FleetRun

RELEASE NOTES

What is new in FleetRun

A clear record of shipped product changes for pilot fleets.

NewJuly 27, 2026

Blog foundation for company, team, family, and personal use cases

  • Added a production-ready blog index with persona filters, tag filtering, search, and featured reads.
  • Added article detail pages with structured data, related reading recommendations, and stable slug handling.
  • Published a public RSS feed endpoint at /blog/rss.xml and wired it into the sitemap.
  • Added article cover images for every post and larger visual treatment for the newest post in the listing.
  • Enabled social-share links from article pages so company blog content can be distributed via X and LinkedIn.
  • Expanded marketing verification for dynamic blog paths in SEO checks and included blog entries in sitemap generation.
NewJuly 26, 2026

A clearer integration roadmap

  • The public homepage is now waitlist-first and states the invite-only pilot boundary plainly: supervised missions, human approvals, operationally enabled schedules, and bounded read-only Google Workspace, Slack, and Notion tools; additional connectors and automation remain roadmap. Its bounded, bot-checked signup endpoint can keep using the separate V1 waitlist store so prior signups remain intact, while duplicate requests receive the same private response.
  • Mission top-ups and approval resumes now preserve the original preflight estimate while tracking the live reservation independently, so historical estimate accuracy is no longer overwritten by later holds.
  • Model-gateway circuit breakers now isolate each version of a Fleet’s own provider credential from the shared platform credential, while network and provider outages still protect every caller through a separate upstream breaker; Fleet-key usage still consumes mission limits but is excluded from FleetRun wallet charges.
  • Security, privacy, legal, developer, and schema copy now accurately describes connector credentials as AES-256-GCM authenticated encryption under one application key, without overstating the key hierarchy or rotation guarantees.
  • Agent photo writes now enforce the same non-kid role boundary as agent edits, while Storage objects and database references must bind to one real agent’s canonical Fleet path; migration stops for explicit cleanup if legacy objects violate that invariant.
  • The Floor now gives its server-rendered heading and briefing stable key-only composition boundaries, removing persistent development warnings without adding layout markup.
  • Customer pages now distinguish unavailable Fleet, billing, usage, agent, crew, support, feedback, and profile reads from genuine empty states, so an outage cannot fabricate zero spend, missing history, or a deleted record.
  • A migration-derived verification guard now rejects ambiguous PostgREST relationship embeds while continuing to allow relationships proven to have exactly one foreign key.
  • Admin deletion operations now keep every pending, approved, and retryable cleanup visible ahead of completed history, use exact status totals, and paginate closed evidence with a stable cursor.
  • The shadcn scaffolding CLI and its MCP/Hono server tree no longer enter production installs or application builds, reducing production advisories from five to four; Next.js still transitively selects one vulnerable Sharp and three vulnerable PostCSS releases pending a supported framework update.
  • Onboarding now treats Enter as step navigation before Review, ignores IME confirmation and pending repeats, and creates a Fleet only from the explicit reviewed action.
  • The public site now publishes canonical URLs, a reviewed public-only sitemap and query-safe robots policy, and truthful CSP-authorized organization, website, and application structured data; private routes fail closed for indexing, and Release notes are linked from shared navigation.
  • Mission requesters and Fleet owners/admins can now stop healthy running work; one Fleet-to-mission lock order fences reservation, membership, approval, and provider-dispatch races, authenticated clients cannot bypass the narrow approval lifecycle APIs with direct updates, precise cumulative spend settles once, and every cancellation is audited.
  • Support ticket creation now commits the ticket and its visible opening message atomically, while stable retry tokens prevent duplicate conversations after lost responses or double submissions.
  • Admin People and Workspaces now provide exact filtered totals and stable forward/back pagination with signed, expiring, filter-bound cursors, keep membership reads scoped to the visible page, and link search and audit results directly into the relevant inventory view.
  • Onboarding and Profile settings now enforce one versioned timezone policy in the app and database, preserving documented aliases without runtime-dependent remapping or silent legacy-data guesses.
  • Daily schedules now atomically catch up the immediately previous local day when a late-evening poll slips past midnight, without duplicate worker dispatch; re-enabling or changing time zones/times starts a fresh lifecycle, and older missed days are reported without replay.
  • Account Preferences now offers light, dark, and system themes across the signed-in app, saves the choice per account, and keeps system mode in sync with live device changes.
  • Mission liveness now uses one shared heartbeat policy across customer views, staff tools, and the automated reaper, preventing their stuck-run decisions from drifting apart.
  • Admin People and deletion-request views now distinguish failed or partial reads from genuinely empty results; deletion evidence also has exact totals and pagination so records beyond the newest page remain discoverable.
  • Successful onboarding now ends with an atomically one-time, reduced-motion-safe celebration; its help links open the real support centre and a prefilled product-bug ticket.
  • A planned Local Filesystem Connector now has a signed, device-bound read-only protocol with exact Fleet/user/agent/root grants, descriptor-relative no-follow path containment, replay protection, bounded operations, and minimized secret-redacted responses.
  • The planned browser automation capability now has a server-only protocol foundation for exact typed actions, Fleet/user/session/device binding, public-network and domain gates, bounded execution, replay protection, secret handoff, foreground approvals, and minimized observations; no browser runtime is live yet.
  • The planned GitHub App pilot now has a bounded server-side read foundation that re-authorizes the actor, Fleet, plan, installation, account, and selected repositories on every call, minimizes repository and issue metadata, and durably records rejected installation tokens for reconnection.
  • The planned Vercel connector now has a backend foundation for strict OAuth account, team, and project selection, independently verified Vercel project/deployment read permissions, and bounded read-only adapters; it remains unavailable until authorization and persistence are wired end to end.
  • AWS, Azure, and Google Cloud now share a deny-by-default identity foundation for Fleet-bound resource selection, short-lived workload federation, read-only policy validation, secret rejection, and minimized verification results; no cloud provider is presented as live yet.
  • A planned Apple Local Connector contract now supports tightly bounded Notes and Reminders operations through macOS Notes Automation and EventKit, with device signatures, resource allowlists, replay protection, minimized results, and mandatory foreground approval for every write.
  • iCloud Mail now has a secure app-specific-password foundation with exact Apple mail endpoints, account-and-Fleet isolation, bounded metadata output, and explicit reauthentication handling; the connector remains planned until a reviewed IMAP runtime and connection flow ship.
  • The Integration Specialist foundation now defines typed lifecycle transitions, signed short-lived handoffs bound to the user, Fleet, provider, and exact scopes, atomic replay protection, and a credential-pattern guard ready to keep secrets out of AI context.
  • A FleetRun-owned provider registry now turns pinned connector metadata into a deny-by-default capability allowlist, with build failures for unreviewed licenses, hosts, scopes, or actions.
  • Admin revenue reporting now uses complete, snapshot-consistent database aggregates instead of capped row downloads, separates paid top-ups from grants and payment reversals, and labels the intentionally ranked per-Fleet detail.
  • The marketing homepage now distinguishes the available Google Workspace, Slack, and Notion connectors from planned integrations in an accessible brand carousel.
  • The Features page now reflects the executable Google Workspace, Slack, and Notion capabilities instead of stale Google-only copy.
  • A shared integration registry and verification guard prevent planned providers from being marketed as available.
  • Gmail approval language now consistently explains that FleetRun creates a draft for you to review and send yourself; FleetRun never sends mail.
  • Sign-in, signup, password-reset, and confirmation-resend forms now request a fresh bot-check token after every completed attempt instead of reusing a consumed token.
  • Family Adults can now complete Gmail-draft and Calendar-event approval workflows under the same authority enforced on the parent approval, including durable provider-result recording.
  • Fleet Wallet checkout now enforces owner/admin billing authority inside the server action, preventing other roles from bypassing disabled top-up controls.
  • Integration entitlements are now rechecked during OAuth completion, MCP configuration, capability discovery, and every tool invocation so downgrades take effect immediately.
  • Editing a pending crew now recomputes its reservation cap from each remaining agent's current model, so removing people or agents cannot underfund the work.
  • Fleet invitations now match email addresses literally, preventing underscores or percent signs from rotating or blocking another recipient's invite.
  • Stripe disputes now reverse credits, record uncollectible debt, and suspend the affected Fleet atomically—even when the disputed credits were already fully spent.
  • Fleet JSON exports now include support conversations, Gmail and Calendar approval payloads, crew plans, customer feedback, agent capability grants, and owner-visible deletion-request history scoped by row-level security; a schema-derived verification guard requires every Fleet-scoped table to be explicitly exported or excluded with a reason while credentials and internal-only data stay out.
  • Feedback and mission-rating prompts now follow the actively selected Fleet, with database enforcement preventing cross-Fleet mission attribution.
  • Gmail search now follows the actively selected Fleet and rejects stale or forged Fleet preferences through the membership-validated Fleet resolver.
  • Schedules, missions, and approvals now reject cross-Fleet agent references at the database boundary, while workers fail closed on any inconsistent legacy rows.
  • Fleet-owned child records now enforce that missions and approvals belong to the same Fleet, with migration preflight checks that surface legacy inconsistencies instead of rewriting them.
  • Stripe partial refunds now reconcile cumulatively per charge, so splitting or reordering refunds cannot leave free credits or create synthetic wallet debt.
  • Reconnecting Google Workspace now preserves a healthy refresh token only for the same verified account, so consent and scope upgrades no longer silently break scheduled work.
  • Won Stripe disputes now clear only their own recorded debt and restore only credits originally removed from spendable balance, preventing double-spendable credits.
  • Approval-gated Gmail drafts now reject MIME header control characters and encode Unicode subjects and message bodies safely, so the approved recipient and content exactly match both initial and retried provider payloads.
  • Onboarding now keeps its action row stable when submission errors appear, clears stale errors on Back and Edit, and moves focus to each new step without unnecessary or motion-heavy scrolling.
  • Support tickets now accept related missions only from the active Fleet, with a database invariant that blocks cross-Fleet references from every writer and stops for operator review if legacy mismatches exist.
  • Mission settlement now serializes concurrent workers into one winner, preventing the same reservation from being charged or released twice while preserving exact replay behavior.
  • Google disconnect now disables agent access before revocation, retains encrypted retry material across credential, network, and provider failures, and removes the connection only after confirmed or definitively already-invalid revocation.
  • Fleet names now show the Fleet noun exactly once throughout the app shell, so names such as “Acme Fleet” no longer render as “Acme Fleet Fleet.”
  • Approval guidance now distinguishes Business owner/admin authority from Family owner/admin/Adult authority, backed by the same canonical role policy used by approval actions and views.
  • Approval-gated Gmail and Calendar writes now claim a stable attempt before contacting Google, preserve uncertain provider outcomes for reconciliation instead of blindly retrying, expose authorized reconciliation and mission-resume controls, and settle blocked missions exactly once after confirmation.
  • Fleet deletion now uses a single-winner, retryable cleanup lifecycle: provider credentials survive failed revocation, every Storage page must be verified and removed, and database deletion remains blocked until all required cleanup succeeds.
  • Continuous integration now runs on the declared Node.js 22 runtime, so the full TypeScript verification suite executes before production builds instead of failing on an unsupported runtime flag.
  • The user menu now uses its identity header as the single profile destination, removing the duplicate Profile row while keeping Team and account navigation easy to scan.
  • Support replies now derive staff authority from the ticket’s Fleet at one database boundary, so changing the active Fleet, role, or membership can never turn a requested internal note into a customer-visible message.
  • The homepage now shares the responsive public-site header and footer, preserving signed-in navigation while restoring canonical links, theme controls, focus treatment, and phone-safe spacing.
NewJuly 25, 2026

Operational workspace and team organization

  • A redesigned, full-height Agents workspace with live team health, approval attention, and a reporting-structure canvas.
  • Zoom controls for large teams, plus drag-to-reassign agents beneath people or other agents.
  • People can now be reorganized beneath other people, with server-enforced workspace boundaries and cycle protection.
  • Agent cards now open their operational profile, including mission history, tool activity, costs, granted tools, and pending approvals.
  • Insights now has an operations queue that links directly to stalled runs, pending approvals, failed work, blocked missions, and an empty Fleet Wallet.
  • Mission recovery improvements: cancel queued work to release credits, safely retry failed work as a new mission, and resolve stuck runs with an audit trail.
  • Slack and Notion connectors are live alongside Google Workspace, with provider safety checks now covering all supported connections.
  • The staff Feedback workspace is now directly accessible from the admin portal, and Pricing, Contact, and Security share the same responsive public-site navigation and footer.
Current pilotJuly 2026

Governed Google Workspace pilot

  • Google Workspace connection health and least-privilege read tools for Gmail, Calendar, and Drive.
  • Approval-gated Gmail draft creation. FleetRun creates drafts after approval; it never sends mail.
  • Mission traces with model usage, tool activity, cost, and errors.
  • Fleet switching, role-aware permissions, wallet reservations, and activity history.
Back to FleetRun