NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Set up, change and watch a project's team of AI agents from one file
Last release today
04 Oct 2026
Too new to tell
only 2 release windows
Most releases are documented
notes for 5 of 6 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
6 releases · first in 2016
A safety patch: on Codex and Cursor the composer's input row is read only under the box's frame, so a person's text can no longer be submitted togethe
A safety patch: on Codex and Cursor the composer's input row is read only under the box's frame, so a
person's text can no longer be submitted together with team's; and Antigravity's and Cursor's
dialogs are recognised as the permission or question they are.
team typed under the glyph, the read-back held the typed text alone, and the Enter submitted theteam had typed. The input row is now read only under theunknown, with no typing and no Enter, closing the limitunknown; they are now read as the permission or question they are. team typedunknown, permission and question all refuse typing alike.One column per quarter.
A feature release: the budgets table falls back per window and names the source each figure was counted from; team doctor runs each account's approved
A feature release: the budgets table falls back per window and names the source each figure was
counted from; team doctor runs each account's approved budget check; overrides.yaml teaches a
shipped profile new dialog and quota patterns without waiting for a release; and every typing path
reads the input row from the captured frame and its prompt column, pressing Enter only when the box
reads back as exactly the typed text. Upgrade: a seat with no label is titled with its model and
version, and team down now clears the session it stopped.
cli; a pane herdr can't list keeps its figure — not knowing is not proofdown could type /exit into a running seat and remove refused it as unsent. Thedown --wait waits and removeteam had sent it; the watch's nudge and the exitdown and remove pressed Enter on an unread box the same way. Every Enter now waitsteam doctor runs each account's approved budget check once, for the owner only, and reports itsoverrides.yaml, beside the approval in ~/.config/team/<project>-<hash>, may add dialogteam approve records it. Until then thedoctor and status name the change.schema/team.schema.json describes the team file (draft 2020-12), assembled from the sameschema:check in CI keeping it current. The schema shipsteam init writes now opens with a# yaml-language-server: $schema=… line pointing at this version's copy.docs/reference/cli.md is a generated CLI reference — every command, flag and positional, fromcontract:check, with the same snapshot ascontract/cli.json. Help text is unchanged.bun run conformance checks an implementation of screen reading and the YAML subset against theteam conformance-adapter is the TypeScript implementation of that protocol. Itteam --help.bun run coverage prints the capture coverage matrix — for each CLI and screen kind, how manycoverage:check keeps contract/capture-coverage.json current in CI, failing on a difference orcapture claim counts whereignore_case: true beside its match — the flagexcept list too. Claude Code's trust question, spelled out in both cases letterprompt, rule, footers,"prompt" cannot ignore case: only a dialog pattern may).screen_module — a code module inside the package's profiles folder — for aworking, every dialog stage and unknown, so a hatch can only add caution, neverclaude opus 5.5). Ateam doctor warns when a seat's name or label repeats the project or the session. The warning(fallback) whenstatus line (fallback) — and status --jsonfallback field on each budget row. The fallback is per window, not perlast seen <age> — the room the figure last held. It never refuses a launch.team down now clears the herdr session it has itself just stopped, its line readingstopped and cleared, so up after down starts the team again instead of refusing on theherdr session delete <session>. up never deletes a session: one it did not stop keeps theteam down now stops a seat the file renamed after up launched it: the state records the CLIdown resolves the file's name first and the state's second,ὠ and a 0, so an\u{…} form.chrome pattern could hide the unmarked second choice of a dialog. The guard tested sixweekly 39% used\r\n broke the contract on its line[\D0-9][\s\S]; the positive class is now refused with the reason when the profile loads.[^\S\n] and a shorthand alone are unchanged.↑ N more lines and the tail; the box is now read as folded, and Enter is pressed only when the4.996 USD against a 5 USD floor printed "5.00 USD, at or below its 5.00 USD floor"; theA safety release: 0.1.1 could type a nudge or an exit into the shell left after Claude Code exited, and a seat could silence the watch's reports about
A safety release: 0.1.1 could type a nudge or an exit into the shell left after Claude Code exited,
and a seat could silence the watch's reports about itself. Upgrade.
down's and remove's exit) also needs herdr to report the agent'sremove --keep and add record the new digest when stopped is the only change, so--no-notify on the watch silenced a report addressed to the owner, and any caller--no-notify drops only the operator's notice — the log line stays, andteam status does not read the flag. The watch's own notices — the operator could not be--no-nudge and --no-notify are the owner's.account:, when one vendor's two accounts are twovendor, and the choice is part of the seat's fingerprint,budgets.accounts — a name the budgetswatch.checks edit is unapproved, the approved list stays in force: nothing new is turnedThese are standing rules, not a task: reply ready and wait for your brief.; a launch option that stays in force on every later--append-system-prompt) closes with only These are standing rules, not a task. A team file whose own rules: already end with that line doesn't get it twice.remove --keep, or parked by hand, since its last approvalseat X changed for each after upgrading, and up and add refuse until the ownerTry " rule.ctrl+c to stop.up, add andstatus count it: a fresh check inside its reserve refuses a launch after the watch has exited, asources decide which reading counts.up, add, status and the watchsources.A safety release: 0.1.0 could type into a Codex permission dialog, and could read a quota figure a seat wrote itself. Upgrade.
A safety release: 0.1.0 could type into a Codex permission dialog, and could read a quota figure a
seat wrote itself. Upgrade.
team could answer a Codex permission dialog. With the status line pinned belowstatus-last composer's pinned line. The dialog is reported and never answered, and rulescheck reading stays first, and a wrong figure can only refuse a launch orfloor refuses a launch: the watch keeps the money each spend check reads in theup and add refuse a seat whose account is at or below its floor. A reading that isbun run build empties dist/ first, so a file left by an older build can no longer end up in aThe first release: set up, change and watch a project's team of AI agents from one file, .agents/team.yaml . Runs on Node 22 or later, with no runtime
The first release: set up, change and watch a project's team of AI agents from one file,
.agents/team.yaml. Runs on Node 22 or later, with no runtime dependencies.
examples/team.yaml. (#2, #11)team init and team status: write the skeleton file and keep it out of git through.git/info/exclude; print the file's seats against the running session, each difference with its--json prints the same facts as one JSON document (format: 1) for scripts. (#3, #33)team approve: record the file, its ceilings and its seats on this machine after a read-back and--show prints the approved copy. (#4, #5)team check: check one commit, a range or a pull request body against the signature rule;team doctor: check this machine for what the file needs — herdr, each CLI, login, launcher,--login checks read-only that each declared CLI is signed in, using eachteam watch: report idle and blocked seats, unsent input and machine figures, and nudge the--no-nudge and --no-notify turn those off. (#6, #7,/proc, soteam answers there as on macOS. (#29)team up and team down: start and stop the session and its seats, each with its caller rule;--dry-run prints the plan and changes nothing. (#5, #13, #14)team up and team add: every machine: start limit — load, memory, disk, free swap and swap--dry-run prints the refusal too. (#26)claude-code, Codex, Antigravity and Cursor: approval flags added only atteam add and team remove: start one declared or temporary seat; stop a seat, then take it out--keep leaves it stopped, --abandon is the owner's. (#19, #20)team worktree new and team worktree remove: create a task worktree from an up-to-date base, ordocs/commands, every example run in CI. (#31)weekly N% left, for the OpenAI account.budgets is an owner section: marks, freshness, and each account's reserve or floor. A checkteam approve. watch.quota_marks is read, with a warning.team status prints a budgets table, and the same rows in --json, when an account is named orteam watch reports a budget: each mark a window crosses, an account inside its reserve or floorbudgets.check_every,status,up and add count it. watch.checks: { budget: off } turns the report off.watch section is an owner section, its timings included: an edit to interval,idle_first, idle_repeat, team_idle, nudge_wait or unsent_after needs a new approval, andwatch.checks keeps its own finer line inside the section.budgets section is an owner section too, its accounts and marks included: an edit tostale_after, check_every or the accounts needs a new approval, and untilup's and add's launch gate, and status's table — runs with the values ofmode: shared and works in worktrees starts in the lobby — the parent ofworkspace.path with .lobby beside the worktrees, inside trust and outside every protectedup and add maketrust or inside a protected checkout, and refuse a seat the fileNothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →