Add self-hosted team memory while preserving local SQLite and Wiki workflows.
This release includes the full team edition and website redesign. Earlier candidate tags v0.19.0 through v0.19.2 remain unchanged and were not published. Clean-package validation now excludes generated distribution files. Windows uses native user-only directory permissions, writable handles for durable snapshot flushes, extended-length replica paths and detached standard handles for automatic workers. No permission or durability checks were removed.
Before this candidate, Pro built and ran the Windows executable under Wine: six team identity/policy/HTTP tests passed, followed by the complete team CLI sync, conflict, authorization and recovery journey. Native x64/ARM64 Windows ACL checks separately verified ownership, inheritance, replacement of broad grants and latency. The release workflow verifies the final native artifacts.
- Synchronize all bound core memory, including temporal events, sources and history, discussions, plans and to-dos. Personal unbound stores and plugin runtime state remain private.
- Run configurable automatic sync with durable outboxes, verified snapshots, resumable receipts, native user-service supervision and conflict signals through Hooks, CLI and MCP.
- Let external Agents claim and merge complete conflict evidence. LWC does not embed a model, call an LLM API or launch an Agent.
- Add instance admission tokens, email-code/Feishu/GitHub sign-in, explicit space grants, device registration and bounded Agent delegation. Signed local policies and server-side content checks enforce capabilities independently.
- Add generated personal-key sign-in, administrator member provisioning, authorized space selection and revocation of derived sessions/devices/Agent credentials.
- Support cloud-only reads without creating a local memory database or replica.
- Add compensating memory recovery and stopped-server backups. Disaster restoration writes a new directory, retains current authorization state and reconciles signed new epochs without discarding local offline work.
- Provide a bilingual React + shadcn/ui console, searchable member selection, constrained inputs, aligned selection menus, memory browsing, access management and recovery actions.
- Add permission-checked knowledge sharing and body-link navigation; provision members and initial space roles atomically.
- Include self-host deployment files, interface assets and a multi-architecture server image in the release workflow.
Core stores migrate to schema 20 and server control stores to schema 6. Back up before upgrading; do not open migrated stores with older binaries. Existing personal workflows do not require a server or account. Team replicas accept only a compatible protocol and their pinned signing identity.
OAuth applications and mail delivery are configured by each deployer. Real external-provider acceptance requires those deployment credentials; local fixture sessions do not establish it. Previously downloaded data cannot be recalled from a revoked device.
Follow deploy/team/README.md. Configure HTTPS, initialize the owner, use the generated private administrator key or distribute the instance token for configured account sign-in, and grant spaces explicitly. Restore uses --authority-data to preserve current permissions; a missing or damaged current authority fails closed instead of reviving historical grants.