Release status
Current source availability, desktop installer status, and release limitations.
This implementation is not ready for general release. Do not publish a signed release label or competitive claim from a local development check.
The product repository is private. Source instructions require authorized repository access. The repository will remain private. Public installers are not yet available; signed installers will use a separate download channel.
Implemented and under integration
- Native shell and bundled service foundation; local setup and discovery review.
- Auth0 callback validation with signed token and key-rotation tests.
- Native system-browser PKCE, account status and scoped sign-out. The native release supplies its service address; the first sign-in needs no config edit. Provider registration and live account journeys remain unqualified.
- Stable configured source handles and claim-definition-bound evidence replay.
- Bounded graph parsing, graph queries and MCP graph serialization.
- Saved-index node search and explicit directed or undirected shortest paths; source exclusions and read permission are rechecked before delivery.
- Durable local source reports, cancellation, stale-source detection and exact repair approval; authenticated local HTTP tests including service restart.
- Revision comparison and exact restore approval, with append-only history, source-change checks, duplicate suppression and competing-proposal tests.
- Managed Work graphs with saved evidence, history, checks and proposals; a spatial node network, accessible record inspection and existing review actions. A revoked source cannot reveal its dependent reports through focused graph queries.
- Bounded local model discovery and metadata checks that refuse known cloud models before sending user prompts. Real model qualification is separate.
- Shared visual tokens and redesigned work and marketing surfaces.
- Current source-controlled architecture diagrams and API documentation.
- Local source-linked briefs with explicit model choice, durable checkpoints, cancellation, separately checked citations, finding-to-source graph links and exact repair/restore review. Real model usefulness and installation remain unqualified. See source-linked briefs.
- Scoped remote source reports are under integration: local folder grants, durable request keys, worker-owned execution and response authorization. See remote reports for scope and limits.
Tests that use local identity and model fixtures do not establish live provider compatibility. A source report checks versions, not the truth of source claims.
Remaining release requirements
| Requirement | Evidence still needed |
|---|---|
| Native distribution | Signed installers, clean-device tests, OS-specific permissions, macOS notarization and verified updates |
| First use | Representative user study; at least 90% useful completion without help or terminal |
| Remote durable work | Integrated owner-grant/reconnect qualification, team roles and general task execution; scoped source reports are under integration |
| Identity | Live Auth0 web and native provider journeys, tenant registration and OS-specific native session qualification |
| Model and tool integrations | Real supported providers, clients and pinned harness/PAIR/Graphify/Hermes versions |
| Full maintenance | General deliverables, independent semantic checks, isolated file repair, workflow promotion and external-action reconciliation; local report revision restore is implemented |
| Hosted operations | PostgreSQL migration, staging and production checks, backup/restore and incident drills |
| Security | Independent review, no unresolved high or critical findings |
| Scale | 500 connected workers, 100 concurrent tasks, 72-hour soak |
| Comparison | At least 120 held-out tasks and evidence for any superiority claim |
| Public release | Final support terms, confirmed download artifacts, privacy review and controlled publication |
The existing acceptance/product.json and source-bound receipt checks remain
active. New code does not create an acceptance receipt automatically. Keep old
requirements unless an explicitly equivalent or stronger check replaces them.
Repository integration and deployment
The locally checked foundation and website changes were merged into the private repositories with owner authorization. GitHub Actions could not start its jobs because the account reported a payment or spending-limit restriction. Merging does not resolve that restriction or count as a successful hosted CI run. The new native advisory job also reports the current unpatched RSA dependency finding. Restoring hosted runners alone will not make that check pass.
Website Git deployment is held for main and codex/* in vercel.json. Keep the
hold until the controlled release decision. A source merge is not publication of
an installer, a production validation or a general release.
See the delivery agreement, the architecture and the work API.