Repository navigation
0.3.0
·
20 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Added
- Atryum can now be embedded as a Go library by downstream programs: import
github.com/validmind/atryum/pkg/atryumand callatryum.Main(...)from
another binary'smainpackage, withWithRoutes,WithMigrations, and
WithDatabaseextension points. - Agent plan preapproval: agents can submit an entire plan for approval
before executing its individual tool calls. Each planned action is
evaluated against the existing invocation rules, and a shared LLM judge
reviews the whole plan for charter compliance once. - Server-side session get-or-create, keyed by agent binding and the
caller's own client session ID. Harnesses (the shared Claude Code/Cursor/
Codex hook, amp, pi) now just send their own session/thread ID on every
tool call — Atryum resolves or creates the matching session itself, so
no harness needs to mint, cache, or retry session creation anymore. - Harnesses can poll a rules endpoint every 5 minutes to fetch their
current approval rules, so agents can read their own rules and reduce
denied calls; the MCP rules tool is available again as well. - Charter preview for agents in the admin UI: synced agents show the
charter hierarchy assembled from the ValidMind backend, local agents
show their own stored charter. - Logout button in the UI.
- Copy-to-clipboard button on the MCP Endpoint field.
- CI workflow publishing the production Atryum image to Docker Hub.
- Initial architecture documentation.
Fixed
ClearSessionsnow stops each session's background watcher immediately
after that session's own delete succeeds, instead of deleting everything
first and cancelling watchers in a second pass — a delete failing partway
through could previously leave already-deleted sessions with a watcher
still running (and still able to approve/deny tool calls) until the
process restarted. The reported cleared-count is also now the honest
partial count rather than always0on error.- A rule whose stored server/tool/agent scope had become corrupted (bad
manual edit, partial write, disk corruption) could silently start
matching everything it wasn't scoped to; corrupted rule data now blocks
the rule load and falls back to human review instead. - A database error while loading rules during an external tool-call
submission is now logged and recorded in the invocation's audit trail,
instead of failing silently. Invokeno longer falls through to the permissive global policy when
approval-rule loading fails (e.g. a brief database hiccup) — a rule-load
failure now safely requires human approval and is logged, matching how
Submitalready behaved.- AI-decided invocations (hard denials and auto-approvals) now persist
theirmatched_rule_id, so the invocation audit view no longer mislabels
a still-present rule as "Deleted Rule". The UI also distinguishes a rule
that is simply not in the loaded list ("Unknown rule") from one that is
genuinely unrecorded or deleted. - Doc generation (
just docs) no longer chops off the first character of
3-space-indented numbered-list continuation lines.
Security
- Fixed an issue where an external executor could mark a tool invocation
as completed, failed, or cancelled before it was approved — bypassing
human approval and forging the audit record. Execution outcomes can now
only be reported for approved invocations, executors may only report on
their own invocations, and recorded outcomes can no longer be
overwritten; retrying an already-recorded outcome is a safe no-op.
What's Changed
- Fix: Invoke fails open to the global policy when rule loading fails by @kam-validmind in #140
- initial arch docs by @kam-validmind in #139
- Tell agents to read in their rules to reduce the number of denied calls by @mdeyell-valid-mind in #119
- ci: publish atryum image to Docker Hub by @eggshell in #76
- Fix: rule matching fails closed on corrupt pattern JSON and Submit's … by @kam-validmind in #141
- Fixed a security issue where an external executor could mark a tool i… by @kam-validmind in #138
- Server-side session get-or-create keyed by agent + client_session_id by @hunner in #142
- scafolding by @mdeyell-valid-mind in #137
- [SC-17293] Add a copy button for "mcp endpoint" field by @juanmleng in #150
- add logout button by @mdeyell-valid-mind in #149
- Agent plan preapprove by @mdeyell-valid-mind in #133
- Update docs and fix md-to-html for continuation indentation by @hunner in #146
- feat: agent charter preview (+ vm_cuid, agent-save enabled fix) by @even-steven in #152
- Fix: ClearSessions stops each watcher by @kam-validmind in #143
- fix: persist matched_rule_id for AI-decided invocations by @hunner in #158
- Add v0.3.0 changelog; fix stale module path in release ldflags by @hunner in #157
New Contributors
- @kam-validmind made their first contribution in #140
- @eggshell made their first contribution in #76
- @juanmleng made their first contribution in #150
Full Changelog: v0.2.0...0.3.0