API & compatibility
Documentation and API Changelog
Customer-visible product documentation, API, and MCP changes.
Documentation and API Changelog
Customer-visible product documentation, external API, and MCP changes are recorded here. Newest entries appear first.
2026-09-30 - Keep the selected app website (pending release)
- Use Topline address remains selected after changing the page name, site names or app content. Saving a page name no longer silently switches the app back to the workspace's default company website.
- Owners can still choose a connected company website explicitly. The app's audience and live publication stay unchanged.
- Availability requires the API release to the affected customer runtime.
2026-09-29 - Simple chat reactions (pending release)
- People can add or remove ๐ ๐ โค๏ธ ๐ ๐ ๐ โ on saved AI messages.
- Topline can react to user messages using the same palette. Reactions persist across refreshes and update connected devices without starting an AI turn.
- Reactions, including โ , are feedback and never authorize an action or approve a plan. Availability requires the web/API release and migration.
- See Chat reactions.
2026-09-29 - Simple app web addresses (pending release)
- Share opens with an App web address section. Owners edit Site name and Page name, preview the full address, and save both with one button.
- The current working link has Open app and Copy link actions. Additional addresses and connected company websites remain under Advanced.
- Connection checks use plain language and can be retried. Topline handles hosted site setup; owners do not need to write code or change DNS settings.
- Saving an address preserves the app's audience and live publication state. Partial saves retain the draft and explain which part needs another attempt.
- Availability requires the web release. Hosted site names still require the approved customer DNS/TLS rollout; this UI change does not provision them.
2026-09-29 - Native Five9 scheduling through the harness (pending release)
- Authorized source managers can ask the assistant to schedule existing Five9 reports with an explicit cron expression and IANA timezone. The assistant routes the request to the trusted coding-agent action without creating an artifact.
- The action uses saved source credentials, preserves operator stops, and returns pipeline, schedule and scheduler job IDs. Schedule provisioning and a verified completed report sync remain separate checks.
- Availability requires the API and coding harness release to the customer runtime. This source change does not activate any customer schedules.
2026-09-29 - Customer-configurable hosted app subdomains (pending release)
- App owners can save a one-label prefix for a live app under their existing
customer.topline.buildhost once wildcard DNS and TLS are verified. - The Share drawer shows the resulting live address and preserves the app path after sign-in on that host. Prefixes are unavailable until the customer runtime has the wildcard certificate and DNS alias.
- This source change requires the guarded customer runtime rollout before the hosted prefix control becomes available to customers.
2026-09-29 - Artifact app address guard (pending release)
- App address settings validate the path while typing and block saving a full URL as a path.
- The Share drawer no longer advertises generated Topline-hosted subdomain routes without DNS and TLS provisioning. New custom live subdomain prefixes are rejected; existing stored prefixes remain unchanged. Use a connected company domain for a custom hostname.
- Availability requires the web and API releases. This source change does not provision DNS or TLS or establish a new customer-facing hostname.
2026-09-28 - Customer billing usage categories (pending release)
- The customer Billing breakdown and CSV group model charges as AI usage and Cursor charges as Coding agent without listing specific model names.
- Amounts and incomplete-cost notices remain visible. Topline Admin retains provider and model detail for authorized operators. Availability requires the relevant app, Admin, and API releases; a source merge alone is not a customer rollout.
2026-09-27 - Admin billing reconciliation alerts (pending release)
- Customer billing, print and CSV use a neutral costs-updating status and retain known totals. Technical reconciliation warnings move to authorized Admin tools.
- Persistent incomplete billing or unavailable health checks notify the existing operational alert channel after two hourly observations, with recovery notices.
- Availability requires shared web/Admin/API, customer API and infrastructure releases. Source validation does not prove live alert delivery.
2026-09-27 - Storyboard authoring through Build MCP (pending release)
- Codex and Claude Code can check out the tenant's published Storyboard source, run Storybook locally, and submit source-only changes as a private draft.
- Build MCP also exposes the existing guarded Storyboard edit and exact-draft publish flow with separate read and write scopes. Local submissions must pass the server's private build before the submitting actor can publish.
- Availability requires the app/API release and a separately published Build MCP helper version; source integration alone does not enable customer use.
2026-09-27 - Topline-owned silent chat learning (pending release)
- Processing approval is a separate, default-off tenant-admin choice for Topline-owned inference. Prior screening approval cannot enable learning; revocation hides learned results, and reapproval starts a new source boundary.
- Screening, extraction and later verification/review run in Topline shared services. Customer runtimes authorize source access and apply scoped results through finite APIs. Tenant processing consent remains required; customer model credentials and fallback inference are removed from this feature.
- Provider tokens and expense are recorded per paid attempt, with one customer charge using the existing configured markup. Unknown expense stays unpriced.
- Pending edits keep their text and retrieve the existing verification result; changed draft revisions and revoked reviewer access prevent stale review.
- Approved edits update the existing scoped proposal and keep it pending review. Customer activation no longer requires a customer inference model selection.
- Shared and customer service settings default off. Availability requires the approved shared release, exact customer runtime/schema rollout, joined-source activation and live provider, billing and quality verification.
2026-09-27 - Connect company domains to app addresses
- Connected domains offer a picker for live apps you own. The app's address drawer preselects the domain and previews its full URL before an explicit save.
- App address setup links to domain settings and returns to the originating app. Failed domain reads offer retry; unavailable selected domains require a new selection. Availability requires the web release.
2026-09-27 - Five9 archived CSV rejection
- Five9 CSV uploads reject archived sources with HTTP 409 and a clear restore message before reading the file or starting import writes.
- Availability requires the API release. Live archived-import acceptance remains pending until the corrected customer runtime rejects an upload without changing data.
2026-09-27 - Account page text reflow
- Billing preserves the full content-panel width on narrow screens, wraps actions and warnings, and uses compact billing-period labels.
- Resources capacity labels and values stack on narrow screens; shared native selects grow to fit enlarged text. Availability requires the web release.
2026-09-27 - Coding model selection recovery
- Coding Agents no longer offers CLI-unsupported Auto Cost, Balance, and Intelligence choices for new coding work. Existing selections remain visible with guidance to explicitly choose Team default or a supported fixed model.
- Unsupported saved selections fail before a new coding task or provider test is allocated, including workspace delegation and task retries. No different model is substituted automatically. Availability requires the web/API release.
2026-09-27 - Source archive and restore controls
- Source settings exposes reversible archive and restore through the existing tenant-scoped, audited source update API.
- Archive confirmation names the source and explains that data is preserved and sync/schedule settings are unchanged. Conflicting revisions require a refreshed review; pending saves block duplicate and competing source writes.
- Availability requires the shared web release. Source integration alone does not establish live archive or CSV rejection acceptance.
2026-09-26 - Offices and audit recovery
- Offices separates loading and failure from an empty list, adds load retry, and uses the shared address-lookup action.
- Audit Log uses shared clear/reset actions and notices, and distinguishes an empty trail from filters or search hiding results.
- Availability requires the web release; cell editing and API access rules remain unchanged.
2026-09-26 - Dotted app paths
- App paths support internal dots, such as
team.stack, alongside letters, numbers, and hyphens. Paths are 1โ64 characters and start and end with a letter or number; surrounding spaces and letter case are normalized. - App-path editors explain the format and show readable save, collision, and reserved-path errors. Saving a path does not publish a draft or change access.
- Availability requires the web/API release and each workspace's runtime and route-constraint migration rollout.
2026-09-26 - Five9 CSV-only sources
- Added CSV-only Five9 source creation without API credentials or automatic syncs, preserving automatic setup as the default.
- Documented export time-zone selection, UTC daylight-saving conversion, invalid local-time recovery, and duplicate-free re-import expectations.
- Clarified that no active sync is expected for CSV-only sources and that configured reports, API access, imported data, and freshness require their own evidence.
- Availability requires the shared UI release and the customer API conversion fixes; source integration alone does not establish live import acceptance.
2026-09-26 - Reviewable silent external chat learning
- Chat Integrations separates capture from optional learning in joined Slack channels and Google Chat spaces. Tenant activation, provider membership, linked human authors, contribution access, and scoped review are required.
- Evidence-backed drafts support fenced review, supported edits, rejection, and dismissal. Private sources retain their audience. Source changes and access removal withdraw affected learning; ordinary messages remain silent.
- Background screening, extraction, edit verification, and canonical proposal review use the canonical model usage ledger and existing managed pricing. Missing costs remain unpriced and reserved for reconciliation instead of being counted as free.
- Live availability requires the schema/API/worker/web release plus approved provider processing configuration; source integration alone is insufficient.
- See Silent external chat learning for controls, review, limits, lifecycle behavior, and billing records.
2026-09-25 - Native assistant MCP plugins
- Developer Access provides private, account-specific Build and Workspace plugin bundles for Codex and Claude Code, with installation and update steps.
- Build uses the published local MCP helper; Workspace uses native HTTP OAuth. Bundles include workflow skills and contain no credentials or account content.
- OAuth consent permits the selected registered callback origin in its form policy so browser approval and cancellation can reach the client. Existing registration, session, PKCE, and replay checks remain required.
- Live availability requires the UI and account API release; local plugin installation does not establish live artifact deployment or cleanup.
2026-09-25 - Harness data coverage and implementation steering
- Clarified source-query and catalog tool guidance: read timestamps and cached results do not establish current source coverage; stale, unknown, missing, or truncated records require bounded conclusions.
- Clarified handoff and steering instructions so corrections to authorized work retain the existing task and requested document/output requirements.
- Operator-input guidance requires the coding run to stop after a persisted pause; the platform resumes it when the saved answers arrive.
- A paused run finishing after an answer can no longer validate or fail the newly resumed run of the same coding task.
- Tool descriptions and coding lifecycle changes take effect after runtime release. Accounts using a saved orchestrator prompt need the equivalent instruction update through System Agents; release does not replace it.
2026-09-18 - Clearer file context and exclusion
- Excluded chat attachments have muted styling, a crossed-out filename, and an explicit Excluded label. The Context summary separates included, excluded, and draft counts while keeping inclusion reversible.
- Documented file availability versus actual model input, token and provider caching behavior, shared conversation state, and recovery. Exclusion blocks fresh access in future replies; it does not delete files or erase prior discussion and may not affect a reply already in progress.
- Source integration does not deploy the UI or publish the updated guides.
2026-09-09 - Native Slack agent setup
- Added Slack Agent messaging setup, reconnect instructions, starter prompts, session states, and scoped Stop behavior to the public provider guide.
- Aligned the in-app server setup drawer and operator steps with the current manifest, agent permission, event subscriptions, and request URLs.
- Ready/Active installation labels are distinguished from live native-session verification. Availability requires a deployed release, Slack app configuration, and the updated OAuth grant; documentation changes do not activate them.
2026-09-06 - Customer usage and daily coding limits
- Added Usage for personal metering and permission-gated organization totals, people filters, recent activity, and a link to monthly coding controls in Billing.
- Added named tiers with daily coding allowances, a default tier, per-person assignments, personal limits and personal pause. Admin-granted unlimited user allowances retain the organization spending cap. Members see allowance-only reports. Daily allowances reset at 00:00 UTC; pending work continues to count and monthly organization spending caps remain.
- Personal requests cannot select another identity or receive internal costs, source references, or organization evidence. Missing data remains unknown.
- Source integration does not publish the page or apply its database migration; the installed release determines availability.
2026-09-06 - Usage metering discovery and review
- Added a customer explanation of usage metering by feature, user and customer, supported measurements, attribution limits, unknown amounts and late corrections.
- Documented how to request an authorized review and how Topline operators use the Accounts metering view. Availability depends on the installed release and source coverage; the detailed view is internal, with no customer self-service metering or billing activation switch.
- Clarified that metering evidence, commercial enablement and invoice approval are separate, and linked the workflow from the product guide.
2026-09-01 - Per-member organizational memory access
Added
- Account administrators can independently allow a member to read organizational memory or contribute new shared memory from Slack, Google Chat, and Topline while adding or managing that person.
Security and behavior
- Turning contribution off leaves otherwise authorized chat available but prevents the linked person's new activity from entering organizational memory. It does not retroactively delete previously accepted memory.
- Reads, contributions, approvals, and passive provider ingestion enforce the current tenant-bound setting at the server. Missing permission records fail closed; existing members are migrated with both settings enabled.
2026-09-01 - Google Chat shared-space completion
Fixed
- The Topline pilot Space is now enrolled by its exact Google
spaces/...resource and routed to the same tenant as the connected Workspace. - Customer-runtime plans now receive only the shared-space routes whose exact target origin belongs to that customer. Unrelated spaces remain unavailable, and an enabled ingress can no longer forward into a destination that still has the shared-space gate turned off.
- Mentions and commands in an enrolled Space retain the existing membership, linked-user, tenant, and originating-thread checks.
- Interactive Space use no longer requires the optional Workspace Events subscription used for passive message capture. Without that subscription, passive capture is reported as not required instead of a failed setup.
2026-09-01 - Google Chat Help recovery
Fixed
- Native /help and Help commands now return through Google Chat's private command response instead of retrying against a synthetic thread that Google can reject.
- When a user opens a Space instead of the Topline app direct message, the recovery text now points explicitly to Apps > Topline and distinguishes it from a Space that happens to be named Topline.
2026-09-01 - Topline creator attribution
Changed
- Platform-provided scheduling apps now show Topline as their creator in the Library instead of exposing the tenant user who owns them for permission purposes.
- Creator filtering and Only mine use the same displayed attribution, while the underlying tenant ownership and team access remain unchanged.
2026-08-31 - Artifact-owned data deletion
Changed
- Permanently deleting an artifact now also tears down its attached schedules
and drops registered workspace tables labeled
artifact_lifetime, including all rows in those tables. - The confirmation identifies the number of artifact-lifetime tables that will
be erased. Tables with
operator_managedor another retention policy are not dropped by artifact deletion.
Safety and recovery
- Topline validates the tenant-bound generated table namespace before granting drop authority. Invalid registrations, unresolved database dependencies, or schedule cleanup failures block the artifact deletion instead of broadening cleanup or leaving it partially reported as complete.
- Artifact deletion remains irreversible, while historical audit records are retained.
2026-08-30 - Google Chat table formatting
Changed
- Google Chat answers convert Markdown tables into labeled native bullet rows, preserving inline formatting while avoiding raw pipe and delimiter syntax.
- Table-like content inside fenced code blocks remains unchanged.
2026-08-30 - Exact-space Google Chat pilot
Added
- Topline can be enabled for a specific Google Chat shared space through an operator-managed exact-space enrollment. Messages and asynchronous progress remain in the originating Google Chat thread instead of adding reply clutter to the space timeline.
Security and behavior
- Direct messages remain the standard customer setup path. Enabling a Google Workspace domain does not enable shared spaces, and Topline never selects a tenant from a participant's email domain.
- Unknown, stale, or conflicting space bindings fail closed. A shared-space response requires both current Google membership and a linked Topline member with Chat access.
- Shared-space membership is rechecked with the installed Chat app's existing bot authority. Help, setup, access-denied, and other visible preflight replies use the same originating thread instead of creating top-level clutter.
2026-08-30 - Company domains for published artifact apps
Added
- Account admins can connect multiple company-owned subdomains, complete DNS ownership and managed-TLS validation, and choose the workspace default for new artifact addresses.
- Artifact owners can assign a connected domain and unique path to an approved live app, switch it back to its Topline-hosted address, or move it to another connected domain.
Security and behavior
- Customer-facing app URLs contain only the owned domain and path. Protected viewers sign in through Topline's stable Auth0 callback and return through a single-use, artifact-bound handoff.
- Viewer, membership, and artifact grants are rechecked on app requests. Access cookies are scoped per artifact path so multiple protected apps can share one company domain.
- Changing the workspace default does not move existing apps, and a domain cannot be removed while an artifact route still uses it.
2026-08-30 - Artifact customer controls simplified
Changed
- Artifact and Library menus no longer expose customer-managed Item tests or Report problem drawers, counts, or attention labels. Customers use normal chat when something needs investigation or repair.
- Automated suites and validation checks continue to run as part of the build and publishing workflow. Default coding-agent instructions require a regression test for a customer-reported bug before the fix and relevant suite run.
- A legacy test that blocks publishing routes directly to the Coding agent for repair.
2026-08-29 - Opt-in Customer Profiles capture and reuse
Added
- Opt-in Customer Profiles can capture Topline-observed PestRoutes changes every five minutes while synthesizing the reusable profile daily or every five minutes. Initial backfill, pause/resume, fixed schedule policy, freshness watermarks, and tenant-attributed cost counters are explicit.
- Customer profile context and activity endpoints return bounded model-safe recent activity without reprocessing every PestRoutes row for future generations. The paginated history endpoint remains the full Topline-observed traversal and keeps raw payloads behind a stronger capability.
- Workspace MCP adds
get_customer_profileandget_customer_activitybehind the dedicatedcustomer_profiles:readscope and the signed-in operator's tenant capabilities.
Clarified
- Five-minute history is observation fidelity against Topline's PestRoutes mirror, not vendor CDC or a guarantee that every intermediate source state was seen.
- Customer pricing remains an effective per-active-customer monthly rate with no V1 limits or overages. Provider and allocated AWS costs stay separate from the customer charge and AWS pass-through.
2026-08-29 - Customer coding usage controls and budget alerts
Added
- Customer administrators can manage coding-agent access, finite organization paid usage, concurrency, default member allowances, and per-person overrides from Account > Billing.
- Billing displays in-product alerts at 80% of included usage, when paid usage begins, and when an organization or person reaches a hard limit.
- Customer administrators can opt active organization admins into one-time email alerts for organization thresholds. Billing keeps the durable monthly alert history even when no email recipient is selected.
- Billing shows a current-pace month-end forecast and recent task-level charged or reserved amounts so administrators can explain usage before changing a limit.
- Customer changes are tenant-bound, capability-gated, and recorded in the audit log.
Changed
- Coding credits now use a versioned customer-charge price. One credit equals $0.01 billed to the customer, and the configured customer charge cannot be below Topline's provider cost.
- Budget admission continues to count committed and reserved usage before a task starts; exact provider reconciliation settles the versioned customer charge without billing above the task's authorized reservation.
- Pause new paid usage now is an immediate stop control separate from next-month allowance and price changes. It preserves access only while included credits remain. Provider overrun absorbed by Topline remains visible but does not consume the customer's budget.
2026-08-28 - Google Chat multiline and formatted updates
Fixed
- Google Chat mention cleanup now preserves line breaks and indentation before the request reaches Topline.
- The single in-place progress response now translates standard Markdown to Google Chat-native formatting for the terminal update, including bold, italics, strike, safe HTTP(S) links, lists, and code fences, without creating a second reply. ATX and setext headings become native bold lines; unsupported link schemes remain literal.
2026-08-28 - Workspace lifecycle and complete page guidance
Added
- Profile gives each signed-in person a dedicated place to manage personal identity and account details.
- Workspace owners can edit a workspace title and upload or restore its Workspace symbol without creating a new workspace. Artifact owners, editors, and scope co-authors can manage an Artifact symbol from its action drawer.
- Library workspace selection now visibly scopes the Apps & outputs table; item menus open details, symbol, tests, and problem-report drawers directly.
- Archived workspaces separates reversible archive and restore from guarded permanent deletion. Deletion remains blocked by active dependencies and requires exact-name confirmation.
- New page-and-workflow, data-source, and artifacts/assets guides cover the current customer route map, connector availability, upload limits, sharing, recovery, and cross-page handoffs.
- Chat
@typeahead can attach exact app, artifact, or schedule context. In a thread the operator owns, selecting a teammate adds that person to the thread roster; shared-in participants cannot widen the roster. - Thread participants can switch between automatic assistant replies and
Mention only. In mention-only mode, unaddressed messages are preserved as
shared context and a standalone
@Toplinestarts the next assistant turn.
Changed
- Product and public-assistant guidance now describes Apps & Workspaces, capability-specific access, selected-source synchronization, current scheduling availability, and the distinct Slack and Google Chat boundaries.
2026-08-28 - Google Chat commands and message actions
Added
- Google Chat adds
/accessand Check connection for a synchronous, metadata-only Workspace and member-access check that does not start an agent turn or read organization data. - Ask Topline about this can explain a selected Google Chat message using the caller's authorized context. The selected message is treated as untrusted quoted material and the turn is restricted to read-only tools.
- A checked production command manifest pins the five Chat command IDs and records that no new OAuth scopes are required.
2026-08-28 - Route and appointment drive metrics
Added
- The nightly scheduling rollup now collects per-route drive metrics: total planned drive per route-day with first, between-appointment, and final legs split out, plus an ordered per-appointment leg record with explicit provenance. Unpriceable days and legs are recorded as unavailable with a reason, never as zero, and reprocessing a day revises it in place.
- The Scheduling metrics app gains a "Planned drive" section with a daily trend, a priced-legs share, and a per-route drill-down into individual legs.
2026-08-28 - Customer-admin Chat Integrations access
Fixed
- Customer administrators can open Account > Chat Integrations and manage
Slack or Google Chat setup through the narrow
external_chat.managecapability without receiving builder, source, secret, browser, or workforce authority.
2026-08-28 - Per-application scheduling lead times
Added
- A registered-applications surface and per-application lead-time controls: one shared days-out default every application inherits, plus opt-in overrides (0 = same-day, 1 = next day, N = N days out). Availability and booking enforce the same effective policy server-side, booking revalidates against the originating application at write time, and unregistered application ids fail closed.
2026-08-28 - Scheduling workspace, regions map, and default shifts
Added
- A default Scheduling workspace per tenant: the configuration and metrics applications are filed into it and shared with every team member with edit access (new members inherit access automatically) instead of appearing as loose view-only artifacts.
- The Regions editor renders a street basemap from Amazon Location Service in the customer's own account, brokered through the platform so the browser holds no credentials; when the basemap is unavailable, regions stay fully readable and editable on a plain background with a retry.
- Regions polish: a first-use explanation with Add region, inline rename, confirmed delete, and focus-on-select.
Fixed
- The Regions map now renders reliably after navigation and layout changes.
- Automatic default shifts now come from the day's route roster and only cover active technicians; office staff, inactive accounts, and unrouted days no longer default. Manual shifts never need a route and are always preserved.
2026-08-27 - Google Chat Marketplace review remediation
- Google Chat now answers
/help, the Help quick command, plainhelp, and@Topline helpbefore tenant routing with setup and usage guidance that does not expose organization data. - Unconnected direct-message users receive actionable account-connection and Chat-only access steps instead of a dead-end error.
- The saved Chat Integrations checklist and public support guide now use
/helpas the deterministic first verification step and clearly separate direct messages from Slack captured spaces. - The operator review guide now pins the two command IDs, compliant listing copy, paid-feature disclosure, synthetic reviewer test, and resubmission gate.
2026-08-26 - Scheduling meetings and blocks
Added
- A Blocks & meetings page in the scheduling workspace: one-off and recurring meetings (weekly days, ordinal weekdays like the first Monday, intervals, skip dates, series bounds) with a save-time-validated recurrence rule and a next-occurrences preview, plus a read-only view of blocked spots swept from the CRM.
- Meetings can carry a location that sets where the technician's routable day starts (and optionally ends); availability search plans routes from the meeting and never books over held time.
- A recurring sweep mirrors CRM-blocked spots into scheduling so dispatcher-blocked time is honored automatically.
2026-08-25 - Google Chat setup status
Changed
- Google Chat administration now retains a four-step checklist for domain enablement, Marketplace installation, Topline member access, and a real direct-message check. A domain that has not received a linked user's message is shown as Setup in progress, not connected.
- Developer Access now labels its personal Google authorization as Connect Drive and Calendar and explicitly distinguishes it from Google Chat domain installation.
- The public Google Chat guide documents Chat-only member setup, the direct-message-only limitation, Marketplace publication waiting, and the difference between personal Drive/Calendar OAuth and domain Chat setup.
2026-08-25 - Scheduling workspace documentation
Added
- A public scheduling guide covering the default scheduling workspace applications, route-aware availability search, technician shifts with the route-first 8-to-5 default, the forkable shift import assistant and its allowances, CRM booking behavior and refusal reasons, and the nightly scheduling metrics.
- A worked end-to-end walkthrough example in the Build Topline Artifact Apps skill, doubling as the minimal single-Bedrock-call reference for artifacts that do not need an agent loop.
Changed
- Public product language now lists the scheduling and routing engine as live in the customer's own account; customer self-booking pages remain listed as coming.
2026-08-25 - MCP 0.7.0 workspace management parity
Added
- Workspace MCP can manage threads and participants, post collaborative messages, manage documents and maintenance guidance, manage todos, bind and unbind skills, and inspect or change direct workspace access.
- Separate schedule tools cover listing, recent runs, creation, updates, and confirmed deletion. Workforce tools cover task creation, progress, guidance, operator answers, retry, and cancellation.
- Explicit personal preferences can be created, updated, or archived when both the OAuth scope and personal-memory confirmation capability are present.
- An attention tool combines pending operator questions, active workforce work, and failed or desynchronized schedules.
Changed
- Developer Access offers narrow read, contribute, manage, and full workspace permission presets across content, skills, access, schedules, workforce, and preferences. Destructive permissions remain separate.
post_thread_messageis idempotent when a client request id is supplied and records the MCP participant message without starting an internal-assistant turn.
2026-08-25 - MCP 0.6.0 workspace lifecycle
Added
- Workspace MCP can create private workspaces and update the name or description of workspaces the operator can edit.
- Workspace deletion uses a separate OAuth scope, an impact plan, an exact-id confirmation, and a state-bound plan token before removing an owned workspace.
- Workspace listings identify whether each visible workspace is writable.
Changed
- Developer Access now offers separate read, manage, and full-access workspace permission presets. MCP-only parity is defined by workspace capability family; account administration and live artifact promotion remain separate authority surfaces.
2026-08-24 - Slack and Google Chat conversation memory
Added
- A public guide for silent, permission-scoped Slack and Google Chat capture,
contextual episode processing, explicit
remember thiscontrols, bounded historical import, provider states, privacy, rollback, and limitations. - Search-quality evaluation cases for app-membership boundaries, passive capture timing, memory-control phrases, failed Google passive delivery, and history import.
Changed
- Public product language now makes clear that Topline cannot read provider conversations where the app is absent and does not make captured spaces company-wide automatically.
- Organization administration no longer widens private provider-space retrieval; current linked membership is required across search, context packs, citations, direct fetches, and review surfaces.
- Historical import uses an inclusive start and exclusive end for both parent messages and Slack thread replies, and stale event receipts recover after a bounded processing lease.
- Shared Google Chat ingress now binds each authenticated added space to one allowlisted tenant origin before passive subscription setup. Group messages, memberships, card actions, batches, and removals route by that immutable space binding instead of a participant's email domain.
- Chat Integration settings keep provider readiness visible when the captured spaces request fails, preserve action errors during background polling, and include router-backed Storybook examples for every documented state.
2026-08-24 - Scheduling availability API and configuration
Added
POST /api/scheduling/availability: probe appointment availability for a location, service type and date range; returns one offer per day and time window with arrival estimates. Requires the tenant's scheduling engine to be enabled and OSRM/VROOM runtimes provisioned.- Scheduling configuration API under
/api/scheduling/config/*: thirteen self-describing config surfaces (_schema,_view), tenant algorithm hooks with signal vocabularies (_hooks), and preview endpoints that replay candidate lock configurations and cost formulas against real data before saving (_preview,_lock_preview,_regions_map). - Scheduling configuration app (forkable artifact app) with a region boundary editor.
2026-08-23 - Hosted MCP server artifacts
Added
- A customer-buildable
kind: "mcp_server"artifact contract based on exact-pinned FastMCP 3.4.7, stateless JSON Streamable HTTP, and a single platform-authenticated machine route. - A public guide covering the tool-server use cases customers can build, the required MCP-specific manifest fields and validation flow, connection to chat and Cursor coding tasks, tool review, version rechecks, and current data/transport limits.
Changed
- The Product, Build MCP, and MCP Server guides now route hosted MCP artifact builders into the existing Connected MCP servers management surface.
- Public documentation search now recognizes hosted MCP, FastMCP, Cursor-tool, machine-auth, and MCP artifact questions.
2026-08-20 - Documentation contracts
Added
- Separate generated hosted Build and Workspace MCP references with available input/output schemas, authorization, tool annotations, and recovery guidance.
- Public Markdown and public-only machine-bundle documentation endpoints with documentation contract and deployed-build metadata.
- Validation and rendering support for an exact, pinned local Build MCP package manifest, kept separate from hosted MCP contracts.
- CI documentation contract checks and a privacy-bounded zero-result search health report.
- Immediate exact-version Build MCP release synchronization, with a daily registry recovery check and a review-only pull request boundary.
- Text-free public-document feedback for helpful, not-helpful, and outdated signals, with validated document/heading ids and bounded anonymous traffic.
- Dedicated Scheduled Work, Assistant Knowledge, Tenant Administration, and Workforce and Storyboard operator guides.
- Revision-aware documentation feedback operations and privacy-bounded search selection outcomes, without raw queries or reader identifiers.
- A weekly privacy-bounded documentation health workflow with retained evidence and a durable review queue for recurring or overdue signals.
- An isolated Admin database health check that alarms on failed or missing managed-secret rotation recovery without copying credentials or restarting services.
- A branch-bound Bedrock invoke-only GitHub OIDC role for the Build MCP live client canary, removing the need for a static provider API key.
Changed
- Public documentation summaries now use canonical public URLs instead of exposing repository source paths.
- Documentation ownership, monthly health review, and post-deployment release verification are explicit requirements.
- Documentation owners now review outdated feedback within two business days and route confirmed or recurring issues to the documentation backlog.
2026-08-19 - MCP 0.5.0
Added
- Build MCP adds a local-only artifact inspection tool that validates package boundaries and reports the bundle identity without authenticating or creating a remote draft. Deploy can require that inspected identity and fails locally if source changed before upload.
- Workspace MCP adds tenant-bound workspace discovery and cursor pagination for conversation search.
Changed
- Content-identical Build packages now produce the same archive hash across retries instead of embedding the packaging time.
- The local Build MCP now rejects credential-bearing or insecure non-loopback API URLs and rejects manifests too large for the remote create envelope before authentication or upload.
- Artifact, deployment-operation, and workspace placement ids are now UUID-validated before database access, and local Build errors redact absolute workspace paths.
- Build workspace placement is filtered to the active tenant, and Build and
Workspace report server version
0.5.0.
2026-08-19 - MCP 0.4.0
Added
- Build MCP
0.4.0adds deterministic retry identity, durable deployment operation progress, workspace and draft discovery, trusted smoke reruns, state-bound cleanup plans, and a dedicated artifact-delete OAuth scope. - The local package adds a minimal artifact scaffold, resumable progress waits, structured recovery errors, and an automated live-client certification run.
- Build MCP trusted artifact validation with bounded smoke and rendered-page evidence that does not require an external browser session.
- Explicitly confirmed cleanup for private, unpromoted drafts created by the same MCP connection.
- Stdio Build connection verification and phase-level deployment progress.
Changed
- Local artifact apps may live anywhere under the configured workspace; the
stdio package now maps them to stable trusted source roots without changing
existing workspace-root or
artifact-apps/...identities. - Build and Workspace report server version
0.4.0.
2026-08-18
Added
- Read-only Workspace MCP conversation search and recent-message tools with an
explicit
chat:readscope and tenant plus conversation-visibility checks. - Per-product OAuth authorization, granted-scope, and last-successful-call status in Developer Access.
- Single-use, product-bound end-to-end connection verification from Developer
Access through
platform_connection_check. - Owner-scoped OAuth authorization listing and revocation with exact per-grant activity state.
- Cursor-paginated conversation reads, workspace names, per-message truncation flags, and bounded visible-transcript search.
Changed
- Every hosted MCP tool now declares its Build or Workspace ownership directly; product catalogs no longer infer Workspace membership as a complement.
- MCP activity telemetry records product, tool, auth kind, and outcome without recording tool arguments.
- Build and Workspace report server version
0.2.0;/mcp/harnessnow sends deprecation and successor-link headers without scheduling a removal date.
2026-07-16
Added
- Public customer documentation at
https://topline.build/docs. - Product, secure-browser, MCP, and external API guides.
- Generated Harness MCP tool and external endpoint references.
- Machine-readable OpenAPI 3.1 specification at
/docs/openapi.json. - OAuth
docs:readscope with MCP documentation search and read tools. - API lifecycle and compatibility policy.
Changed
- Documentation search now indexes full curated document content and returns ranked excerpts.
- Customer documentation is separated from internal runbooks and contribution material.