Smart Agent Teams

Changelog

What changed in SAT, newest first, grouped by month, from the repository's history on main.

Changes are grouped by the month they reached main, newest first, with pull request numbers. SAT is deployed continuously from main, so there are no numbered releases for the current product; the API reports a fixed version of 2.1.0.

October 2026 is a new product

In October 2026 SAT was rebuilt as a control plane for an AI agent company: a React web app, a company-scoped API with Alembic migrations, the sat CLI and runner, and a new release system for the hosted environments. Entries before October 2026 describe an earlier, tmux-based design whose web apps, CLIs and deploy paths have since been removed.

October 2026

Agents run from your machines (#54, 5 Oct)

  • sat CLI (apps/cli): every control-plane action from a terminal, with profiles for local, staging and prod, credentials in the OS keychain, --json output and stable exit codes. Ships as a single signed binary. See CLI.
  • sat runner: claims queued runs and executes them through Claude Code or Codex, in a git worktree per run for projects with a repository. Streams transcripts, heartbeats its lease, posts the agent's reply on the task and moves it to in_review (or blocked on a BLOCKED: reply). --simulate runs the loop without model calls. See sat runner.
  • sat scheduler: evaluates routine and agent heartbeat crons and expires stale runs. See Scheduler.
  • Personal API keys: sat_live_ keys at /api/me/api-keys for runners, CI and scripts; creating and revoking them requires a password session. See Security.
  • Run claims and leases: POST /runs/claim atomically takes the oldest runnable queued run; POST /runs/{run_id}/heartbeat keeps the lease; runs whose runner stops reporting for RUN_LEASE_SECONDS (default 300) are failed. Migration 004. See How runs work.
  • Agent attribution: task, comment and subtask writes made with a running run's run_id are attributed to its agent in the audit log.
  • Runners require an API key, and each agent process gets only that key and an empty config directory.
  • Fixed: everyone signed out after 30 minutes on PostgreSQL. Refresh-token expiry and the login lockout compared naive and timezone-aware datetimes, so every refresh failed. The new cli-e2e CI job runs the CLI against PostgreSQL to catch this class of bug.
  • The legacy Python CLIs were retired, and the local API entry points (main.py, start_api_local.py) now default to port 8080.

Account and personalisation (1 Oct)

  • Locale, time zone, density and accent preferences (#53).
  • Saved task views, pins and recents (#52). See Views and preferences.
  • A personal, customisable dashboard: choose the range (7, 14 or 30 days), order and hide cards, and see your own open tasks (#51).
  • Profile and preferences saved to the account, through PATCH /api/me and PATCH /api/me/preferences (#50).
  • Sign-in redesign with a "continue as" chip for the last account (#49), and a public homepage (#48).
  • Forgot password: emailed single-use reset links that expire after 30 minutes and end every session (#41). Migration 003. See Account.
  • Brand: "Smart Agent Teams by Yarlis" identity (#40).

Deploys through Tollgate (1 Oct)

  • The hosted environments, staging and prod (https://app.yarlis.com), are deployed by Tollgate, the Yarlis release system (#38, #39).
  • Cutover: legacy deploy scripts (Cloudflare, Netlify, Kubernetes, deploy-staging.sh) removed; a conformance check enforces Tollgate as the only deployer (#46).
  • Prod rolls out as a one-step canary gated on /health, with automatic rollback.
  • The API runs under its own service account (#43) and is reachable without Google credentials so the browser can open the live-event stream (#42).
  • The web build bakes in the events origin for each environment (#44, #47).
  • The web build can install @yarlisai/ui during deploys (#45).
  • See Architecture.

The React control plane (1 Oct)

  • New web app (apps/web): React 19, Vite, Tailwind 4, SWR and zustand. Dashboard, inbox, tasks (list and board), org chart, goals, projects, agents, approvals, costs, routines, activity and a command palette, with live updates (#30, #31). The Angular app was removed.
  • Agent-company API (apps/api/company): companies, members, agents with an org chart, goals, projects, tasks with keys like NF-12, comments, runs, approvals, routines, budgets with automatic pauses, dashboard, costs, activity log and a server-sent event stream (#29). Migrations 001 and 002; the schema is now managed by Alembic and applied at startup.
  • Typed API client (libs/api-client) generated from the API's OpenAPI schema.
  • Monorepo tooling: npm and Nx replaced by Bun workspaces and Turborepo, with Biome for lint and format (#28).
  • Playwright end-to-end suite with axe accessibility checks.
  • Fixes: auth error codes and a required JWT_SECRET_KEY outside development; health checks compatible with SQLAlchemy 2; live events streamed straight from Cloud Run because Firebase Hosting buffers them (#34). /health answers 503 when the database or migrations are broken (#37). CI runs on every pull request (#37) and puts apps/api on the pytest path (#35).
  • Docs refreshed with C4 diagrams and screenshots (#36). Dependency updates (#32).

September 2026

  • Dependabot version updates disabled.
  • Build coverage and OS metadata ignored in git.

April 2026

  • Web app deployed to Firebase Hosting, with /api rewritten to Cloud Run.
  • Cloud Run-ready API Dockerfile and a production dependency cleanup.
  • The Next.js frontend from March was removed and Angular restored as the shipped UI (both since replaced by apps/web).
  • Scripts and docs reorganised into numbered folders.

March 2026

  • A Next.js 16 web app replaced Angular Material and was deployed to Firebase Hosting (removed in April).
  • CI overhaul for recurring daily failures; deprecated GitHub Actions upgraded.
  • Dependency upgrades and a root directory cleanup.

September 2025 (legacy)

  • v2.1.0 "production-ready" release of the tmux-based orchestration system.
  • v2.0.0 with a Flutter console and a broader test framework.
  • Cloudflare Pages deployment for the Angular web console (since removed).

August 2025 (legacy)

  • v1.0 MVP of the tmux-based agent orchestrator, with a Python CLI, an "intelligent app builder", multi-user API server and Cloud Run deployment with Cloudflare DNS (all since removed or replaced).
  • CI/CD pipeline, integration tests and published MkDocs documentation.

On this page