Goal: Build an all-in-one agent platform for Global × China enterprises — delivered through three progressive modes: Standalone (portal assistant), Copilot (embedded in host system), Hub (central cross-system orchestration). Principles: Provider-agnostic (no vendor lock-in), minimal-abstraction, protocol-first, connector-first (integration is the core value).
Produktvision
FIM One ist eine All-in-One-Agent-Plattform, die drei progressive Liefermodi bietet:Bekannte Probleme
Nachverfolgter Bugs, die in der Produktion reproduzierbar sind, aber noch nicht behoben wurden. Jeder Eintrag nennt das Symptom, den vermuteten Bereich und die Workaround (falls vorhanden). Elemente werden in einen Versionsabschnitt verschoben, sobald eine Behebung geplant und terminiert ist.- Playground-Stopp-und-Wiederholung zeigt vorübergehende visuelle Artefakte, die ein Seitenaktualisierung immer behebt. Drei gleichzeitige Render-Quellen —
activeConversation.messages(DB-Snapshot), der SSE-messages-Stream und der optimistischependingQuery-Platzhalter — werden nicht in einen einzelnen abgeleiteten Zustand zusammengefasst, sodass zwischen dem Klicken auf „Wiederholen” und der Ankunft der gepaarten Assistentantwort die Benutzeroberfläche (a) kurzzeitig dieselbe Abfrage zweimal im Pre-Stream-Fenster rendern kann, (b) vorherige verwaiste Benutzerblasen aus dem Wiederholungsverlauf löschen kann, währendhasLiveMessageswahr ist und bevor der Snapshot neu geladen wird, und (c) im engen Fenster zwischen dem SSE-„done”-Ereignis und der nächstenselectConversation-Aktualisierung flackern kann. Daten gehen niemals verloren — jede Benutzernachricht (einschließlich abgebrochener Wiederholungen) wird inconversation.messagesbeibehalten, übernormalize_alternating_messagesin den nächsten LLM-Aufruf übernommen und nach der Aktualisierung überHistoryTurn.orphanUserContents(eingeführt in der Render-Behebung48ba08c6) korrekt gerendert. Zum Kontext: Claudes eigene Web-Benutzeroberfläche weist eine analoge Klasse von Bugs auf — das Stoppen mitten in einer Antwort und das sofortige Senden einer Folgeanfrage verzweigt die Folgeanfrage manchmal als Geschwister-Bearbeitungszweig der ersten Abfrage, anstatt sie als neue Runde anzuhängen — daher ist dies ein bekanntes schwieriges Problem in optimistischen UI + SSE + persistierten Verlaufsdesigns, kein FIM-One-spezifischer Defekt. Eine ordnungsgemäße Behebung erfordert das Zusammenfassen der drei Render-Quellen in einen einzelnen abgeleiteten Zustand; aufgeschoben bis zu einer umfassenderen Playground-Zustandsmaschinen-Umgestaltung.
Backlog (Low Priority)
Aufgeschobene Härtung — nicht blockierend; nur aufgreifen, wenn das entsprechende Szenario auftritt.- DAG evidence gets its own truncation budget, decoupled from
DAG_ANALYZER_TRUNCATION, so source evidence isn’t re-clipped by the summary budget before the analyzer/synthesis verify against it. - Structure-aware evidence truncation (head+tail / keep lists & tables) so long enumerations survive the cap instead of silently losing their tail.
- Port the source-fidelity guideline into the ReAct fallback synthesis prompt so total/severity mislabels are caught in ReAct too, not only in DAG.
Shipped Versions
v0.1 (2026-02-22) — MVP: ReAct + DAG Planner
- ReActAgent mit Tools (calculator, python_exec, web_search)
- DAG Planner (LLM generiert Abhängigkeitsgraphen)
- Portal UI mit Streaming + KaTeX
v0.2 (2026-02-24) — Multi-Model + Memory
- Retry / rate limiting / usage tracking
- Native function calling (no JSON-only parsing)
- Multi-model support (fast + main LLM)
- Memory: WindowMemory, SummaryMemory
- FastAPI backend with SSE streaming
v0.3 (2026-02-25) — Web Tools + MCP
- Web tools (web_search, web_fetch) via Jina/Tavily/Brave
- File operations tool
- MCP client (standard tool integration)
- Tool auto-discovery + categories
- DAG visualization with click-to-scroll
- Code exec in Docker (
--network=none)
v0.4 (2026-02-25) — Multi-Turn + Agents
- Mehrturn-Gespräche (DbMemory)
- Tool-Schritt-Faltungs-UI
- HTTP-Anfrage- und Shell-Exec-Tools
- Agent-Verwaltung (erstellen, konfigurieren, veröffentlichen)
- JWT-Authentifizierung
- Pro-Agent-Ausführungsmodus + Temperaturkontrolle
v0.5 (2026-02-28) — Full RAG + Grounded Gen
- Full RAG pipeline (embedding + vector store + FTS + RRF + reranker)
- Grounded Generation (citations, confidence scores)
- Knowledge base document management (CRUD, search, retry, schema migration)
- ContextGuard + pinned messages (token budget manager)
- DbMemory persistence + LLM Compact
- DAG Re-Planning (up to 3 rounds)
v0.6 (2026-03-01) — Connector Platform
- Connector CRUD: create, read, update, delete
- ConnectorToolAdapter: converts Connector → BaseTool
- Per-user credentials: AES-GCM encryption
- Confirmation gate: write operation approval
- Audit logging: all tool calls recorded
- Circuit breaker: graceful degradation on failures
- Utility tools: email_send, json_transform, template_render, text_utils
- Embedding options: Jina, OpenAI, custom providers
v0.7 (2026-03-06) — Admin Platform + Multi-Tenant
- Admin Platform: Benutzerverwaltung, Rollenwechsel, Passwort-Zurücksetzen, Konto aktivieren/deaktivieren
- Nur-auf-Einladung-Registrierung: drei Modi (offen/Einladung/deaktiviert) + Einladungscode CRUD
- Speicherverwaltung: Speichernutzung pro Benutzer, Löschen, verwaiste Bereinigung
- Gesprächsmoderation: Admin-Liste/Löschen aller
- Erzwungenes Logout pro Benutzer: alle Token widerrufen
- API-Gesundheits-Dashboard: Systemstatistiken, Connector-Metriken
- Assistent für erste Einrichtung: geführte Admin-Kontoerstellung
- Persönliches Zentrum: globale Anweisungen pro Benutzer, Spracheinstellung
- JWT auth: Token-basierte SSE-Authentifizierung, Gesprächseigentümerschaft
- Globale MCP-Server: von Admin bereitgestellt, in allen Sitzungen geladen
- Rückwärtskompatibilität: registration_enabled → registration_mode automatische Migration
v0.7.x (2026-03-07 to 2026-03-12) — Stability + Refinements
- Invite code management
- Per-user quotas (429 enforcement)
- Structured audit logging
- Sensitive word filtering
- Admin login history
- Admin file browser
- Enhanced admin views (model_name, tools, kb_ids fields)
- Docker Compose deployment (single image, named volumes)
- OAuth auto-detection from window.location
- Extended thinking / reasoning support (
LLM_REASONING_EFFORT,LLM_REASONING_BUDGET_TOKENS) for OpenAI o-series, Gemini 2.5+, Claude - Admin per-tool enable/disable (disabled tools excluded from chat at runtime)
- MCP servers management moved to Connectors page
- Dual database support: SQLite (zero-config default) + PostgreSQL (production); Docker Compose auto-provisions PostgreSQL
- Models configuration documentation page with extended thinking setup per provider
- SSE Protocol v2: real-time answer streaming with
delta_reasoning,usagefields, and splitdone/suggestions/title/endevents; SQLite pool size 5 -> 20 - AI Builder expansion: 7 new builder tools (GetSettings, TestConnection, ImportOpenAPI for connectors; ListConnectors, AddConnector, RemoveConnector, SetModel for agents),
is_builderflag on agents, builder prompt auto-refresh, SSRF guard - SSE v2 frontend: streaming dot-pulse cursor, DAG re-plan round snapshots as collapsible cards, DAG layout decoupled from step states
- AI Builder concept documentation page with connector and agent builder guides
- Organization system: full CRUD with role-based membership (owner/admin/member), admin management UI
- Three-tier resource visibility (personal/org/global) for agents, connectors, knowledge bases, MCP servers
- Publish/unpublish API for all resource types; owner delegation for published agents
- Admin set-visibility endpoint (replaces clone-to-global); unified
build_visibility_filter()query helper - Database Connectors (Phase 1-3): direct SQL access to PG/MySQL/Oracle/SQL Server + Chinese legacy DBs; schema introspection, AI annotation, read-only query execution, encrypted credentials, 3 tools per connector (
list_tables,describe_table,query) - Evaluation Center: quantitative agent quality benchmarking — test dataset CRUD (prompt + expected behavior + assertions), eval runs (parallel execution + LLM grader + per-case pass/fail/latency/token results), results viewer with auto-polling; migration
r8t0v2x4z567 - Three model roles (General/Fast/Reasoning) with per-tier env config isolation; fast model no longer inherits main model settings
StepOutputdataclass replacing plain string step results for structured data and artifact passing- Tool cache for DAG execution — identical tool calls cached per-run with async lock stampede prevention (
DAG_TOOL_CACHE) - Per-step LLM verification with 1 retry on failure (
DAG_STEP_VERIFICATION) - Auto-routing: fast LLM classifies queries as ReAct or DAG;
/api/autoendpoint; frontend 3-way mode toggle (AUTO_ROUTING) -
Shadow Market Organization + Resource Subscriptions: Built-in Market org (shadow, no auto-join) replaces Platform org; resources discovered via marketplace browsing and explicitly subscribed (pull model); Market API for subscribing to shared resources; publish-to-Market always requires review; Resource subscriptions table; org-based resource sharing replacing global visibility -
Agent Auto-discovery and Sub-agent Binding:discoverableflag on agents;sub_agent_idswhitelist; CallAgentTool for delegating tasks to specialist agents -
MCP Server Credentials + Per-User Override:mcp_server_credentialstable;PUT /api/mcp-servers/{id}/my-credentialsendpoint;allow_fallbackflag for credential fallback behavior -
Connector/KB Toggle:POST /api/connectors/{id}/toggleandPOST /api/knowledge-bases/{id}/togglefor suspending/resuming resources -
Standalone KB Conversations:kb_idsfield on conversations for direct KB chat without agent binding
v0.8 (2026-03-20) — Connector Declarative Config + Progressive Disclosure
- Database connectors: direct SQL access (PostgreSQL, MySQL, Oracle) (shipped in v0.7.x — Phase 1-3)
- RBAC: per-user/role connector access control (shipped in v0.7.x — org system + three-tier visibility)
- Connector credential encryption + per-user override:
connector_credentialstable, Fernet encryption viaCREDENTIAL_ENCRYPTION_KEY,allow_fallbackflag,GET/PUT/DELETE /my-credentialsendpoints, per-user credential resolution in chat tool loading - Publish review UI: Org-level publish review system — review toggle per org, ReviewsSheet with approve/reject workflow, status badges on resource cards, review notice in publish dialog, resubmit for rejected resources
- Connector Progressive Disclosure (Phase 1-2): single
ConnectorMetaToolreplaces per-action tools; system prompt receives lightweight stubs only (name + 1-line description, ~30 tokens/connector vs ~250 tokens/action); agent callsdiscover(connector)to load full action schema on demand — schema only loads when the model selects a connector, keeping the prompt prefix stable for caching. Follows the deferred tool-loading pattern common in modern agent frameworks.executesubcommand; feature flag for backward compatibility. - Agent Skill System + Compact Instructions: On-demand skill loading for agent instructions —
Skillmodel (name, content/SOP, optional scripts) attached to agents; referenced in system prompt by name only (~10 tokens/skill); agent callsread_skill(name)to load full content on demand. Reduces per-conversation instruction token cost by ~80% while allowing richer SOP libraries. Counterpart to ConnectorMetaTool’s progressive disclosure applied at the instruction level. Enables the “指令 + 工具 + 技能” differentiation story. Also addscompact_instructionsfield to Agent model — per-agent compression priority list injected intoContextGuardwhen compacting (e.g., “preserve order IDs and amounts, drop raw API responses”), replacing the current static generic prompt. Follows the Compact Instructions convention widely adopted in modern agent frameworks. - Connector import/export: share connector templates
- Connector fork: clone + customize existing connectors
- Workflow Phase 2 Nodes: Iterator, Loop, VariableAggregator, ParameterExtractor, ListOperation, Transform, DocumentExtractor, QuestionUnderstanding, HumanIntervention — 9 advanced node types with full frontend + backend + 150 new tests (275 total). Node retry with exponential backoff, safe expression evaluation. Stats panel with success rate bar. 12 built-in templates. Pane context menu (Paste, Select All, Fit View, Auto Layout).
- Workflow Phase 3 Nodes: SubWorkflow + ENV — 2 new node types (25 nodes total), 14 new tests (306 total), 14 built-in templates. SubWorkflow: full DB-backed nested workflow executor with target workflow selection, variable mapping, and configurable depth limit to prevent infinite recursion. ENV: reads encrypted environment variables with key picker and fallback defaults. Full frontend (node components, config panels, palette entries, minimap colors). Per-node execution statistics panel (success rates, durations, failure counts sorted worst-first).
getNodeStatsAPI client +NodeStatEntrytype. Keyboard shortcuts dialog (?key). - Workflow Scheduled Triggers: Per-workflow cron configuration with timezone, default inputs, and next-run-at calculation. Preset cron buttons, 30 trigger tests.
- Workflow API Triggers: Public per-workflow API keys (
wf_prefix) for external execution without user auth, with rate limiting. API key management dialog with generate/regenerate/revoke, trigger URL, and cURL/JS examples. - Workflow Batch Execution:
POST /batch-runwith up to 100 input sets, configurable parallelism (1-10), collapsible per-item results, JSON export. 14 batch execution tests. - Workflow Execution Log Viewer: Real-time chronological SSE event stream in the run panel with timestamps, color-coded badges, and event type filter toggles.
- Workflow Run Stats: Backend batch-fetches run counts and success rates via GROUP BY subquery; frontend displays stats on workflow cards with color-coded success rate indicators.
- Workflow Scheduler Daemon: Background async service polling every 60s for due cron-based workflows. Croniter timezone support, semaphore concurrency,
last_scheduled_attracking, webhook delivery. 14 tests. - Workflow Import Conflict Resolver: Detects unresolved agent/connector/KB/MCP references during import. Batch DB queries with visibility filtering, frontend toast warnings. 17 tests.
- Workflow Test-Node Execution: Isolated single-node testing with mock variables, integrated into editor (config panel Test button + context menu). 23 tests.
- Workflow Version Diff: Side-by-side blueprint comparison with node/edge change detection, color-coded indicators (added/removed/modified).
- Workflow Run Management: Delete individual runs (
DELETE /runs/{run_id}) and clear all completed runs (DELETE /runs), with frontend confirmation dialogs. - Workflow Run Replay Overlay: “View on Canvas” button in run history to overlay past execution results on the canvas, showing per-node status and output without re-executing.
- Workflow Favorites/Pinning: Star/pin workflows to the top of the list with localStorage persistence.
- Workflow Run History Export: Export run history as JSON file download with full run metadata and per-node results.
- Admin Workflows Management: Admin panel tab for managing all workflows across users — list, toggle active/inactive, delete with confirmation. Batch endpoints for delete, toggle, and publish with audit logging.
- Workflow Templates System:
WorkflowTemplateORM model with admin CRUD, public listing/clone API, and 5 seed templates auto-inserted on first startup. - Workflow Inline Validation Badges: Real-time per-node
ValidationBadgeon canvas with error/warning tooltips for immediate visual feedback during editing. - Workflow Execution Trace Viewer: Timeline-based trace viewer Sheet with engine
trace_levelparameter and per-node variable snapshots for step-through debugging. - Workflow Rate Limiting and Timeout: Per-user
WorkflowRateLimiter(sliding window 10 runs/min, 3 concurrent) and default 10-minute global run timeout. - Workflow Blueprint System: Visual workflow editor for designing and executing multi-step automation blueprints —
Workflow/WorkflowRunORM models, full CRUD + SSE execution API, import/export, duplicate, blueprint validation endpoint,WorkflowEnginewith topological sort + semaphore-based concurrency + condition branching and 12 node types (Start, End, LLM, ConditionBranch, QuestionClassifier, Agent, KnowledgeRetrieval, Connector, HTTPRequest, VariableAssign, TemplateTransform, CodeExecution),VariableStorewith{{node_id.output}}interpolation andenv.*namespace, error strategies per node (STOP_WORKFLOW / CONTINUE / FAIL_BRANCH) with per-node timeout and advanced config UI, React Flow v12 visual editor with drag-and-drop palette + node config panel + variable picker combobox + add-node-on-edge + auto-layout (ELK.js) + run history sheet, Dify-style compact node design with ring-based run status styling and animated edge transitions, 4 built-in starter templates (Simple LLM Chain, Conditional Router, Knowledge-Augmented QA, HTTP API Pipeline) with template picker dialog andGET /templates+POST /from-templateAPI, stats endpoint,?run=trueURL param auto-open, subprocess-based code execution security, 105-test suite (templates, eval namespace flattening, blueprint validation warnings, node/edge deletion, import/export/duplicate, deadlock detection, multi-condition branching) - Operation audit: detailed logging of who did what — admin review log audit tab added (publish review trail per org/resource)
- Semantic Schema Annotations: extend connector schema fields with
semantic_tag,description, andpiiflags; annotations surfaced in LLM tool descriptions so the agent understands field intent without guessing from column names
v0.8.1 (2026-03-29) — Progressive Disclosure Maturity + ReAct Hardening
- Progressive Disclosure für DB-Konnektoren (
DatabaseMetaTool), MCP-Server (MCPServerMetaTool) und bedarfsgesteuertes Tool-Laden (request_toolsMeta-Tool) - DAG-Qualitätsüberholung (5 Verbesserungen: Modell-Upgrade, automatische Skill-Erkennung, Zitierverifizierer, strukturierte Inhaltsbewahrung, domänengesteuertes Routing)
- Domänenmodell-Eskalation in ReAct (spezialisierte Domänen eskalieren automatisch zum Reasoning-Modell)
- Pro-Modell Native Function Calling Toggle (
tool_choice_enabled) - ReAct-Zyklenerkennung (deterministische Duplikat-Tool-Call-Prävention)
- ReAct-Abschluss-Checkliste (Vor-Antwort-Verifikation bei verwendeten Tools)
- Resource Fork Phase 1 (MCP Server + Skill Fork Endpoints mit Abstammungsverfolgung)
- Workflow Connection Dep Auto-Subscribe (rekursive Sub-Workflow-Abhängigkeitsauflösung)
- Vorgefertigte Lösungsvorlagen (8 vertikale Lösungen beim ersten Registrieren auf dem Markt bereitgestellt)
- Verbesserungen der Admin-Benachrichtigungen (Zeitzone-bewusst, Master-Schalter, SMTP Reply-To)
- Pro-Turn Token-Budget Circuit Breaker (
REACT_MAX_TURN_TOKENS) - Zentralisierte Tool-Kürzung, dynamische System-Prompt-Budgetierung
- Dateianhang-Download, Duplikat-Nachrichteneinreichungs-Fix
v0.8.2 (2026-04-10) — Agent Core Hardening + Vision Documents
- Agent Core Phase 0 — Compact prompt upgraded to 9-section structured format; empty tool result protection (descriptive message instead of
(no output)); anti-loop prompt + cycle detection threshold lowered to 2; domain classifier + pre-flight DB config resolution parallelized (400–1100 ms saved per request); SSEendevent sent immediately after answer, with title/suggestions moved to background tasks - Agent Core Phase 1 (Context Anti-Bloat) —
MicroCompactrule-based old tool result cleanup (keep last 6);REACT_TOOL_RESULT_BUDGET=40000aggregate cap; reactive compact on context overflow (auto-compact to 50% budget and retry instead of crashing) - Agent Core Phase 2 (Speed) — Keyword-based tool pre-selection (skips LLM call on obvious matches, 200–500 ms saved);
SharedHttpClientLLM connection pooling; completion check skipped for answers >200 tokens;FallbackLLMwraps primary+fast with automatic failover on 429/503/529/connection errors - Intelligent Document Processing (Vision-Aware) — Adaptive document handling: PDF pages rendered as images via PyMuPDF for vision-capable models (GPT-4o, Claude 3/4, Gemini), text-only fallback via pdfplumber. Per-model
supports_visionflag. Modes viaDOCUMENT_PROCESSING_MODE,DOCUMENT_VISION_DPI,DOCUMENT_VISION_MAX_PAGES. DOCX/PPTX embedded image extraction. Multi-turn vision persistence across conversation turns. Smart PDF processing (text-rich pages extract text + images; scanned pages render as full-page PNG). Pre-built sandbox image (Dockerfile.sandbox) with common data-science packages for--network=nonecode execution - Resource Fork completion — Agent / Connector / Workflow fork endpoints added, completing the five-type lineage tracking (KB fork removed — inherently user-local)
- File integrity guardrail — System prompt rule prevents the agent from substituting unrelated file contents when a target file is unreadable; uploaded files now include
file_idin message context for directread_uploaded_fileaccess
v0.8.3 (2026-04-16) — Universal Document Conversion + Agent Core Phase 3
- Universal Document Conversion (
convert_to_markdown+ OCR) — Built-in Agent tool wrapping Microsoft MarkItDown; converts PDF, Word, Excel, PowerPoint, HTML, JSON, CSV, XML, ZIP, EPUB, Outlook .msg, images, audio, YouTube URLs to Markdown.LiteLLMOpenAIShimenables OCR via any vision-capable LLM (Claude, Gemini, Bedrock, Azure). Vision-aware RAG ingestion with zero-regression text-only fallback.LLM_SUPPORTS_VISIONenv var for opt-out - Agent Core Phase 3 (Runtime Invariant Hardening) — Conversation recovery (dangling
tool_useauto-repair); structured compact work card (WorkCardtyped merge across compaction rounds); turn-level profiler (REACT_TURN_PROFILE_ENABLED); per-user rate limiting (LLM_RATE_LIMIT_PER_USER); empty-content assistant message withtool_callsno longer dropped
v0.8.4 (2026-04-17) — Prompt Cache + Reasoning Correctness
- System prompt section registry with cache breakpoints — Memoized
PromptRegistrysplits system prompts into stable prefix + dynamic suffix; cache-capable providers (Claude, Bedrock Anthropic, Vertex Claude) receivecache_control: {"type": "ephemeral"}on the prefix for ~60-80% per-turn input token savings. Non-cache providers get a single concatenated message (zero behavior change) - Prompt cache observability —
cache_read_input_tokensandcache_creation_input_tokenstracked throughUsageSummary→TurnProfiler→done_payload.cachefield. Structuredturn_cachelog line per turn. Doubles as relay cache-honesty probe - Conversation recovery MVP — Synthetic
tool_resultrows persist after interrupted turns;POST /chat/resumereplays cached SSE events from a monotonic cursor; frontenduseSseResumehook auto-reconnects with exponential backoff (300ms → 1s → 3s, max 3 attempts) and “Reconnecting…” indicator - Thinking-block persistence with signature —
reasoning_content+ Anthropicsignaturepersisted inmetadata_["thinking"]and replayed on subsequent turns; fixes HTTP 400 signature mismatch on Claude 4 multi-turn conversations - Provider-aware reasoning replay policy — Centralized
reasoning_replay_policy()incore/prompt/reasoning.pygates serialization per provider family: Claude replays thinking blocks with signature; DeepSeek-R1/Qwen-QwQ/Gemini-thinking/o-series dropreasoning_contenton outbound (previously leaked, breaking provider KV caches and violating API docs)
v0.8.5 (2026-04-23) — Channel Integration + Hook System + Contributor i18n
- Feishu Channel (Phase 1 subset) — Org-scoped
Channelresource with Fernet-encrypted credentials;FeishuChannelsupports interactive card send + callback (signature verification + URL challenge); Settings → Channels management UI (list, create/edit with dirty-state protection, details with copyable callback URL, test-send); CRUD API (/api/channels) and event callback endpoint (/api/channels/{id}/callback). Shipped early for 2026-04-24 roadshow - Agent Hook System (live in ReAct + DAG runtime) —
PreToolUseHook/PostToolUseHookabstraction insrc/fim_one/core/hooks/; agents declaringhooks.class_hooksinmodel_config_jsonhave hooks instantiated and registered per chat session. First consumerFeishuGateHookposts an Approve/Reject card to the linked Feishu group when an agent calls arequires_confirmation=Truetool, blocks execution, and resumes or aborts based on verdict - Configurable confirmation gate (inline OR channel) — Every agent gets an Approval section with three routing modes (Auto / Inline only / Channel only), approver-scope selector (initiator / owner / anyone in org), per-tool override, and explicit approval-channel picker. Auto mode gracefully falls back to an inline approval card when no channel is linked.
POST /api/confirmations/{id}/respondshares a single decision-recording path with the Feishu webhook - Per-agent task completion notifications — Long-running ReAct or DAG agents can push a summary card to the org’s channel when a task finishes. First consumer of the generic outbound notification pattern
- Hook Approval Playground — Channels details sheet has a “Test Approval Flow” action that exercises the full production path (genuine
ConfirmationRequestrow, real Feishu callback, status transitions) — same code path a production hook uses - Contributor-friendly i18n CI fallback —
.github/workflows/i18n-sync.ymltranslates EN → ZH/JA/KO/DE/FR on master after PR merge and auto-commits with[skip ci]; contributors no longer needLLM_API_KEYlocally. Pre-commit locale-edit guard refuses manual edits to generated locale files (ALLOW_LOCALE_EDIT=1override for legitimate translation fixes). End-to-end verified via smoke-test push - Exa integration docs — Dedicated Integrations section with a first-class Exa page covering the full Exa search surface (neural / fast / deep-reasoning / instant), filtering, content retrieval, and three tuned presets
- Xinchuang (信创) database support — Database Connector now lists KingbaseES (人大金仓), HighGo (瀚高), and DM8 (达梦) alongside PostgreSQL/MySQL. PG-compatible drivers reuse
asyncpg; DM8 usesdmPython.scripts/test_xinchuang_dbs.pyverifies live connectivity from the CLI - Channels + Hook System architecture docs —
docs/architecture/hook-system.mdxexplains the three hook points and walks through FeishuGateHook end-to-end; existing architecture pages cross-link; README lists Messaging Channels as a first-class capability - Hardening — Duplicate Feishu callback clicks produce a replacement card instead of double-deciding; concurrent callback clicks resolved via conditional
UPDATE ... WHERE status='pending'rowcount check; pending approvals auto-expire afterCHANNEL_CONFIRMATION_TTL_MINUTES(default 24h) via background sweeper; Settings → Channels respects org role (members see read-only UI); parallel tool-call aggregator handles providers that reuseindex=0for every delta; session-expiry redirect preserves query string
v0.8.6 (2026-05-08) — Stripe Billing + Refinements
- Stripe billing MVP — Free + Pro tiers; Checkout, Customer Portal, webhook lifecycle;
/settings?tab=billing; admin plan/subscription CRUD; quota enforcement respects each user’s plan - Admin-controlled billing feature flag —
system_settings.billing_enabledgates the entire Stripe pipeline so private deployments without Stripe credentials never surface a non-functional payment UX - Per-user unlimited quota — empty inherits global default,
0grants unlimited; previously both collapsed into the same state - Translation glossary as single source of truth —
scripts/translation-glossary.mdconsolidates per-locale rules; pre-commit unconditionally refuses manual edits to generated locale files - License + governing law migrated to FIM Labs Pte. Ltd. (Singapore); SIAC arbitration in English; new top-level
NOTICEfile - Playground follow-up suggestions restored, opt-in per agent
- Stability fixes — strict-alternation provider history, parallel tool-call boundary detection, unbound-agent confirmation flow, channel role gating, retry-duplicate suppression, post-rejection no-paraphrase
v0.8.7 (2026-06-10) — Security Hardening + Guardrails v0 + Billing Correctness
- JWT token-type confinement — closes a 2FA bypass where any same-signed token (temp/refresh/ticket) could authenticate API and SSE endpoints
- OAuth hardening — email auto-link requires a provider-verified email (account-takeover fix); OAuth refresh tokens stored hashed so session rotation works
- Content guardrails v0 — input/output tripwire layer (
core/agent/guardrail); ships jailbreak detector + max-length output guardrail, env-var configured -
file_ops.apply_patch— V4A diff patches with fuzzy whitespace matching, complementsfind_replace - Billing-cycle correctness — quota resets on the subscription anniversary (not calendar month); renewals advance the period via authoritative Stripe lookup; usage display aligned to the enforcement window
- Reliability fixes — pseudo-protocol tool-call leak stripped from answers; tunable HTTP keep-alive ends
APIConnectionErrorbursts; API-key usage stats persist on read-only requests - Billing tab visual overhaul — full-width, consistent with other Settings tabs
v0.8.8 (2026-06-22) — SSRF Hardening + Reliability & Reasoning Fixes
- SSRF hardening — blocklist unwraps IPv4-mapped IPv6 (
::ffff:instance-metadata bypass); MCP SSE/Streamable-HTTP server URLs SSRF-validated on create + connect - LLM reliability — shared HTTP pool self-heals after a LiteLLM client-cache eviction closes it; chat sends stream instantly (history folded in background, no full reload)
- Anthropic adaptive-thinking protocol for Opus 4.6+/Sonnet 4.6/Fable 5 — extended thinking works where the old fixed-budget param 400s on 4.7/4.8; warns on OpenAI-proxy misroute
- Reasoning detail preserved end-to-end — genuine final answer streamed verbatim; survives compaction, context rebuilds, and sub-agent steps (no lossy re-synthesis)
-
PreToolUseenforcement hooks fail closed on error — a crashing approval gate no longer silently allows the call; non-enforcement hooks keep fail-open viafail_open - Force-logout timestamp comparison normalized to UTC by conversion + Docker Compose
POSTGRES_*credential override (no shippedfim:fimdefault)
v0.8.9 (2026-07-08) — Module Slim-down + Sharing Convergence + Approval Hardening
- Skills & Workflows soft-shelved behind admin module flags (default off) — core-only boot; nothing deleted, reversible from Admin → Settings → Modules
- Sharing converged — KB sharing removed (KBs reach others only via shared Agents), DB connectors unshareable + raw SQL owner-only, workflow builder trimmed to 9 reference-only nodes
- Feishu approval hardening — card clicks enforce approver identity, callback signatures fail closed + encrypted envelopes decrypted, approvals never routed to an unintended chat
- Use-time access re-checks — shared MCP servers and bound KBs re-verified per run; leaving an org revokes subscriptions and saved credentials immediately
- Agent loop hardening — plan board, background tools, incremental DAG replan + checkpoint resume, compaction keeps tool pairing, truncation continuation, 529/504 retry
-
run_workflowagent tool + workflow correctness — Agent node runs the full agent, confirmation gates fail closed, connector calls access-checked and audit-logged - Account deletion unified — admin and self-serve funnel through one purge routine covering every record and on-disk file; org owners must transfer ownership first
- Owner-credential fallback now opt-in (breaking) — connectors/MCP servers default
allow_fallbackoff, existing rows flipped; no-fallback resources you lack credentials for are hidden from the toolset - Webhook/cron workflow runs metered to the owner’s token quota — the unmetered free-LLM trigger path is closed
- Resource binding unified on visibility — subscribed connectors/KBs/MCP servers bindable to agents; workflow connector steps enforce the runner’s access
- Conversation workspace wired into chat —
workspace://offload of oversized tool results, budget-truncation rescue, pre-compaction transcript snapshots
Geplante Versionen
Neu geplant 2026-07-08: FIM One ist eine Agent-Runtime — ein Kernel (ReAct-Engine, Credentials, Approval Gate, Audit, Multi-Tenant-Orgs) hinter mehreren Delivery-Oberflächen: Web UI, API, JS Embed, MCP Output. Jede Oberfläche nutzt die gleiche Assembly-Schicht für Auth, Credentials, Approval und Metering: mehr Frontends, nie mehr Logik. Die kurzfristige Richtung ist die Konvergenz auf den Data-Q&A-Slice (ChatBI), wobei Szenarien statt einer Plattform verkauft werden.v0.9 — Connector Fences + Scenario Onboarding
Ziel: Die nach der Reduktion zusammengestellten Assets bilden ein vollständiges Daten-Q&A-Produkt — Read-Only-DB-Konnektoren + Fences + Approval Gate + IM-Eintrag. Tier-1-Fences wandeln Sicherheitsschulden in Produktfunktionen um.DB Connector Fences — Tier 1, drei PRs
- PII-Spaltenredaktion (
ConnectorScopeGuardPreToolUse Hook) - Schemasichtbarkeit — Tabellen-/Spalten-Allow-Deny + Verb-Blocking (Read-Only-Durchsetzung)
- Fence-Nachverfolgbarkeit —
caller_user_id,effective_credential_source,scope_rules_appliedinConnectorCallLog - Pro-Hook-Konfigurationsübergabe (
{"name", "config"}Schema) — der Träger für ScopeGuard-Regeln - Genehmigungsgates bleiben über Delegierung erhalten —
call_agentund Workflow-AGENT-Knoten führen die eigenen Hooks des Agenten aus, anstatt keine
Antwort-Rendering
- Antworten rendern Mermaid-Diagramme, SVG-Figuren und kartenförmige Vergleichstabellen mit Kopier-/Exportfunktion für Antworten, Code-Blöcke und Tabellen
- Gerendertes Markdown wird bereinigt, wodurch Raw-HTML-Injection aus Modellausgabe und hochgeladenen Dateien verhindert wird
- Diagramme und Code-Blöcke können als Dateien heruntergeladen werden; Reasoning wird in Live- und früheren Gesprächen standardmäßig zu eizeiligen Vorschauen eingeklappt
- Gesprächsexporte sind für CJK gesetzt — PDF bettet eine echte Schriftart ein (korrekte Abstände, Aufzählungszeichen und Fettdruck), DOCX deklariert eine Ostasiatische Schriftart, beide auf einer Größenskala
Workbench UX
- Sidebar reorganized around the chat cluster — conversations directly under New chat/Search, module nav in a compact bottom dock
-
/clearslash command starts a fresh conversation from the input box - Admin model lists support checkbox multi-select with Shift-click ranges and one-request bulk delete
- Running agent steps show generated one-line titles in a single folded header, kept in conversation history
- A newly sent message rises to the top of the transcript, with the answer growing into the space below it
Kontextrobustheit
- Kontextbudgets liegen 8% unter dem Modell-Hardlimit; beim Start wird gewarnt, wenn das Fenster des schnellen Modells das allgemeine Budget nicht halten kann
- Plan-Board-Disziplin: Wiederholungs- und No-Plan-Erinnerungen, und das Abschließen mit offenen Plan-Elementen erzwingt nun einen Verifizierungsdurchlauf
- Chunked-Kompaktionseingabe und modellbewusste Budgets auf dem Hauptchat-Pfad, damit jede Modellmischung innerhalb des Fensters bleibt
Szenario-Onboarding
- Der erste Durchlauf startet mit einer Szenariovorlage (solution_seeds) statt einer leeren Workbench
- Die Dokumentations-Landingpage führt mit drei vertikalen Szenariogeschichten statt einer Modulreferenz an
- Eine Szenariovorlage pro abgeschlossenem Engagement destilliert — der Wettbewerbsvorteil liegt in Szenario-Assets × Liefergeschwindigkeit
v0.10 — Two Mouths: JS Embed + IM Inbound
Ziel: Die zwei verkäuflichsten Lieferflächen, beide auf demselben Kernel und der gleichen Assembly-Schicht.- JS bubble / iframe embed — ein Snippet in ein Host-System; anonyme Besucher-Identität + Abrechnungszuordnung vor dem Build entschieden
- Feishu inbound @mention — Agenten leben in der Gruppe: Daten abfragen, Datei-Genehmigungen, Ablaufverfolgung
- Outbound-Muster: Fehleralerts, Budget-Warnungen, geplante Digests, Eskalation, Audit-Belege
- WeCom / DingTalk Kanäle nach Feishu-Vorbild
Geparkt — signalgesteuert
Starten Sie diese nicht ohne ihren Auslöser (siehe Neuplanung §3): Das MCP-Gateway wartet auf ≥2 unaufgeforderte „Mount your tools in my agent”-Anfragen; Channelization wartet auf eine Implementierer-Frage zur Lizenzierung; IdP/OrgSync wartet auf Kundenpull; der Rest wartet auf ein bereitgestelltes Engagement, das sie benötigt.- MCP gateway output — reverse-expose connector discover/execute as MCP tools for downstream agents
- Channelization / white-label enablement — commercial-license path already in place
- Identity Provider module + Channel slim-down — Feishu SSO, org graph sync
- Connector authorization Tier 2 (require per-user credentials, key-binding health) + Tier 3 (login-ticket exchange)
- Public API Phase 2 — per-key rate limits/quotas, versioning, SDKs, developer portal
- Observability — Agent Trace Layer (Trace/Span model, timeline viewer, OTel export) + metrics dashboard
- Agent Workspace remainder — handoff notes, file browser UI, cross-session recall, compaction segments (grep-able on-disk summary the agent reads back)
- Guardrails v1 — off-topic filter, PII redactor output guardrail, per-agent guardrail config UI
- Hook System extras — built-in hooks,
SessionStart+ user YAML hooks - Connector platform depth — Progressive Disclosure Phase 3-4, YAML/JSON connector config, DB connectors Phase 4 (Oracle / SQL Server / GBase), MCP connection pooling
- Prompt cache follow-ups — Gemini context cache adapter, per-agent
cache_ttl - Hot mid-stream DAG resume — SSE reconnect re-attaches to a running turn (cold retry-resume already shipped)
- Ecosystem — scheduled/event-triggered agents, workflow trigger-identity observability, per-workflow
credential_policy, DB Schema Advanced Builder, sandbox hardening v2
Aus dem Pre-Replan v0.9-Plan ausgeliefert
-
Auth & Security: JWT Token-Type-Beschränkung + OAuth-Fixes (v0.8.7); PG Zeitzonen-bewusste Zeitstempel (v0.8.6); Force-Logout UTC +POSTGRES_*Override + SSRF IPv6-Mapped-Fix (v0.8.8); Owner-Fallback Opt-in + Visibility-Unified Binding + Webhook/Cron-Metering (v0.8.9) -
Provider-Kompatibilität: Anthropic Adaptive Thinking + Shared LLM Pool Self-Heal (v0.8.8) -
Content Guardrails v0: Tripwire Layer + Jailbreak Detector (v0.8.7) -
Hook-System: Skeleton + FeishuGateHook + Approval Playground + ReAct/DAG Runtime (v0.8.5); PreToolUse Enforcement Fail-Closed (v0.8.8) -
Feishu-Kanal Phase 1 + Task-Completion-Benachrichtigung (v0.8.5) -
run_workflowAgent-Tool (v0.8.9); Reasoning-Details End-to-End beibehalten (v0.8.8); Workspace Tool-Output-Offloading in Chat integriert (v0.8.9) -
Agent Loop Hardening: Plan Board, LLM-Call-Resilienz, Background Tools, Inkrementelles DAG-Replan + Checkpoint Resume, Compaction Tool-Pairing (v0.8.9) -
Circuit Breaker, Workflow Run Retention Cleanup, Workflow Version Diff Summaries(v0.8 / v0.8.1) -
DAG Quality Overhaul, Domain Model Escalation, Per-Model NFC Toggle(v0.8.1) -
DatabaseMetaTool, MCPServerMetaTool, On-Demand(v0.8.1)request_tools -
Workflow Connection Dep Auto-Subscribe, Workflow Real Executors(v0.8.1) -
ReAct Cycle Detection, Completion Checklist(v0.8.1) -
Vorgefertigte Lösungsvorlagen (8 vertikale Bundles), Resource Fork (MCP/Skill/Agent/Connector/Workflow)(v0.8.1) -
Vision-Dokumentenverarbeitung (PDF / DOCX / PPTX), MarkItDown OCR(v0.8.2 / v0.8.3) -
Smart File Content Injection +(v0.8)read_uploaded_file -
Agent Core Phase 3: Conversation Recovery MVP, Compact Work Card, Turn Profiler, Per-User Rate Limiting(v0.8.3) -
Conversation Resume MVP, System Prompt Registry + Cache, Thinking-Block Persistence, Reasoning Replay Policy, Cache Observability(v0.8.4)
v1.0 — Hot-Plug + Embeddable
Ziel: Connector-Hinzufügung ohne Neustart, Paket-Ökosystem und eingebettete Bereitstellung.-
Connector Progressive Disclosure (Phase 5): Semantic-Guided Tool Selection (Entity-Extraktion aus Abfrage → Ontology Registry-Lookup → Connector-Set-Reduktion; 90%+ Token-Reduktion für 50+ Connector-Bereitstellungen); Scale-Modus für Batch-/ETL-Connectors; CLI-ähnliche universelle
connector <name> <action> <params>Schnittstelle - Cross-Connector Entity Alignment (Ontology Registry) — herabgestuft 2026-04-21: bedarfsgesteuerte benutzerdefinierte Bereitstellung, keine Kernfunktion: Definieren Sie gemeinsame Entity-Typen (Customer, Order, Asset) mit Feldmappings über Connectors hinweg; DAGPlanner löst Cross-System-JOIN-Schlüssel automatisch auf; ermöglicht Cross-Connector-Abfragen (z. B. „Kunden in Salesforce, die in Shopify bestellt haben”) ohne hartcodierte Feldnamen
- Hot-plug Connectors: OpenAPI-Spezifikation hochladen, KI generiert Konfiguration, live in 5 Minuten (kein Neustart)
-
Marketplace Redesign Phase 1 — Solutions + Components: Zwei-Ebenen-Marktmodell (Solutions: Agent/Skill/Workflow; Components: Connector/MCP Server); Scope-Selector (Global Market / org); einheitliches Abonnementmodell (org auto-appear entfernt); KB aus Market-Scope entfernt; Datenmigration füllt Abonnements für bestehende Org-Mitglieder auf -
Market Package System: Verteilbare Ressourcen-Bundles für den Marketplace — ersetzt Pro-Typ-„Marketplace” durch eine einheitliche Packaging-Schicht.
fim-package.yamlManifest deklariert: Metadaten (Name, Version, Beschreibung, Autor, Lizenz, Tags,min_fim_version), Entry Point (primärer Skill oder Agent), Ressourcenliste (Agents, Skills, Connectors, KBs, MCP Server, Workflows) mit Konfigurationsreferenzen, paketübergreifende Abhängigkeiten (Semver-Bereiche), erforderliche Anmeldedaten (auf Connector-Refs für die Erfassung bei der Installation abgebildet) und benutzerkonfigurierbare Variablen mit Standardwerten. Zwei Verbrauchsmodi: (1) install — Batch-Erstellung aller Ressourcen + automatische Verdrahtung interner Referenzen über ID-Substitution; Installation mit Quelle verknüpft für Versionsaktualisierungsbenachrichtigungen;POST /api/market/packages/{id}/install; (2) fork — Klonen als benutzergesteuerte bearbeitbare Kopien ohne Aktualisierungslink (dies IST der Template-Modus);POST /api/market/packages/{id}/fork. Zusätzliche Endpunkte: Veröffentlichung (POST /api/market/packagesmit Review-Workflow), Deinstallation (DELETE /packages/{id}/uninstallmit Abhängigkeitsprüfung + Bestätigung geänderter Ressourcen), Versionsverlauf (GET /packages/{id}/versions), Upgrade (POST /packages/{id}/upgrademit Pro-Ressourcen-Diff-Vorschau). Abhängigkeitsauflöser für verschachtelte Paketanforderungen mit Konflikt-Erkennung.PackageInstallationTabelle verfolgt installierte Pakete pro Benutzer mit Ressourcen-ID-Mapping für Deinstallation/Upgrade. Koexistiert mit individueller Ressourcenveröffentlichung — Package ist eine Kompositionsschicht, kein Ersatz; ein einzelner Connector ist immer noch eigenständig veröffentlichbar. Beispiel-Abhängigkeitsbaum:Package: contract-review→Skill: contract-review(Entry Point) →Agent: contract-analyst+Agent: risk-scorer→KB: legal-clauses+Connector: docusign-api+MCP: pdf-extractor+Workflow: contract-approval-flow - Creator Program: Marketplace-Monetarisierungsschicht — Creator-Profile mit Portfolio-Seiten, Pro-Paket-Analytik (Installationen, Forks, aktive Benutzer, Bewertungen/Rezensionen), Affiliate-Provisionserfassung, wenn Pakete neue Abonnements fördern. Kostenpflichtiger Paket-Tier mit Preisgestaltung, Kaufablauf und Genehmigungsworkflow. Creator-Dashboard mit Installationstrends, Umsatzberichterstattung und Benutzer-Feedback. Öffentliche Creator-API für programmgesteuerte Paketveröffentlichung (CI/CD für Paketautoren). Community-Funktionen: Paket-Kommentare, Q&A, Changelogs pro Version
-
Embeddable Widget:
<script src="fim-one.js">in Host-Seite eingefügt - Page Context Injection: Widget liest Host-Seiten-Kontext (aktuelle ID, URL, DOM-Selektoren)
- Advanced Triggers: Webhook-Inbound-Events; Verbesserungen geplanter Jobs (Multi-Zeitzone, Kalender-bewusst)
- Batch-Ausführung: Verarbeitung von 1000+ Elementen über DAG
- Enterprise Security: IP-Whitelisting, Verschlüsselung im Ruhezustand, SSO
- KB Advanced Editor: Builder-Modus-Agent für Power-User, die große Wissensdatenbanken verwalten — Massen-URL-Erfassung, Duplikat-Erkennung, Gap-Analyse, Dokumenten-Lebenszyklusmanagement; erweitert vorhandenen KB-KI-Chat mit ReAct-Tool-Loop
-
Stripe Billing (v1 MVP — Pro Subscription): Free + Pro Zwei-Ebenen-Abonnement mit monatlichem Token-Kontingent. Stripe Checkout (gehostet) + Customer Portal (Self-Service) + Webhook-gesteuerte Lebenszyklen (
checkout.session.completed/customer.subscription.updated|deleted/invoice.payment_succeeded|failed). Soft-Cap bei Kontingent-Erschöpfung (HTTP 402 + Upgrade-Aufforderung) — keine Übergebühren in v1. Nur Pro-Benutzer-Abrechnung; Org-/Team-Abonnements auf v3 verschoben. Voraussetzungen:-
Datenmodell + SDK-Grundlagen (P1) —(ausgeliefert in v0.8.6)billing_plans/subscriptions/stripe_webhook_eventsTabellen, ORM-Modelle, Stripe SDK Singleton, Free + Pro Seeds -
Backend-API + Webhook-Handler (P2) —(ausgeliefert in v0.8.6)/api/billing/*+/api/webhooks/stripemit Signaturverifizierung + Idempotenz; Plan-bewusstes Kontingent; stündliche Lebenszyklusbereinigung -
Frontend Billing-Tab + 402 Upgrade-Dialog (P3) —(ausgeliefert in v0.8.6)/settings?tab=billingKontingent-Anzeige, Upgrade-CTA,past_dueBanner, Mid-Stream 402 Dialog -
Admin Plan-Management (P4) —(ausgeliefert in v0.8.6)admin/billing/{plans,subscriptions}CRUD -
Admin-gesteuertes Billing-Feature-Flag (P5) —(ausgeliefert in v0.8.6)system_settings.billing_enabledgated die Stripe-Pipeline; idempotente Aktivierung Seeds Free+Pro, setzt Standard-Plan-Pointer, füllt Benutzer auf; Toggle aus/an ist reines Flag-Flip nach Aktivierung - Reconciliation + e2e + Go-Live (P6) — nächtliches
subscriptions↔stripe.Subscription.list()Reconcile-Skript für Missed-Webhook-Recovery; vollständiger Happy-Path / Cancel-Mid-Period / Past-Due Regressionstests; Wechsel von Test-Modusstripe_price_idzu Liveprice_id; Smoke-Test auf Staging mit echter Karte.
-
-
Team Plan (Stripe Seats) — Pro-Seat-Preisgestaltung über
stripe.Subscription.quantity, integriert mit Organization-Mitgliedschaft. Ermöglicht Unternehmen, einen teamweiten Plan mit N Seats zu abonnieren; Kontingent und Feature-Flags werden über die Seat-Gruppe statt über den einzelnen Benutzer aufgelöst. Baut auf dem v1.0 Stripe MVP und dem vorhandenen Organization-Modell auf. -
Group-Level Token-Kontingent für Nicht-Billing-Bereitstellungen — Enterprise-/Private-Bereitstellungen ohne Stripe konfigurieren organisationsweit Token-Budgets. Kontingent-Kette erweitert zu
override > group > plan > default; Gruppen-Auflösung verwendetmax(user_quota, group_quota), sodass einzelne VIPs nicht durch die Team-Cap eingeschränkt werden. Landet neben dem Team Plan, sodass die gleichen Primitiven sowohl abgerechnete als auch selbst gehostete Topologien bedienen.
Gefrorene Funktionen (Ausgeliefert, nur Wartung)
Gemäß der Orthogonality Strategy sind diese Funktionen ausgeliefert und funktionsfähig, erhalten aber keine neuen Funktionen (nur Fehlerbehebungen):Überlegungen (Auf unbestimmte Zeit aufgeschoben)
Gemäß der Orthogonalitätsstrategie würden diese hohen Aufwand erfordern und Absorptionsrisiken bergen:Wie Versionen Mit Modi Ausgerichtet Sind
Resource Allocation (v0.8–v1.0)
The Orthogonality Strategy shapes where effort goes:Metric-Driven Milestones
Success is measured by:Open Questions / TBD
- Marketplace moderation: How to validate community packages and individual resources? Automated scanning for credential leaks in package configs? (v1.0)
- Token economics: How to price multi-user, multi-agent scenarios? (v1.0)
- Package versioning: Breaking changes in installed packages — auto-upgrade with migration scripts, or manual approval per update? Dependency diamond problem resolution? (v1.0)
- Package pricing: Free vs paid tiers, commission rates for Creator Program, payment provider integration? (v1.0)
- Package credential UX: Install-time credential collection — wizard-style step-by-step or deferred setup? Credential sharing across packages that use the same connector type? (v1.0)
- Telemetry opt-out: How to honor privacy preferences? (v0.8)
- Connector versioning: How to manage breaking changes in connector APIs? (v0.8)
- Rate limiting: Per-user workflow rate limiting shipped (sliding window 10 runs/min, 3 concurrent). Per-connector and per-agent rate limiting TBD (v0.9)
- Connector authorization tier selection: how does an admin discover which tier applies to a given upstream system? Auto-probe (try per-user API key → fall back to login-ticket → fall back to shared-DB) vs. explicit declaration in the connector spec? How do we express “this connector supports Tier 2 but the admin chose to operate in Tier 1” in the UI without confusing non-technical admins? (v0.9)
- Integration vs Connector duality: when a Feishu binding is simultaneously an SSO provider AND an API-call surface, how do we present it in Settings? One object with three toggles, or three separate bindings that share a credential? Implications for uninstall semantics (does revoking SSO kill the Connector?) (v0.9)