improvements + +An Assistant conversation is now stored once. The transcript that already served +history, replay, rename, and delete is also what the model reads back as prior +context, replacing a second copy that was kept in a table with no organization, +no owner, and no link to the conversation it belonged to. + +Prior context is now read in whole question-and-answer turns rather than by +counting messages. The question of the turn currently being answered can no +longer be sent to the model twice, a turn that failed before answering no longer +occupies the window, and the window can no longer begin partway through an +exchange. Deleting a conversation removes its context in the same operation +instead of relying on a separate call. + +### Make Assistant prompt controls consistent and accessible + +#### Improvements + +The Assistant composer now uses a consistent Prompt Input control set for its +model picker, status-aware submit behavior, keyboard composition, tooltips, and +future action menus. Text submission, stop controls, and input-method editing +remain predictable without enabling file, screenshot, voice, or source +attachment capabilities. + +### Show Assistant Skill activity without a blank wait + +#### Improvements + +The Assistant now keeps its progress state visible until answer text appears +and shows a compact, current-turn receipt when it successfully activates a +governed Skill. Skill titles are bounded plain text, denied or failed Skills +remain unnamed, and the receipt clears safely when a turn ends without an +answer. + +### Match Assistant requests against authorized Skills + +#### Fixes + +The Assistant now sees the current user's authorized Skill names and +descriptions before choosing a workflow, so natural-language requests can +activate the matching exact release without inventing catalog search terms. +Unavailable Skills remain hidden, and activation still rechecks access. + +### Keep Assistant activity visible until the answer appears + +#### Fixes + +Assistant thinking and Skill activity now stay in one stable transcript +position until meaningful answer text appears. Skill receipts no longer expose +an empty disclosure when there is no resource detail to show. + +### Stop losing an Assistant answer that was already on screen + +#### Fixes + +An Assistant answer could disappear from a conversation after being delivered. +When two turns of the same conversation finished at the same moment, only one of +them was saved; the other was rolled back and was gone on the next reload, even +though the person asking had watched it arrive. Both are now kept. + +Long answers with many sources also render far more cheaply. Each arriving +source used to discard and rebuild the entire answer shown so far, which made a +long, heavily cited reply progressively slower to display and could leave the +page unresponsive while it finished. The answer is now updated in place as its +sources arrive. + +### Separate data clearance from user roles + +#### Improvements + +The user "role" field is now a data clearance with two values, Standard and +Executive, matching what the system actually enforces: Executive widens +confidential and restricted document access, while action permissions stay +governed by organization roles. Administrators can now assign a user's +department (required for confidential document access), raising someone to +Executive asks for confirmation and states its reach, and every user can see +their own department and clearance in the account menu. Legacy titles such as +Team lead, Manager, Director, and the misleading Admin label are removed; +existing Executive users keep Executive and everyone else becomes Standard. + +### Reuse exact query embeddings across retrieval requests + +#### Improvements + +GraphRAG and hybrid knowledge retrieval now reuse exact query embeddings within +an explicit projection namespace. Repeated requests avoid duplicate embedding +provider work while authorization, evidence selection, and citation verification +continue to run normally. Cached vectors remain isolated by embedding profile, +provider version, and dimensions, with bounded PostgreSQL retention and expiry. + +### Keep synthetic redaction fixtures in secret scanning + +#### Fixes + +Secret scanning now narrowly recognizes the API-key-shaped value in the +assistant redaction regression as synthetic test data while continuing to scan +all other files and generic API-key findings. + +### Keep GraphRAG degree ranking within its retrieval budget + +#### Fixes + +GraphRAG degree ranking now resolves authorized relation visibility once and +uses indexed source and target endpoint lookups. PostgreSQL also cancels an +abnormally slow degree query before the assistant retrieval deadline, avoiding +orphaned database work that could degrade later chat turns. + +### Bound authorized GraphRAG relation loading + +#### Fixes + +GraphRAG now resolves authorized relation candidates with set-based entity and +relation visibility checks instead of repeating correlated ACL work for each +candidate. Relation reads also use the transaction-scoped PostgreSQL timeout so +a retrieval cancellation cannot leave database work running in the background. + +### Restore fast authorized GraphRAG relation scoring + +#### Fixes + +GraphRAG now limits relation contribution and relation-weight authorization work +to the requested candidate relations before checking independently visible source +and target entities. These reads also use the transaction-scoped PostgreSQL +budget, preventing an expensive plan from continuing after retrieval is +cancelled. + +#### Improvements + +Snapshot retrieval now reports bounded, payload-free timings for each graph +storage operation under the existing retrieval operation identifier, making +future latency regressions attributable without recording prompts, answers, or +evidence identifiers. + +### Filter and page the Documents list + +#### Improvements + +Documents can now be narrowed by Knowledge Space and classification alongside +the existing status tabs, so the Space shown on every row is finally something +you can filter by. Filtering and search run on the server and the list is paged, +so a large library no longer arrives in one response. Status tab counts describe +the whole filtered library rather than the page you happen to be on, and a +document still processing keeps its real status instead of disappearing while it +publishes. The knowledge graph search now runs as you type, matching the +Documents tab instead of waiting for a separate button. + +### Keep the knowledge graph stable while its panel is sizing + +#### Fixes + +The knowledge graph now waits for a visible, positively sized canvas before +starting Sigma, and releases the renderer if the panel becomes size-less during +a layout transition. Opening the graph while its tab or flex layout is still +settling no longer crashes the page with a zero-height container error. + +### Put production services on one shared Docker DNS fabric + +#### Fixes + +OrgMemory, documentation, and observability services now join the same external +Docker DNS network while retaining their existing private and proxy networks. +Cross-stack diagnostics and integrations can use stable service names instead of +container IP addresses without publishing additional host ports. + +### Keep the document list working for organization-wide sources + +#### Fixes + +The Documents list no longer fails when a source belongs to an +organization-wide Knowledge Space. Those sources carry no owning department, +and the provenance lookup rejected the missing identifier. + +### Clarify document provenance and content availability + +#### Fixes + +The Documents ledger now identifies each document's Knowledge Space, owning +department, and uploader. Published documents outside the current user's +content scope now show honest access guidance instead of being described as +still waiting for publication. + +### Enforce the supported Assistant question length + +#### Fixes + +The Assistant composer now displays and enforces the 1,000-character question +limit before a turn starts. Questions at the boundary remain accepted, while +longer input is blocked instead of opening a stream that later fails. + + + ## orgmemory@0.2.0 ### Route ACL reads through an owned query boundary diff --git a/release/artifacts.json b/release/artifacts.json index d0fa0f7a..e260cf60 100644 --- a/release/artifacts.json +++ b/release/artifacts.json @@ -1,57 +1,57 @@ { "schemaVersion": 1, - "releaseSourceSha": "ffd985d31a83d81d849fb3e7ae1c207b562d8e78", + "releaseSourceSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927", "product": { - "decisionRunId": 30884855805, - "manifestRunId": 30789073005, - "commitSha": "a767823d8306f954687b95b717125de4970c9b36", + "decisionRunId": 31165242294, + "manifestRunId": 31165242294, + "commitSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927", "images": [ { "component": "api", - "reference": "ghcr.io/kl3init/orgmemory-api:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:f1666d862107fead1091fda62a89a1d95411388a3930b606f7757ed6c5b7687e", - "sourceSha": "a767823d8306f954687b95b717125de4970c9b36" + "reference": "ghcr.io/kl3init/orgmemory-api:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:cc3f6d1ef3c2f42af530c6d681a7a28e6e1b8f3aa042485f441a55f1340fd597", + "sourceSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927" }, { "component": "worker", - "reference": "ghcr.io/kl3init/orgmemory-worker:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:529acb473fdeffe8bfe8f1f9b5281ba17cce589c3450ff534a403f7cf9b9dc2d", - "sourceSha": "a767823d8306f954687b95b717125de4970c9b36" + "reference": "ghcr.io/kl3init/orgmemory-worker:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:a9f67a78582c51d7c7129721246f4fcafddbd1dc4666ba1e06b423b9a9ce8feb", + "sourceSha": "5995a1a804faf11eae25e9b350f910ee039978f8" }, { "component": "mcp", - "reference": "ghcr.io/kl3init/orgmemory-mcp:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:b3bd299a46cbf8cba42c47a04e2bfc26a42f15dc7a0464cced6711f19b49b7ff", - "sourceSha": "4abcf19ea59fee7716495bd8d15965b463b94054" + "reference": "ghcr.io/kl3init/orgmemory-mcp:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:b1d19a71559cc1efc3cb29fe7eb352bce0a108a59674e3c5681dcaa387eef127", + "sourceSha": "5995a1a804faf11eae25e9b350f910ee039978f8" }, { "component": "web", - "reference": "ghcr.io/kl3init/orgmemory-web:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:a93bf8231d6fb70879db70c42aa3afc2185689dc0e493ae164b1082f71d06c0c", - "sourceSha": "4abcf19ea59fee7716495bd8d15965b463b94054" + "reference": "ghcr.io/kl3init/orgmemory-web:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:7d3035025906bd9cc20f51fbfb3d2d3660a889abbae8834c92b69b1cd2afbbe5", + "sourceSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927" }, { "component": "keycloak", - "reference": "ghcr.io/kl3init/orgmemory-keycloak:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:f797347d7a743e7ad99688b3014c3a55790c3637995d02a1532c3102691494aa", - "sourceSha": "4abcf19ea59fee7716495bd8d15965b463b94054" + "reference": "ghcr.io/kl3init/orgmemory-keycloak:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:4504331621500a0be3291d5a45b0fa15ecf816c22c78edc7a0fef3a819573c95", + "sourceSha": "5995a1a804faf11eae25e9b350f910ee039978f8" }, { "component": "postgres-rag", - "reference": "ghcr.io/kl3init/orgmemory-postgres-rag:sha-a767823d8306f954687b95b717125de4970c9b36", - "digest": "sha256:4ee6dfc0bc49a21a4f41e6e74931d6f34a4b1b901c3f6af1ad0c952e71883c03", - "sourceSha": "4abcf19ea59fee7716495bd8d15965b463b94054" + "reference": "ghcr.io/kl3init/orgmemory-postgres-rag:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:758c13bf728acda1e9bd16a17d029abc17acd545fee65498f429a4685cbba958", + "sourceSha": "5995a1a804faf11eae25e9b350f910ee039978f8" } ] }, "docs": { - "decisionRunId": 30884855745, - "manifestRunId": 30743000571, - "commitSha": "24c31aeaeee8c9a582fc619b49289dd4eb836b21", + "decisionRunId": 31165242257, + "manifestRunId": 31165242257, + "commitSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927", "image": { - "reference": "ghcr.io/kl3init/orgmemory-docs:sha-24c31aeaeee8c9a582fc619b49289dd4eb836b21", - "digest": "sha256:5adb99d074126242f7ad2b379e2f660a8ecaeb27ab9aea997b2baa1a12c94a2d", - "sourceSha": "24c31aeaeee8c9a582fc619b49289dd4eb836b21" + "reference": "ghcr.io/kl3init/orgmemory-docs:sha-e71975a228f53633dd8d5d7a42ee0a055ee1c927", + "digest": "sha256:9e5e5829edc26af483dc5a85605349635e6c6ca275d1aae34c020288564b2e12", + "sourceSha": "e71975a228f53633dd8d5d7a42ee0a055ee1c927" } } } diff --git a/release/product.json b/release/product.json index bd51258e..fcfbaca0 100644 --- a/release/product.json +++ b/release/product.json @@ -1,4 +1,4 @@ { "name": "orgmemory", - "version": "0.2.0" + "version": "0.3.0" }