team 0.1.2
A safety release: 0.1.1 could type a nudge or an exit into the shell left after Claude Code exited,
and a seat could silence the watch's reports about itself. Upgrade.
Security
- In 0.1.1, a shell prompt left after Claude Code exited read as an idle composer, so a nudge, a
first message or an exit could be typed into a shell. A composer now reads idle only inside its
own frame — the rule above the box or the status footer under it — and every typing path (the
nudge, rules delivery,down's andremove's exit) also needs herdr to report the agent's
process in the pane, read again immediately before the Enter. - In 0.1.1, parking or stopping a seat was not drift, so a seat could silence its own idle
reports by editing its entry in the file. Parking and stopping are now part of what the owner
approves;remove --keepandaddrecord the new digest whenstoppedis the only change, so
those commands still leave that file approved, and an approval recorded before this stays valid
while the file is unchanged since the approval. - In 0.1.1,
--no-notifyon the watch silenced a report addressed to the owner, and any caller
could run the session's only watch with it. Each report is now routed to the owner or the
operator, and--no-notifydrops only the operator's notice — the log line stays, and
team statusdoes not read the flag. The watch's own notices — the operator could not be
nudged, herdr does not answer, the file cannot be read, a typed nudge was not sent, the watch
stopped — are the owner's and survive the flag too.--no-nudgeand--no-notifyare the owner's. - In 0.1.1, a watch on a session other than the file's own saved its readings into the state a
launch gate counts. Such a watch now reads and reports as before, says so once, and saves no
reading — budget or spend — so a session the file doesn't name can never decide a launch.
Added
- A seat may name the budget account it spends,
account:, when one vendor's two accounts are two
buckets; without it a seat spends itsvendor, and the choice is part of the seat's fingerprint,
so the owner approves it. It must be a key of the file'sbudgets.accounts— a name the budgets
don't hold is refused where it is — and an unapproved edit to it folds none of that seat's figures
until the owner approves. A figure measuring the seat's vendor lands on the seat's own account,
and a figure naming another account stays that account's, whichever seat's screen showed it.
Changed
- While a
watch.checksedit is unapproved, the approved list stays in force: nothing new is turned
off, and an approved-off check stays off. Before, every check ran until the owner approved. - A seat could take the rules message for a task. Every seat's rules text now ends with a line
saying the rules are not a task. A first message closes withThese are standing rules, not a task: reply ready and wait for your brief.; a launch option that stays in force on every later
turn (claude-code's--append-system-prompt) closes with onlyThese are standing rules, not a task.A team file whose ownrules:already end with that line doesn't get it twice. - A team whose seats were stopped by
remove --keep, or parked by hand, since its last approval
showsseat X changedfor each after upgrading, andupandaddrefuse until the owner
approves once.
Fixed
- A greyed suggestion in a Claude Code input box is no longer read as text that was never sent:
input text whose characters are all faint is the box's placeholder, and the seat reads idle. Text
with any other styling reads as unsent text, and a line with no styling keeps theTry "rule. - Cursor's running turn is the braille spinner, or the prompt line that ends in
ctrl+c to stop.
The same words quoted in the transcript are not a turn, and text typed on that prompt is unsent in
the composer. - A subscription check reading is kept in the state beside the screen readings, and
up,addand
statuscount it: a fresh check inside its reserve refuses a launch after the watch has exited, a
stale one outside its reserve reads unknown, and the account'ssourcesdecide which reading counts. - Budget readings are kept per project, not per herdr session:
up,add,statusand the watch
read the one cache, so a figure one session saw counts for every session, and state files written
before this change migrate as they are read — no reading is lost. - A stale check reading inside its reserve keeps refusing until its known reset, as a stale screen
reading does; an unconfirmed screen reading no longer hides a fresh check reading later in
sources. - A Claude question is the dialog's own last line. Prose that says "Esc to cancel", and a transcript
of "1. Yes" / "2. No" above an empty box, stay idle. - An Antigravity permission dialog whose rule line has scrolled out of the window (a long command)
is still read as the dialog, and a Claude Code question with a line below its footer and no rule
in the window is still read as a question. - The watch folds its readings inside the state's own lock, so two watches of one project fold onto
each other's figures instead of overwriting them.