Changelog

Changelog

GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC. Every change to the runtime is taken as a numbered decision (DEC) in its own record; this page publishes the ones that change what GembaOS does, one line each, with the date. Internal paths, people and customers are left out. Current version: v0.2, as of 16 September 2026.

September 2026

DateDecisionWhat changed
2026-09-16Websitegembaos.dev launched in three languages with the contact form connected; the SEO/GEO layer (sitemap, structured data, llms.txt) and this changelog.
2026-09-16DEC-156Escalation conditions written in a playbook are enforced by the host; suspicious input raises a host-side risk flag that routes the action to a person.
2026-09-16DEC-157One mirror record per mirrored work item; host entries are marked at restart.
2026-09-16DEC-158, DEC-159The presenter’s demo builds the localized data roots the website captures use; a third demo act shows a bug fix prepared in a probed sandbox.
2026-09-15DEC-153 to DEC-155Demo mode: one tenant per language on one port; batch children are created in row order (an ordering bug found by the demo, fixed).
2026-09-11DEC-151, DEC-152Attachments in every chat box; a picture is treated as an injection surface: re-encoded on ingest, pixels only at the edge stage, a typed concern routes the run to a person.
2026-09-09DEC-146 to DEC-148REST adapter: OAuth2, constant headers, wire shapes and search; one neutral CRM pack in three vendor wire shapes; host work items close with an outcome; classified answers are errors, never guesses.
2026-09-08DEC-141The host executes after approval: playbook preconditions are re-read against the facts on the request, and a changed world returns the request instead of executing.
2026-09-08DEC-138 to DEC-140Orchestrator review: decisions redelivered at boot, panic isolation, wall-clock limits enforced; a turn cursor per step; the gateway reserves, executes and consumes a clearance in that order.
2026-09-07DEC-128 to DEC-135Gap Register: agents report gaps, a ledger and a review desk hold them, proposed procedures wait for a person, a monthly review and a desk digest close the loop.
2026-09-07DEC-125 to DEC-127LangGraph integration recipe; the approval verb follows the locale pack; record text is kept apart from console chrome; each tenant has its own business clock.
2026-09-06DEC-120 to DEC-124Model egress ceiling per tenant and playbook; employee directory import from the customer’s export; SQL transport with a customer-provided runner; knowledge source scan produces drafts; delivery toolchain (config check, policy explain).
2026-09-06DEC-114 to DEC-119Mirror lanes per external system; authority domains enforced at the gateway; batch console page; rate buckets per playbook; a rate-limited batch item keeps its clearance and waits; a refused pre-read is a recorded fact.
2026-09-05DEC-101 to DEC-113Unattended operations: scheduled and system-event triggers, adapter packs (REST, file, worker over mutual TLS), aggregated approval for batches, mirroring into ticket systems, the alert-to-triage pipeline, the operations console.
2026-09-05DEC-098 to DEC-100A turn’s input has a budget; governed library reads are trimmed by role; the whole model-facing skeleton follows the locale.
2026-09-04DEC-097Recovery from an interrupted run: quota exhaustion is its own failure and a failed run is re-enterable.

Earlier decisions (DEC-001 to DEC-096, May to early September 2026) built the core: work items, approval requests, clearance tokens, the signature chain, the capability gateway, policy replay, golden tests, red-team cases, multi-tenant runtimes, passkey stamps, SSO, the channels (email, chat, telephony, web widget), the governed knowledge library and the meeting room. They are summarized in the glossary and on the security page.

Last updated: · GembaOS v0.2