Hire-step owner URLs and sweep tuning in the SecurityService ConfigMap
Audit role and security changes; ARTIFICIAL template and AI floor in model endpoints
Member profile AI state, relabel locks, immediate rights recalculation and audit
A verification resend that names its account goes to the account's own org
An organization with no domain has no register host of its own, so its members land on register.<platform apex>, whose host names the platform. The resend endpo...
Internal routes for credentials, the exchange, the roster, profiles, the charter and the sweep
AI member state, pause/resume/retire and hiring checklist endpoints
Pause, resume and retire AI members; org pause-all; the platform kill switch
Hire AI members as seat-consuming team members with hire steps and no mail
Hire-step orchestrator with prerequisites, budget and replaceable handlers
One step's database failure no longer ends the sweep or a member's run: the step is logged and retried once due, and the steps behind it still run.
Accept either read-timeout message in the owner-client test
OkHttp arms the socket's SO_TIMEOUT ("Read timed out") and its own watchdog ("timeout") with the same 300 ms; either can fire first, so the assertion failed abo...
MANAGER step and remote clients for every owner hire step
MANAGER and the mailbox/extension copy-back write one column each with a conditional UPDATE (only while empty) instead of saving the member entity: the sweep's ...
Hire-step owner client with bounded timeouts that never throws
A final RuntimeException catch keeps the no-throw promise when the HTTP library rejects a URL before any I/O (a blank base URL leaves a relative one) or cannot ...
Hire-step store with claim, backoff record and retry
An outcome or a prerequisite wait lands only on a step that is still PENDING or WAITING, so a retire during an in-flight attempt keeps the step SKIPPED (SP02-T1...
Hire-step model, owner outcome mapping, backoff and the handler seam
AI members take and release a seat on the organization's primary plan
The claim never takes a spare row beyond the paid seat count (SP02-T17).
A hot reassign's first note creates the lead's stream linked to the lead
The stream is created for the lead, as the lead view's feed creates it, so its MEDIA_SESSION_POST row carries LEAD_ID and POST_CREATED goes to media.feed.lead.<...
A hot reassign requires its call note on the server, not only in the dialog
The Tasks tab is tasks — served by KBService, gated here like the lead itself
Pre-sized copies of every org logo beside the original
Every surface drew org logos from the original upload: 2.2 MB for crm's full logo at a 30-56px nav/header, 2.95 MB (its .svg stand-in) in the email composer, 4....
Own NATS login, Redis login, KamoAI secret; host the LOS webhook worker
Capabilities come from the shared seat rule the servers enforce
EntitlementService reads the seat facts and asks SeatCapabilityRules for the decision, then maps it onto the unchanged MemberCapabilities wire shape, so the con...
Point loan officers at the card they will actually find — Lender credentials
Both the MeridianLink and the Arive 'officer not linked' refusals named cards that no longer exist under those titles.
Layout choices, and saving contact details as they go
The publish dialog now chooses how the public mortgage application lays itself out (kamo-shared-library ac83bea1): NORMAL or SQUEEZE, contact details at the STA...
Arive through Zapier — connection, inbound events, and per-lead actions
A market bound to Arive gets a connection (four Zapier Catch Hooks for create-loan, update-loan, update-lead and convert-lead, plus one inbound URL whose token ...
Start a coder session in the cloud, and say which terminals are
repository as cwd) and answers `cloud: true`; the machine builds the a cloud session can start from. The terminal listing carries the agent's `cloud` mark throu...
The forgot-password hint is the account's address, whatever it is
d7ff5ed called the address on the user account "personal" everywhere: in the 409's message, the response field and the class. It is not always personal. An admi...
A work address on forgot-password asks for the account's own, shown masked
Members open their account with a personal address (gmail, yahoo) and are later given a work address by their organization, which is the one they remember and t...
Add per-org primary application: toggle endpoint + by-host lookup
PUT **************** designates (or clears) a product's published application as the org's primary, mirroring the existing mlos-default single-active toggle. Ne...
DKIM and DMARC advisory endpoints for /setup/dns
Adds two endpoints alongside the existing SPF one, so an org's transactional mail (password resets, invitations, notifications) can carry a DKIM signature and t...
Rename apps DNS alias to apply
The apps.* host serves the loan-application and patient-portal pages (kamo-apps), not app downloads, so rename the alias everywhere it is enumerated: KnownAlias...
Computers is a standard alias, and the link uses the org's own
Every white-label org points a fixed set of labels at Kamo and computers was not one of them, so an org could follow /setup/dns to the letter and still have a H...
Maintain commit_logs.translation_count at write time
DDL: **************** (column + partial-friendly index, applied to production already) and **************** (one-time catch-up, already run — 19,373 rows, all l...
Use the lean LeadVendorProduct reads, not the 8-way eager findById
Caller half of the kamo-shared-library fix: switches every findById() call on LeadVendorProductRepository in securityservice to whichever lean method matches wh...
List only the Getting Started steps an organization is asked
An organization whose security model fixes every Compliance answer (no product a member may switch, one age range for each member type) was still counted agains...
Read the public changelog's commit counts from a ledger, not COUNT(*)
pg_stat_statements: `SELECT COUNT(c) FROM CommitLog c WHERE c.project IN (:~33 public projects) [AND c.commitTypeId = :t]` ran ~140K times a day at 100-200 ms e...
Gift cards take the Discounts tab's pricing rights
Listing gift cards, issuing one and editing one (including its balance, which the shared library sets again as of the companion kamo-shared-library commit) chec...
A member's official title and status need member security too, on their own record
Department and job title already needed MANAGE_MEMBER_SECURITY (or an open god window) on /member-security, your own record included. The rest of the Position c...
CommerceMarketController's retail sub-resources are org-scoped
CommerceMarketController's get-one/update/delete handlers under /retail/... called RetailService methods that took no orgId (bare findById/deleteById) - a same-...
Drop 4 newly-guarded handlers from the unguarded-endpoints ratchet
**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), ...
Scope roles, member access and profile writes to the caller's org
Five gaps let a signed-in member reach outside their own organization, or reach a colleague's account, with no right check: - **************** resolved no sess...
An entry page reads three rows, not the whole public changelog
pg_stat_statements put the public changelog's single-entry reads at the top of the database by a distance: the slug lookup and the two neighbour lookups ran ~90...
Forward the actor when relaying a commission line
addLine/updateLine relayed memberId (normalized to Long in 789c544) but never who was making the call — unlike openDraft, send, voidLine and every Stripe-config...
Forward subjectMemberId and role so TimecardService can verify punch ownership
**************** resolved the caller's role against a CLIENT-SUPPLIED subjectMemberId (resolveRole -> EMPLOYEE whenever actor==subject) but never forwarded that...
Adding people and member security need their rights
POST /members/create, /create-team-member and /bulk-create, and GET /members/lookup-user, now require MANAGE_MEMBERS or an open god window. They checked only fo...
Scrub copies of live credentials from config and dumps
A sweep of every repo for the values of the cluster's live Secrets (2026-09-23) found copies here: the JWT signing secret as a `${JWT_SECRET:<literal>}` default...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
