Skip to content

0.3.0

Choose a tag to compare

@nibalizer nibalizer released this 27 Jul 15:18
· 20 commits to main since this release
Immutable release. Only release title and notes can be modified.
4bd5043

Added

  • Atryum can now be embedded as a Go library by downstream programs: import
    github.com/validmind/atryum/pkg/atryum and call atryum.Main(...) from
    another binary's main package, with WithRoutes, WithMigrations, and
    WithDatabase extension points.
  • Agent plan preapproval: agents can submit an entire plan for approval
    before executing its individual tool calls. Each planned action is
    evaluated against the existing invocation rules, and a shared LLM judge
    reviews the whole plan for charter compliance once.
  • Server-side session get-or-create, keyed by agent binding and the
    caller's own client session ID. Harnesses (the shared Claude Code/Cursor/
    Codex hook, amp, pi) now just send their own session/thread ID on every
    tool call — Atryum resolves or creates the matching session itself, so
    no harness needs to mint, cache, or retry session creation anymore.
  • Harnesses can poll a rules endpoint every 5 minutes to fetch their
    current approval rules, so agents can read their own rules and reduce
    denied calls; the MCP rules tool is available again as well.
  • Charter preview for agents in the admin UI: synced agents show the
    charter hierarchy assembled from the ValidMind backend, local agents
    show their own stored charter.
  • Logout button in the UI.
  • Copy-to-clipboard button on the MCP Endpoint field.
  • CI workflow publishing the production Atryum image to Docker Hub.
  • Initial architecture documentation.

Fixed

  • ClearSessions now stops each session's background watcher immediately
    after that session's own delete succeeds, instead of deleting everything
    first and cancelling watchers in a second pass — a delete failing partway
    through could previously leave already-deleted sessions with a watcher
    still running (and still able to approve/deny tool calls) until the
    process restarted. The reported cleared-count is also now the honest
    partial count rather than always 0 on error.
  • A rule whose stored server/tool/agent scope had become corrupted (bad
    manual edit, partial write, disk corruption) could silently start
    matching everything it wasn't scoped to; corrupted rule data now blocks
    the rule load and falls back to human review instead.
  • A database error while loading rules during an external tool-call
    submission is now logged and recorded in the invocation's audit trail,
    instead of failing silently.
  • Invoke no longer falls through to the permissive global policy when
    approval-rule loading fails (e.g. a brief database hiccup) — a rule-load
    failure now safely requires human approval and is logged, matching how
    Submit already behaved.
  • AI-decided invocations (hard denials and auto-approvals) now persist
    their matched_rule_id, so the invocation audit view no longer mislabels
    a still-present rule as "Deleted Rule". The UI also distinguishes a rule
    that is simply not in the loaded list ("Unknown rule") from one that is
    genuinely unrecorded or deleted.
  • Doc generation (just docs) no longer chops off the first character of
    3-space-indented numbered-list continuation lines.

Security

  • Fixed an issue where an external executor could mark a tool invocation
    as completed, failed, or cancelled before it was approved — bypassing
    human approval and forging the audit record. Execution outcomes can now
    only be reported for approved invocations, executors may only report on
    their own invocations, and recorded outcomes can no longer be
    overwritten; retrying an already-recorded outcome is a safe no-op.

What's Changed

New Contributors

Full Changelog: v0.2.0...0.3.0