Skip to content

Releases: validmind/atryum

v0.4.0

Choose a tag to compare

@nibalizer nibalizer released this 27 Jul 18:39
Immutable release. Only release title and notes can be modified.
18fb4cd

Added

  • Agents can now carry free-form tags: editable for every agent (including
    ValidMind-synced ones) from the Agents UI or the tags field on the
    agent create/update API, and preserved across re-syncs (tags are
    Atryum-native and are never reset by a sync). Tags are forwarded on every
    AI-judged evaluation as agent_tags, laying the groundwork for the
    commercial Global Charters feature; the FOSS charter-preview call
    intentionally continues to omit tags, since it hits a hierarchy-only
    backend endpoint with no concept of organization-wide charters.

Changed

  • Breaking: privileged HTTP API paths have been renamed and reorganized
    under a flatter, non-"admin" prefix. Existing integrations, scripts, or
    reverse-proxy rules that reference the old paths must be updated:
    • /api/v1/admin/invocations... → /api/v1/review/invocations...
      (also gains a /{id}/summarize action)
    • /api/v1/admin/servers... → /api/v1/servers... (also gains a
      /{name}/tools action)
    • /api/v1/admin/rules... → /api/v1/rules...
    • /api/v1/admin/agents... → /api/v1/agents... (also gains /sync and
      /{id}/charter-preview)
    • /api/v1/admin/settings, /api/v1/admin/policy → /api/v1/settings,
      /api/v1/policy
    • /api/v1/admin/managed-agents/... → /api/v1/managed-agents/...
      (session management also gains list/clear/delete, not just register)
    • /api/v1/admin-auth/config → /api/v1/auth/config
    • Plan approval now has its own top-level surface:
      /api/v1/plans, /{id}, /{id}/events, /{id}/approve, /{id}/deny,
      /{id}/revise, /{id}/expire, /stream
    • New /api/v1/model-configs, /api/v1/llm-configs,
      /api/v1/llm-configs/{id}, and /api/v1/vm/organizations,
      /api/v1/vm/record-types, /api/v1/vm/custom-fields surfaces
    • The "Admin authentication" docs section and terminology are now
      "UI and privileged API authentication"; behavior is unchanged.

Fixed

  • Generated integration docs (connect-agents.html) are back in sync with
    their markdown source, which had documented post-logout URL setup and the
    sign-out flow without the HTML being rebuilt.

What's Changed

Full Changelog: 0.3.0...v0.4.0

0.3.0

Choose a tag to compare

@nibalizer nibalizer released this 27 Jul 15:18
Immutable release. Only release title and notes can be modified.
4bd5043

Added

  • Atryum can now be embedded as a Go library by downstream programs: import
    github.com/validmind/atryum/pkg/atryum and call atryum.Main(...) from
    another binary's main package, with WithRoutes, WithMigrations, and
    WithDatabase extension points.
  • Agent plan preapproval: agents can submit an entire plan for approval
    before executing its individual tool calls. Each planned action is
    evaluated against the existing invocation rules, and a shared LLM judge
    reviews the whole plan for charter compliance once.
  • Server-side session get-or-create, keyed by agent binding and the
    caller's own client session ID. Harnesses (the shared Claude Code/Cursor/
    Codex hook, amp, pi) now just send their own session/thread ID on every
    tool call — Atryum resolves or creates the matching session itself, so
    no harness needs to mint, cache, or retry session creation anymore.
  • Harnesses can poll a rules endpoint every 5 minutes to fetch their
    current approval rules, so agents can read their own rules and reduce
    denied calls; the MCP rules tool is available again as well.
  • Charter preview for agents in the admin UI: synced agents show the
    charter hierarchy assembled from the ValidMind backend, local agents
    show their own stored charter.
  • Logout button in the UI.
  • Copy-to-clipboard button on the MCP Endpoint field.
  • CI workflow publishing the production Atryum image to Docker Hub.
  • Initial architecture documentation.

Fixed

  • ClearSessions now stops each session's background watcher immediately
    after that session's own delete succeeds, instead of deleting everything
    first and cancelling watchers in a second pass — a delete failing partway
    through could previously leave already-deleted sessions with a watcher
    still running (and still able to approve/deny tool calls) until the
    process restarted. The reported cleared-count is also now the honest
    partial count rather than always 0 on error.
  • A rule whose stored server/tool/agent scope had become corrupted (bad
    manual edit, partial write, disk corruption) could silently start
    matching everything it wasn't scoped to; corrupted rule data now blocks
    the rule load and falls back to human review instead.
  • A database error while loading rules during an external tool-call
    submission is now logged and recorded in the invocation's audit trail,
    instead of failing silently.
  • Invoke no longer falls through to the permissive global policy when
    approval-rule loading fails (e.g. a brief database hiccup) — a rule-load
    failure now safely requires human approval and is logged, matching how
    Submit already behaved.
  • AI-decided invocations (hard denials and auto-approvals) now persist
    their matched_rule_id, so the invocation audit view no longer mislabels
    a still-present rule as "Deleted Rule". The UI also distinguishes a rule
    that is simply not in the loaded list ("Unknown rule") from one that is
    genuinely unrecorded or deleted.
  • Doc generation (just docs) no longer chops off the first character of
    3-space-indented numbered-list continuation lines.

Security

  • Fixed an issue where an external executor could mark a tool invocation
    as completed, failed, or cancelled before it was approved — bypassing
    human approval and forging the audit record. Execution outcomes can now
    only be reported for approved invocations, executors may only report on
    their own invocations, and recorded outcomes can no longer be
    overwritten; retrying an already-recorded outcome is a safe no-op.

What's Changed

New Contributors

Full Changelog: v0.2.0...0.3.0

v0.2.0

Choose a tag to compare

@hunner hunner released this 14 Jul 21:14
Immutable release. Only release title and notes can be modified.
v0.2.0
435d6a8

Added

  • Invocation Audit section in the FOSS UI, with audit event instrumentation
    showing AI evaluation reasons, failed states, and clear handling of
    no-match and deleted-rule cases.
  • Grounding eval suite for the LLM-as-judge, runnable against any
    OpenAI-compatible endpoint.
  • Session context for the judge, reconstructed from Atryum-tracked tool
    calls, with trust fencing, a byte cap, and expiry.
  • Pagination for the Invocations list UI.
  • Auto-sync of agent charters from ValidMind, with stale-record
    reconciliation on every sync.
  • insert_before support: rules created from "Always approve/deny" insert
    at the top of the rule list and immediately apply their disposition to the
    triggering invocation.
  • rule_evaluated audit events for human-fallback dispositions, keyed by
    rule ID.
  • Release builds run from a pristine clone of the release tag, with the
    tag's commit stamped into the binaries as VCS provenance, and GitHub
    release notes are drawn from this changelog.
  • atryum version command (also --version). Release builds report the
    release tag and VCS revision; the same version is announced in MCP
    handshake metadata (serverInfo/clientInfo) instead of a hardcoded
    0.1.0.

Changed

  • Rule creation from "Always approve/deny" now opens a pre-filled modal
    instead of a bare form.
  • Shared agent hooks moved to the session model.
  • Charter sync uses a JOIN instead of a subquery when listing ValidMind
    CUIDs with bindings.
  • Token harness refreshed.

Fixed

  • SSE updates no longer fail to refresh the invocation list after
    pagination.
  • Rule-creation success callback branches on the saved rule's action rather
    than the original menu item.
  • Disposition check matches what Atryum actually emits (human, not
    human_approval); human disposition copy corrected for direct
    human-approval rules.
  • MCP server endpoints reject spaces.
  • ADD COLUMN store migrations are idempotent.
  • Charter sync guards DeleteSyncedStaleForOrg against an empty org CUID.

Security

  • External session routes are gated behind authentication, and
    RecordExecution enforces session ownership.
  • Empty agent bindings are rejected on session mint and use.
  • Judge session context is trust-fenced, byte-capped, and expiring;
    tool-use caches are bounded.

What's Changed

  • Don't allow spaces in mcp server endpoints by @mdeyell-valid-mind in #123
  • [SC-16888] Reconcile stale agents on sync to prune archived/deleted VM records by @even-steven in #124
  • Add pagination to Invocations list UI by @even-steven in #129
  • Add Invocation Audit section to FOSS UI + audit event instrumentation by @even-steven in #127
  • Token harness refresh by @mdeyell-valid-mind in #125
  • Track tool history in sessions and reconstruct judge context server-side by @hunner in #126
  • Refactor rule creation UX: pre-filled modal for always approve/deny by @even-steven in #132
  • Add grounding eval suite for the LLM-as-judge by @hunner in #128
  • Curated release notes and worktree-isolated release builds by @hunner in #134
  • Build releases from a local clone of the tag, not a worktree by @hunner in #135
  • Central version injected at release time, exposed via atryum version by @hunner in #136

Full Changelog: v0.1.0...v0.2.0

v0.1.0

Choose a tag to compare

@hunner hunner released this 06 Jul 17:42
Immutable release. Only release title and notes can be modified.
c4ee17f

What's Changed

New Contributors

Full Changelog: v0.0.4...v0.1.0

v0.0.4

Choose a tag to compare

@nibalizer nibalizer released this 14 Jun 15:45
Immutable release. Only release title and notes can be modified.
a586dd7

What's Changed

New Contributors

Full Changelog: v0.0.3...v0.0.4

v0.0.3

v0.0.3 Pre-release
Pre-release

Choose a tag to compare

@nibalizer nibalizer released this 05 Jun 21:05
1b0534e
Merge pull request #43 from validmind/codex/update-atryum-backend-api…

v0.0.2

v0.0.2 Pre-release
Pre-release

Choose a tag to compare

@nibalizer nibalizer released this 05 Jun 07:00
feat: set atryum.org custom domain for GitHub Pages

Co-authored-by: Amp <amp@ampcode.com>

0.0.1

0.0.1 Pre-release
Pre-release

Choose a tag to compare

@nibalizer nibalizer released this 04 Jun 20:24
feat: set atryum.org custom domain for GitHub Pages

Co-authored-by: Amp <amp@ampcode.com>