Two quick toggles sent overlapping saves that could land out of order, and a
failed first save put back a list without the second choice. The choices
now lock while a save is in flight.
Each tool's Customize link is described by the tool's name. The partial
badge reads "Not all via API". When the agent has no API key yet, the
note under What this agent uses says Access Details lists the changes
once it has one.
Tool tiles keep the caller's own In my chats switch, with the same
visibility and revert-on-failure as before, but without the label text
beside it; screen readers still get its name. A connected tool whose
connection needs signing in again has Sign in again in its menu, and a
paused synced source has Reconnect on its tile, both for the reader's own
connection and in place where the wizard can do it.
Connect your data no longer closes the dialog and navigates away, which
lost an unsaved agent or chat draft. It lists the services that sync,
one per service and in the Connectors page's order (catalog helpers now
shared with that page), and picking one opens the connect wizard in
place for Knowledge, with a Back to the source types. Only the Knowledge
page adds a Browse all connectors link. The tile's description leaves
out GitHub, which has its own tile.
Nothing opens the Google Drive, SharePoint, Confluence, S3 or Reddit
forms in Add knowledge any more: those services sync through the connect
wizard. Their pickers, saved-key account logic, setup notice, advanced
fields and strings go, and the remote upload sends the form's own
fields.
The tile names up to three services this instance can sync (then "and
more"), rather than services it may not offer, and spans the grid's
width so its line doesn't wrap into a tall tile.
The source picker lists what needs no account (upload, URL, crawler,
GitHub, wiki) and one tile that opens the Connectors page on the services
that sync, in place of a tile per connection under two headings. GitHub
keeps its hand-over to connecting an account for private repositories.
Tool cards no longer carry the In my chats switch; the chat's Tools
picker (and a connection's drawer) still sets it, for the same tools. The
Manage connection item goes from tool and source menus, with the
in-place connection drawer on Tools: connections are managed on the
Connectors page. The owner's connected tool keeps Share and Delete; a
teammate's still opens the tool editor.
A connector's Allow is the in-chat permission; changes through an
agent's API, widget or public link need the agent's own allowlist. The
badge in "What this agent uses" now reads "Not via API", its note says
where Allow applies, and for the owner it opens Access details with the
allowlist unfolded. The connector permission hint says the same.
Access details now shows the actions API, widget and public-link users
may take as the owner as a collapsed section with a summary line (which
tools can make changes, how many of all are allowed). Open, each tool has
one Off / All choice with its actions one by one under Customize, like a
connector's permissions. Entries and saving are unchanged.
people_named_to decides whom the edit page and the share dialog name:
the reader, the holder's owner, anyone sharing a team with the reader and,
for the owner, whoever sponsored something on the holder. A resource's
owner, named as whom to ask or whose credentials a tool uses, also needs
the reader to see that resource. Sponsors, runs_as, contact and account
in resource_states and sponsors in sponsor_details all follow it; anyone
else is left unnamed and the pages say someone else.
A tool's run details (note, credential_mode, account, writes) come from
one function and only for a tool that runs. The share dialog keys each
person's own account on the per_user_account note, as the notice does,
and the unused noteKey helper and its string are gone.
Only removing a connection notes it on a kept tool. A config save through
update_tool or update_tool_config carries the stored note and ignores the
client's copy, so it can neither fake nor clear it; creating a tool, an
MCP server save and an agent import start without one. The note is now
written even for a connection with no catalog key, and a kept tool its
owner gave credentials of its own since runs again.
When the read doesn't name whom to ask, the notice asks the item's owner
without naming them. Items the reader may not see show their kind and a
short id instead of "Unnamed item". The workflow canvas notice fits narrow
screens, and closing it leaves a chip with the number of items not running
that opens it again.
A member-mode tool runs on each caller's own account, so the owner's
account no longer marks it stopped: it is active with the note
per_user_account, and only an admin turning its service off stops it.
connection_removed now needs the note remove_connection leaves on a kept
tool, so a tool that never had a connection (a tokenless ntfy) runs.
Whom to ask is contact_role resource_owner; contact names them only when
the reader can see the resource or they own the holder. connection carries
its id only with can_reconnect and the account's own name only for its
owner. Run state and audience are best effort (a failure logs and leaves
them out of the read), resolve answers are cached for the rest of a read,
and a workflow read names node resources by the run state's own names.
The table adds tools with saved credentials, says API and widget users
get the owner's account on a tool each person connects, that a sponsored
item runs as the owner again once the owner can use it, and that a
teammate's name shows only to people who share a team with them. The
editor switches are named per resource type, public-link users are said
to be asked only for writes that need approval, the allowlist is said to
cover sponsored and workflow node tools, and the badge names and the new
resource_states fields match the app.
The share dialog's list now follows who an item runs as now (runs_as),
not a sponsor on record, and names whose saved credentials a tool
without a connection uses. A tool each person connects says API and
widget users get the owner's account, and a tool whose owner the reader
shares no team with says it's someone else's. Badges say whether all or
some of a tool's writes are off for API use, or that an admin turned
changes off. The note names only API and widget users for tools each
person connects, since public-link users use their own account there.
The API write allowlist now builds its choices from the agent's
resource_states, so it offers tools an editor sponsored and a workflow
agent's node tools as well as the owner's own; the owner's tool list only
adds action descriptions. Both read the agent through one shared hook.
resource_states gains runs_as, the live sponsor a running item runs as
(None once the owner can use it, even with a sponsor on record), and
writes_allowed, False when an admin turned off changes through the
tool's connector (its writes are then not listed for the allowlist).
account now also names the owner of an API tool's saved key, a signed-in
MCP server or stored secrets, not only of an owner-mode connection, and
only to a reader who shares a team with that person. A running tool's
connection id is no longer sent.
A new "Sharing agents and what they use" section covers viewers and
editors, whose access each tool, source and prompt runs with as the share
dialog labels it, sponsors, stopped resources, what API, widget and
public-link users can't do without the write allowlist, the wiki switch
and research steps. The sharing rules now mention the editor switches and
member-mode tools, the guardrails page no longer says editors can't
change guardrails, the connector guide uses the new tool share labels,
and related pages link to the section.
The agent share dialog gains a collapsed "What this agent uses" section:
each attached tool, source and prompt, and a workflow agent's node tools
and sources, with whose access it runs with (your access, a sponsor's, the
owner's, your or someone's service account, or each person's own).
Stopped items are marked with why they stopped, and the section opens by
itself when one did. Tools with writes on stored credentials that aren't
in the API write allowlist are marked, with a note that API, widget and
public-link users can't make those changes until they're allowed in
Access Details. Only owners and editors get the data it reads.
A tool's share dialog uses the same words: "Your account" or "Each
person's own", and "The owner's account" for an editor who may share it.
resource_states now carries, for a running tool, its credential mode when
it has a connection (after any mode an admin forces), whose account an
owner-mode connection acts as, and the write actions it takes on
credentials its owner stored, which API, widget and public-link users can
run only from the agent's API write allowlist. The service of a connected
tool is named whether it runs or not. Still only for people who may edit
the agent or workflow.
The agent page shows one notice in place of the sponsored-resources one:
who added what runs with their access, and every attached tool, source or
prompt that stopped, with the reason in plain words and what the reader
can do. Reconnect signs the account in again in place, Run it with my
access now asks first in the sponsor dialog naming who reaches the agent
and is sent with the next save, Remove takes the item off the form, and
when the reader can't fix it the notice says whom to ask.
The workflow builder shows the same notice over the canvas for its node
tools and sources, with take-over sent on the next save and Remove taking
the item off every agent node.
The agent and workflow reads now return resource_states to people who may
edit them: every attached tool, source and prompt (and workflow node tool
and source) with active or stopped and the reason: deleted,
owner_lost_access, the sponsor reasons, connection_needs_reconnect,
connection_removed or connector_disabled. Each entry names the sponsor,
someone other than the reader who can fix it, the service for a connection
reason, and whether the reader may take it over or reconnect it. When
something can be taken over, sponsor_audience says who it would reach.
The state comes from the checks the run itself uses (ref_access,
resolve_holder_tool and the tool's connection as the run resolves it), so
the page and the run can't disagree. A run that leaves a resource out logs
resource_stopped with the holder, type, id and reason.
The workflow read gives sponsor details, run state and node resource names
only to people who may edit it, and names only resources the workflow runs,
someone sponsored, or the reader can see. Owner saves and new workflows
now refuse node tools and sources the owner can't use, like editor saves.
The sponsored-resources notice now says why each item stopped (the person
can no longer edit the agent, or can no longer edit the item) and offers
"Run it with my access" for items the reader may sponsor; the next save
sends that confirmation. Saves go through one confirmation round trip
shared by the agent form and the workflow builder, so the details sheet
closes on a confirmed save and stays open without an error when the
editor declines. An outdated confirmation shows a translated message and
reloads the sponsor details. The tool picker forgets a removed tool's row
once the removal is saved, and workflow node pickers keep a remove-only
option for the owner's private tools and sources.
A resource attached in a save now ignores any sponsor recorded for it
before it was removed: the caller must be able to sponsor it and confirm.
YAML import prunes the sponsors of resources it drops, for agents and
workflow graphs. Sponsor details, with the resources' names, go only to
people who may edit the agent. The workflow read returns the names of
every node tool and source, so editors can remove the owner's private
ones. An agent image is stored only once the save is known to go ahead.
Research steps ran each tool call straight through the executor, never
asking check_pause, so approval-gated actions (including a public-link
visitor's wiki edits) and an outside caller's writes on the owner's
accounts ran unchecked. A step can't pause, so it now checks each call
first and answers any pause with a refusal the model reads, journaled
like a headless denial. Headless and research runs share the journaling.
Public-link visitors edit only wikis they can edit themselves and approve
each edit. The docs also note that with authentication off every caller
is the owner's local user, so the switch has no effect there.
A paused turn is found by the agent owner's id, so anyone holding one of
the owner's agent keys could resume the owner's own chat with its saved
wiki edit rights. A resume now counts as an API or widget caller when
either the saved state or the resuming request is one, cuts the wiki tool
to wiki_view unless the wiki allows outside edits, and gives the tool
executor the same flags. A request that names an agent, by key or id, may
only resume that agent's turn; otherwise the claim is released and the
request refused.
Public-link visitors run as themselves and reach only wikis they may edit,
so the wiki switch no longer applies to them. Instead every wiki write in
a public-link run waits for the visitor's approval, so the agent owner's
prompt or sources can't steer an edit to the visitor's wiki unasked.
Saving an agent or workflow that the server refuses with
sponsor_confirmation_required opens a dialog naming each tool, source or
prompt and who reaches it through the agent (its teams, API key and
widget, public link, webhook), then saves again with confirm_sponsor. A
save the caller may not sponsor shows why instead of the raw message.
The tool picker adds a remove-only row for each attached tool the editor
can't list, so the owner's private tools can be taken off the agent.
Sponsoring a tool, source or prompt the agent's owner can't use now takes
owning it or having edit access to it; use access alone no longer extends it
to the agent's audience. A save that would make the caller a new sponsor is
refused with 409 sponsor_confirmation_required (the resources and the
agent's audience) until it is retried with confirm_sponsor listing them.
When a sponsor loses access, the resource stops instead of passing to
whoever saves next; another editor takes it over only by confirming.
Workflows follow the same rules. sponsor_details now reports each
sponsorship's state, the reason it stopped, and whether the reader can
take it over.
A wiki's owner gets a Wiki settings item in the source's menu. It opens a
dialog with one switch, "Let API, widget and public-link users edit this
wiki", which saves at once and flips back if the server refuses. Editors
and viewers don't get the item; anyone without manage_settings who reaches
the dialog sees the switch read-only.
A run from an agent's API key or widget acts as the agent's owner, so it
could rewrite any wiki the owner can edit. A new per-wiki setting,
wiki_outside_edits (off by default), decides whether such runs, and runs
from the agent's public link, get the wiki's edit actions. While it is off
they are offered only wiki_view, and the tool refuses writes itself after
reading the live setting. The owner changes it through the owner-only
/api/sources/<id>/wiki/settings route; tokens can read it but not change it.
It covers writes on any credentials the owner holds, for API-key and
widget callers, public-link users and the schedules they set, not only
connected accounts reached with the API key.
The owner sets a webhook up and its URL is a secret, and a webhook run
already refuses every action that needs approval, so holding it to the
API write allowlist only broke the owner's own automations. Webhook runs
no longer count as external callers; schedules keep their caller rules.
The allowlist copy no longer names webhooks.
Every API tool counted as holding the owner's credentials, so outside
callers were refused any write on one even when it sends nothing the
owner stored. Now an action counts only when its headers or query
parameters carry a saved value (sealed or legacy plaintext) or the tool
stores credentials; the allowlist lists just those writes.
The answer routes refuse such a request with 401, but only after building
the agent, so a public agent's prompt tools were pre-fetched, and their
actions run, for nobody. Anonymous chat without an agent key is not
supported, so the processor now stops before any setup and the route
answers 401 as before.
A scheduled or webhook run acts as the agent's owner with no one to
approve, so a public-link user or API-key caller could have the agent
schedule a write and have it run on the owner's accounts. Runs now keep
the caller's rules: a schedule set by someone who reaches the agent only
by its public link runs as a public-link caller, one set through the API
(recorded as created_via 'api', migration 0042) and every webhook run as
an external caller, each with the agent's API write allowlist.