Make MediaService correct on more than one pod, and run two
MediaService has only ever run a single replica, so a deploy of it was a total chat outage and an OOM was the same. It could not run two, for reasons that were ...
Bake the sign-in and sign-up logo overlays into config.json
kamo-login and kamo-register run on their own hosts with no OrgContext, so this file is the only route their branding takes - the same one KamoMeet already uses...
A logo overlay for the sign-in and sign-up sites
Two more columns in the vocabulary home_logo_overlay already established: a token, not a hex, so an org that rebrands keeps an overlay matching its new colours....
Answer the link in an address-change letter
/verify-email-change spends the token in a change-of-address letter and says what happened. It lives here rather than in the workspace because the letter goes t...
Change your own address, and a platform tab for every account
Two surfaces, joined by one distinction the platform has never explained to anybody: a user account is the PERSON, and a member is one organization's relationsh...
Add a queue-group subscribe, so work is shared rather than pinned to one pod
Companion to subscribeEphemeral. Two different jobs, two different consumers: subscribeEphemeral every pod must see every message (anything ending in a STO...
Add an ephemeral subscribe, so more than one pod can serve a conversation
A durable push consumer admits exactly ONE subscriber. The second pod to bind the same name is refused with [SUB-90012] Consumer is already bound to a subscript...
"What happened?" fills the window, so maximizing enlarges it
Every other field on the report form is sized by its content. The description is the one somebody is actually writing in, so it now takes whatever height is lef...
Change a personal address by proving it, and administer accounts
Two surfaces on the USER account, which until now had no server of its own — the account's fields were reachable only through MemberController, an endpoint scop...
The two reads the platform Users list is built on
A paged, searched finder over USERS, and a batched membership count. The finder is unfiltered by isFake on purpose. Reviewing and clearing that flag is part of...
Buzz a member's phone when mail arrives
MessageIndexer is already a durable consumer of email.inbox.> and already resolves the mailbox OWNER, so it is where this belongs — one notification per genuine...
An EMAIL type, and every push now names its org
EmailService raises the notification off IMAP IDLE and asks MediaService to deliver it through the internal dispatch endpoint that exists for exactly this — eve...
Preview variables for the two email-change letters
Both new canonical templates render in the console the moment this service is rebuilt onto the shared library that carries them; without a sampleVariables arm t...
A right for user accounts, and a parked address for changing one
Three additions, all of them the shared half of work that lands in SecurityService and kamo-internal. PlatformRightType.MANAGE_USERS, appended. A user account ...
Public rides the SEND TO AI row, and arms the hand-off for god
The Publish control was a bordered block of its own further down the form, carrying two lines of hint under the switch. It is now a compact toggle on the headin...
Gate Publish on god ELIGIBILITY, not an open window
The Publish flag shipped gated on godModeActive — GD plus a deliberately opened 30-minute break-glass window. Every god-eligible operator then found the switch ...
Ending a terminal takes its window and hexhead with it
Ending a terminal from the Interaction Center killed the shell and left the window behind, showing a red `closed` status over something that no longer exists. T...
Read a domain's live SPF record and say what it actually needs
GET /api/security/domains/{id}/spf, for the SPF step on /setup/dns. The setup page cannot give one set of SPF instructions to everybody, because the right inst...
Tell each domain what its SPF record actually needs
/setup/dns walked a customer through ownership, subdomains and SSL and then said nothing about the record that decides whether the mail we send for them is beli...
Copy your referral link from any public role
Referrals are the highest-converting channel a job board has, and what stops them here is friction rather than unwillingness: the careers site answers on a diff...
The CV reader, employee referral links, and the form shape on the public listing
Three things the public careers site needed from this service. The form shape now rides on the public listing (the twelve ask* settings, the additional-info pr...
Three public transactional templates, and the org patch keys behind them
The careers site now writes to people who have no account, which is new for this platform: every other transactional template goes to a member. Three canonical ...
Carry the application claim token across the register handoff
A candidate can now apply from the public careers site without an account. The application is stored against the email address they typed, and the receipt carri...
Benefits, the public funnel, the network opt-in, and claiming an application
Five changes, all of them the workspace half of something the public careers site now does. - Benefits & perks on the posting editor. It reaches the public adv...
A Publish switch on a god-mode bug report
An operator with an open god-mode window filing a bug or enhancement now gets a Publish switch. It is off when the window opens and does not remember its last p...
Let a god-mode operator file a system bug privately
Posting a report now offers a Publish switch to an operator with an open god-mode window. It defaults to off: the report stays with god mode until somebody rele...
The Publish flag on a system bug, and the query rule behind it
A system bug already crossed the tenancy line in one direction. This adds the second visibility rule on top of it: a report a god-mode operator filed privately ...
System_bug.published, defaulting to TRUE
The column behind the Publish flag: a god-mode operator can now file a report that stays with god mode until somebody releases it. DEFAULT TRUE is the whole re...
Apply-first, the job network, alerts, translation and retention
Eight things, all behind the anonymous careers surface, and all sharing the rules the single-org board already enforces rather than growing their own. APPLY-FI...
Make hr_job_application.member_id nullable
ddl-auto adds columns; it never relaxes constraints. Flipping optional=false to true on the entity changes what the ORM believes and nothing about what the data...
The schema behind apply-first, the network, alerts and retention
member_id on hr_job_application becomes NULLABLE, which is the whole of apply-first: five steps stood between pressing Apply and answering the first question, a...
Force KamoMobile Logout on a member's account activity
Force Logout deletes sessions, which ends a browser. It does not end a phone: KamoMobile holds a durable device token and mints a fresh session from it immediat...
Force KamoMobile Logout — revoke a member's mobile devices
Force-logout deletes *** sessions, which ends a browser. It does NOT end a phone: KamoMobile holds a durable device token and mints a fresh *** from it the mome...
A switch per platform registration, and bring-your-own on the org side
Each OAuth2 card on Platform Configuration → Advanced gets an enable/disable switch in its top-right corner. It writes only the enabled flag, is unavailable unt...
Teams Phone falls back to the org's own Entra app
The per-phone-server credentials still win — that is the most specific source. What changes is the fallback underneath them: the org's own MICROSOFT_TEAMS regis...
Resolve Canva, Meta, X and meeting credentials per organization
Every flow here now reads whichever app the org is on — its own registration if it brought one, otherwise Kamo's platform app. The Canva and Meta entry points ...
Resolve mailbox OAuth credentials per organization
Google, Microsoft 365 and Zoho mailbox connects now read whichever app the org is on — its own registration if it brought one, otherwise Kamo's platform app. T...
Org-side CRUD for an organization's own OAuth2 client
The org-scoped twin of PlatformOAuthClientController, behind **************** Same DTO shape, same encrypt-on-write, same never-return-a-secret rule, plus platf...
An organization can bring its own OAuth2 client
Until now the client id and secret for every OAuth provider came from one platform-wide registration, so an org could only connect what Kamo had registered — an...
A product gallery at /screenshots
A page for showing the product as it actually looks. It is built around a data module rather than markup, because more screenshots are coming and adding one sho...
Start one from the Interaction Center tab
The tab listed terminals and gave a member no way to open one — the only starting points were the Linux Desktop submenu and the navigator's header, neither of t...
Remember which job advert brought a candidate here
The public careers site links to /team?jobId=<uid>. Registration is several steps, crosses hosts and bounces through email verification, so the uid is parked in...
Publish an advert externally, and pick the candidate back up
Three changes, all in service of the new public job board at careers.<apex>. The posting editor gains "list on our public careers site". It sits with status an...
The anonymous API behind careers.<apex>
The public job board reads this. It is the only surface in Careers with no session, so the safety comes from the QUERY rather than from a rights check: PublicCa...
The two columns a public job board needs
publish_externally decides whether an advert reaches careers.<apex> at all. It is a separate axis from status: an internal-only posting is fully AVAILABLE and m...
Serve an org's branding from the host it is browsed on
A white-label sign-in screen is reached at login.<customer domain> with no ?org= on the URL and nothing in sessionStorage, so the front end has no way to name t...
Careers is a platform alias, not an org's own
OrgResolutionService.byHost reads a leading label that is not a known platform alias as an ORGANIZATION's alias within the domain behind it, so without this ent...
Footer Badges — a row of images under the signature
The Content tab's 'Footer Image' was one picture chosen from three fixed sources and sized by a percentage. It is now 'Footer Badges': the same three plus anyth...
Email_signature_badges, and the columns that order them
The footer badge library plus footer_badges / footer_badge_spacing / footer_badge_height on email_signature_templates. A runner and not just ddl-auto for the u...
A library of footer badges, and the row each scope prints
The signature footer went from one image to a row of them. The library is org-wide; the selection and its order are per scope, so an image uploaded while editin...
Like what you see shipping?
Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.