Mojo UpDocs
Release notes

AI Workbench

What changed in each release of the AI Workbench desktop app and its headless node.

The 20 most recent releases, newest first. The desktop app shows the same notes under What's new after it updates, and a node prints its version with mojoup-node version.

0.47.0

  • Updates come from Mojo Up AI Cloud. The app reads its releases from https://ai.mojoup.com.au/releases/v1/workbench/<channel>/latest.json, or from your organisation's own platform when you are signed in to an Enterprise one (it answers for the ring your computer is in, and may hold a release back or offer an earlier one). Settings → Updates → source still overrides it with a URL or a folder. A release the publisher withdrew is never offered, and a manifest for another product is ignored.
  • Nightlies and stable releases are signed with Mojo Up's publicly trusted certificate (Azure Trusted Signing), the installer and the app inside it, and now the node executable too. The certificate on the dev box signs test builds only.
  • Your licence decides the edition. Signed in to Mojo Up AI Cloud or an Enterprise organisation, the workbench asks the platform for its licence (the plan — Free, Teams or Enterprise — and what it allows), checks the platform's signature on it, and keeps it with the sign-in; the edition follows it, including through two weeks of grace when the platform cannot be reached. A Cloud team held to the Free plan is Free. Without a licence (an older platform) the organisation's own plan stands in.
  • Nodes, the mesh and organisation backups are offered only where the licence allows them.
  • Your organisation's settings policy reaches the updater. A locked update channel, source, signature rule or node auto-update from the organisation wins over the local setting, as it already did for hosts and nodes.
  • The node updates from the same feed. mojoup-node update reads the platform's release manifest (its channels are stable and nightly; preview still works as a name for nightly), sends the node's token so an Enterprise answers for its ring, and the install scripts read the same manifest. The node package is built and signed from CI and published with every release.
  • The organisation sees which mesh agent each machine runs, from the version bundled with the app or the node package.
  • CI fixes. A repository under a symlinked folder (macOS's /var, a Windows short name) has one worktree container whichever way it is reached; a write outside the agent's worktree is reported by the path the tool named; a routine named by a number is never confused with an id starting with that digit.

0.46.4

  • The setup guide sees an install the moment it finishes. After Install on Git Credential Manager, the Git rows now read git again, so the row turns green without restarting the app; Re-check and the live refresh do the same. Re-check and the live refresh were reading everything but git.
  • Installing shows it is working. The row and its button say "Installing…" with a spinner and tell you to approve the password prompt, until the install ends and the row has been re-read. Starting Docker and the other Install rows do the same.
  • Installing Docker Engine on Linux no longer stalls. Docker's own install script asked for a second sudo password that had nowhere to be answered, so Install sat waiting. It now fetches the script and runs it, and adds you to the docker group, in one step behind a single system password dialog. When it finishes the setup guide, and the install's own terminal output, tell you to sign out and back in once so your account can use Docker, then Re-check.
  • Docker that is up but refuses you now says so. Right after Docker Engine is installed on Linux your login session is not in the docker group yet, so every call gets "permission denied". The row used to offer Start Docker, which cannot help; it now says to sign out and back in once, then Re-check.
  • A quiet log before you open a project. The app logged "dropped … no ready host for its root" every minute on the Welcome screen, where there is no project and so no host to ask. It now logs that only for a window that has a project but no ready host.
  • A CLI that is not installed no longer floods the log. Reading documents for the memory graph through an agent CLI (Copilot, Codex, Claude Code, Antigravity) started a fresh agent for every chunk, so a CLI that was missing or signed out failed hundreds of times, two warnings each. After three failures in a row it now stops starting the CLI for two minutes, says so once, and tries again after that.
  • The dock shows AI Workbench's icon, not a generic cog, on Ubuntu. The window now carries the same name as its launcher, which GNOME needs to tie the two together.
  • A first-start wizard about the computer, not a project. Project, Where, Source and Prepare are gone from it: nothing there is needed to get started. It is now This computer, Agent CLIs, Local model, Who does the work, What helps your agents (the same steps as Settings → Setup, embedded), then three specialists for every project: a Generalist, a Scribe and a Researcher, each with a name, a character, a runtime and a model, saved at the global layer. Finish lands on the Welcome screen with New project…; the specialists are already there for it. Settings → Setup has Run first-time setup again, which until now was offered only on the Welcome screen while no project existed.
  • All three specialists are saved, and they follow your default runtime. Saving three at once kept only the last: each save read the shared list of definitions, changed one entry and wrote the whole list back, so the writes overwrote each other, yet every one was acknowledged as saved. Those writes now take turns on the host. The first-start Agent CLIs step is the Setup wizard's own Runtimes step, which is where the default runtime is chosen (the old step had no way to), and the specialists and the starter team start on that default when it is ready instead of whichever CLI is first in the list. A computer whose Chat, Operations Manager and Worker already agree on one working runtime, and that has never chosen a default, gets that runtime as its default when the Agent CLIs step opens, with a line saying so; before, it showed Copilot because that is the built-in fallback.
  • Memory and merge conflicts take a model, once the CLI is signed in. Under Who reads the documents and a separate conflict agent there is now a model row. On a subscription runtime (Claude Code, Codex, Copilot CLI, Antigravity) it first asks you to sign in, because the models offered are the ones your plan lists; the same applies to each specialist's model. The memory model picker also understands "Default runtime", which it used to treat as a free-text prompt, and keeps the model on the computer when no project is open.
  • A first run opens with the left menu expanded and the bottom and right panes closed. The menu's labels are how a new person finds their way around, and the workspace gets the room; a pane opens when something asks for it or when you open it. Anyone who has collapsed the menu or opened a pane keeps it as they left it.
  • The Researcher shows its character in Research. A research conversation records who ran it as its team id, and the transcript only looked for a specialist id, so a research run by a specialist was drawn with a plain initial. It now finds the specialist from either.
  • Approving from the Inbox, a notification or the tray works. Those went to the agent's workbench as the desktop's own service actor, which a workbench does not know and treats as a remote client, so its policy refused the person's own high-risk approvals ("not allowed from remote clients") and an allow sometimes took several tries, while Mission Control worked. They now go as the person who pressed the button, as Mission Control always did.
  • The workbench's own read-only tools are no longer held for approval. Every MCP tool reached the policy as kind "other", so a read-only task_list or memory_search counted as medium risk and was held under an approval setting meant to stop only risky actions. Reading the board, the inbox, a conversation and memory, looking at a browser, and an agent reporting on its own task (task_start, task_done, task_blocked, ask_human) are low risk. Driving a browser, messaging other agents and changing the board or memory stay medium, and only the workbench's own server counts: its name is reserved.
  • Mission Control lists every agent in the repository. It showed only the current workspace's agents while showing everyone's approvals, so an agent could ask for permission and not be in the panel (a Researcher running a research, whose session carries its own name as its team). The current workspace's come first and the others say whose they are.
  • An approval toast's Open goes to the agent that asked, not just to Mission Control.
  • The log says why the app quit (a menu or tray Quit, the last window closing, a relaunch for an update or a space) instead of only "quit requested".
  • A research run that got no answer no longer files a "report". When the researcher's startup timed out (a 3-minute wait, here on an approval nobody had answered) the run appended its own error to the conversation and then filed that text as a research artifact: an 898-byte "report" of one error line, flagged for missing ## [findings] and ## [recommendation] sections. A report is now filed only when someone contributed or a final report exists, and a run that did not says "No report was filed" with what to check.
  • Research with a specialist runs it solo, like Chat. It started the specialist as a team of one, so its session carried the specialist's name as its team and its plan was filed on a board named after it (researcher.json) instead of the Solo board. A specialist's research now starts it the way Chat does, on the Solo board, and reuses that session on the next question. A research team or council is a real team and keeps its own board.
  • Quitting asks first when something would be lost. A menu or tray Quit, or closing the last window, asks "N agents are running / N approvals are waiting — Quit?" (Keep running is the default) when agents are working or approvals are waiting. Quits the app starts itself, such as a relaunch for an update, are not asked about.
  • The tasks a research run files can be found. A research run starts its specialist as a team of one, so its plan (T-1…T-3) is filed on a board named after the specialist, while the Tasks view's board picker hides specialists because chat with one is solo work on the Solo board. The tasks were on disk and unreachable, the ones waiting for review included, until you switched the board's backend to see them. A specialist that has a board with tasks on it now appears in the picker.
  • Setup works before any project exists. With no project open there was no workbench to answer the setup steps, so they could not load. The desktop now starts one on demand, on a folder of its own, for a window that shows no project, and stops it when nothing has asked it anything for ten minutes. It answers only the setup messages; a board or agent message from such a window is still dropped.
  • Setup → Runtimes offers to install the Claude Code adapter. A runtime found on the machine whose adapter is still fetched with npx on every first start (Claude Code, say) had no button in the setup wizard, although its note says installing the adapter skips that wait. It now shows Install adapter. A runtime that is fully installed still shows none there; Settings → Models has Reinstall.
  • One word for installing a runtime. Codex said "Set up Codex CLI" where every other runtime said "Install"; a runtime with nothing installed now reads "Install".
  • Specialists start with sensible approvals everywhere. A specialist made in any wizard (first start, Teams, Team Builder) cleans its worktree up on its own and auto-approves low- and medium-risk tools, asking only for high-risk ones.
  • Research writes OKF, Markdown and HTML by default into docs/research; Settings → Research still turns each format off.
  • Research tasks go straight to Done. A research run's own tasks no longer wait for your review. Turn on Settings → Research → "Review a run's tasks before they are done" to hold them in Review. A specialist set to wait for review still waits.
  • Choose which GPU runs the local model. On a laptop with an NVIDIA or Radeon card beside the graphics built into the processor, llama.cpp split the model over both, and the slow integrated GPU held the card back. The runner now asks the installed build which GPUs it can use (llama-server --list-devices), and Automatic runs on the discrete card (--device), the one with the most memory among equals. Settings → Local models → Engine and the setup guide show a GPU picker when there is more than one — Auto, each GPU with its memory, or all of them split — and say which GPU the model runs on. New setting localRunner.device; a device that is gone falls back to Automatic, and a --device in the extra arguments still wins.
  • Research builds prototypes, and hands them on. A specialist researches in a worktree of its own, on a research/<topic> branch, and may prototype the options it compares there; nothing of it reaches the checkout. A prototype with a screen is shown in the integrated browser: the researcher walks its user flows, keeps a screenshot of each step (browser_screenshot can now save a PNG into the agent's worktree with saveTo), writes the flows into the report as steps to try, and leaves the best option open in a tab. After each run the branch's changes are copied beside the report (<report>-prototype/: prototype.patch, the changed files, a README) and the report gains a Prototype section showing the screenshots. Send to Team Work gives the team the report and that copy (the patch to start from), then removes the research branch so the researcher can take the next question.
  • The Inference pane names the right machine. On Linux and macOS (and Windows outside WSL) it said "Start it on the Windows side"; the desktop app's own service serves every platform, so it now reads "Start the local model". Settings shows "Detect on Windows" for a local server only inside a WSL distro.
  • Memory → Find starts folded. Every group in the index starts closed, so a long one (Roadmap) no longer pushes the rest out of sight; the groups you open stay open.
  • Research follows the specialist's approvals. A research run started the specialist unlinked from its own approval settings, so it fell back to the chat defaults and asked about every read (conversation_read, say). Every specialist session now follows its specialist, and a specialist saved with no approval settings uses the specialist defaults (low and medium automatic, high asks) instead of asking about everything. What a research run does ask now shows above its own composer, not only in the side panel.
  • A long research run is not cut off. A research question had three minutes, like a planning prompt, and on the timeout its opening sentences were filed as the report. It now times out only after ten minutes with nothing from the researcher (never while it waits on your approval); a timed-out question files nothing and its turn is cancelled, so the conversation never shows done while the researcher is still at work.
  • One card per research report. A research run writes its report in up to three formats (OKF, a web page, plain Markdown), and each showed as a card of its own, in the conversation and in the Artifacts panel, with the header counting three. The formats are now a choice on one card: Open, Preview and Download act on the one picked (the OKF report first, since it opens in the Library), the card's menu still sends the report on, and the Artifacts count counts reports.
  • Stop an agent from the pixel office again. Selecting an agent in the pixel office offered a small × only for an agent with no role, so a team's members could be stopped from their cards and not from the office. The office now shows Stop on every selected agent (never a subagent), with the card's words, and both views stop through the one path: a stop pressed in either says "Stopping" in both until the agent has gone.
  • One Library entry per research report. A research run that writes its report as OKF, plain Markdown and a web page put three rows under Research in the Library, two of them tagged OKF. They are now one row, named by the OKF report's title, and the viewer has a Format switch — Web page, OKF, Markdown — that opens on the web page, else the OKF report, else the Markdown. The web page reads in the same sandboxed frame as before and is read-only there; the Markdown formats keep their front matter, outline, checks and editing. Opening a particular file from elsewhere ("Open in the Library") lands on the report's row with that format picked, and the Research count counts reports.
  • Agent worktrees are never nested, and the ones that hold no work are tidied. An isolated agent restored (or a specialist started) with its old worktree as its folder made its new worktree next to that one — .mojoup-worktrees/<repo>-<hash>/mojoup/solo/.mojoup-worktrees/researcher-<hash>/… — because the managed folder was worked out from the folder the agent started in. It is now always the main repository's. At start-up (and on demand with mjuWorkbench.tidyWorktrees) the workbench removes its own worktrees that hold nothing: under the managed folder, on a mojoup/ agent branch (not integration), with no agent working in it, a clean git status and every commit also on another branch. Anything else — uncommitted changes, commits found on no other branch, a research or feature branch, a detached review checkout — is kept, and the log says why. It never forces a removal.
  • An agent asks before writing outside its worktree. An agent with a worktree of its own that edits a file anywhere else (the checkout, another agent's worktree) is asked about it whatever its approval settings or mode, Full access included; the request is high risk and its title names where it writes. The system's temporary folder is exempt, and reads are never held.
  • Every run says where its work is. Research and Team Work end with a note naming each agent's branch and worktree, the files changed there, what is not committed and what is not on the checkout's branch yet, and any file it wrote straight into the checkout (only files its own tool calls named, so your edits are not blamed on it). A Chat turn notes checkout writes the same way.
  • The report a researcher writes is the report. A report the researcher wrote itself in the research folder (in the checkout, or in its worktree, then copied over) is linked as the conversation's report, instead of a second one written beside it from the chat reply.
  • A question is not ended by the agent's startup briefing. A research question sent while a new agent was still in its briefing listened from the start, and the briefing's own end (its cancellation by the three-minute watchdog) was taken for the answer: the run closed with "no answer", and the agent then worked on the question with nobody listening, so its approval requests reached no conversation. The question now waits for the briefing. A request the agent makes during the briefing that the approval policy does not let through within two seconds is declined (the briefing does no work) instead of holding the agent, unseen, for three minutes.
  • One agent per specialist on the Solo board. Chat started a specialist per conversation and research started another, and after a restart a restored one was forgotten, so two Researchers could stand side by side with one waiting on an approval nobody could find. A chat with a specialist, its research and its tasks now all go to the one already running there (restored ones included, with the specialist's approvals); a restore brings back one of each. Only "Ask several…", which asks another model on purpose, starts a second.
  • Source Control knows research branches. A research/… branch read as "external, not created by the workbench"; it now shows as the research conversation that made it. A prototype's packages are installed in its own folder only, never system-wide, and the report says what was installed.
  • Research asks you as it goes. A researcher is told to ask (ask_human) when something only you can settle would change the answer, as soon as it comes up, instead of listing it under Open questions at the end. The run waits for your answer, gives it to the researcher and carries on to the report; Stop ends the wait. The question shows above the Research conversation's composer (it looked on the specialist's own board, where nothing is filed). An answer to a question from an agent on the Solo board now reaches it: the lookup expected a team name those agents do not have, so the answer was never delivered.
  • Research ends on a card. A research run closes with one "Research done" card in the conversation: the report with Open; the acceptance criteria of the plan the researcher made, each with its evidence, to pass or fail right there (or close the plan anyway, with a reason); and Send to Team Work, the same as the header's button, which then shows that it went. When the plan's work is done its UNIFY is asked for at once — closed when every criterion passed, held for your verdict otherwise — where before a research plan stayed open for ever unless you found it in Plans.
  • A window that gives out says so, and comes back. A window's page dying (a renderer crash, the GPU process, out of memory) or hanging left nothing in the log, so a window that vanished mid-run read only as "the last window was closed". The log now records why a page went, when it stops and starts responding, and every window close; a page that died is reloaded instead of leaving an empty frame.
  • Ctrl+W no longer closes the window on Windows and Linux, and quitting asks while agents work. Ctrl+W (Close Window, also brought by the menu's "close" role) fired from a text box or the terminal, where it means "delete the last word", and closing the only window quits the app: it went mid-Team Work, tray icon and all. Close Window stays in the menu without a shortcut; macOS keeps Cmd+W. The question before quitting now asks each host how many agents it has at that moment instead of trusting its last status frame, which had let a quit through with a team running.
  • No more "merge-back failed" for a branch that is gone. Approved tasks whose branch was deleted (its worktree tidied away) were retried on every backoff for ever, each attempt a warning. A held merge whose branch no longer exists is now dropped once, with a line in the orchestration log, and the merge itself says there is nothing to merge instead of failing.
  • A restarted agent's old processes are really gone. Stopping an agent signalled its process group, but returned as soon as the agent itself exited, so a child that ignored the signal (an MCP sidecar) lived on and called the workbench every five seconds on a revoked credential. The kill now waits for the whole group and forces what is left; and the task-board sidecar stops watching for tool changes once its session's access has ended, instead of retrying it for as long as it runs.
  • Source Control's Worktrees and Branches fit the card. Their rows were table rows that could not shrink: the actions (Merge, Open PR, Push, Open, Switch, Delete) and the worktree path ran off the right edge with no scroll. Each row now wraps: the path or commit subject truncates (the path from its start, so its end shows; the whole of it is the tooltip) and the actions drop to a line of their own when the card is narrow. The Branches tab's badge, which counts work waiting to land rather than branches, says so on hover.
  • The conversation keeps its room while you answer. What sits above the composer (an agent's questions, the brief, the plan, the tasks) now takes at most 45% of the window and scrolls inside itself, and the question cards have Hide, which shrinks them to one line ("Ben asks …") until you want them again; the composer still answers the first.
  • You are told when an agent asks you something. A question raised no notification while its conversation was open in the window, even with the card below the fold or the window behind another app, so only approvals ever reached you. A question is now announced as an approval is, and neither is held back because the window is merely visible: one behind another app counts as not being looked at.
  • No phantom "Needs approval" while an agent starts. A request an agent made during its startup briefing that the approval policy answered at once left the agent showing Needs approval, with nothing anywhere to approve, until the briefing ended: the briefing keeps "starting" on the agent and ignored the change that ends an approval wait. An answered wait now goes back to "starting".
  • Steps say which command and which page. A tool call's first title is often only the tool ("Terminal", "Fetch"), so Chat, Research and Team Work showed "Ran a command" and "Fetching a page", and Mission Control and Agent history the bare tool name. The agent manager now puts what a call acts on (the page, the search, the pattern, the file) on its events beside the command it already carried; a step reads "Ran npm test" or "Fetching conductor.build", with the whole line when opened, and a later update that brings the full title fills the step in.
  • A specialist keeps its approvals across a context reset or restart. Both give its session a new id, and only a Chat conversation's binding followed it, so a reset Researcher fell back to the chat defaults and asked to approve every page it fetched. Its approvals, its research run and its place as the specialist's one session now follow the new id.
  • A researcher's own report gets every format you configured. When the researcher wrote its report as a Markdown file, only that file was linked. Every format in Settings → Research is now made from it, beside it under its name (OKF in its place, the whole report inside), so the Library lists one report and the reader switches between them, web page first.
  • A fresh install lays the panes out the way they are used. The bottom dock holds the machine (Terminal, Usage, Inference, Updates, Notifications) and the right sidebar the work (History, Mission Control, Files, Editor, the graph), in that order. A layout you already arranged is kept.
  • Auto-approved requests no longer flash up as cards. Every request is written down as it arrives and the approval policy answers the ones it allows a tick later; the list of open approvals went to the window at once, so each of those appeared above the composer and vanished. The list is now sent a moment after it changes, by when those are answered and gone; one that waits for you appears as before.
  • Notifications know where you are. An approval or a question no longer pops up (in the app or as a system notification) while you are looking at it: the window focused on the conversation the agent works in, or on that agent in Mission Control. It is announced the moment you look away while it still waits: another view, another conversation, another app. Approvals used to notify even with their conversation open, and anything held back was never announced later.
  • A research run that fails still files what the researcher wrote. A researcher that wrote its report into its worktree and then hit a usage limit left the run with no answer, and the report stayed on the research branch: one format, reachable only by an external editor (a file outside the checkout opens there). The research branch is now collected however the run ended, so the report lands in the research folder in every configured format and opens in the Library.
  • Mission Control lets you pick an agent again. Opening it on one agent (from its card, or a toast's Open) was re-applied on every sessions update, so with any agent at work it snapped back to that agent and no other tab could be chosen. The request is now applied once.
  • Research branches are never merged. A research run's own plan tasks, on finishing, went through the ordinary merge-back, which merged the agent's current branch — the research branch — onto the integration branch on its way into the base branch: prototype code, the report and all. A research/… branch is now refused by every merge-back and dependency merge; its work goes on beside the report as designed.
  • Toasts keep their button, and say it once. A toast's action is no longer pushed off the edge by a long message (the toast wraps), and "approved commits are waiting to land" no longer repeats its own sentence.
  • The Library's Page / Source switch is the sidebar's segment. It uses the same sliding control as the colour mode switch at the foot of the sidebar, with an icon beside each word, instead of two detached buttons.
  • The browser's + opens a tab while a blank one is open. Opening a tab fills an untouched blank tab rather than starting another (right for an agent opening a page), so + only showed the blank tab again and a second tab could not be added until the first had a page in it. + now always opens a new tab.
  • Views pop out into windows of their own. Tasks, Plans, Roadmap, the Office (agent cards and the pixel office), Watchlist, Pipelines, Operations, Memory, Decisions, Library and Architecture have an "Open in a window of its own" button beside the view's name in the title bar. The window shows just that view, on the project it came from (a project switch in the main window leaves it be), named "Tasks — <project>"; one per view, so a second press brings it forward. Links inside it to the same view stay there; links to another view open in the main window, which comes forward, and a file opens in an editor window. The browser dialog has the same button: its tabs move into the new window and come back to the main window when it closes, and agents keep driving them throughout.
  • On Linux, closing the last window leaves the app running in the tray, as on Windows, so agents and schedules carry on. Quit from the tray menu; Settings › Close to tray turns it off.

0.46.3

  • Install buttons ask for your password in the system dialog on Linux. The setup guide's Install buttons (Git Credential Manager, Git, the OpenSSH client, starting Docker) ran sudo in a terminal pane that could sit unseen while sudo waited for a password. They now use pkexec where it is installed, which shows the desktop's own password prompt. Git Credential Manager installs through apt, so its dependencies come with it.

0.46.2

  • Checked on native Ubuntu. The .deb and AppImage build and all three test suites pass on Ubuntu 26.04; no changes to how the app behaves.

0.46.1

  • The Watchlist's workflow picture starts folded into a one-line tile: Show the picture opens it, Hide the picture folds it again, and your choice is remembered.

0.46.0

  • The Watchlist's workflow, plain. An opened entry starts with where it is — a risk Identified, Assessed, Treating, Monitoring, Settled; an issue Open, Working, Resolved; a bug Open, Fixing, Fixed — and a Next step card with the one thing to do: assess it, decide what to do, assign the treatment or accept it, see who is working on it, rate it again, mark it reviewed.
  • Settle… asks how it ended, in words: Resolved, Accepted (with a reason), It happened (raise the issue), No longer relevant; a bug Fixed, Won't fix or Duplicate. Settled entries say how, by whom and when, and can be reopened. One line tells who answers for a risk from who does the work.
  • A picture of the workflow heads the Watchlist, with how many entries sit at each step. Press a step to see what it means and who does it; Show me filters the list to it.
  • A proper tags field: chips, Enter or a comma to add, suggestions from tags already used; the Watchlist filters by tag.
  • The open project's repositories in the switcher, above the projects: which is running, which machine it is on, and Ctrl-click for a new window.
  • The Watchlist no longer names the product its risk model came from.

0.45.0

  • The rings, two ways and a second picture. Nine tiers as before, or five themes — Direction, Governance, Structure, the agent's kit and Memory — with a tier an arc of its theme's ring. Quiet at rest; the ring under the pointer wakes up. Opening a group keeps the whole picture: the other rings become a rim, the group's children fill a wide ring inside it, split into arcs by status, folder or family, with counted links to the rim, as deep as the hierarchy goes. Shelves show the same hierarchy as rows. A View pill beside Explore switches, and remembers.
  • Still while you read. The rings' sweep and the centre's breath pause while the pointer is over the picture or anything is open.

0.44.0

  • Chat history shows each conversation's kind, and selecting is in plain sight: tick on hover, selection mode, and a bar to archive, group or delete several at once.
  • The @ picker opens whole above the composer in Chat, Research and Team Work.
  • Stop an agent from its card in the office's card view, and Stop and discard for a stuck one.
  • A projects-only switcher in the title bar, with search, Add project and All projects.
  • Source Control's colours mean something: red needs you, amber has work not committed or pushed, green is clean; merge conflicts count as needing you.
  • Rating a risk is plain: Overall or By dimension, and "Follow the controls" shows its working. Names stored without a space are tidied.
  • Agents use the Watchlist and decisions: every agent can raise risks, issues and bugs and propose decisions; reviewers raise bugs; new routines for a weekly risk review, harvesting decisions and lessons, and bug triage.
  • Routines at scale: list, grid and by-project views with search, filters and sort.
  • Daily reviews you can clear: Done and Dismiss fold away, with Undo and Move back.
  • Governance and Library rings in Memory, and tracing a link to the exact item it points at.
  • Fixes: the Memory view no longer says the engine is installing while it only checks it.

0.43.0

  • Undo a turn. Every agent turn in its own worktree is snapshotted. Chat shows what each turn changed, and Edit from here takes the conversation back to before a message, with or without its file changes. Fork a reply into a new conversation; re-run a Research report another way; quote a passage into your reply. Chat work now merges after ten quiet minutes or when you say Keep it.
  • Sending while it runs. One send button: Interrupt, Steer or Queue, Resume, Launch or Refine. A queue you can reorder and edit, kept across restarts; ↑ recalls what you sent; Ctrl/⌘+S stashes a prompt. Approvals and questions dock above the composer.
  • Where Chat runs. Choose this checkout, a worktree of its own or the last one, and the branch it starts from; agent, model, thinking and access sit in the composer. A context meter with Compact, and banners for usage limits (Resume at reset), sign-in and branch drift.
  • Turns at a glance. A finished turn folds into "Worked for 2m 14s"; tools read as sentences. Long conversations open fast and page in older turns; a minimap jumps between turns.
  • Permission modes. Supervised, Auto-accept edits, Auto or Full access per agent, capped by policy. Approvals are written down, survive a restart and are answered once.
  • Ask several. One prompt to two to four specialists or models, compared side by side.
  • Switch agent mid-conversation with a handoff that carries the conversation.
  • Your subscriptions. Your own Claude, ChatGPT, Copilot and Google subscriptions, each used only by its own vendor's runtime, in your own profile on shared nodes; sign in on a node from the inbox. Several signed-in accounts per runtime, chosen per member.
  • Team Work undo. Revert a task's changes or run it again, from the task or the conversation.
  • Pull requests from GitLab, Forgejo, Gitea and Bitbucket; a merged pull request closes its task.
  • Nodes install in one command and update themselves safely, rolling back a version that does not start; an out-of-date node or desktop says so and offers the update.
  • Desktop updates install in place on Linux and follow a stable or nightly channel.
  • Security. Organisation sign-ins bound to this device's key (DPoP); paired remote clients expire when unused; every Control API method needs its scope.
  • Fixes. Research shows its progress as it runs; Chat shows a reply's thinking; Retry keeps attachments; each conversation keeps its own draft; the project switcher no longer overlaps long names.

0.42.2

  • The live monitor's Machine tab reads the hardware again when there is no local model on this computer, or the desktop's service runs it. It used to wait on "Reading the hardware…" for ever; model figures still appear when a model is running.

0.42.1

  • Quick runs on Home. Pin any routine, or make a new one with no schedule, and run it from Home on both All projects and This project; each card says what it does, where and who runs it, and how its last run went; routines you already run by hand are suggested.
  • Chat history you can organise. Filters (kind, status, who, date, artifacts), an Active toggle, search through message text, named and coloured groups, archive (one or many, or after days idle), and Delete now asks first.
  • Library and Memory show what they are waiting for. The tree, documents, pages, templates, rings in every scope, the centre panel, Look it up, project notes and the first memory build; buttons that are working say so.
  • A simpler Watchlist. The scale is "Standard 5×5" with no standard's name in the way, and the Metadata tab is one line under the form.

0.42.0

  • Home across every project. An All projects dashboard: what needs you, agents at work, routines due or failing, spend, and a card per project; Run now for routines; Routines across every project.
  • An Inbox. What needs you — approvals, decisions, escalations, held landings, updates, sign-in — grouped by organisation, project and repository, with Done and Snooze; Notifications is a quiet log.
  • Projects at scale. Detailed, List, Grid and By machine views with search, filters and sort; rename a repository; open any project in a new window (File → New Window); "Find it again" for a repository whose machine or folder is gone, moving several to a new WSL distro at once.
  • Setup without assumptions. A local model is optional; memory, merge conflicts and data protection explained in one step, none defaulting to a local model; choose any runtime as the default; llama.cpp follows the newest checked release; MLX detected on Apple silicon.
  • Kilo Code as an agent runtime, with its usage and cost.
  • Settings for a meta harness. Plain words, no editor-era leftovers; change a setting for this workbench, this machine, the project or the repository, with overrides you can undo; what your edition allows.
  • Watchlist. Risks, issues and bugs on the ISO 31000 5×5 standard: inherent and residual assessment, controls, appetite, heatmap and list; assign any item to a team or specialist; status reports carry a Watchlist section.
  • Decisions. A register filled from the roadmap, plans, answered questions and ADRs; agents are told the decisions that bear on their work and warned off what was already decided; a Decisions ring in Memory.
  • Architecture shows the organisation's reference architecture, standards and templates; the Scribe can follow a template; Open on the map lands on the thing.
  • Source Control for the whole project, organisation teams from the Teams view, copy any message, timelines rebuilt for work before the run log, and a clearer Teams header.
  • Graphify per its own guidance. One pinned engine per machine (old copies cleaned up), broken installs repair themselves, secrets and runtime files kept out of the graph, code-only updates between scheduled document reads, backups trimmed, and sharing the graph in git as a choice.
  • Fixes. CI green on Windows, macOS and Linux again; several waits that could hang or race.

0.41.1

  • Code blocks readable in dark mode. Plain-text boxes in the Library (and anywhere the Glass theme draws a code block) were dark grey on dark; they are light now.
  • Show on the map shows the links. A memory answer lights every result on the rings and draws how they connect, and to what, with everything else dimmed; pressing one result draws its own links and opens its details. Clear or Escape puts the rings back.
  • A new mark for the node. mojoup-node opens with the icon's circle and cube drawn as an amber outline in quadrant blocks, which the terminal draws itself, so it is clean in Windows Terminal and any font. On a terminal too narrow for it the banner is the three text lines alone.

0.41.0

  • Reports read as pages. Retrospectives, status reports, research and pages agents make open in the Library as designed pages, light and dark; Page / Source switches to the file; save as HTML, PDF, Markdown or OKF. Research pages number their sources and list them as references. Scheduled status reports land in the Library under a dated name.
  • Retrospectives that teach. What went well, what did not, and what we will change, from the board, reviews, timeline and risks; agent notes shortened to one line each. Act on any item: make a task (choose who does it and whether it lands on its own, as with the Scribe), add a line to Team guidelines, or keep it as a lesson agents read when they start. Opened from a card on the plan.
  • Timeline cards. Runs, agents, run time, tokens and cost as cards.
  • The rings' centre shows the architecture's own summary and only a real vision, as formatted text with Read more.
  • Architecture loads again on repositories whose descriptions grew long: one long description no longer drops the whole picture; it is shortened and flagged.
  • Credits. pixel-agents (MIT) and Graphify (Apache 2.0) now show their licences.

0.40.0

  • Rings are the Memory picture. The rings replace the old repository graph, with a switch for this repository, the whole project or your organisation. Explore opens them full screen with connection filters, zoom and the most-connected list. The Applications ring is now Tools.
  • The centre says what it is. Press the AI Workbench mark in the middle for what the repository, project or organisation is and where it is going, with when and by whom each was last updated; when nothing is written, ask the Scribe to write it. The Roadmap and Architecture views say when they were last updated too.
  • Your organisation, within your access. Organisation rings show your projects, the organisation's skills and tools and its memory topics. A personal project's agents can ask the organisation's knowledge as you; your project's memory still stays with you. Project notes say where a project's memory is kept.
  • Built-in engineering skills. Debugging, test-driven work, codebase design and prototyping skills (from Matt Pocock's skills, MIT) come built in. A team member's chosen skills now limit what it sees, and each team can have short Team guidelines.
  • Reviews, retrospectives and pull requests. Reviews report the repository's standards apart from the verdict; retrospectives propose fixes to how the team works, which you can turn into tasks; a pull request from a plan says how risky the merge is.
  • Who is stuck. Agents show Waiting for you, Stuck, or Finished, not yet reviewed; every finished task says why it closed; a handed-off task nobody picks up is chased, then passed to the team lead, then to you. Agent cards warn when an agent's context is nearly full, and automatic messages wait while you are typing to that agent.
  • Plans with care. Plans are cut into slices one agent can finish; shaping asks one decision at a time with a recommended answer; each plan step can be Quick, Standard or Careful; the roadmap keeps a list of rejected ideas. After a context reset an agent gets a short recap, and plan changes reach a running agent on its next turn.
  • The Library. Retrospectives, reports and artifacts have their own group, Open in the Library lands on the file, the file pane can be widened, templates are named by their front matter, documents and templates can be deleted, and your organisation or team can publish templates.
  • Faster, clearer loading. Source Control shows your branches before it checks the remote, and slow pictures show what they are loading, with Retry when it fails.
  • Fixes. Team dropdowns no longer cut off their values; a personal project's "Ask the organisation" asks the organisation; Plans no longer says "No plans yet" while loading.

0.39.0

  • Full screen. Architecture (the picture and "About this picture"), the Library, Timeline, Roadmap, Plans and Tasks have a full-screen control; Escape leaves it.
  • Back up and restore, and move machines. Settings → Back up & restore keeps your settings and each repository's chat history, plans and runs, matched by repository rather than by folder, so a restore onto a new WSL distro or a moved folder finds them again and only asks when unsure. Backups run on a schedule; signed in to your organisation, it keeps a copy for you. A repository that moved keeps its history.
  • Projects in your organisation match the workbench. A repository's committed project file now follows the project you put it in, so old personal projects stop coming back, and the ones you no longer use are offered for removal.
  • Acceptance before Unify. A plan waits for you to pass or fail its acceptance criteria before it closes, or to close it anyway with a reason. A plan closed with criteria unmet says so.
  • Plans that span repositories run there. A part of a plan for another repository goes to that repository's team and starts; work that depends on it waits, and the plan waits for it before closing.
  • Project memory. Agents are steered to the project's memory when a question crosses repositories, the planner reads it, and queued memory writes survive a restart. The Memory view lists the project's notes, lessons and decisions per repository.
  • Rings with depth. The Architecture and Roadmap rings in Memory show their top level; click a node to open what sits under it, with a breadcrumb and Back.

0.38.2

  • "Land it automatically" lands. A scribe task you asked to land on its own no longer waits in Review because the agent asked for a look, or because it finished with a text marker. Only work finished with concerns still waits for you.
  • Review buttons read as they are. Approve is the solid button; a line says why Request changes needs your feedback first.
  • Open in external editor on Windows no longer fails with "spawn … code ENOENT": the workbench runs VS Code's code.cmd, not the script beside it.

0.38.1

  • Your Copilot instructions file stays. Removing old graphify skill copies no longer deletes .github/copilot-instructions.md when graphify's section was all it held: that file is Copilot's instructions for the repository. Only the section is taken out, and only when the file holds other instructions too.

0.38.0

  • Open in external editor works again. From the Files pane and the editor's toolbar it now opens VS Code (or your chosen editor), including files in WSL. It had been opening the built-in editor.
  • Sandboxed nodes. A Linux node can run each agent session in its own NVIDIA OpenShell sandbox, with the network rules enforced and API keys kept out of the agent's reach. The node checks at start whether the machine can, and says why not. This needs a run on a native Linux node before it is relied on.
  • Routines on a node. A routine for a repository on a node is saved and run on that node; the Routines list says where each one runs. mojoup-node routines lists, runs and removes them.
  • Plans say what they produce. A brief asks whether the work should produce a document, changes, or both. A plan step can name the document it delivers, and an agent cannot approve the step until that document exists.
  • Memory. Lessons are kept as one item per repository at the project's home, a node only shows a peer what its clearance allows, and search finds "ledger" in a name like BillingLedger.
  • Fewer secrets on disk. Two access tokens moved out of the repository's .mojoup/ folder, and agents no longer inherit the workbench's own credentials. Hosted providers go through the local proxy, so agents get a stand-in key.
  • Smaller things. Publish a skill to your team from Settings → Skills; download artifacts from SSH and node machines; one artifacts panel in Research; the blocked-work routine comments on the project tasks it chases; risk dots on the roadmap board; a renamed project's new name reaches your organisation.

0.37.0

  • Risks and issues. A new Risks view keeps what may go wrong and what has, for a repository or the whole project, with a rating, an owner, a response and what each one threatens. Roadmap items and tasks it threatens carry a dot; a blocked task can raise an issue in one step; agents can read and raise them too.
  • Timeline. A new Timeline view shows when each agent worked, on what, for which plan, task and roadmap item, and who set it going: you, another agent, or a routine. It also appears in Plans, Roadmap, Tasks, Mission Control and the office.
  • Retrospectives and status reports. A finished plan gets a retrospective, and a status report covers a repository or the whole project over a week or a month. Both are Markdown or OKF from a template your repository can change, made by hand, by an agent or by a routine, and saved to the Library.
  • Artifacts. Chat, Research and Team Work list what a session made — a report, a document, a diagram, a table — with Open in the Library, Preview and Download. The composer's new "Make" choice says whether you want a document or changes to the project.
  • Secrets. Settings → Secrets keeps the keys and tokens your tools need, for this machine, the project, a repository or your team, and shows what each repository asks for. Your organisation can keep them too. Agents only see a secret that says they may; everything the workbench keeps is masked for credentials.
  • Tool servers. Settings → Tool servers shows every MCP server agents use and how it is governed. When your organisation asks to be asked first, an agent's tool call waits for you with Allow once, Allow for this task or Refuse.
  • Where agents may connect. Your organisation's network rules now apply to the built-in browser's pages and to tool servers reached by address.
  • Routines for the whole project. A routine can run for the whole project, with five new project templates and a weekly status report. The list says what each routine belongs to.
  • Ask the Scribe, whole project. It now asks whether to land the change or hold it for your review, and describes every repository first, so one ask draws the whole project.
  • A tidier board. Scribe and routine tasks leave the board an hour after they finish, done tasks after 14 days, and the Done column shows the latest eight. An agent's name on a card is no longer cut off.
  • One memory skill. The workbench no longer writes a graphify skill into your repository's .github and .copilot folders. Agents get a built-in memory skill instead, and your organisation or team can publish its own. Copies earlier versions left are offered for removal.
  • Renamed. Documents is now the Library, and Git is now Source Control.

On this page