Repository navigation
Releases: validmind/atryum
Releases · validmind/atryum
Release list
v0.4.0
Added
- Agents can now carry free-form tags: editable for every agent (including
ValidMind-synced ones) from the Agents UI or thetagsfield on the
agent create/update API, and preserved across re-syncs (tags are
Atryum-native and are never reset by a sync). Tags are forwarded on every
AI-judged evaluation asagent_tags, laying the groundwork for the
commercial Global Charters feature; the FOSS charter-preview call
intentionally continues to omit tags, since it hits a hierarchy-only
backend endpoint with no concept of organization-wide charters.
Changed
- Breaking: privileged HTTP API paths have been renamed and reorganized
under a flatter, non-"admin" prefix. Existing integrations, scripts, or
reverse-proxy rules that reference the old paths must be updated:/api/v1/admin/invocations...→/api/v1/review/invocations...
(also gains a/{id}/summarizeaction)/api/v1/admin/servers...→/api/v1/servers...(also gains a
/{name}/toolsaction)/api/v1/admin/rules...→/api/v1/rules.../api/v1/admin/agents...→/api/v1/agents...(also gains/syncand
/{id}/charter-preview)/api/v1/admin/settings,/api/v1/admin/policy→/api/v1/settings,
/api/v1/policy/api/v1/admin/managed-agents/...→/api/v1/managed-agents/...
(session management also gains list/clear/delete, not just register)/api/v1/admin-auth/config→/api/v1/auth/config- Plan approval now has its own top-level surface:
/api/v1/plans,/{id},/{id}/events,/{id}/approve,/{id}/deny,
/{id}/revise,/{id}/expire,/stream - New
/api/v1/model-configs,/api/v1/llm-configs,
/api/v1/llm-configs/{id}, and/api/v1/vm/organizations,
/api/v1/vm/record-types,/api/v1/vm/custom-fieldssurfaces - The "Admin authentication" docs section and terminology are now
"UI and privileged API authentication"; behavior is unchanged.
Fixed
- Generated integration docs (
connect-agents.html) are back in sync with
their markdown source, which had documented post-logout URL setup and the
sign-out flow without the HTML being rebuilt.
What's Changed
- SC-17522: Rename admin API endpoints by @mdeyell-valid-mind in #155
- docs: regenerate connect-agents.html for post-logout URL docs by @nibalizer in #159
- feat: agent tags (free-form, FOSS primitive for commercial Global Charters) by @even-steven in #156
- chore: changelog for v0.4.0 by @nibalizer in #161
Full Changelog: 0.3.0...v0.4.0
0.3.0
Added
- Atryum can now be embedded as a Go library by downstream programs: import
github.com/validmind/atryum/pkg/atryumand callatryum.Main(...)from
another binary'smainpackage, withWithRoutes,WithMigrations, and
WithDatabaseextension points. - Agent plan preapproval: agents can submit an entire plan for approval
before executing its individual tool calls. Each planned action is
evaluated against the existing invocation rules, and a shared LLM judge
reviews the whole plan for charter compliance once. - Server-side session get-or-create, keyed by agent binding and the
caller's own client session ID. Harnesses (the shared Claude Code/Cursor/
Codex hook, amp, pi) now just send their own session/thread ID on every
tool call — Atryum resolves or creates the matching session itself, so
no harness needs to mint, cache, or retry session creation anymore. - Harnesses can poll a rules endpoint every 5 minutes to fetch their
current approval rules, so agents can read their own rules and reduce
denied calls; the MCP rules tool is available again as well. - Charter preview for agents in the admin UI: synced agents show the
charter hierarchy assembled from the ValidMind backend, local agents
show their own stored charter. - Logout button in the UI.
- Copy-to-clipboard button on the MCP Endpoint field.
- CI workflow publishing the production Atryum image to Docker Hub.
- Initial architecture documentation.
Fixed
ClearSessionsnow stops each session's background watcher immediately
after that session's own delete succeeds, instead of deleting everything
first and cancelling watchers in a second pass — a delete failing partway
through could previously leave already-deleted sessions with a watcher
still running (and still able to approve/deny tool calls) until the
process restarted. The reported cleared-count is also now the honest
partial count rather than always0on error.- A rule whose stored server/tool/agent scope had become corrupted (bad
manual edit, partial write, disk corruption) could silently start
matching everything it wasn't scoped to; corrupted rule data now blocks
the rule load and falls back to human review instead. - A database error while loading rules during an external tool-call
submission is now logged and recorded in the invocation's audit trail,
instead of failing silently. Invokeno longer falls through to the permissive global policy when
approval-rule loading fails (e.g. a brief database hiccup) — a rule-load
failure now safely requires human approval and is logged, matching how
Submitalready behaved.- AI-decided invocations (hard denials and auto-approvals) now persist
theirmatched_rule_id, so the invocation audit view no longer mislabels
a still-present rule as "Deleted Rule". The UI also distinguishes a rule
that is simply not in the loaded list ("Unknown rule") from one that is
genuinely unrecorded or deleted. - Doc generation (
just docs) no longer chops off the first character of
3-space-indented numbered-list continuation lines.
Security
- Fixed an issue where an external executor could mark a tool invocation
as completed, failed, or cancelled before it was approved — bypassing
human approval and forging the audit record. Execution outcomes can now
only be reported for approved invocations, executors may only report on
their own invocations, and recorded outcomes can no longer be
overwritten; retrying an already-recorded outcome is a safe no-op.
What's Changed
- Fix: Invoke fails open to the global policy when rule loading fails by @kam-validmind in #140
- initial arch docs by @kam-validmind in #139
- Tell agents to read in their rules to reduce the number of denied calls by @mdeyell-valid-mind in #119
- ci: publish atryum image to Docker Hub by @eggshell in #76
- Fix: rule matching fails closed on corrupt pattern JSON and Submit's … by @kam-validmind in #141
- Fixed a security issue where an external executor could mark a tool i… by @kam-validmind in #138
- Server-side session get-or-create keyed by agent + client_session_id by @hunner in #142
- scafolding by @mdeyell-valid-mind in #137
- [SC-17293] Add a copy button for "mcp endpoint" field by @juanmleng in #150
- add logout button by @mdeyell-valid-mind in #149
- Agent plan preapprove by @mdeyell-valid-mind in #133
- Update docs and fix md-to-html for continuation indentation by @hunner in #146
- feat: agent charter preview (+ vm_cuid, agent-save enabled fix) by @even-steven in #152
- Fix: ClearSessions stops each watcher by @kam-validmind in #143
- fix: persist matched_rule_id for AI-decided invocations by @hunner in #158
- Add v0.3.0 changelog; fix stale module path in release ldflags by @hunner in #157
New Contributors
- @kam-validmind made their first contribution in #140
- @eggshell made their first contribution in #76
- @juanmleng made their first contribution in #150
Full Changelog: v0.2.0...0.3.0
v0.2.0
Added
- Invocation Audit section in the FOSS UI, with audit event instrumentation
showing AI evaluation reasons, failed states, and clear handling of
no-match and deleted-rule cases. - Grounding eval suite for the LLM-as-judge, runnable against any
OpenAI-compatible endpoint. - Session context for the judge, reconstructed from Atryum-tracked tool
calls, with trust fencing, a byte cap, and expiry. - Pagination for the Invocations list UI.
- Auto-sync of agent charters from ValidMind, with stale-record
reconciliation on every sync. insert_beforesupport: rules created from "Always approve/deny" insert
at the top of the rule list and immediately apply their disposition to the
triggering invocation.rule_evaluatedaudit events for human-fallback dispositions, keyed by
rule ID.- Release builds run from a pristine clone of the release tag, with the
tag's commit stamped into the binaries as VCS provenance, and GitHub
release notes are drawn from this changelog. atryum versioncommand (also--version). Release builds report the
release tag and VCS revision; the same version is announced in MCP
handshake metadata (serverInfo/clientInfo) instead of a hardcoded
0.1.0.
Changed
- Rule creation from "Always approve/deny" now opens a pre-filled modal
instead of a bare form. - Shared agent hooks moved to the session model.
- Charter sync uses a JOIN instead of a subquery when listing ValidMind
CUIDs with bindings. - Token harness refreshed.
Fixed
- SSE updates no longer fail to refresh the invocation list after
pagination. - Rule-creation success callback branches on the saved rule's action rather
than the original menu item. - Disposition check matches what Atryum actually emits (
human, not
human_approval); human disposition copy corrected for direct
human-approval rules. - MCP server endpoints reject spaces.
ADD COLUMNstore migrations are idempotent.- Charter sync guards
DeleteSyncedStaleForOrgagainst an empty org CUID.
Security
- External session routes are gated behind authentication, and
RecordExecutionenforces session ownership. - Empty agent bindings are rejected on session mint and use.
- Judge session context is trust-fenced, byte-capped, and expiring;
tool-use caches are bounded.
What's Changed
- Don't allow spaces in mcp server endpoints by @mdeyell-valid-mind in #123
- [SC-16888] Reconcile stale agents on sync to prune archived/deleted VM records by @even-steven in #124
- Add pagination to Invocations list UI by @even-steven in #129
- Add Invocation Audit section to FOSS UI + audit event instrumentation by @even-steven in #127
- Token harness refresh by @mdeyell-valid-mind in #125
- Track tool history in sessions and reconstruct judge context server-side by @hunner in #126
- Refactor rule creation UX: pre-filled modal for always approve/deny by @even-steven in #132
- Add grounding eval suite for the LLM-as-judge by @hunner in #128
- Curated release notes and worktree-isolated release builds by @hunner in #134
- Build releases from a local clone of the tag, not a worktree by @hunner in #135
- Central version injected at release time, exposed via
atryum versionby @hunner in #136
Full Changelog: v0.1.0...v0.2.0
v0.1.0
What's Changed
- Add quickstart link to README by @nibalizer in #75
- fix(pi): Add judge reject reason in pi agent hook by @hunner in #77
- feat(judge): Add tool call tool description to judge context by @hunner in #83
- fix(oauth): Refresh OAuth tokens for MCP upstreams by @hunner in #95
- docs: generate docs pdf in addition to web by @nibalizer in #93
- fix: Add Apache-2.0 NOTICE file and compatible license enforcement by @hunner in #96
- Always have temperature as zero when talking to the llm by @mdeyell-valid-mind in #101
- Add context to LLM judge for claude managed agent, amp, pi, codex, claude by @mdeyell-valid-mind in #92
- Make into Just + Claude Managed Agents doc edit by @validbeck in #98
- feat(ui): add custom headers to New Server form by @cachafla in #106
- fix(sync): persist ValidMind agent charter on sync by @cachafla in #108
- chore: move atryum default validmind url by @nibalizer in #109
- fix(mcp): populate custom headers in server edit form by @cachafla in #111
- Add oauth to non admin endpoints used by agent harnesses by @mdeyell-valid-mind in #102
- Add desktop notifications by @mdeyell-valid-mind in #113
- feat(invocations): Add agent logos and downloader by @hunner in #94
- Add admin auth by @mdeyell-valid-mind in #110
- mv /api/v1/admin/oauth/callback to /api/v1/mcp/oauth/callback by @mdeyell-valid-mind in #121
- [SC-16780] Allow machine keys on admin endpoints by @even-steven in #122
New Contributors
Full Changelog: v0.0.4...v0.1.0
v0.0.4
What's Changed
- External invocations: self-declared agent_id + demo-friendly Keycloak… by @nibalizer in #39
- [codex] Support no-auth agent id hints by @hunner in #44
- Add FOSS React UI with optional ValidMind connection by @even-steven in #47
- Add pi connection by @mdeyell-valid-mind in #46
- feat: add agent identity to pi agents by @nibalizer in #48
- Build & Deploy by @nibalizer in #49
- [codex] Handle upstream MCP session negotiation by @hunner in #45
- [SC-16712] LLM-as-judge and local LLM configurations for FOSS UI by @even-steven in #50
- Harness integration testing suite by @hunner in #51
- Claude managed agents by @mdeyell-valid-mind in #52
- fix(store): allow creating VM-path ai_evaluation rules (NOT NULL on atryum_llm_config_id) by @johnwalz97 in #55
- Nibz/very misc by @nibalizer in #56
- Rod/UI changes by @gtagle in #54
- Add Go unit tests workflow by @mdeyell-valid-mind in #60
- [SC-16731] Rename constitution to charter everywhere by @even-steven in #57
- Add gofmt check to CI by @mdeyell-valid-mind in #61
- add Apache 2 license by @hunner in #63
- Added 1px mb to align label by @gtagle in #62
- Refactor MCP SSE response boundaries by @hunner in #59
- [SC-16740] Remove invocation ID column from table by @even-steven in #67
- Guard against duplicate agent_ids across agents by @even-steven in #66
- fix(integration-tests): Various agent harness integration test harness fixups by @hunner in #68
- [codex] remove root MCP aggregate endpoint by @hunner in #70
- docs static site: Atryum MVP by @validbeck in #65
- Add MCP debug logging by @mdeyell-valid-mind in #69
- Enhance README with project overview and links by @nibalizer in #71
- Extend claude managed agents in the ui by @nibalizer in #64
- Create CONTRIBUTING.md for project guidelines by @nibalizer in #72
- docs: simple not on sqlite vs postgres by @nibalizer in #73
- Pull get rules tool by @nibalizer in #74
New Contributors
- @johnwalz97 made their first contribution in #55
- @gtagle made their first contribution in #54
- @validbeck made their first contribution in #65
Full Changelog: v0.0.3...v0.0.4