Skip to content

chore(parity): re-read hermiq's six competitor columns from source code and docs, add 53 demand rows - #958

Merged
rubenvdlinde merged 12 commits into
developmentfrom
parity/wave5-competitor-source-read
Sep 26, 2026
Merged

rubenvdlinde merged 12 commits into
developmentfrom
parity/wave5-competitor-source-read

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

Wave 5: hermiq's competitor columns re-read from source code

Data file only: openspec/parity/capabilities.json. No page is wired and no code changes, so the product's suites cannot be affected; they were not run. Read against development at 5277c0d (the base of this branch).

What changed. Every competitor column is re-rated. The five open-source systems were read from their source at a release tag (shallow clones), with path:line evidence for each cell:

  • Hermes Agent v2026.9.24 (f97608f)
  • Dify 1.17.1 (8387590)
  • n8n n8n@2.40.7 (09b3ce6)
  • Open WebUI v0.11.4 (8bd8b4f)
  • Nextcloud Assistant v4.0.0 (366d5ee) with Context Agent v2.8.0 (99936dd)

Microsoft Copilot Studio is closed source and was read from its public documentation only, with no trial account.

Grades. No instance was booted, so every column is graded docs-only with readOn 2026-09-26. A source-read cell says "source read at , not driven"; the grade enum has no value for a source read. Every system now carries a sources object in the hydra#706 shape: absent fields are null, with the reason under nullReasons. Every row mined from demand signals carries origin and originUrl. Hermiq's own column is rated from its code on every new row, with built.evidence, reachedOn and built.state.

Rulings applied across columns (also recorded in the file's _comment and each system's readHow):

  • Nextcloud-phrased rows: a competitor rates partial when it has the same kind of capability on its own surface, with the missing Nextcloud part named; it rates no when nothing like it exists.
  • Plugins, add-ons and separate repos: a capability that exists only as a marketplace plugin, a community add-on or in a separate repo is partial or no, with the reason.
  • Licences: licence-gated features are partial, marked enterprise-licensed.
  • Opt-in modules: shipped opt-in modules (n8n's Agents module, Dify's Agent v2 flag) count as shipped, with an opt-in note.
  • Copilot Studio: preview features are partial, and features needing a second Microsoft product or licence are partial.

Per-system grade and counts, before (development 5277c0d) and after

system grade before grade after read before read after yes/partial/no/unknown before (214 rows) after, same 214 rows after, all 277 rows
hermiq self self 2026-09-26 2026-09-26 139/29/45/1 139/29/45/1 148/47/80/2
nextcloud-assistant docs-only docs-only 2026-07-12 2026-09-26 26/3/18/167 56/53/104/1 64/68/142/3
hermes-agent docs-only docs-only 2026-07-23 2026-09-26 55/13/0/146 95/79/40/0 120/96/61/0
copilot-studio docs-only docs-only 2026-07-12 2026-09-26 14/7/5/188 82/97/33/2 102/123/49/3
dify docs-only docs-only 2026-07-23 2026-09-26 30/21/0/163 70/81/63/0 88/104/85/0
n8n docs-only docs-only 2026-07-23 2026-09-26 30/17/1/166 99/74/41/0 121/106/50/0
open-webui docs-only docs-only 2026-07-23 2026-09-26 42/11/0/161 77/61/76/0 93/85/99/0

Rating deltas per column (rows that existed before)

  • hermiq: 0 changed;
  • nextcloud-assistant: 181 changed; unknown→no 98, unknown→partial 44, unknown→yes 24, no→yes 7, no→partial 5, yes→partial 2, partial→yes 1
  • hermes-agent: 159 changed; unknown→partial 65, unknown→yes 41, unknown→no 40, yes→partial 7, partial→yes 6
  • copilot-studio: 195 changed; unknown→partial 91, unknown→yes 66, unknown→no 29, partial→yes 5, yes→partial 3, no→partial 1
  • dify: 185 changed; unknown→partial 65, unknown→no 62, unknown→yes 36, partial→yes 13, yes→partial 8, yes→no 1
  • n8n: 178 changed; unknown→yes 63, unknown→partial 63, unknown→no 40, partial→yes 9, yes→partial 3
  • open-webui: 176 changed; unknown→no 75, unknown→partial 47, unknown→yes 39, yes→partial 9, partial→yes 5, partial→no 1

The full change log (every changed cell, before, after, evidence) is posted as comments on this PR, because it exceeds the body limit. Rows new in this PR are not in the delta table; they are listed below.

Demand-signal rows added (63)

id area origin row hermiq nextcloud-assistant hermes-agent copilot-studio dify n8n open-webui
td-no-training compliance tender Guarantee that the organisation's data is never used to train the models its agents call. partial partial partial yes partial partial partial
td-explain oversight tender See in plain language how an AI outcome came about, so a person keeps the final say. partial partial partial partial partial partial partial
td-validated-sources memory tender Limit an assistant to answering only from documents the organisation has validated. partial partial no yes partial partial partial
td-ai-literacy compliance tender Help users build AI literacy with explanation or training modules inside the product. no no partial no partial no no
td-bias-test reuse tender Test agents for bias on a regular basis and keep the result. partial no no partial no partial no
dm-task-board flows changelog Put tasks on a shared board that several agents claim, hand off and close. no no yes no no no no
dm-standing-goal agents changelog Give an agent a standing goal it keeps working on across turns until a check says it is reached. no no yes partial partial partial partial
dm-model-ensemble models changelog Answer one prompt with several models at once and merge their answers into one reply. no no yes no partial partial yes
dm-key-rotation models changelog Spread calls over several API keys for one provider and rotate to the next key when one runs out. no no yes no yes partial no
dm-backup-restore operations featureRequest Back up all agent data automatically and restore it to an earlier point after a bad change. partial no partial yes partial partial partial
dm-remote-agent flows featureRequest Hand a task to an agent running on another server and get its answer back. no no yes yes partial yes partial
dm-rate-cap models featureRequest Cap how many requests per minute an agent sends to a model provider. no no no partial partial partial no
dm-temperature models featureRequest Set the temperature an agent's model answers with. yes no partial partial yes yes yes
dm-project-memory memory featureRequest Keep a separate memory per project next to a shared memory. partial no partial no no partial partial
dm-cross-channel chat featureRequest Carry one conversation over from one channel to another, such as from a messenger to the desktop. unknown no partial no partial no no
dm-build-snapshot agents changelog Start every run of a published agent from the exact files and installed tools it had when it was built. no no no yes yes partial no
dm-install-cli-tool tools changelog Let an agent install a command line tool from a package registry and use it in its runs. no no yes no yes partial partial
dm-sandbox-choice operations changelog Choose whether an agent's shell and code run on the own server or in a hosted cloud sandbox. no no yes yes yes partial partial
dm-approval-api oversight changelog Answer a waiting approval step from another program through the API. yes yes yes partial yes yes yes
dm-named-approvers oversight featureRequest Name the people who must answer a human approval step, so nobody else can. yes no partial yes partial yes no
dm-context-meter chat featureRequest See how full the agent's context window is while chatting. no no yes no no partial yes
dm-folders operations featureRequest Sort agents and flows into folders. no no no partial partial partial partial
dm-run-compare observability featureRequest Compare two runs of a flow side by side to see what changed. partial no no partial no partial no
dm-claimed-tool-call oversight featureRequest Flag an answer when the agent claims a result without calling the tool it needed. no no partial partial no partial no
dm-deep-research tools featureRequest Run a deep research task where the agent searches many sources and writes a cited report on its own. partial partial yes partial partial partial partial
dm-second-factor operations featureRequest Require a second factor such as an authenticator code when signing in. yes yes no yes no yes no
dm-user-key-encryption compliance featureRequest Encrypt my conversations with a key only I hold, so even the administrator cannot read them. no no no no no no partial
dm-mcp-user-auth tools featureRequest Connect an MCP tool server with each person's own login, so tool calls run with that person's rights. partial no partial yes partial partial yes
dm-responses-api models featureRequest Connect a model through the provider's Responses API instead of chat completions. no unknown yes no partial yes yes
dm-prompt-cache models featureRequest Cache repeated prompt parts at the model provider automatically to cut cost and wait time. no unknown yes unknown partial yes partial
dm-ask-mid-run oversight changelog Let the agent pause mid-run and ask me a question with suggested answers before it continues. partial partial yes yes yes yes yes
dm-agent-form-fields agents changelog Fill in form fields an agent declares, such as a dropdown or text box, before the conversation starts. no partial no partial yes partial yes
dm-fork-chat chat changelog Fork a conversation at any answer to try another path without changing the original. no no partial no partial yes yes
dm-flow-change-review oversight changelog Require a named reviewer to approve a change to a flow before it goes live. no no no partial no partial no
dm-log-redaction-policy compliance changelog Hide sensitive inputs and outputs from run logs with an instance-wide policy. yes no yes partial no partial partial
dm-agent-workspace tools changelog Give an agent its own writable workspace for the files it creates during a session. partial partial yes partial yes partial partial
dm-native-pdf models changelog Hand a PDF straight to a model that reads PDFs natively, without turning it into text first. no partial no partial yes yes partial
dm-browser-use tools changelog Let an agent drive a web browser: open pages, click and fill in forms. no no yes yes partial yes partial
dm-tool-call-cap oversight featureRequest Stop an agent after a set number of tool calls so it cannot loop forever. partial partial yes no yes partial yes
dm-tool-error-recovery tools featureRequest Let an agent carry on when a tool fails or returns nothing, with the error passed back to it. yes yes yes partial yes partial yes
dm-subscription-login models featureRequest Sign in to a model provider with an account subscription instead of pasting an API key. partial no yes no no partial partial
dm-failed-run-fix observability changelog Have an assistant investigate a failed run and propose a fix. no no partial no partial yes no
dm-builtin-table memory changelog Give an agent a built-in table to read and write structured records without an outside database. yes yes no yes no yes no
dm-bulk-delete-chats chat featureRequest Delete many conversations at once instead of one by one. no no yes no no no yes
dm-prompt-placeholders agents featureRequest Use placeholders such as my name or today's date in the instructions an agent follows. no partial partial yes yes yes yes
dm-ai-label compliance featureRequest Label files and text an agent produced as AI-generated. partial partial no partial no partial partial
dm-skill-search skills featureRequest Let an agent find the right skill by searching when there are too many to list. no no partial partial partial no no
dm-app-tools tools featureRequest Let other installed apps add their own tools to the agent. yes partial yes partial yes yes yes
dm-mcp-oauth operations featureRequest Let outside AI clients sign in to the instance's MCP server with OAuth. no partial no partial partial yes no
dm-show-reasoning observability changelog See the model's reasoning next to its answer. no yes yes partial yes yes yes
dm-speech-translate chat changelog Translate a spoken recording into another language and hear the result. partial yes partial partial partial yes partial
dm-subtitles delivery changelog Generate a subtitle file for a video or recording from Files. no yes no no no no no
dm-image-chat chat changelog Send images to the agent in chat and get images back in its answer. no yes yes partial yes yes yes
dm-computer-use tools changelog Let an agent operate desktop applications on a Windows machine by looking at the screen and clicking, when the application has no API. no no yes yes no partial no
dm-custom-metrics observability changelog Define my own analytics measures in plain language and see them next to the built-in ones. no no no partial no partial no
dm-question-themes observability changelog See the questions people ask an agent grouped into themes, and drill into each theme. no no no partial no no partial
dm-savings-tracking observability changelog Track how much time and money an agent saves compared with doing the work by hand. no no no yes no partial no
dm-call-consent compliance changelog Ask a caller for consent before a voice call with an agent is recorded and transcribed. no no no yes no no no
dm-async-flow-step flows changelog Let a long-running flow step return its result to the agent later instead of failing on a time limit. partial no partial yes no yes partial
dm-builder-upgrade reuse changelog Upgrade an agent someone built in the lightweight in-chat builder into the full agent builder without starting over. no no no yes partial yes no
dm-metadata-filter memory changelog Limit which documents an agent searches by their metadata, such as owner, file name or modified date. partial partial partial yes yes yes partial
dm-eval-in-pipeline reuse changelog Run an agent's test set automatically from a build pipeline through an API and fail the build on regressions. yes no no partial no partial no
dm-agent-as-code reuse changelog Edit an agent as files in a code editor, keep it in git and sync the changes back to the builder. partial partial yes yes yes partial partial

The five td-* rows come from TenderNed requirements in the intelligence database; originNote names the tender and requirement ids. The dm-* rows were mined per system: Hermes 10 (4 changelog, 6 feature requests), Dify 9 (4 changelog, 5 feature requests), Open WebUI 9 (3 changelog, 6 feature requests), n8n 10 (7 changelog, 3 forum requests), Nextcloud 10 (4 changelog PRs, 6 enhancement issues), Copilot Studio 10 (What's new).

Sources object per system

  • nextcloud-assistant: present: docs, sourceRepo, featurePage, featureRequests, issueTracker, changelog, apiReference, marketplace, pricing, accessibilityStatement, securityDocs, demoInstance, community, videos, caseStudies, partnerDirectory, jobPostings. Null: roadmap (searched nextcloud.com and both repos (no GitHub projects, discussions disabled on both); search found no public roadmap, only that Enterprise customers can influence it.); reviews (G2 and Capterra pages for Nextcloud return 403 to fetches; no Assistant-specific review page found.); trainingCurriculum (searched nextcloud.com for training and certification: only webinars, events and partner-delivered training, no curriculum page.); tenders (searched the intelligence database on 2026-09-26 (tenders name, description and keywords, and requirements text_nl/text_en, word-boundary match on 'nextcloud assistant', 'context agent'): no tender names it; 'nextcloud' alone matches Middelburg VTH (tender 1184, a Nextcloud storage integration requirement) and two Austrian tenders, none about the Assistant).
  • hermes-agent: present: docs, sourceRepo, featurePage, featureRequests, issueTracker, changelog, apiReference, marketplace, securityDocs, community, videos, caseStudies, jobPostings. Null: roadmap (no ROADMAP file in the repo at v2026.9.24 (find -iname 'roadmap' hit only a skill asset), hermes-agent.nousresearch.com/roadmap and /docs/roadmap return 404, GitHub Discussions are disabled (has_discussions false, /discussions 404); GitHub Projects could not be listed (token lacks read:project).); pricing (the agent is MIT-licensed and free; the only paid surface is the Nous Portal subscription, and portal.nousresearch.com/pricing returned HTTP 429 so it was not seen resolving (portal.nousresearch.com itself resolves, title 'Nous Portal').); accessibilityStatement (no accessibility statement: hermes-agent.nousresearch.com/accessibility 404; grep -ril accessib in website/docs only hits install and desktop pages, none a statement.); demoInstance (no hosted demo: the product is a self-installed CLI, desktop app and gateway; the homepage and README link install scripts, not a demo.); reviews (no review-site listing found or linked from README or the docs site; none seen resolving.); partnerDirectory (no partner or integrator directory linked from README, the docs site or nousresearch.com.); trainingCurriculum (no training or certification curriculum; the docs have guides (e.g. /docs/guides/tips resolves) but no course.); tenders (searched the intelligence database on 2026-09-26 (tenders name, description and keywords, and requirements text_nl/text_en, word-boundary match on 'hermes agent', 'nous research'): no tender names it).
  • copilot-studio: present: docs, featurePage, featureRequests, roadmap, changelog, apiReference, marketplace, pricing, accessibilityStatement, securityDocs, community, videos, trainingCurriculum, tenders. Null: sourceRepo (closed source SaaS; only github.com/microsoft/CopilotStudioSamples (samples, resolved 200) and the docs sources (MicrosoftDocs/businessapps-copilot-docs-pr is private) exist.); issueTracker (no public product issue tracker; support goes through Microsoft support tickets (fundamentals-support page); the ideas portal is under featureRequests.); demoInstance (only sign-in trials (go.microsoft.com/fwlink/p/?linkid=2252408 from the feature page); Ruben's rule forbids trial accounts, and no public demo agent is published.); reviews (g2.com/products/microsoft-copilot-studio/reviews returns 403 to curl and WebFetch; not verified.); caseStudies (feature page links microsoft.com/en-us/customers/search; fetched with a Copilot Studio filter it rendered 0 results (client-side), so no verified story URL.); partnerDirectory (appsource.microsoft.com/en-us/marketplace/partner-dir returned 403; not verified.); jobPostings (jobs.careers.microsoft.com search for "copilot studio" redirects to the generic apply.careers.microsoft.com page, query dropped; no stable listing URL.).
    • tenders: 7 (intelligence database, word-boundary match on copilot studio in tender name or description; all licence purchases, none carries requirements)
  • dify: present: docs, sourceRepo, featurePage, featureRequests, issueTracker, roadmap, changelog, apiReference, marketplace, pricing, securityDocs, demoInstance, community, reviews, videos, caseStudies, partnerDirectory, trainingCurriculum, jobPostings. Null: accessibilityStatement (https://dify.ai/accessibility returns 404; release 1.15.0 notes accessibility polish but no statement page found in docs or site); tenders (searched the intelligence database on 2026-09-26 (tenders name, description and keywords, and requirements text_nl/text_en, word-boundary match on 'dify'): no tender names it).
  • n8n: present: docs, sourceRepo, featurePage, featureRequests, issueTracker, changelog, apiReference, marketplace, pricing, securityDocs, demoInstance, community, reviews, videos, caseStudies, partnerDirectory, trainingCurriculum, jobPostings. Null: roadmap (no public roadmap: n8n.io/roadmap/ and n8n.io/product-roadmap/ return 404, community.n8n.io/c/roadmap 404, GitHub Discussions and Projects are disabled (gh repo view: hasDiscussionsEnabled false, hasProjectsEnabled false); the only forum topic titled roadmap is from 2022 (community.n8n.io/t/13545).); accessibilityStatement (n8n.io/accessibility/ and docs.n8n.io/accessibility/ return 404; no 'accessib' link on n8n.io, n8n.io/legal/ or docs.n8n.io home pages.); tenders (searched the intelligence database on 2026-09-26 (tenders name, description and keywords, and requirements text_nl/text_en, word-boundary match on 'n8n'): no tender names it).
  • open-webui: present: docs, sourceRepo, featurePage, featureRequests, issueTracker, roadmap, changelog, apiReference, marketplace, pricing, securityDocs, community, reviews, videos, caseStudies, partnerDirectory, jobPostings. Null: accessibilityStatement (docs.openwebui.com/accessibility returns 404 and the docs sitemap has no accessibility page; the repo has none either); demoInstance (no public demo linked from README.md, docs.openwebui.com or openwebui.com; the product is self-hosted only); trainingCurriculum (docs sitemap has how-to tutorials (docs.openwebui.com/tutorials) but no structured course or certification); tenders (searched the intelligence database on 2026-09-26 (tenders name, description and keywords, and requirements text_nl/text_en, word-boundary match on 'open webui'): no tender names it).

The full objects, URLs included, are in the file.

Verifier (hydra development, fetched fresh; hydra#707 made origin a free string)

Before, on development 5277c0d, report profile:

parity-verify: _lane/base.json
  200 rated rows, 14 pending, 7 systems

system-without-sources  (6)
    system 'nextcloud-assistant' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for
    system 'hermes-agent' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for
    system 'copilot-studio' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for
    system 'dify' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for
    system 'n8n' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for
    system 'open-webui' has no sources object, so nobody can tell which of its docs, roadmap, changelog and tenders were looked for

unknown-cells  (1)
    992 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[ag-create] nextcloud-assistant, capabilities[ag-create] n8n, capabilities[ag-create] open-webui, capabilities[ag-list] nextcloud-assistant, capabilities[ag-list] hermes-agent, capabilities[ag-list] copilot-studio, capabilities[ag-list] n8n, capabilities[ag-list] open-webui

7 finding(s) in 2 check(s)
report-only: pass --strict to fail on these

Before, --strict:

parity-verify: _lane/base.json
  200 rated rows, 14 pending, 7 systems

unknown-cells  (1)
    992 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[ag-create] nextcloud-assistant, capabilities[ag-create] n8n, capabilities[ag-create] open-webui, capabilities[ag-list] nextcloud-assistant, capabilities[ag-list] hermes-agent, capabilities[ag-list] copilot-studio, capabilities[ag-list] n8n, capabilities[ag-list] open-webui

1 finding(s) in 1 check(s)

After, --strict (exits 1 on the unknown-cells census only):

parity-verify: openspec/parity/capabilities.json
  263 rated rows, 14 pending, 7 systems

unknown-cells  (1)
    8 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[ch-stream] copilot-studio, capabilities[me-compression] copilot-studio, capabilities[mo-personal-key] nextcloud-assistant, capabilities[dm-cross-channel] hermiq, capabilities[dm-responses-api] nextcloud-assistant, capabilities[dm-prompt-cache] nextcloud-assistant, capabilities[dm-prompt-cache] copilot-studio, pending[me-permissions] hermiq

1 finding(s) in 1 check(s)

After, report profile:

parity-verify: openspec/parity/capabilities.json
  263 rated rows, 14 pending, 7 systems

unknown-cells  (1)
    8 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[ch-stream] copilot-studio, capabilities[me-compression] copilot-studio, capabilities[mo-personal-key] nextcloud-assistant, capabilities[dm-cross-channel] hermiq, capabilities[dm-responses-api] nextcloud-assistant, capabilities[dm-prompt-cache] nextcloud-assistant, capabilities[dm-prompt-cache] copilot-studio, pending[me-permissions] hermiq

1 finding(s) in 1 check(s)
report-only: pass --strict to fail on these

Images pulled

None. No lab was booted in this lane, so there is nothing to remove afterwards and there is no market-intelligence lab PR. Every column stays docs-only. Driving the rows the code reading could not settle is left to a lab wave.

Where the method was harder

  • What an agent is differs per product. An agent is a profile in Hermes, a roster entry plus the Studio apps in Dify, a workspace Model preset in Open WebUI, an AI Agent node inside a workflow in n8n, and one fixed agent in Nextcloud Assistant. Per-agent rows therefore split across several objects or fail by construction.
  • Capabilities sit outside the tagged tree. Dify's connectors and model providers are marketplace plugins, read on GitHub main rather than at a tag. Open WebUI's terminal and computer-use features live in separate first-party repos. Nextcloud Assistant depends on nextcloud/server and integration_openai, which were not read. The plugin rule keeps these partial even where the catalogue is large.
  • Nextcloud-phrased rows needed one rule. Readers first rated them differently and some rewrote cells, so the lane settled the rule above.
  • Copilot Studio docs were rate-limited. learn.microsoft.com answered 429, so the docs tree was saved once and Power Platform pages were read from the MicrosoftDocs GitHub sources.
  • Readers died and were relaunched from their partial packs. Two account session limits killed readers mid-run; every pack written survived and was folded.
  • Tenders are thin. The intelligence database holds no tender naming any competitor except Copilot Studio (7 licence purchases). The category's 74 tenders are mostly RPA licence buys.
  • Live checks owed: sc-once and dm-tool-call-cap (Nextcloud Assistant) say "Needs a live check".

🤖 Generated with Claude Code

…ine rows mined from its changelog and issues
… and nine rows mined from its discussions and releases; record the Nextcloud-phrased row rule
…reading, its sources object and ten rows mined from its issues and 4.0.0
…rces object and ten rows mined from What's new
…n limit (hermiq on 53 demand rows, hermes-agent 45, dify 10)
…gs on dify's responses-api and native-pdf cells
@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 1 of 8

nextcloud-assistant: every rating change (before → after, evidence)

  • ag-create unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'agent' in assistant:lib/Db, lib/Migration and context_agent:ex_app: tables hold chat sessions, messages, assignments and task notifications only (assistant:lib/Migration/Version030500Date20260430083738.php:33). One fixed Context Agent with a hard-coded system prompt (context_agent:ex_app/lib/agent.py:134-142); no way to create a named agent. Note: The closest things are scheduled tasks (title + prompt) and skills, rated on their own rows.
  • ag-list unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'agent' entities and list views in assistant:src and lib/Controller: no agent list; one built-in agent. Session list only (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:25-45).
  • ag-detail unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent entity or page. Nearest: a scheduled task's session shows its prompt and recurrence (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:59-66); tool categories are an admin checkbox list (context_agent:ex_app/lib/main.py:88-94). No page combining configuration, schedules, runs and skills.
  • ag-model unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the agent's model is whatever provider serves the task type core:text2text:chatwithtools (context_agent:ex_app/lib/nc_model.py:27,170-179), chosen instance-wide in the server's AI admin settings (nextcloud/server, not read); provider apps linked from assistant:src/components/AdminSettings.vue:55-120. No per-agent choice.
  • ag-visibility unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'visibility|group|share' in assistant:lib and context_agent:ex_app: the single agent is available to every user with the app enabled; no per-agent visibility setting.
  • ag-quota unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'quota|limit|budget|token' in assistant:lib and context_agent:ex_app: only a history cap (MAX_MESSAGE_HISTORY=42, context_agent:ex_app/lib/nc_model.py:87-89); no run or token cap per agent.
  • ag-enable unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the agent can be switched off only instance-wide: disabling the context_agent ExApp unregisters its providers (context_agent:ex_app/lib/main.py:132-135) and tool categories can be unticked (context_agent:ex_app/lib/main.py:88-94, tools.py:33); users can hide the Assistant (assistant:lib/Listener/BeforeTemplateRenderedListener.php:61-62). One agent, no per-agent off switch.
  • ag-owner unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent entity, so no owner field; assignments carry the user who created them (assistant:lib/Db/Assignment.php:40), searched 'owner' in both repos: none.
  • ag-offboard unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: on user deletion the user's assignments and chats are deleted, not handed over (assistant:lib/Listener/UserDeletedListener.php:42-48); searched 'transfer|owner' in both repos: nothing.
  • ag-nl-builder unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent builder; plain language builds a scheduled task (create_scheduled_task, context_agent:ex_app/lib/all_tools/assignments.py:14-39; ChattyLLMInputForm.vue:119-127 'Ask chat to create one') or a skill (store_skill, context_agent:ex_app/lib/all_tools/skills.py:115-180). The agent itself is not built from the description.
  • ag-app-slug unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'appId|slug' in context_agent:ex_app and assistant:lib/Service: apps call the one agent through the task type core:contextagent:interaction (context_agent:ex_app/lib/provider.py:20-26); no per-app agent binding.
  • ag-capability-profile unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: admin settings list tool categories as checkboxes (context_agent:ex_app/lib/main.py:88-94, categories from tools.py get_categories); skills listed via GET /api/v1/skills (assistant:lib/Controller/AgentSkillsApiController.php:57-59). Instance-wide, no single per-agent screen of skills, tools and data.
  • ag-delete unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent entity to delete. Deleting a scheduled task via DELETE /assignments/{id} (assistant:lib/Controller/AssignmentsApiController.php:205-208) is rated under schedules.
  • ag-import-export unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'export|import' in assistant:lib and context_agent:ex_app: no agent export or import.
  • ch-stream unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: context_agent posts intermediate output to taskprocessing stream-result (context_agent:ex_app/lib/main.py:193-205, agent.py:256-283); the chat listens on notify_push channel taskprocessing:task_id_* and updates the streaming message (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:993-1003,1079-1096). Note: Added in assistant 4.0.0 (changelog 'Streaming responses'). Needs notify_push; without it the UI polls.
  • ch-sessions unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: session list with new conversation, select and title edit (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:9-57); GET /chat/sessions (assistant:appinfo/routes.php:48, lib/Controller/ChattyLLMController.php:322).
  • ch-session-delete unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: delete conversation with confirmation dialog (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:36-42,202-217) is a hard delete of session and messages (assistant:lib/Service/ChatService.php:142-152). Searched 'trash|restore' in both repos: no bin or restore.
  • ch-tool-steps unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: agent reports used tools as 'sources' (context_agent:ex_app/lib/agent.py:274-281); chat shows them live while streaming and in an 'Information sources & actions' popover with translated tool labels (assistant:src/components/ChattyLLM/Message.vue:54-72,85, lib/Controller/ChattyLLMController.php:120-170).
  • ch-attach unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: attach button with 'Upload from device' and 'Select from nextcloud' file picker (assistant:src/components/ChattyLLM/InputArea.vue:160-173); attachments passed as file ids to the multimodal agent (assistant:lib/Service/ChatService.php:402-408, context_agent:ex_app/lib/agent.py:220-224). Note: Multimodal attachments need a provider for core:contextagent:multimodal-interaction.
  • ch-feedback unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'thumb|feedback|rating' in assistant:src, assistant:lib and context_agent:ex_app: no answer rating. Message actions are copy, regenerate, delete (assistant:src/components/ChattyLLM/MessageActions.vue:9-32).
  • ch-companion unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: header menu entry injected on every page when enabled (assistant:lib/Listener/BeforeTemplateRenderedListener.php:61-88, src/components/AssistantHeaderMenuEntry.vue:8) opens the non-modal Assistant dialog (assistant:src/components/AssistantTextProcessingModal.vue:126).
  • ch-object-leaf unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: only for files: Files actions send the selected file to summarise, transcribe, speak or subtitle (assistant:src/files/fileActions.js:63,102,141,180 -> POST /api/v1/file-action/{fileId}/{taskTypeId}). Searched 'context|current' in assistant:src/assistant.js: no hand-over of a record from other apps into the chat.
  • ch-prompt-library unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: chat offers hard-coded suggestion prompts (weather, share link, scheduled task, deck card, slides) in assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:355-400. Not set by the organisation and not per record type.
  • ch-voice-out unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: audio chat answers carry an audio attachment and TTS runs when needed (assistant:lib/Listener/ChattyLLMTaskListener.php:100-112,134,185); personal setting 'Auto-play audio chat responses' (assistant:src/components/PersonalSettings.vue:24); Files action 'Text-To-Speech using AI' (assistant:src/files/fileActions.js:86-102).
  • ch-search-history unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'search|filter' in assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue and lib/Controller/ChattyLLMController.php: session list has no search and GET /chat/sessions takes only isAssignment (ChattyLLMController.php:322).
  • ch-citations unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: Context Chat answers show referenced sources as links (assistant:src/components/ContextChat/ContextChatOutputForm.vue:20-42, ContextChatSource.vue:46); in agent chat only tool names are listed (assistant:src/components/ChattyLLM/Message.vue:54-72). Note: Source links rely on the context_chat app and backend (not read).
  • ch-share-link unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'share' in assistant:lib/Controller: only sharing a task's output file (POST /api/v1/task/{id}/file/{fileId}/share, assistant:appinfo/routes.php:34); no link to a conversation.
  • sc-cron no → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: scheduled tasks use an RFC 5545 RRULE, not cron (assistant:lib/Db/Assignment.php:108-116, context_agent:ex_app/lib/all_tools/assignments.py:25), checked by a 10-minute background job (assistant:lib/BackgroundJob/RunAssignmentsJob.php:201-208). No cron expression field. Note: Old 'no' rested on July docs; assistant 4.0.0 added Assignments.
  • sc-interval no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: RRULE with FREQ/INTERVAL, e.g. 'FREQ=HOURLY' (tool doc context_agent:ex_app/lib/all_tools/assignments.py:16-25), created by chat or POST /assignments (assistant:lib/Controller/AssignmentsApiController.php:59-62), evaluated by Assignment::isDueToRun (assistant:lib/Db/Assignment.php:131-150). Note: Granularity is the 10-minute background job. Old 'no' is superseded by assistant 4.0.0 Assignments.
  • sc-once no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: startsAt plus a non-repeating rule (tool doc says an empty rule means no repeat, context_agent:ex_app/lib/all_tools/assignments.py:25-26; COUNT=1 works in Recurr) stored on the assignment (assistant:lib/Service/AssignmentsService.php:46-60). Note: Needs a live check that an empty RRULE evaluates in Recurr; isDueToRun swallows errors and returns false (Assignment.php:151-155).
  • sc-nl no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the user asks in chat and the agent translates it into an RRULE and start time via create_scheduled_task (context_agent:ex_app/lib/all_tools/assignments.py:14-37); chat suggestion 'Create a scheduled task to send me the weather every morning' (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:366-367).
  • sc-timezone no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: each assignment stores an IANA timezone defaulting to the user's (assistant:lib/Service/AssignmentsService.php:63-67) and the RRULE is expanded in that timezone by Recurr (assistant:lib/Db/Assignment.php:136-138); tests with offsets (assistant:tests/unit/Db/AssignmentTest.php).
  • sc-webhook-secret unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no inbound webhook exists (searched 'webhook|secret' in both repos).
  • sc-manual-event-choice unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: two start modes exist, by hand in chat and by schedule (assistant:lib/Service/ChatService.php:360,501); no event start, so the choice is incomplete.
  • sc-overlap no → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the next run is skipped while the previous run still waits for approval (assistant:lib/Service/AssignmentsService.php:141-144), but the job allows parallel runs (lib/BackgroundJob/RunAssignmentsJob.php:201) and does not check a still-generating run.
  • sc-list no → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: 'Scheduled tasks' view lists them, showing prompt and recurrence and past results (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:19-22,59-66,112-121); GET /assignments (assistant:lib/Controller/AssignmentsApiController.php:87-90). No next-run time shown.
  • tl-web-search unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: DuckDuckGoSearchResults tool (context_agent:ex_app/lib/all_tools/duckduckgo.py:7-11) and web_fetch that reads a page by URL (context_agent:ex_app/lib/all_tools/web.py:13-20); the system prompt tells the agent to fetch search results (context_agent:ex_app/lib/agent.py:143-158). Note: Both are admin-toggleable categories.
  • tl-register unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'openregister|register' in context_agent:ex_app and assistant:lib: no OpenRegister tool. Only indirectly if OpenRegister exposes a unified search provider (search.py), which is not in these repos.
  • tl-mcp-client partial → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: admin 'MCP Config' JSON field (context_agent:ex_app/lib/main.py:103-110) fed to langchain MultiServerMCPClient, tools prefixed mcp_ (context_agent:ex_app/lib/all_tools/mcp.py:14-30); MCP tools are always treated as dangerous (context_agent:ex_app/lib/tools.py:48); chat labels them 'MCP server: x' (assistant:src/components/ChattyLLM/Message.vue:289). Note: Old 'partial' said streamable_http only; the config is passed straight to MultiServerMCPClient, so its transports apply. Admin-only, one config for everyone.
  • tl-mcp-server unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: ExApp route 'mcp' with USER access (context_agent:appinfo/info.xml routes), FastMCP server mounted at /mcp (context_agent:ex_app/lib/main.py:38-41,269), each call authenticated as the calling user (context_agent:ex_app/lib/mcp_server.py:31-41) and the enabled tools re-registered as MCP tools (mcp_server.py:47-73).
  • tl-catalog unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: admins see tool categories as a checkbox list (context_agent:ex_app/lib/main.py:88-94); the chat can be asked 'Which actions can you do for me?' (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:370-371). No page listing each tool with what it does.
  • tl-grants unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: tool categories switch on or off for the whole instance (context_agent:ex_app/lib/tools.py:23,33-35); no per-agent or per-user grant.
  • tl-request-access unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'request|access|grant' in context_agent:ex_app: a disabled category is silently skipped (tools.py:33-35); no access request flow.
  • tl-code-exec unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'exec|sandbox|python|subprocess|code' across context_agent:ex_app/lib/all_tools/: no code execution tool.
  • tl-git unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'git|repository|commit' in context_agent:ex_app: no git tool.
  • tl-invocations-export unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: tool names per answer are stored in the message's sources column (assistant:lib/Listener/ChattyLLMTaskListener.php:97-98); searched 'export' in assistant:lib: no export of tool calls.
  • tl-integrations-page unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: personal settings 'Configured backends' list the providers behind each feature (assistant:src/components/PersonalSettings.vue:52-60) and admin settings flag missing providers (AdminSettings.vue:55-120). No health status per outside connection, MCP servers not shown.
  • me-long-term no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: two paths: 'Remember this' on a conversation makes it a memory summarised by a background job (assistant:lib/Service/ChatService.php:121-126, lib/Service/SessionSummaryService.php:54-150) and injected into every run (context_agent:ex_app/lib/agent.py:160-161); on-demand memory tools store markdown files (context_agent:ex_app/lib/all_tools/memory.py:246-248). Note: Old 'no' predates assistant 3.1.0 memories and context_agent 2.8.0 memory tools.
  • me-user-profile no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: memories are per user: summaries of remembered chats about the user's circumstances and preferences (assistant:lib/Service/SessionSummaryService.php:62) and memory files in the user's own Assistant folder (context_agent:ex_app/lib/all_tools/memory.py:26,184-186).
  • me-view-edit no → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: remembered conversations are listed in personal settings (assistant:src/components/PersonalSettings.vue:61-65) and the toggle is on each chat (ChattyLLMInputForm.vue:68-82); memory files live in 'Context Agent/Memories' in the user's Files, so they can be opened, edited and deleted there (context_agent:ex_app/lib/all_tools/memory.py:26).
  • me-consolidate no → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: outdated chat summaries are regenerated by a background job (assistant:lib/Service/SessionSummaryService.php:81-88) and the agent may overwrite a memory file with store_memory (context_agent:ex_app/lib/all_tools/memory.py:246-260). No merging of duplicates or dropping of stale facts.
  • me-context unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: Context Chat 'Selective context' picks files, folders or providers for one query (assistant:src/components/ContextChat/ContextChatInputForm.vue:25,158-162); no named bundle carried into every run.
  • me-compression unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: older turns are cut, not summarised: history capped at 42 non-tool messages and old tool outputs truncated to 2000 chars (context_agent:ex_app/lib/nc_model.py:87-89,104-148); plain chat sends the last N messages (admin setting, assistant:src/components/AdminSettings.vue:167-178).
  • me-knowledge-graph unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'relation|graph|link' in context_agent:ex_app and assistant:lib: no record relation model; the agent's graph is the LangGraph loop (context_agent:ex_app/lib/graph.py).
  • me-object-grounding unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'current|context' in assistant:src/assistant.js and lib: the chat receives no record from the page on screen, only attachments the user adds (assistant:src/components/ChattyLLM/InputArea.vue:160-173).
  • me-external-kb unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no SharePoint or wiki connector; outside sources only through admin-configured MCP servers (context_agent:ex_app/lib/all_tools/mcp.py) or other apps' unified search providers (context_agent:ex_app/lib/all_tools/search.py). Context Chat content providers are Nextcloud apps (context_chat.py:16-26).
  • sk-catalog unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: skills are listed via GET /api/v1/skills merging personal and admin global skills (assistant:lib/Service/AgentSkillsService.php:65-90) and shown to the agent in its prompt (context_agent:ex_app/lib/agent.py:165-177). No browsing UI; users see the SKILL.md folders in Files. Note: Skills added in assistant 4.0.0 / context_agent 2.8.0.
  • sk-install unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: a skill is installed by placing a SKILL.md folder in 'Context Agent/Skills' (assistant:lib/Service/AgentSkillsService.php:31) or by the agent's store_skill (context_agent:ex_app/lib/all_tools/skills.py:115-180); admins set a global folder (assistant:src/components/AdminSettings.vue:183-214). No one-action install from a catalogue.
  • sk-format unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: skills follow the agentskills.io layout: folder with SKILL.md and YAML frontmatter name/description (context_agent:ex_app/lib/all_tools/skills.py:15-18, assistant:lib/Service/AgentSkillsService.php:33-37,156).
  • sk-self-improve unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: store_skill can overwrite an existing skill ('created'|'overwritten', assistant:lib/Service/AgentSkillsService.php:187,218) but the prompt limits it to explicit user requests (context_agent:ex_app/lib/agent.py:178-182). No proposal from run learnings.
  • sk-draft-review unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: store_skill is a dangerous tool, so the user sees skill name, description and content in the confirmation card before it is written (assistant:src/components/ChattyLLM/AgencyAction.vue:6-17, AgencyConfirmation.vue:10-30). No diff against the old version.
  • sk-auto-create unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the agent may store a skill on its own only when the user describes 'a clearly reusable procedure' (context_agent:ex_app/lib/agent.py:178-182), still behind confirmation (context_agent:ex_app/lib/all_tools/skills.py:116).
  • sk-curator unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'merge|archive|duplicate|curat' in assistant:lib/Service/AgentSkillsService.php and context_agent:ex_app/lib/all_tools/skills.py: none.
  • sk-maturity unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: skill metadata is name and description only (assistant:lib/Service/AgentSkillsService.php:37); no usage or maturity data.
  • sk-versions unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no skill versioning in the Assistant; SKILL.md is an ordinary Nextcloud file (assistant:lib/Service/AgentSkillsService.php:233-239), so server file versions apply (files_versions, not read).
  • sk-github unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'github|git' in assistant:lib and context_agent:ex_app: none.
  • sk-learnings unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'learn|lesson|rule' in skills code (assistant:lib/Service/AgentSkillsService.php, context_agent:ex_app/lib/all_tools/skills.py): none.
  • sk-export unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no export action; each skill is a SKILL.md file in the user's Files (assistant:lib/Service/AgentSkillsService.php:31-33) that can be downloaded there.
  • sk-install-source unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'url|download|http' in assistant:lib/Service/AgentSkillsService.php: skills come only from the user's or the admin's folder.
  • sk-evals unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'eval|test case' in both repos' runtime code: none (unit tests only cover parsing, assistant:tests/unit/Service/AgentSkillsServiceTest.php).
  • mo-providers unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the Assistant and agent call the instance's TaskProcessing task types (context_agent:ex_app/lib/nc_model.py:27,170-179); commercial providers are connected in integration_openai, which the admin page links (assistant:src/components/AdminSettings.vue:70-77). That app is not read.
  • mo-local yes → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: model calls go through the server's TaskProcessing, and the admin page links the local LLM app llm2 (assistant:src/components/AdminSettings.vue:64-66). llm2 and Ollama support sit in other apps, not read.
  • mo-provide-text2text unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: context_agent registers providers for core:contextagent:interaction and its multimodal variant (context_agent:ex_app/lib/provider.py:20-35, main.py:119-121), so any Nextcloud app can hand work to the agent through TaskProcessing; the Assistant also registers its own providers (assistant:lib/TaskProcessing/*Provider.php). Note: It is offered as an agent task type, not as plain core:text2text.
  • mo-per-agent unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: one agent; a different provider per task type is possible because each TaskProcessing type has its own preferred provider, shown as 'Provider: {name}' (assistant:src/components/AssistantTextProcessingForm.vue:64-73). Chosen in the server AI settings (not read), not per agent.
  • mo-tenant-policy unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'model|provider' policy settings in assistant:lib/Settings and context_agent:ex_app/lib/main.py: no per-organisation model limit.
  • mo-per-feature unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: each feature is its own TaskProcessing task type (summary, chat with tools, image, speech) and the UI names the provider serving it (assistant:src/components/AssistantTextProcessingForm.vue:64-73, PersonalSettings.vue:52-60). Note: The per-type provider choice itself is in the server's AI admin settings (not read).
  • mo-failover unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'fallback|failover|retry' in context_agent:ex_app/lib/nc_model.py and assistant:lib/Service: scheduling is retried on connection errors and rate limits are waited out (nc_model.py:206-219), but no second provider. Server TaskProcessing not read.
  • mo-sensitivity-routing unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'sensitive|classification|confidential' in both repos: none.
  • mo-cli-runner unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'claude|cli|subprocess' in context_agent:ex_app: none.
  • mo-key-broker unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no key handling in the agent; model keys sit once per instance in the provider app's admin settings (integration_openai, not read) and the HERE key in the Context Agent admin form (context_agent:ex_app/lib/main.py:95-102). Central by construction, not a credential store.
  • mo-eu yes → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the Assistant and agent send model calls only to the instance's own TaskProcessing (context_agent:ex_app/lib/nc_model.py:165-179); staying on premise needs a local provider (llm2, linked at assistant:src/components/AdminSettings.vue:64-66, not read). Web, weather and routing tools call outside services but can be switched off (context_agent:ex_app/lib/main.py:88-94). Note: Old 'yes' rested on a marketing line; the code makes it possible, not guaranteed.
  • dl-talk-bridge unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'bot|webhook|spreed' in assistant:lib and context_agent:ex_app: the agent can post to Talk but no Talk bot receives room messages. Talk bots from other Nextcloud apps are not in these repos.
  • dl-talk-grouping unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent rooms exist; create_public_conversation makes an ordinary room (context_agent:ex_app/lib/all_tools/talk.py:38-39).
  • dl-webhook-out unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'webhook|hmac|signature' in both repos: signature.py only signs the conversation token (context_agent:ex_app/lib/signature.py); web_fetch is GET only (context_agent:ex_app/lib/all_tools/web.py:14-20).
  • dl-notification unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: 'Get notified when the task finishes' (assistant:src/components/AssistantTextProcessingForm.vue:92, POST /api/v1/task/{id}/notify) and notifications for scheduled tasks succeeded, failed or pending review (assistant:lib/Notification/Notifier.php:341-401, lib/Service/NotificationService.php:138-166).
  • dl-target-pref unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'target|deliver|default' in assistant:lib/Settings and PersonalSettings.vue: no default delivery setting.
  • dl-messengers unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'telegram|slack|teams|signal|matrix' in both repos: none. Outside AI clients can call tools over MCP (tl-mcp-server) but that is not a messenger channel.
  • dl-digest unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: a scheduled task can prompt the agent to post into Talk (suggestion at assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:366-367, context_agent:ex_app/lib/all_tools/talk.py:49-50), but posting is a dangerous tool, so each run stops at 'Scheduled task is pending review' (assistant:lib/Notification/Notifier.php:341-346).
  • dl-dedupe unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'dedupe|duplicate|count' in assistant:lib/Service: none.
  • dl-dashboard-widget unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no dashboard widget registered in assistant:lib/AppInfo/Application.php:78-120 (capability, reference providers, notifier only); searched 'IWidget|Dashboard' in both repos: none.
  • dl-embed-web unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'PublicPage|embed|iframe' in assistant:lib/Controller: all routes need a logged-in user.
  • ov-approval unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the LangGraph agent interrupts before any dangerous tool (context_agent:ex_app/lib/graph.py:81), the chat shows 'The Assistant wants to perform sensitive actions on your behalf' with Cancel and Confirm (assistant:src/components/ChattyLLM/AgencyConfirmation.vue:10-30), and a deny is fed back to the agent (context_agent:ex_app/lib/agent.py:206-216).
  • ov-approval-inbox unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: pending actions show inside each conversation, and scheduled tasks send a 'pending review' notification (assistant:lib/Notification/Notifier.php:341-363). No inbox across conversations.
  • ov-approval-context unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: each pending action shows the tool name and its arguments with More/Less (assistant:src/components/ChattyLLM/AgencyAction.vue:6-17) plus a hint to adjust the request instead (AgencyConfirmation.vue:76).
  • ov-risk-threshold unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: tools are marked safe or dangerous per function (context_agent:ex_app/lib/all_tools/lib/decorator.py safe_tool/dangerous_tool); only dangerous ones interrupt (context_agent:ex_app/lib/graph.py:66-81), reads run without asking. Note: The split is fixed in code, not configurable.
  • ov-talk-reaction unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: approval happens only through the chat UI or /chat/generate?agencyConfirm (assistant:lib/Controller/ChattyLLMController.php:491); searched 'reaction' in approval code: none.
  • ov-draft-hold unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: send_email, send_message_to_conversation and reply_to_message are dangerous tools (context_agent:ex_app/lib/all_tools/mail.py:16, talk.py:49,137), so the drafted text is shown for confirmation before it is sent (assistant:src/components/ChattyLLM/AgencyAction.vue:6-17).
  • ov-kill-switch unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: disabling the context_agent ExApp unregisters its providers so no agent run starts (context_agent:ex_app/lib/main.py:132-136) and the admin can turn the Assistant off (assistant_enabled, assistant:lib/Controller/ConfigController.php:67-75). Instance-wide app switches, no dedicated kill switch or per-organisation scope.
  • ov-kill-agent unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: a running Assistant task can be cancelled (assistant:src/components/TaskListItem.vue:60, AssistantTextProcessingForm.vue:99) and a scheduled task deleted (DELETE /assignments/{id}); no stop for one agent as a whole.
  • ov-guardrail-input unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'redact|pii|secret|filter' in context_agent:ex_app and assistant:lib/Service: prompts go to the provider unfiltered (context_agent:ex_app/lib/nc_model.py:97-157).
  • ov-guardrail-output unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'moderation|guardrail|block' in both repos: output is stored as returned (assistant:lib/Listener/ChattyLLMTaskListener.php:128-131).
  • ov-tool-risk unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: every tool is classed safe or dangerous in code (context_agent:ex_app/lib/all_tools/lib/decorator.py), MCP tools always dangerous (context_agent:ex_app/lib/tools.py:48); dangerous ones require confirmation (context_agent:ex_app/lib/graph.py:81). Note: Two fixed classes, not admin-set.
  • ov-egress unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the admin can switch off the Web access, DuckDuckGo, YouTube, weather and routing categories (context_agent:ex_app/lib/main.py:88-94); when on, web_fetch reaches any URL (context_agent:ex_app/lib/all_tools/web.py:14-20). No allow-list.
  • ov-anonymise unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'anonym|pseudonym|redact' in both repos: none.
  • ov-ai-oversight unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'oversight|review|audit' in assistant:lib and src: no after-the-fact review page; only the user's own task list (assistant:src/components/TaskList.vue).
  • ov-automation-bias unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'bias|approve all|rubber' in assistant:src/components/ChattyLLM: none.
  • ov-tool-oversight unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: each answer lists the tools it used (assistant:src/components/ChattyLLM/Message.vue:54-72) for the user themselves; no admin review or misuse flag.
  • co-audit-log unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: context_agent logs task inputs to the Nextcloud log (context_agent:ex_app/lib/main.py:169-178) and messages keep tool names (assistant:lib/Listener/ChattyLLMTaskListener.php:97-98); searched 'audit|immutable' in both repos: no tamper-proof trail.
  • co-audit-export unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'export|audit' in assistant:lib: none.
  • co-retention unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'retention|expire|cleanup' in assistant:lib: chats are kept until deleted by the user or on user deletion (assistant:lib/Listener/UserDeletedListener.php:42-48).
  • co-ai-register unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'register|risk' in both repos: none.
  • co-risk-class unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'AI Act|risk class|high-risk' in both repos: none.
  • co-dpo-ack unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'dpo|sign off|approval' in assistant:lib/Settings: none.
  • co-control-packs unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'ISO|42001|control' in both repos: none.
  • co-factsheet unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'factsheet|model card' in both repos: only the app store 'Ethical AI Rating' text in context_agent:appinfo/info.xml description, not generated per agent.
  • co-compliance-export unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'compliance|report' in assistant:lib: none.
  • co-incident unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'incident' in both repos: none.
  • co-authority-notify unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'incident|authority|notify' outside user notifications in both repos: none.
  • co-access-review unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agent owners to review; searched 'review|attest' in assistant:lib: none.
  • co-transparency unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the chat states 'Output shown here is generated by AI. Make sure to always double-check.' (assistant:src/components/ChattyLLM/ChattyLLMInputForm.vue:178) and the app listing carries an Ethical AI Rating (context_agent:appinfo/info.xml description). No published plain-language explanation per agent.
  • co-residency unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: users see which provider backs each feature under 'Configured backends' (assistant:src/components/PersonalSettings.vue:52-60) and per task 'Provider: {name}' (AssistantTextProcessingForm.vue:73); where that provider processes data is not shown.
  • co-disable-dept unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the Assistant has one global switch and a per-user switch (assistant:lib/Listener/BeforeTemplateRenderedListener.php:61-62); limiting an app to groups is a server app-management feature (not read). No per-department AI switch or proof in these repos.
  • ob-runs unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: per task type the Assistant lists past tasks with status Succeeded, Failed, Running, Scheduled (assistant:src/components/TaskList.vue, TaskListItem.vue:101-105; GET /api/v1/tasks). Agent chat turns and scheduled runs show only as chat messages, not in a run list.
  • ob-trace unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: an answer shows the tools used and any reasoning content (assistant:src/components/ChattyLLM/Message.vue:36-72); tool arguments are shown only when approval is asked (AgencyAction.vue). No ordered step trace with tool results.
  • ob-replay unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: 'Regenerate message' reruns the last turn with current state (assistant:src/components/ChattyLLM/MessageActions.vue:18, GET /chat/regenerate); searched 'replay' in both repos: no replay of a past run.
  • ob-dry-run unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: every write tool is dangerous and stops for confirmation (context_agent:ex_app/lib/graph.py:81), so a user can see intended actions and cancel; searched 'dry|simulate' in both repos: no dry-run mode, safe read tools still run.
  • ob-analytics unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'analytics|metrics|stats' in both repos: none.
  • ob-cost-per-run unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'token|cost|usage' in assistant:lib and context_agent:ex_app/lib/nc_model.py: usage is not read or stored.
  • ob-budget unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'budget|spend' in both repos: none.
  • ob-estimate unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'estimate|cost' in both repos: only the provider's expected_runtime=60 (context_agent:ex_app/lib/provider.py:23).
  • ob-fail-alert unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: Nextcloud notifications on task failure and on scheduled task failure (assistant:lib/Notification/Notifier.php:158,389-401, lib/Listener/ChattyLLMTaskListener.php:40-52). Note: Alerts go to the user who ran the task, not to an admin.
  • ob-drift unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'drift|quality' in both repos: none.
  • ob-metrics unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: context_agent ships a container healthcheck script only (context_agent:healthcheck.sh); searched 'metrics|prometheus' in both repos: none.
  • ob-external-tracing unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'langfuse|langsmith|tracing|opentelemetry' in context_agent:ex_app and pyproject.toml: none configured.
  • ob-reports unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'report|digest' in assistant:lib/BackgroundJob: jobs are assignments and chat summaries only.
  • ob-feedback-stats unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no answer rating exists (ch-feedback); searched 'feedback' in both repos: none.
  • fl-canvas unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'flow|canvas|workflow|node' in assistant:src: no flow builder. The agent loop is fixed in code (context_agent:ex_app/lib/graph.py).
  • fl-agent-node unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows in these repos (searched 'flow|workflow' in both). Other Nextcloud flow tools could schedule the agent task type, but none is in these repos.
  • fl-approval-step unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows; approval exists only inside the agent loop (ov-approval).
  • fl-subagent unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'subagent|delegate|handoff' in context_agent:ex_app: single agent graph (context_agent:ex_app/lib/graph.py:48-80).
  • fl-branch unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no user-built flows; the only branch is the fixed safe/dangerous tool routing (context_agent:ex_app/lib/graph.py:56-72).
  • fl-run-history unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows, so no flow run history.
  • fl-seed-flows unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows ship with either app (searched 'flow|template' in both).
  • fl-n8n unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'n8n' in both repos: none; only reachable if an admin adds an n8n MCP server via the MCP config (context_agent:ex_app/lib/all_tools/mcp.py).
  • fl-code-step unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows and no code tool (searched 'exec|code' in all_tools).
  • fl-subflow unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows in these repos.
  • fl-validate unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no flows in these repos.
  • re-store unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'store|template|marketplace' in assistant:src: no agent store; one built-in agent.
  • re-template-from-agent unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no agents or templates to create (searched 'template' in assistant:lib/Service).
  • re-template-github unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'github|template' in both repos: none.
  • re-template-approve unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no templates exist.
  • re-agent-versions unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'version|history|rollback' in assistant:lib/Db: no agent entity, no versions.
  • re-evals unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'eval|test case|expected' in runtime code of both repos: none.
  • re-baseline unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the system prompt is hard-coded (context_agent:ex_app/lib/agent.py:134-142); searched 'baseline|compare' in both repos: none.
  • re-community unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'community|library|hub' in both repos: skills come from the user's or admin's folder only (assistant:lib/Service/AgentSkillsService.php:65-90).
  • re-template-cross-tenant unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no tenants or templates in these repos.
  • re-course-recs unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'course|learner' in both repos: none.
  • op-airgap unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: nothing in the agent requires the internet: models come from the instance's TaskProcessing (context_agent:ex_app/lib/nc_model.py:165-179) and online tools (DuckDuckGo, web_fetch, weather, HERE, OSM, YouTube) can be switched off (context_agent:ex_app/lib/main.py:88-94). Needs a local provider and a local image registry (not read).
  • op-multi-tenant unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'tenant|organisation|organization' in both repos: data is scoped per user (assistant:lib/Db/ChattyLLM/SessionMapper.php by user_id), not per organisation.
  • op-tenant-quota unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'quota|tenant' in both repos: none.
  • op-tenant-ops unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: no tenants; admin settings are instance-wide (assistant:lib/Settings/Admin.php:35-83).
  • op-sso unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the Assistant runs as the logged-in Nextcloud user and the agent acts as that user (context_agent:ex_app/lib/main.py:190-191); sign-in and groups come from the server's user backends (SAML/OIDC/LDAP apps, not read).
  • op-credential-vault unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the only outside key (HERE) is a PASSWORD field in the ExApp admin form (context_agent:ex_app/lib/main.py:95-102) and MCP credentials would sit in the plain MCP JSON field (main.py:103-110); searched 'vault|secret' in both repos: none.
  • op-agent-credential unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the agent always acts as the requesting user through AppAPI (context_agent:ex_app/lib/main.py:189-191); searched 'service account|credential|token' in context_agent:ex_app: no per-agent credential.
  • op-setup-wizard unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: admin settings explain missing providers per feature with links to llm2, integration_openai, stable diffusion and whisper (assistant:src/components/AdminSettings.vue:55-120); no guided wizard.
  • op-health unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: admin settings show whether TaskProcessing providers and the Context Agent are available (assistant:lib/Settings/Admin.php:36-45,63-76); the chat shows a no-provider empty state (assistant:src/components/NoProviderEmptyContent.vue). No health page with dependency status.
  • op-flat-cost unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the code has no licence or seat check in either repo (searched 'licen|subscription|seat'); both are free under AGPL. Nextcloud's paid support is priced per user (see sources.json pricing), not per instance.
  • op-scale no → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: context_agent handles several tasks at once in an asyncio TaskGroup (context_agent:ex_app/lib/main.py:144-179) inside one container; searched 'worker|replica|queue' in context_agent:ex_app: no multi-worker scaling in the app. Note: Old 'no' rested on a docs line; concurrency inside one ExApp exists.
  • op-outside-agent unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: outside AI agents can call the tools over MCP at /mcp, each call running as the Nextcloud user whose credentials it presents (context_agent:ex_app/lib/mcp_server.py:17-41); only the instance-wide tool categories limit what it may call (context_agent:ex_app/lib/tools.py:33). No per-client registration.
  • ag-identity unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the agent always runs with the rights of the person who asked (context_agent:ex_app/lib/main.py:190-191) and MCP calls with the caller's login (context_agent:ex_app/lib/mcp_server.py:31-41); no choice of owner or service account.
  • ch-shared-session unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: sessions belong to one user (assistant:lib/Service/ChatService.php:50,175-180 by userId); searched 'share|participant' in chat code: none.
  • ch-intake unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'PublicPage|guest|anonymous' in assistant:lib/Controller: every route needs a logged-in user.
  • tl-connectors unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: about 30 built-in tool modules for Nextcloud apps and a few web services (context_agent:ex_app/lib/all_tools/: calendar, deck, mail, talk, tables, forms, bookmarks, cookbook, openproject, weather, osm, here, youtube) plus any admin-added MCP server (mcp.py). Not hundreds of ready-made connectors.
  • me-permissions unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: every agent run and MCP call executes as the requesting user (context_agent:ex_app/lib/main.py:190-191, mcp_server.py:31-41), so file, share and search results are limited to what that user may see; memories and skills live in the user's own folder (context_agent:ex_app/lib/all_tools/memory.py:26).
  • me-context-docs unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: skills are markdown instruction documents (SKILL.md) the agent loads when relevant (context_agent:ex_app/lib/agent.py:165-177, context_agent:ex_app/lib/all_tools/skills.py:84-113); admins also set chat user instructions (assistant:src/components/AdminSettings.vue:123-141).
  • sk-share-tenants unknown → partial: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: an admin can point a global skills folder that all users of the instance get (assistant:lib/Service/AgentSkillsService.php:331-361, src/components/AdminSettings.vue:183-214); no organisations to share between.
  • dl-api unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: documented OCS API in assistant:openapi.json for chat sessions, messages, /chat/generate and /assignments (assistant:appinfo/routes.php:40-60, lib/Controller/AssignmentsApiController.php:59-208); the agent itself is reachable as TaskProcessing task type core:contextagent:interaction (context_agent:ex_app/lib/provider.py:20-26).
  • co-algoritmeregister unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'algoritme|register' in both repos: none.
  • co-dpia unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: searched 'dpia|assessment' in both repos: none.
  • fl-parallel unknown → no: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: the graph routes on the first tool call only ('This assumes single tool calls', context_agent:ex_app/lib/graph.py:62-66); searched 'parallel|subagent' in context_agent:ex_app: no sub-agents.
  • op-languages unknown → yes: source read at assistant v4.0.0 and context_agent v2.8.0, not driven: assistant:l10n/nl.json (209 translated strings) and context_agent:l10n/nl.json; tools answer in the user's language (context_agent:ex_app/lib/agent.py:136-138).

hermes-agent: every rating change (before → after, evidence)

  • ag-create partial → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:18 hermes profile create <name> --description; web/src/pages/ProfilesPage.tsx:442 New Profile form -> POST /api/profiles (hermes_cli/web_routers/profiles.py:704); ProfilesPage.tsx:556 edit SOUL.md (personality / system prompt) -> PUT /api/profiles/{name}/soul (profiles.py:906); web/src/pages/ProfileBuilderPage.tsx:32 builder wizard (identity, model, skills, MCPs) Note: An agent in Hermes is a profile: a name, a description and SOUL.md instructions. Old partial undersold it.
  • ag-list unknown → partial: source read at v2026.9.24, not driven: web/src/pages/ProfilesPage.tsx:1184-1217 profile list shows gateway running/stopped, model and skill count; hermes_cli/subcommands/profile.py:14 hermes profile list; hermes_cli/profiles.py:538 ProfileInfo has no owner field (name, model, provider, gateway_running, description, role only) Note: No owner column and no organisation: one operator's install lists its own profiles.
  • ag-visibility unknown → partial: source read at v2026.9.24, not driven: gateway/authz_mixin.py:32-37 per-platform _ALLOWED_USERS / ALLOW_ALL_USERS allowlists read per profile home (authz_mixin.py:339 _authorization_home_for_source); gateway/slash_access.py:1-27 admin vs user command lists Note: Who may talk to a profile's bot is a per-platform user-id allowlist; no only-me / group / organisation visibility model and no org directory.
  • ag-quota unknown → partial: source read at v2026.9.24, not driven: hermes_cli/config_defaults.py:53-63 agent.max_turns (turn cap) and agent.run_budget_seconds (wall-clock per run), per profile config.yaml; hermes_cli/config_defaults.py:1338 delegation.max_iterations per subagent; gateway/platforms/api_server.py:1322 api_server.max_concurrent_runs; searched 'max_cost|spend_limit|token_budget|cost_cap' in *.py: no token or run-count quota per agent Note: Caps iterations and wall clock per run, not tokens or number of runs.
  • ag-enable unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/pause.py:1-27 hermes pause / hermes resume write/remove the ESTOP sentinel; agent/estop.py:31-39 sentinel lives in the profile's $HERMES_HOME, so hermes -p <profile> pause holds that profile's cron, kanban and new gateway turns without deleting it; web/src/pages/ProfilesPage.tsx:1184 per-profile gateway running/stopped Note: CLI only; the dashboard shows gateway state but has no pause toggle (searched 'estop' in web/src and hermes_cli/web_routers: none).
  • ag-owner unknown → no: source read at v2026.9.24, not driven: hermes_cli/profiles.py:538-575 ProfileInfo fields (name, model, provider, description, display_name, role) carry no owner; searched 'owner' in hermes_cli/profiles.py and profile_identity.py: only file-permission and routing-index ownership Note: Single-operator install; no human owner per profile.
  • ag-offboard unknown → no: source read at v2026.9.24, not driven: searched 'owner|transfer|hand over|reassign' in hermes_cli/profiles.py and profile_cmd.py: none; hermes_cli/subcommands/profile.py:86 profile rename and :115 export/import move a profile, not an owner Note: No owner concept to hand over.
  • ag-nl-builder unknown → partial: source read at v2026.9.24, not driven: skills/autonomous-ai-agents/hermes-agent/SKILL.md:26 bundled skill teaches the agent Hermes' own profiles so it can run hermes profile create through its terminal tool; hermes_cli/profile_describer.py:1-25 auto-generates a description from an existing profile (the reverse); searched 'create.*bot.*from.*descri' and profile-creating tool names in *.py: no dedicated plain-language agent builder Note: The agent can build a profile only by driving the CLI itself; the dashboard builder is a form wizard.
  • ag-app-slug unknown → partial: source read at v2026.9.24, not driven: gateway/platforms/api_server.py:1-6 under gateway.multiplex_profiles each profile is served at /p//v1/...; api_server.py:1336-1345 /v1/models advertises the profile name as the model id; gateway/profile_routing.py:1-11 routes senders/chats to profiles Note: A caller addresses an agent by profile name in the URL; no registry that ties an agent to a consuming application.
  • ag-capability-profile yes → partial: source read at v2026.9.24, not driven: web/src/pages/SkillsPage.tsx:140 skills / toolsets / hub views scoped by profile (SkillsPage.tsx:169 getToolsets(selectedProfile)); hermes_cli/web_routers/tools.py:230 GET /api/tools/toolsets; web/src/pages/ProfileBuilderPage.tsx:753 review step lists model, skills and MCPs Note: Skills and toolsets per profile are on one page (tabbed); MCP servers sit on McpPage; data access is not modelled (tools reach the whole host). Old yes rested on a docs line; the data part of the sentence has no screen.
  • ag-delete unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:52 hermes profile delete; hermes_cli/profiles.py:1682 delete_profile removes the profile home (jobs live under it); web/src/pages/ProfilesPage.tsx:725 deleteProfile -> DELETE /api/profiles/{name} (hermes_cli/web_routers/profiles.py:869); web/src/i18n/en.ts profiles.confirmDeleteMessage 'deletes profile ... config, keys, memories, sessions, skills, cron jobs'

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 2 of 8

hermes-agent (continued)

  • ag-import-export unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:115 profile export to .tar.gz and :122 profile import; hermes_cli/web_routers/profiles.py:988 POST /api/profiles/{name}/export and :1006 POST /api/profiles/import; hermes_cli/commands.py:88-90 /export and /import slash commands Note: Moves between Hermes installs; there is no Nextcloud target.
  • ch-stream unknown → yes: source read at v2026.9.24, not driven: gateway/stream_consumer.py:1-5 on_delta() queues model deltas and progressively edits one platform message; hermes_cli/cli_stream_mixin.py streams tokens in the CLI; hermes_cli/web_routers/chat_ws.py:432 PTY stream to the dashboard chat
  • ch-session-delete unknown → partial: source read at v2026.9.24, not driven: hermes_cli/web_routers/sessions.py:696 DELETE /api/sessions/{id} and :414 bulk-delete (web/src/i18n/en.ts sessions.confirmDeleteMessage 'permanently removes ... cannot be undone'); hermes_cli/subcommands/sessions.py:123 sessions archive soft-hides, sessions.py:750 PATCH archived flag; searched 'trash|undelete|recycle|soft.?delete' in hermes_state_sessions.py and hermes_cli/sessions*.py: no bin Note: Delete is permanent and archive is a soft hide; there is no bin to restore a deleted conversation from.
  • ch-attach unknown → partial: source read at v2026.9.24, not driven: gateway/platforms/base.py:1183-1231 SUPPORTED_DOCUMENT_TYPES (.pdf, .docx, .md, .csv ...) accepted as chat file attachments from messaging platforms; hermes_cli/web_routers/files.py:501 POST /api/files/upload and :330 /api/chat/image-upload; hermes_cli/commands.py:297 /image; searched 'nextcloud' repo-wide (excluding website/): only tests/tools/test_ssh_environment.py Note: Attaching a file and asking about it works; there is no Nextcloud Files source.
  • ch-feedback unknown → no: source read at v2026.9.24, not driven: searched 'thumbs|feedback.(up|down)|rate.(answer|response)' in *.py and *.ts outside tests: none; agent/reactions.py:1-15 only detects affection ('good bot', hearts) to animate the pet, it records no rating
  • ch-companion unknown → partial: source read at v2026.9.24, not driven: apps/desktop/electron/quick-entry.ts:1-19 Quick Entry, a global-hotkey (Cmd/Ctrl+Shift+Space) mini composer over any desktop app; searched 'nextcloud' repo-wide (excluding website/): only tests/tools/test_ssh_environment.py Note: Reachable from anywhere on the desktop via the Electron app, not from inside Nextcloud pages.
  • ch-object-leaf unknown → partial: source read at v2026.9.24, not driven: hermes_cli/commands.py:264 /browser connects the agent to the user's live Chromium browser via CDP so it can read the page being viewed (tools/browser_cdp_tool.py); tools/computer_use_tool.py screen access; searched 'nextcloud' repo-wide (excluding website/): only tests/tools/test_ssh_environment.py Note: The agent can read whatever page is open, but no app hands it the current record as context.
  • ch-prompt-library unknown → partial: source read at v2026.9.24, not driven: agent/skill_commands.py:1 every installed skill is a /skill-name slash command in CLI and gateway; hermes_cli/commands.py:226 /bundles; plugin-catalog/prompt-snippets.yaml:1-5 community desktop prompt-snippet library (catalog plugin, not core); searched 'record type' concepts: none Note: Ready-made prompts exist as skills and snippets, but none is scoped to a record type or set centrally for an organisation.
  • ch-voice-in unknown → yes: source read at v2026.9.24, not driven: tools/voice_mode.py:1-5 push-to-talk capture with STT via tools/transcription_tools.py; hermes_cli/commands.py:202-205 /voice and /wake ('Hey Hermes' wake word); gateway/run_voice.py transcribes inbound voice messages on messaging platforms
  • ch-smart-picker unknown → no: source read at v2026.9.24, not driven: searched 'nextcloud' repo-wide (excluding website/): none outside one test; searched 'insert into|smart picker|text field' in apps/desktop/electron and web/src: the desktop Quick Entry (apps/desktop/electron/quick-entry.ts:2) opens a composer, it does not insert results into other apps' text fields
  • ch-text-tasks unknown → no: source read at v2026.9.24, not driven: searched '"summarize"|"translate"|"rephrase"|"reformulate"' as command or action names in *.py and *.ts outside tests: no one-click text action; summarising or translating happens only by asking in chat Note: The chat can do it when asked; no one-click action on a selected text.
  • ch-citations unknown → partial: source read at v2026.9.24, not driven: agent/anthropic_message_convert.py:52-56 carries provider citation blocks through the transcript; tools/web_tools.py web_search/web_extract return result URLs that the model quotes in its text; searched 'citation' in *.py: no source panel or structured citation rendering in gateway, CLI or dashboard Note: Sources appear only as links the model writes into the answer.
  • ch-share-link unknown → no: source read at v2026.9.24, not driven: searched 'share.*(link|url)|public.*session|shared_session' in hermes_cli/web_routers/sessions.py and gateway/platforms/api_server.py: none; hermes_cli/web_routers/sessions.py:787 GET /api/sessions/{id}/export and hermes_cli/commands.py:66 /save export to a file; hermes_cli/shared_session_attach.py:1-4 attaches local runtimes, not colleagues Note: Export to a file exists; no share link.
  • sc-interval unknown → yes: source read at v2026.9.24, not driven: cron/jobs.py:791-792 'every 30m' / '30m' become recurring interval schedules; web/src/i18n/en.ts cron.scheduleModes.interval 'Every interval' with minutes/hours/days units on CronPage
  • sc-once unknown → yes: source read at v2026.9.24, not driven: cron/jobs.py:801-812 ISO timestamp parses to a one-shot job in the configured timezone; web/src/i18n/en.ts cron.scheduleModes.once 'Once' / onceAt 'Run at'
  • sc-timezone partial → yes: source read at v2026.9.24, not driven: hermes_time.py:1-5 tz-aware now() in the configured IANA timezone (HERMES_TIMEZONE or config timezone); cron/jobs.py:1195-1216 next fire computed on local wall clock with both DST folds tried so 09:00 local stays 09:00 across fall-back; cron/jobs.py:832 intervals measure elapsed time across DST Note: Old partial; the scheduler handles DST explicitly.
  • sc-run-now unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/cron.py:157 hermes cron run (next scheduler tick); hermes_cli/web_routers/cron.py:292 POST /api/cron/jobs/{id}/trigger behind web/src/i18n/en.ts cron.triggerNow 'Trigger now' on CronPage
  • sc-pause unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/cron.py:149-152 cron pause / cron resume; hermes_cli/web_routers/cron.py:282-287 POST /api/cron/jobs/{id}/pause|resume behind CronPage Pause/Resume (web/src/i18n/en.ts cron.pause)
  • sc-webhook-secret unknown → partial: source read at v2026.9.24, not driven: hermes_cli/webhook.py:136 re-running webhook subscribe <name> --secret <new> replaces the route secret (else keeps it); hermes_cli/subcommands/webhook.py:58 webhook remove revokes the route; web/src/pages/WebhooksPage.tsx:335-355 secret shown once at creation; hermes_cli/subcommands/hooks.py:34 revoke is for hooks, not webhook secrets Note: Rotation is a re-subscribe with a new secret on the CLI; no rotate or revoke-secret action in the dashboard.
  • sc-event unknown → partial: source read at v2026.9.24, not driven: gateway/platforms/webhook.py:1-5 routes accept events from outside systems with header event filters (GitHub, GitLab, Linear, generic); gateway/hooks.py:1-9 lifecycle hooks (session, agent, command events) run handlers; cron/scheduler_script.py pre-run script gates a job; searched 'nextcloud' repo-wide: none Note: Agents start on outside-system events via webhooks, not on Nextcloud file or record events.
  • sc-manual-event-choice unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/webhook.py:47-51 a webhook route can fire an existing cron job (--cron-job); the same job keeps its schedule (cron/jobs.py:772 parse_schedule) and can be run by hand (hermes_cli/web_routers/cron.py:292 trigger); cron/jobs.py:2650-2657 manual run-now without consuming the next slot Note: Triggers are chosen per job or route rather than per profile.
  • sc-retry unknown → partial: source read at v2026.9.24, not driven: cron/unreachable_retry.py:1-17 and :31 RETRY_DELAYS_SECONDS (300, 900, 1800): growing waits, stops after three, but only for fires that never reached the model (transient network error, zero API calls); cron/quota_hold.py:1-12 parks a job until a provider quota window reopens Note: Generic run failures are not retried; the bounded ladder covers unreachable-model failures only.
  • sc-dead-letter unknown → partial: source read at v2026.9.24, not driven: cron/incidents.py:1-10 durable failure incidents grouped by job and error signature (detected, alerted, closed); hermes_cli/subcommands/cron.py:174-181 hermes cron incidents list|ack; cron/jobs.py:2254 dead-pin auto-pause Note: Failing jobs land in an incident list someone can acknowledge; the failed runs are not parked for replay and there is no dashboard view of incidents.
  • sc-overlap unknown → yes: source read at v2026.9.24, not driven: cron/jobs.py:2648-2670 claim_job_for_fire refuses a new fire while a fresh fire_claim exists (cleared by mark_job_run on completion, TTL for crashes); cron/jobs.py:3050 still-in-flight runs are skipped
  • sc-list unknown → yes: source read at v2026.9.24, not driven: web/src/pages/CronPage.tsx with web/src/i18n/en.ts cron.last 'Last', cron.next 'Next', overdueSince; hermes_cli/web_routers/cron.py:233 GET /api/cron/jobs and :243 /runs; hermes_cli/subcommands/cron.py:20 cron list and :168 cron runs
  • tl-files unknown → partial: source read at v2026.9.24, not driven: tools/file_tools.py:1133-1270 read_file, write_file, patch, search_files tools and :1371 registration in the file toolset, plus terminal tool for moves; searched 'nextcloud' repo-wide (excluding website/): none outside one test Note: Works on the host or sandbox filesystem; no Nextcloud Files connection.
  • tl-calendar unknown → yes: source read at v2026.9.24, not driven: skills/productivity/google-workspace/SKILL.md:1-27 bundled skill reads Google Calendar, checks conflicts and creates events through a gws CLI or bundled Python client (needs Google OAuth); optional-mcps/calendly; searched 'nextcloud|caldav|carddav' in plugin-catalog/, optional-mcps/, skills/, optional-skills/: none Note: Google Calendar only; no CalDAV, so a Nextcloud calendar is out of reach.
  • tl-contacts unknown → yes: source read at v2026.9.24, not driven: skills/productivity/google-workspace/SKILL.md:15-22 Contacts via the Google People API in the bundled google-workspace skill; searched 'nextcloud|caldav|carddav' in plugin-catalog/, optional-mcps/, skills/, optional-skills/: none Note: Google Contacts only; no CardDAV or Nextcloud Contacts.
  • tl-deck unknown → partial: source read at v2026.9.24, not driven: tools/kanban_tools_schemas.py:89-371 kanban_create, kanban_comment, kanban_complete tools on Hermes' own multi-profile kanban board (hermes_cli/kanban.py); optional-mcps/ has asana, linear, monday, clickup MCP entries; searched 'nextcloud|caldav|carddav' in plugin-catalog/, optional-mcps/, skills/, optional-skills/: none Note: Cards on Hermes' own board or third-party boards; no Nextcloud Deck.
  • tl-mail unknown → yes: source read at v2026.9.24, not driven: skills/email/himalaya/SKILL.md:1-3 bundled IMAP/SMTP skill; plugins/platforms/email/plugin.yaml:5-8 email gateway polls IMAP and replies over SMTP; tools/send_message_tool.py:35 send_message delivers to the email target; skills/productivity/google-workspace Gmail
  • tl-tasks unknown → yes: source read at v2026.9.24, not driven: skills/apple/apple-reminders/SKILL.md:1-3 'add, list, complete' reminders (macOS); tools/kanban_tools_schemas.py:89 kanban_complete and :371 kanban_create; optional-mcps/todoist; tools/todo_tool.py in-session todo list Note: No CalDAV tasks; Nextcloud Tasks is not reachable.
  • tl-unified-search unknown → no: source read at v2026.9.24, not driven: searched 'nextcloud' repo-wide (excluding website/): none outside one test; tools/session_search_tool.py searches only Hermes' own conversations and tools/file_tools.py:1270 search_files only the host filesystem Note: No Nextcloud unified search provider or equivalent cross-app search.
  • tl-register unknown → no: source read at v2026.9.24, not driven: searched 'openregister|register' as a record store in *.py and optional-mcps/: none; searched 'nextcloud' repo-wide (excluding website/): none outside one test
  • tl-mcp-server unknown → partial: source read at v2026.9.24, not driven: mcp_serve.py:1-7 hermes mcp serve stdio MCP server exposing a channel bridge: mcp_serve.py:468 conversations_list, :600 messages_send, :626 channels_list, :662-672 approvals; plugins/platforms/a2a lets outside agents message Hermes Note: Outside agents reach conversations, messaging and approvals, not Hermes' own tool set (files, terminal, web, skills).
  • tl-request-access unknown → no: source read at v2026.9.24, not driven: searched 'request.{0,20}(tool|toolset).{0,20}(access|enable)|ask.{0,20}(user|owner).{0,20}enable' in *.py: none; hermes_cli/tool_availability_notices.py:1-6 only prints startup notices for toolsets missing requirements; tools/tool_search.py:1-7 discloses deferred tools that are already granted Note: The agent cannot ask its owner for a new tool through any built-in flow.
  • tl-custom-tool unknown → yes: source read at v2026.9.24, not driven: hermes_cli/plugins.py:456 register_tool in the plugin context; hermes_cli/subcommands/plugins.py:18 hermes plugins install from a git URL, into ~/.hermes/plugins; web/src/i18n/en.ts pluginsPage.installHeading 'Install from GitHub / Git URL'; hermes_cli/subcommands/mcp.py:27 add any MCP server
  • tl-integrations-page partial → yes: source read at v2026.9.24, not driven: web/src/pages/ChannelsPage.tsx:42-51 live connected/disconnected/fatal state per messaging platform; web/src/pages/SystemPage.tsx:106 runs doctor with a live log and :187 memory-provider status, :210 credential pool; hermes_cli/web_routers/mcp.py:195 POST /api/mcp/servers/{name}/test; hermes_cli/doctor_connectivity.py:1-4 provider API probes Note: Spread over Channels, MCP and System pages rather than one list. Old partial.
  • me-view-edit yes → partial: source read at v2026.9.24, not driven: memories are plain files $HERMES_HOME/memories/MEMORY.md and USER.md (hermes_cli/web_routers/ops.py:481-492); web/src/pages/SystemPage.tsx:1234-1243 shows their sizes and Reset buttons only; hermes_cli/commands.py:223 /memory pending|approve|reject reviews staged writes; tools/memory_tool.py:311 agent can replace/remove entries on request Note: No viewer or editor in dashboard or CLI; correcting means editing the file by hand or asking the agent.
  • me-consolidate unknown → yes: source read at v2026.9.24, not driven: tools/memory_tool.py:56 hard char budgets (memory 2200, user 1375) and :323-324 'IF FULL ... reissue as ONE batch that removes or shortens enough stale entries'; agent/background_review.py:1-6 background review updates existing memory; plugins/memory/holographic/init.py:1-5 trust scoring and temporal decay
  • me-kb-upload unknown → partial: source read at v2026.9.24, not driven: plugins/memory/retaindb/init.py:515-564 retaindb_upload_file, retaindb_ingest_file, retaindb_list_files with semantic search (RetainDB cloud API); plugins/memory/openviking/init.py:1-6 OpenViking tiered knowledge with semantic search; searched 'knowledge base|vector|embedding' for a built-in document store: none Note: Only through a bundled memory-provider plugin backed by an outside service, driven by agent tools; no upload UI or built-in knowledge base.
  • me-context unknown → partial: source read at v2026.9.24, not driven: agent/prompt_builder.py:1656-1668 every run loads the working directory's .hermes.md, AGENTS.md chain, CLAUDE.md and .cursorrules plus the profile SOUL.md; agent/context_references.py:1 @file:, @folder:, @git:, @url: references per message; agent/context_file_sources.py:1-6 /context lists what was loaded Note: Context follows the working directory and per-message references; there is no named, reusable bundle of files and records attached to an agent.
  • me-knowledge-graph unknown → no: source read at v2026.9.24, not driven: searched 'record|relation|knowledge graph|graph traversal' in agent/ and tools/: agent/learning_graph.py:1-6 only draws a desktop graph of learned skills and memory chunks; plugins/memory/holographic/init.py:1-3 resolves entities in stored facts but offers no link-following over records Note: No record store, so nothing to follow links across.
  • me-object-grounding unknown → no: source read at v2026.9.24, not driven: searched 'nextcloud' repo-wide (excluding website/): none outside one test; no record or object-on-screen concept in agent/prompt_builder.py context sources (agent/prompt_builder.py:1656-1661)
  • me-external-kb unknown → yes: source read at v2026.9.24, not driven: optional-mcps/atlassian/manifest.yaml:1-9 Nous-approved catalog entry for Confluence pages and Jira; optional-mcps/notion, microsoft-learn, deepwiki; skills/productivity/notion bundled skill; plugin-catalog/microsoft365.yaml:1-5 SharePoint and OneDrive via a community plugin Note: SharePoint only through a community catalog plugin; wikis such as Confluence and Notion through core catalog MCP entries.
  • sk-draft-review unknown → yes: source read at v2026.9.24, not driven: tools/write_approval.py:1-9 skills.write_approval stages agent skill writes under pending/skills/.json with a difflib diff; hermes_cli/commands.py:217-221 /skills pending|diff|approve|reject|approval; hermes_cli/write_approval_commands.py:1 Note: Off by default; the operator switches the gate on.
  • sk-versions unknown → partial: source read at v2026.9.24, not driven: hermes_cli/subcommands/skills.py:112 skills diff against the stock bundled version and :94 reset; agent/curator_backup.py:1-6 tar.gz snapshot of the whole skills tree before each curator pass with rollback; tools/write_approval.py:1-9 staged diffs for pending writes Note: No per-skill version history; rollback is whole-tree curator snapshots and compare is only against the bundled stock copy.
  • sk-github unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/skills.py:165-171 skills tap add owner/repo adds a GitHub repo as a skill source; tools/skills_hub_github.py search and install; hermes_cli/subcommands/skills.py:148-153 skills publish --to github --repo
  • sk-learnings partial → yes: source read at v2026.9.24, not driven: tools/memory_tool.py:319-322 corrections for a kind of work belong in that task's skill via skill_manage; agent/background_review.py:1-6 post-turn review patches the skill with the lesson; hermes_cli/commands.py:124 /refine saves lessons to memory/skills Note: Old partial; the review loop writes lessons into skills.
  • sk-export unknown → partial: source read at v2026.9.24, not driven: hermes_cli/skills_hub.py:1260-1280 skills snapshot export writes only hub identifiers and taps to JSON; hermes_cli/subcommands/profile.py:115 profile export carries all skills; hermes_cli/subcommands/skills.py:148 publish to GitHub/ClawHub; skills are plain SKILL.md folders on disk Note: No single-skill export action; a skill is exported by copying its folder, publishing it, or exporting the whole profile.
  • sk-evals unknown → no: source read at v2026.9.24, not driven: searched 'eval|with and without|baseline' in tools/skill*.py, hermes_cli/subcommands/skills.py and optional-skills/*/SKILL.md: no skill test-case runner; tools/skillevaluator_scan.py:1-7 is an advisory security scan on install; evals/ holds developer regression harnesses (evals/compaction, evals/tool_search ...) with no user surface
  • mo-nc-assistant unknown → no: source read at v2026.9.24, not driven: searched 'nextcloud|taskprocessing' repo-wide (excluding website/): none outside one test; no provider plugin for Nextcloud's AI task processing in plugins/model-providers/
  • mo-provide-text2text unknown → partial: source read at v2026.9.24, not driven: gateway/platforms/api_server.py:1-6 OpenAI-compatible /v1/chat/completions and /v1/responses serve the agent to any OpenAI client (per profile under /p//); searched 'nextcloud|taskprocessing' repo-wide: no Nextcloud provider registration Note: Another system can use Hermes as an OpenAI-compatible text model; there is no Nextcloud text-generation provider.
  • mo-tenant-policy unknown → no: source read at v2026.9.24, not driven: searched 'allowed_models|model_allowlist|blocked_models' in *.py: only tools/mcp_tool_sampling.py:181 limits which models an MCP server's sampling requests may use; no organisation or tenant model in hermes_cli/profiles.py:538 ProfileInfo Note: No tenants and no model allowlist per group of agents.
  • mo-per-feature unknown → yes: source read at v2026.9.24, not driven: hermes_cli/config_defaults.py:715-790 auxiliary. provider/model per feature: vision, compression, approval, title_generation, curator, kanban_decomposer, profile_describer, goal_judge, background_review, monitor, moa_aggregator and more
  • mo-sensitivity-routing unknown → no: source read at v2026.9.24, not driven: searched 'sensitiv|classification|pii.*route|route.*pii' in agent/ and hermes_cli/: no data-class routing; hermes_cli/model_data_policy_guard.py:1-6 only warns at model selection when a tier trains on prompts; agent/redact.py redacts secrets from logs and output Note: No rule that keeps sensitive data away from particular models.
  • mo-cli-runner unknown → partial: source read at v2026.9.24, not driven: plugin-catalog/claude-subscription-directsdk.yaml:1-5 official NousResearch catalog plugin runs Hermes turns through the logged-in claude CLI (Agent SDK path); skills/autonomous-ai-agents/claude-code/SKILL.md:1-3 bundled skill delegates coding to the Claude Code CLI; tools/environments/docker.py can host the terminal Note: The turn runner is a catalog plugin, not core, and nothing places the claude CLI in its own container by design.
  • mo-personal-key unknown → partial: source read at v2026.9.24, not driven: gateway/profile_routing.py:1-11 routes a sender user_id to a profile, and each profile has its own .env/auth.json keys (agent/secret_scope.py:1-10); searched 'per.?user.{0,20}(key|credential)|byok' in *.py: only tool-provider BYOK rows (hermes_cli/tools_config_providers.py:760) Note: A person gets their own key only by being routed to their own profile; no per-user key field.
  • dl-talk unknown → partial: source read at v2026.9.24, not driven: cron/scheduler_delivery.py:1-2 delivers job output to origin, home or explicit chat targets on connected platforms (telegram, discord, slack, matrix, mattermost, teams and more under plugins/platforms/); web/src/i18n/en.ts cron.deliverTo; searched 'nextcloud|spreed' repo-wide (excluding website/): none outside one test; plugins/platforms/ has no Talk adapter Note: Delivery into a team chat room works; Nextcloud Talk is not a target.
  • dl-talk-bridge unknown → partial: source read at v2026.9.24, not driven: gateway/run_inbound.py handles group-room messages and replies in the same room on every platform adapter; gateway/platforms/access_policy_mixin.py:6-68 group allowlists per chat; searched 'nextcloud|spreed' repo-wide (excluding website/): none outside one test; plugins/platforms/ has no Talk adapter Note: Chat-room bridging exists for other chat systems, not for Nextcloud Talk.
  • dl-talk-grouping unknown → no: source read at v2026.9.24, not driven: searched 'nextcloud|spreed' repo-wide (excluding website/): none outside one test; plugins/platforms/ has no Talk adapter; hermes_cli/commands.py:76 /branch opens a new thread on Discord/Telegram/Slack/Matrix, which separates sessions but does not group agent rooms apart from human rooms
  • dl-webhook-out unknown → yes: source read at v2026.9.24, not driven: agent/outbound_webhooks.py:1-7 hooks.outbound entries POST lifecycle events (hermes_cli/plugins.py:108-118 post_llm_call, post_tool_call, on_stream_end ...) HMAC-SHA256 signed via X-Hermes-Signature-256; cron/scheduler_delivery.py:32 'webhook' is a cron delivery target
  • dl-email unknown → yes: source read at v2026.9.24, not driven: cron/scheduler_delivery.py:32 'email' delivery target; plugins/platforms/email/plugin.yaml:5-8 IMAP/SMTP email adapter; web/src/i18n/en.ts cron.delivery.email on CronPage
  • dl-notification yes → partial: source read at v2026.9.24, not driven: hermes_cli/terminal_notify.py:1-5 OS notifications via OSC 9/777 from the CLI; apps/desktop/electron/notification-ipc.ts:53 native desktop notifications; cron/scheduler_delivery.py:43-47 run results and approval prompts land in the home channel on Telegram, Discord, Slack, Signal; searched 'nextcloud' repo-wide: none Note: Notifies through desktop and messaging channels, not Nextcloud notifications. Old yes rested on a docs line about notifications in general.
  • dl-target-pref unknown → yes: source read at v2026.9.24, not driven: hermes_cli/commands.py:148 /sethome sets this chat as the home channel; cron/scheduler_delivery.py:43-47 _HOME_CHANNEL resolves the default target; web/src/i18n/en.ts cron.deliverTo with 'set a home channel first'
  • dl-digest unknown → yes: source read at v2026.9.24, not driven: cron/scheduler_delivery.py:1-2 scheduled job output delivered to a chat target; web/src/i18n/en.ts cron.namePlaceholder 'e.g. Daily summary' with deliverTo; skills/productivity/google-workspace/SKILL.md:27 daily brief procedure; hermes_cli/web_routers/cron.py:393 blueprints for ready-made automations
  • dl-dedupe unknown → partial: source read at v2026.9.24, not driven: cron/incidents.py:1-10 repeat failures with the same job and error signature resolve to one incident and repeat alerts are withheld for cron.failure_repeat_alert_hours; gateway/platforms/webhook_coalesce.py:1-8 debounces bursts of events on one entity into one run; searched 'repeat.?count|collapsed' in gateway/ and cron/: no 'N times' counter on delivered reports Note: Duplicates are suppressed or coalesced, but not collapsed into one report with a count.
  • dl-dashboard-widget unknown → partial: source read at v2026.9.24, not driven: optional-skills/productivity/live-dashboard/SKILL.md:1-3 optional skill builds self-updating dashboards; web/src/plugins/slots.ts:1-13 plugins can inject components into dashboard slots; searched 'nextcloud' repo-wide: none Note: No Nextcloud dashboard widget; agent output on a dashboard needs an optional skill or a dashboard plugin.
  • dl-embed-web unknown → no: source read at v2026.9.24, not driven: searched 'embed.{0,20}(chat|widget)|chat.?widget|web.?chat' in plugin-catalog/, plugins/platforms/, gateway/platforms/, web/src: only the dashboard's own chat page; gateway/platforms/api_server.py:1178 cors_origins lets a site call the key-protected API but ships no embeddable widget or anonymous access
  • ov-approval-inbox unknown → partial: source read at v2026.9.24, not driven: mcp_serve.py:662-670 permissions_list_open lists pending approvals across conversations seen by the MCP bridge, :672 permissions_respond; hermes_cli/commands.py:223 /memory pending and :217 /skills pending list staged writes Note: Approvals surface in the conversation that raised them; the only cross-conversation list is through the MCP bridge, with no inbox page.
  • ov-approval-context unknown → yes: source read at v2026.9.24, not driven: gateway/platforms/base_exec_approval.py:1-16 every approval card states what Hermes wants to run, why it was flagged (EA_REASON_LABEL_TEXT) and that silence means it does not run; tools/approval.py:1106-1109 tool approvals carry the tool name and reason; tools/approval_smart.py:1-8 guardian LLM risk assessment of the command
  • ov-talk-reaction unknown → partial: source read at v2026.9.24, not driven: plugins/platforms/matrix/adapter.py:2419-2442 a reaction on the approval prompt resolves it (_handle_approval_reaction); plugins/platforms/telegram/adapter.py:4256-4280 inline Approve Once / Always Approve buttons; searched 'nextcloud|spreed' repo-wide: none Note: Approve by reaction works in Matrix, by buttons elsewhere; not in Nextcloud Talk.
  • ov-draft-hold unknown → partial: source read at v2026.9.24, not driven: tools/approval.py:1095-1110 request_tool_approval lets a plugin pre_tool_call hook hold any tool call, including send_message, for a human; searched 'draft.{0,30}(approv|review|hold)|confirm.{0,20}before.{0,10}send' in *.py: no built-in hold on agent-written replies Note: Holding outgoing messages needs a plugin hook; nothing ships that queues drafts for review.
  • ov-kill-switch unknown → partial: source read at v2026.9.24, not driven: agent/estop.py:1-8 and :36-39 hermes pause at the root home halts cron dispatch, kanban dispatch and new gateway turns for every profile; hermes_cli/commands.py:94 /pause; agent/estop.py:1-4 in-flight work is never killed Note: Stops new work everywhere at once; running turns finish. No organisations, so the scope is the whole install.
  • ov-kill-agent unknown → yes: source read at v2026.9.24, not driven: gateway/slash_commands.py:425-437 /stop interrupts a running agent and force-cleans a hung session; hermes_cli/commands.py:92 /stop kills background processes; agent/estop.py:31-33 hermes -p <profile> pause holds one profile; hermes_cli/subcommands/gateway.py stops a profile's gateway
  • ov-guardrail-input yes → partial: source read at v2026.9.24, not driven: agent/redact.py:871 redact_sensitive_text and :1157 redact_terminal_output mask API keys and tokens in terminal/tool output; gateway/session.py:193-203 and :382-385 privacy.redact_pii hashes user and chat ids in the model-visible session context; agent/redact.py:66 vault values redacted; searched 'pii|personal data' in agent/ tools/ gateway/: no content-level PII filter Note: Secrets are masked and identifiers can be hashed; personal data inside messages or files reaches the model unfiltered.
  • ov-guardrail-output unknown → partial: source read at v2026.9.24, not driven: hermes_cli/plugins.py:108-111 transform_llm_output hook lets a plugin replace or block a final answer; plugins/security-guidance/README.md:1-10 bundled plugin flags dangerous code the agent writes (warns, still writes); gateway/response_filters.py:1-5 only suppresses intentional no-reply markers Note: No shipped content-rule check on answers; it takes a custom plugin hook.
  • ov-tool-risk unknown → yes: source read at v2026.9.24, not driven: tools/approval_detection.py:51 hardline commands blocked unconditionally, other dangerous patterns routed to approval; tools/tirith_security.py:1-4 pre-exec scan with allow/block/warn verdicts; tools/approval.py:1095-1104 plugins can escalate any tool to the human gate; hermes_cli/config_defaults.py:1656-1670 smart mode, smart_policy and deny globs
  • ov-egress unknown → yes: source read at v2026.9.24, not driven: tools/website_policy.py:1-5 security.website_blocklist enforced on URL-capable tools; hermes_cli/proxy_cli.py:234-254 iron-proxy allowed_hosts plus default-deny CIDRs for sandboxed terminals (tools/environments/docker_egress.py:1-5); hermes_cli/subcommands/egress.py:10-15 hermes egress Note: The host allowlist applies to the Docker sandbox through iron-proxy (off by default); the web tools use a blocklist.
  • ov-anonymise unknown → no: source read at v2026.9.24, not driven: searched 'anonymi' in *.py outside tests: only tools/browser_use_cli.py:155 disabling a telemetry flag; plugin-catalog/ has no anonymiser entry; agent/redact.py masks secrets, not personal data in documents
  • ov-ai-oversight unknown → partial: source read at v2026.9.24, not driven: web/src/pages/SessionsPage.tsx browses every past session with tool messages (web/src/i18n/en.ts sessions.roles.tool) and an Automation filter for cron runs; hermes_cli/subcommands/approvals.py:13-23 approvals suggest mines past approval decisions; searched 'oversight|audit page' in web/src: none Note: After-the-fact review means reading transcripts; no oversight page that lists AI decisions for review.
  • ov-automation-bias unknown → no: source read at v2026.9.24, not driven: searched 'automation.?bias|rubber.?stamp|approv\w* everything|approval fatigue' in *.py and *.ts outside tests: only a code comment in gateway/authz_mixin.py:474; hermes_cli/subcommands/approvals.py:22-23 approvals suggest goes the other way, proposing allowlist entries from repeated approvals
  • ov-tool-oversight yes → partial: source read at v2026.9.24, not driven: agent/insights.py:1-2 tool and skill usage breakdowns behind /insights (hermes_cli/commands.py:287) and web/src/i18n/en.ts models.toolCalls on AnalyticsPage; agent/tool_guardrails.py:1-6 flags tool-call loops within a turn; hermes_cli/config_defaults.py:1666 denial breaker after repeated guardian denials Note: Tool usage is counted and loops are caught; no review queue that flags misuse for a person. Old yes rested on a docs line.
  • co-audit-log unknown → partial: source read at v2026.9.24, not driven: hermes_state_messages.py / state.db keep every message and tool call per session; cron/executions.py:1-6 durable per-attempt execution ledger with immutable terminal states; agent/curator_backup.py:37 append-only curator ledger; searched 'tamper|hash.?chain|audit trail' in *.py: no tamper-evident log, and sessions are deletable (hermes_cli/web_routers/sessions.py:696) Note: Runs and tool calls are recorded but can be deleted or pruned; nothing prevents change afterwards.
  • co-retention unknown → yes: source read at v2026.9.24, not driven: hermes_cli/config_defaults.py:2231-2245 sessions.auto_prune with retention_days (default 90) deletes ended sessions on startup sweeps; hermes_cli/subcommands/sessions.py:105 sessions prune by age, source or title; :123 archive
  • co-ai-register unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; hermes_cli/inventory.py:1-2 is a provider/model inventory for pickers, not an AI-feature register
  • co-risk-class unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; hermes_cli/profiles.py:538-575 ProfileInfo has no risk-level field
  • co-dpo-ack unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; no sign-off or go-live gate on profiles, skills or plugins beyond tools/write_approval.py staged writes
  • co-control-packs unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; hermes_cli/subcommands/security.py and skills audit scan code and skills for security patterns, not against a control framework
  • co-factsheet unknown → partial: source read at v2026.9.24, not driven: hermes_cli/profile_cmd.py:384-395 profile show prints model and provider, gateway state, skill count, SOUL.md presence and distribution; hermes_cli/profile_cmd.py:564-570 profile info prints description, author, licence, requirements, source of a distribution Note: A profile summary exists; it does not describe data used or purpose in fact-sheet form or export one.
  • co-compliance-export unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; the nearest exports are session transcripts (hermes_cli/subcommands/sessions.py:69) and hermes debug reports (hermes_cli/commands.py:303), neither a compliance report
  • co-incident unknown → no: source read at v2026.9.24, not driven: cron/incidents.py:1-10 records operational cron failure incidents (job id, error signature, ack) with no impact or remediation fields; searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none Note: Operational failure incidents only; no AI-incident record.
  • co-authority-notify unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; cron/incidents.py:1-10 alerts only the operator's home channel
  • co-access-review unknown → no: source read at v2026.9.24, not driven: searched 'owner|attest|review.{0,20}(access|owner)|recertif' in hermes_cli/profiles.py and hermes_cli/profile_cmd.py: no owner field and no periodic review; hermes_cli/profiles.py:538-575 ProfileInfo
  • co-transparency unknown → no: source read at v2026.9.24, not driven: searched 'transparency|explain.{0,20}agent|public.{0,20}(page|description)' in web/src and hermes_cli/web_routers: none; profile descriptions (hermes_cli/web_routers/profiles.py:928) feed the kanban router and are not published to anyone
  • co-residency unknown → partial: source read at v2026.9.24, not driven: hermes_cli/status.py:157 hermes status prints the effective provider; hermes_cli/config_defaults.py:715-790 auxiliary..provider per feature in config; hermes_cli/model_data_policy_guard.py:1-6 warns when a tier trains on prompts; searched 'region|residency|data location' in hermes_cli/: no per-feature residency view Note: You can read which provider each feature uses from config and status, but not where that provider processes the data.
  • co-disable-dept unknown → no: source read at v2026.9.24, not driven: searched 'department|group|org' scoping in hermes_cli/profiles.py and gateway/authz_mixin.py: no organisational units; agent/estop.py:31-39 pauses a whole profile or install and gateway/authz_mixin.py:32-37 allowlists individual user ids, with no proof-of-off report Note: Cutting a set of users off is possible by editing allowlists, not by department, and nothing proves it.
  • ob-runs unknown → yes: source read at v2026.9.24, not driven: web/src/pages/SessionsPage.tsx with web/src/i18n/en.ts sessions.filterAutomation 'Automation' lists cron and other runs with time; hermes_cli/web_routers/cron.py:243 GET /api/cron/jobs/{id}/runs; hermes_cli/subcommands/cron.py:168 cron runs durable attempts with status (cron/executions.py:1-6)
  • ob-replay unknown → partial: source read at v2026.9.24, not driven: hermes_cli/commands.py:68 /retry resends the last message, :71 /undo backs up N turns and re-prompts, :76 /branch forks a session; hermes_cli/subcommands/cron.py:157 re-runs a job; agent/replay_cleanup.py:1-5 only sanitises resumed history; searched 'replay' for a run re-execution feature: none Note: You can re-run from a point in a live session, but not replay a stored past run to reproduce it.
  • ob-dry-run unknown → partial: source read at v2026.9.24, not driven: hermes_cli/commands.py:132 /plan writes a plan without executing anything; hermes_cli/commands.py:213 /tools disable to remove write-capable tools for a run; hermes_cli/commands.py:83 /rollback restores filesystem checkpoints (tools/checkpoint_manager.py); searched 'dry.?run' in hermes_cli/commands.py: only /worktree prune and /compress previews Note: No mode that runs an agent end to end while blocking every side effect.
  • ob-analytics unknown → partial: source read at v2026.9.24, not driven: hermes_cli/web_routers/analytics.py:143 /api/analytics/usage and :305 /api/analytics/models behind web/src/pages/AnalyticsPage.tsx: tokens per day, sessions, API calls, estimated cost, tool calls, top skills (web/src/i18n/en.ts analytics, models); agent/insights.py:1-2 /insights Note: Cost, volume and tool use are charted; success rate and speed are not, and there is no per-agent breakdown across profiles on one dashboard.
  • ob-cost-per-run unknown → partial: source read at v2026.9.24, not driven: hermes_state_usage.py:29-56 per-session estimated_cost_usd and actual_cost_usd with token counts; hermes_cli/commands.py:138 /status and :280 /usage show session tokens; gateway/runtime_footer.py:1-6 optional per-reply footer (model, context %, latency) Note: Tokens and cost are kept per session (run), not per step.
  • ob-budget unknown → partial: source read at v2026.9.24, not driven: hermes_cli/config_defaults.py:53-63 agent.max_turns hard cap with budget_warning_ratio one-time warning and run_budget_seconds wall-clock budget with an 80% notice; hermes_state_maintenance.py:71 max_cost is only a session filter; searched 'max_cost|spend_limit|budget_usd|cost_cap' in *.py: no money budget Note: Warning plus hard stop exist for turns and time, not for spend.
  • ob-estimate yes → partial: source read at v2026.9.24, not driven: hermes_cli/model_cost_guard.py:1-26 warns before selecting a model priced above the input/output cost thresholds; hermes_cli/subcommands/prompt_size.py:13 hermes prompt-size byte breakdown of system prompt and tool schemas; hermes_cli/commands.py:143 /context usage gauge; searched 'estimate.{0,20}cost|forecast' for a pre-run cost estimate: none Note: Warns about expensive models and shows prompt size; no cost forecast for a run before it starts. Old yes rested on a docs line.
  • ob-fail-alert unknown → yes: source read at v2026.9.24, not driven: cron/scheduler_failure_copy.py:1-6 plain-language failure notice delivered to the job's chat with the exact fix command; cron/incidents.py:1-10 alert state with repeat throttling; agent/monitoring/cron_health.py cron health events
  • ob-drift unknown → no: source read at v2026.9.24, not driven: searched 'drift' in agent/ cron/ gateway/ hermes_cli/ excluding clock, schema, config and terminal drift: only prompt-cache and table-padding comments; cron/monitor.py:1-8 detects changes in a monitored source, not drift in agent results
  • ob-metrics unknown → yes: source read at v2026.9.24, not driven: gateway/platforms/api_server.py:1591-1592 GET /health and /health/detailed; hermes_cli/web_routers/status.py:115 /api/health and :555 /api/system/stats; agent/monitoring/otlp_exporter.py:1-6 exports health and diagnostic events to an OpenTelemetry collector; hermes_cli/subcommands/monitoring.py:19 Note: Metrics are pushed over OTLP; the pull endpoints are health checks, not a Prometheus scrape.
  • ob-external-tracing unknown → yes: source read at v2026.9.24, not driven: plugins/observability/langfuse/plugin.yaml:1-3 bundled Langfuse plugin traces conversations, LLM calls and tool usage (opt-in); agent/monitoring/otlp_exporter.py:1-6 OTLP export
  • ob-reports unknown → partial: source read at v2026.9.24, not driven: agent/insights.py:1-2 usage insights (tokens, cost, tool/skill use, activity, model/platform breakdowns) on demand via /insights (hermes_cli/commands.py:287) and hermes insights; searched 'weekly report|periodic report|digest.{0,20}usage' in cron/ and agent/: no scheduled usage report Note: Reports are on demand; a periodic one would be a hand-built cron job.
  • ob-feedback-stats unknown → no: source read at v2026.9.24, not driven: no answer rating exists to aggregate: searched 'thumbs|feedback.(up|down)|rate.(answer|response)' in *.py and *.ts outside tests: none; agent/reactions.py:1-8 only detects affection for the pet animation
  • fl-canvas unknown → no: source read at v2026.9.24, not driven: searched 'canvas|flow editor|node editor|reactflow' in web/src and apps/desktop/src: no visual flow builder; plugins/kanban/dashboard/manifest.json:1-10 the Kanban tab is a drag-drop task board, not a step canvas
  • fl-agent-node unknown → partial: source read at v2026.9.24, not driven: hermes_cli/commands.py:249-257 /kanban create, assign, link: tasks assigned to profiles (agents) and linked as dependencies; hermes_cli/kanban_parser.py:314-321 'dependency' blocks auto-promote when parents finish; hermes_cli/kanban_db_graph.py:1 task graph persistence; plugins/kanban/dashboard/manifest.json board tab Note: Multi-agent work is a dependency graph of kanban cards, not a flow with agent steps.
  • fl-approval-step unknown → partial: source read at v2026.9.24, not driven: hermes_cli/kanban_parser.py:314-321 kanban block --kind needs_input parks a card for a human and dependants wait until it is unblocked; hermes_cli/kanban_parser.py:216-218 --initial-status blocked for cards that need human ops; hermes_cli/kanban_pr_acceptance.py:1 PR acceptance gate Note: A human gate is a blocked card in the task graph, not an approval step with approve/deny.
  • fl-run-history unknown → partial: source read at v2026.9.24, not driven: hermes_cli/kanban_parser.py:416-418 kanban log and kanban runs per task; hermes_cli/subcommands/cron.py:168 cron runs; plugins/kanban/dashboard/manifest.json:4 board shows which profile is running what Note: Run history per task or job; no flow canvas to show it on.
  • fl-n8n unknown → yes: source read at v2026.9.24, not driven: optional-mcps/n8n-official/manifest.yaml:1-12 Nous-approved catalog entry connects the agent to an n8n instance's official MCP server with OAuth, so the agent can call n8n workflows as tools; hermes_cli/subcommands/mcp.py:27 hermes mcp add
  • fl-code-step unknown → partial: source read at v2026.9.24, not driven: cron/job_definition.py:15 script and no_agent (script-only jobs) and monitor_script fields; web/src/i18n/en.ts cron.scriptRequired 'Script-only jobs need a script path'; hermes_cli/subcommands/webhook.py:43-46 --script transform on a webhook route; tools/code_execution_tool.py code in a run Note: Custom code runs as a job, pre-run gate or webhook transform; there is no flow to put a code step in.
  • fl-subflow unknown → partial: source read at v2026.9.24, not driven: cron/scheduler_prompt.py:95-97 context_from injects the latest output of other jobs into a job's prompt (job chaining); hermes_cli/kanban_decompose.py:1-6 fans a task out into a graph of child tasks; hermes_cli/subcommands/webhook.py:47-51 a route can fire an existing job Note: Jobs and task graphs can be chained; there is no named flow to embed in another.
  • fl-validate unknown → partial: source read at v2026.9.24, not driven: hermes_cli/subcommands/cron.py:193 cron doctor checks scheduled jobs for common health issues; hermes_cli/kanban_diagnostics.py:1-8 actionable diagnostics on task graphs shown as dashboard buttons; cron/lifecycle_guard.py:1-7 rejects self-destructive job specs at creation Note: Checks exist for jobs and task graphs; no pre-run wiring check of a flow.
  • re-store unknown → partial: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:129-137 hermes profile install <git URL> installs a ready-made profile distribution (hermes_cli/profile_distribution.py:1-5); web/src/pages/ProfilesPage.tsx:1117-1122 shows distribution name and version; searched 'distribution' with 'catalog|registry|hub' in hermes_cli/profile_distribution.py: no browsable store Note: One-command install from a known repo URL; no store to browse.
  • re-template-from-agent unknown → partial: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:115 profile export packs a profile into a shareable archive and :122 import; hermes_cli/profile_distribution.py:175 write_manifest is only called by the installer (:547); searched write_manifest callers: no command that turns a profile into a distribution template Note: Sharing is by archive; making a reusable distribution means hand-writing distribution.yaml in a repo.
  • re-template-github unknown → partial: source read at v2026.9.24, not driven: hermes_cli/profile_distribution.py:235-249 github.com/user/repo sources for profile install and :594 profile update re-pulls; hermes_cli/subcommands/skills.py:148 publish exists for skills only; searched 'publish' in hermes_cli/profile*.py: no profile publish Note: Install from GitHub yes, finding and publishing agent templates no.
  • re-template-approve unknown → no: source read at v2026.9.24, not driven: searched 'approv' in hermes_cli/profile_distribution.py and hermes_cli/profiles.py: none; plugin-catalog/README.md curation is Nous review of plugins, not an organisation approving agent templates
  • re-agent-versions unknown → partial: source read at v2026.9.24, not driven: hermes_cli/commands.py:85-87 /snapshot create|restore of Hermes config/state; hermes_cli/config_backups.py:1-8 point-in-time copies of config.yaml; hermes_cli/subcommands/profile.py:147-158 distribution update with version in ProfileInfo Note: Whole-state snapshots and config backups allow rollback; no per-agent version list or compare view.
  • re-evals unknown → partial: source read at v2026.9.24, not driven: batch_runner.py:1-6 runs the agent over a JSONL prompt dataset in parallel with trajectories and tool-usage statistics; evals/ developer harnesses; searched 'expected|assert.{0,20}answer|score' in batch_runner.py: no expected-answer scoring Note: A dataset runner exists as a repo script; it does not compare against expected answers.
  • re-baseline unknown → no: source read at v2026.9.24, not driven: searched 'baseline|a/b|compare.{0,20}prompt|prompt version' in hermes_cli/ and agent/: none for user prompts; evals/openrouter_pkce_ab and evals/toolperf_abeval are developer harnesses, not a user surface
  • re-template-cross-tenant unknown → partial: source read at v2026.9.24, not driven: hermes_cli/subcommands/profile.py:115-122 export/import a profile archive including its cron jobs; hermes_cli/profile_distribution.py:396-406 distributions ship and merge cron jobs into another install; hermes_cli/subcommands/profile.py:34 --clone-channels kept off by default Note: Automations move between installs by archive or distribution; there are no client organisations inside one instance.
  • re-course-recs unknown → no: source read at v2026.9.24, not driven: searched 'course|learner|curriculum' in agent/ tools/ hermes_cli/ plugins/: none; outside the product's domain
  • op-airgap unknown → partial: source read at v2026.9.24, not driven: hermes_cli/models_local.py:1-5 local Ollama/LM Studio models; hermes_cli/config_defaults.py:2297-2305 telemetry collection and sending both off by default; :1762-1765 allow_lazy_installs false for air-gapped installs; tools/environments/docker.py:765 docker_network false air-gaps the sandbox; searched 'HERMES_OFFLINE|offline.?mode|air.?gap' in *.py: no global offline switch Note: Offline operation is assembled from settings, not a supported mode; not driven, so network calls such as model catalog refreshes were not verified to stay off.
  • op-tenant-quota unknown → no: source read at v2026.9.24, not driven: searched 'quota' in hermes_cli/profiles.py, hermes_cli/config_defaults.py and gateway/: only provider quota holds (cron/quota_hold.py:1-12) and gateway/platforms/api_server.py:1322 a global max_concurrent_runs; no per-organisation or per-profile quota
  • op-tenant-ops unknown → no: source read at v2026.9.24, not driven: searched 'tenant|organisation|organization' in web/src/pages and hermes_cli/web_routers: only the kanban tenant filter (web/src/i18n/en.ts kanban.tenant); web/src/pages/ProfilesPage.tsx manages profiles one by one with no quota or retention per organisation
  • op-sso unknown → partial: source read at v2026.9.24, not driven: plugins/dashboard_auth/self_hosted/plugin.yaml:1-4 OIDC sign-in to the dashboard against Keycloak, Authentik, Zitadel, Okta and others; plugins/dashboard_auth/self_hosted/init.py:262-270 groups are folded into a free-form org_id string that no access check reads (hermes_cli/dashboard_auth/base.py:12-16); chat users are platform ids in allowlists (gateway/authz_mixin.py:32-37) Note: Sign-in with company accounts works for the dashboard; groups do not map to rights.
  • op-admin-settings yes → partial: source read at v2026.9.24, not driven: web/src/pages/ConfigPage.tsx:384-391 sectioned config editor for config.yaml plus EnvPage (Keys) and ModelsPage in the Hermes dashboard; hermes_cli/subcommands/setup.py:11 hermes setup; searched 'nextcloud' repo-wide: none Note: Set up from Hermes' own dashboard and CLI, not from Nextcloud admin settings.
  • op-setup-wizard unknown → yes: source read at v2026.9.24, not driven: hermes_cli/subcommands/setup.py:11-26 hermes setup interactive wizard with sections; hermes_cli/gateway_setup_wizard.py:1 hermes gateway setup per-platform prompts; apps/desktop/e2e/core/onboarding-first-chat.spec.ts desktop onboarding to a first chat; web/src/pages/ProfileBuilderPage.tsx:32 profile builder
  • op-health unknown → yes: source read at v2026.9.24, not driven: web/src/pages/SystemPage.tsx:106 doctor run with live log and :187 memory-provider status; web/src/i18n/en.ts status.* gateway running/failed, connected platforms, active sessions on the status overview; hermes_cli/web_routers/status.py:115 /api/health and gateway/platforms/api_server.py:1592 /health/detailed
  • op-flat-cost partial → yes: source read at v2026.9.24, not driven: LICENSE:1-3 MIT, no seat or message licence in the code; agent/billing_view.py:1 and hermes_cli/nous_subscription.py cover an optional Nous portal plan; model spend is paid per token to whichever provider is configured Note: Software is free; model usage is billed by the provider, per token.
  • op-outside-agent unknown → partial: source read at v2026.9.24, not driven: plugins/platforms/a2a/plugin.yaml:5-25 inbound A2A endpoint with Agent Card; plugins/platforms/a2a/security.py:1-4 peer identity from credentials (A2A_PEER_TOKENS token -> name), trusted-peer allow-list, JSONL audit, injection filtering; gateway/slash_access.py:1-10 command lists per user id Note: Outside agents can be registered and admitted by token; their tasks run in the agent's session with its full toolset, with no per-peer tool scope or run-as identity.
  • op-preferences unknown → yes: source read at v2026.9.24, not driven: tools/memory_tool.py:325 USER.md holds the user's preferences and style and loads every session; hermes_cli/commands.py:163 /personality, :207 /busy, :176 /verbose, :170 /timestamps; web/src/pages/ConfigPage.tsx config editor Note: Preferences are per profile; separate people get separate preferences only through separate profiles or a user-modelling memory provider.
  • ag-identity unknown → partial: source read at v2026.9.24, not driven: gateway/profile_routing.py:1-11 a requester's user id can route to their own profile, whose own keys and credentials then apply (agent/secret_scope.py:1-10); tools/environments/ssh.py runs the terminal as a configured remote account; searched 'run.?as|impersonat|service account|on behalf of' in agent/ and gateway/: no per-run identity choice Note: Tools act with the host or backend account and the profile's keys; choosing requester, owner or service identity per agent is not a setting.
  • ch-shared-session unknown → yes: source read at v2026.9.24, not driven: gateway/config.py:574-596 thread_sessions_per_user false by default, so everyone in a thread shares one session with the agent (group_sessions_per_user can be switched off for whole groups); gateway/session.py:634-641 session key resolution; hermes_cli/commands.py:76 /branch opens a shared thread
  • ch-intake unknown → partial: source read at v2026.9.24, not driven: gateway/authz_mixin.py:35 _ALLOW_ALL_USERS lets anyone message the bot on WhatsApp, SMS, Telegram and others without an account; gateway/run_inbound_unauthorized.py:1-9 strangers otherwise get a pairing code; searched 'intake|case|file.{0,10}request' in gateway/ and tools/: no intake flow that files a request Note: A public bot is possible; filing the request somewhere is left to whatever tools the agent has.
  • tl-connectors unknown → yes: source read at v2026.9.24, not driven: tools/connectors/init.py:1-6 and tools/connectors/gateway/client.py:1-3 managed connector accounts through the Nous tool gateway; optional-mcps/ 65 Nous-approved MCP servers (asana, atlassian, notion, stripe, supabase, ...); plugin-catalog/ ~290 curated plugins Note: The managed connector set needs a Nous account; the MCP and plugin catalogs are self-configured.
  • me-rag-files unknown → partial: source read at v2026.9.24, not driven: tools/file_tools.py:1133-1270 read_file and search_files let the agent read and grep documents on the host on demand; gateway/platforms/base.py:1183-1231 attached documents are read into the turn; searched 'nextcloud' repo-wide: none, and no document index in core (RAG only via plugins/memory/retaindb, openviking) Note: Grounding in local files by reading them, not in Nextcloud Files and not through an index.
  • me-permissions unknown → no: source read at v2026.9.24, not driven: searched 'acl|permission.{0,20}(user|requester)|allowed to see' in tools/file_tools*.py, tools/session_search_tool.py and agent/: file access follows the host account and tools/file_tools_write_guards.py protects Hermes' own files, not per-requester visibility; tools/session_search_tool.py:1-9 searches the whole profile's sessions Note: All users of one profile share what the agent can read; nothing filters by the asking person.
  • me-context-docs partial → yes: source read at v2026.9.24, not driven: agent/prompt_builder.py:1656-1661 loads .hermes.md, AGENTS.md chain, CLAUDE.md and .cursorrules as instructions; hermes_cli/commands.py:234 /init generates AGENTS.md from a repo scan; SOUL.md per profile (web/src/pages/ProfilesPage.tsx:556); skills as SKILL.md documents Note: Old partial; document instructions are core.
  • sk-share-tenants unknown → partial: source read at v2026.9.24, not driven: tools/skills_sync_client_org.py:1-7 org-shared skills under ~/.hermes/skills/_org/<org_id>/ with pull and propose; tools/skills_sync_client.py:6-8 the sync is INERT unless the user is a Nous portal admin (pre-launch gate); hermes_cli/subcommands/profile.py:20-23 --clone copies skills to another profile Note: Org skill sharing exists in code but is switched off for ordinary users; profiles on one install share by cloning.
  • co-algoritmeregister unknown → no: source read at v2026.9.24, not driven: searched 'algoritme|algorithm register' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none
  • co-dpia unknown → no: source read at v2026.9.24, not driven: searched 'ai.?act|risk.?class|iso.?42001|dpia|data protection officer|algoritme' in agent/ tools/ hermes_cli/ gateway/ cron/ plugins/ web/src: none; hermes_cli/profiles.py:538-575 ProfileInfo has no link or document field for an assessment
  • op-rbac unknown → partial: source read at v2026.9.24, not driven: gateway/slash_access.py:1-27 per platform allow_admin_from (all commands) vs user_allowed_commands for other allowed users; gateway/authz_mixin.py:32-37 allowlists decide who may chat; plugins/dashboard_auth/basic/init.py:1-8 the dashboard has one username and every signed-in user has full control (hermes_cli/dashboard_auth/base.py:12-16 no role field) Note: Two chat roles (admin, user) for slash commands; no builder role and no roles in the dashboard.

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 3 of 8

hermes-agent (continued)

  • op-languages unknown → partial: source read at v2026.9.24, not driven: web/src/i18n/ ships af, ar, de, en, es, fr, ga, hu, it, ja, ko, pt, ru, tr, uk, zh, zh-hant; locales/*.yaml the same set for CLI and gateway strings; apps/desktop/src/i18n adds no nl either; searched for nl locale files repo-wide: none Note: The model answers in Dutch when addressed in Dutch, but dashboard, CLI and desktop text have no Dutch translation.

copilot-studio: every rating change (before → after, evidence)

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 4 of 8

copilot-studio (continued)

dify: every rating change (before → after, evidence)

  • ag-detail unknown → partial: source read at 1.17.1, not driven: web/features/agent-v2/agent-detail/navigation.tsx:62-86 detail page with Configure (model, prompt, tools, skills, knowledge, files), Access Point, Logs, Monitoring; api/controllers/console/agent/roster.py:1133 logs. No schedules: agents have no scheduler of their own, schedules only exist as trigger nodes on workflow apps Note: schedules are missing from the agent page
  • ag-quota unknown → partial: source read at 1.17.1, not driven: api/controllers/console/agent/roster.py:749 PUT /agent sets max_active_requests, enforced in api/services/app_generate_service.py:153,384 (concurrent requests per app); dify-agent/src/dify_agent/runtime/runner.py:94,403 a fixed 500-step and run-timeout limit per run. No per-agent run count or token budget Note: only a concurrency cap and a server-wide step limit, no token or run quota
  • ag-enable unknown → partial: source read at 1.17.1, not driven: web/features/agent-v2/agent-detail/access/components/web-app-access-card.tsx:254 and service-api-access-card.tsx:114 per-surface In service/Out of service toggles; api/controllers/console/agent/roster.py:1013 POST /agent//api-enable. No single off switch: workflows that bind the agent as a node keep running it (models/agent.py:407 WorkflowAgentNodeBinding) Note: off per access point, not per agent
  • ag-owner unknown → partial: source read at 1.17.1, not driven: api/services/app_service.py:672 created_by is set to the creating account and api/services/app_service.py:282 filters on it ('Created by me'); no owner field that can be assigned, models/agent.py:212 only created_by/updated_by/archived_by Note: creator is recorded, not an accountable owner that can be named
  • ag-offboard unknown → no: source read at 1.17.1, not driven: searched 'transfer|owner|created_by =' in api/controllers/console and api/services/app_service.py: only workspace ownership transfer exists (api/controllers/console/workspace/members.py:418 send-owner-transfer-confirm-email); no endpoint or UI reassigns an agent or app to another member
  • ag-app-slug unknown → yes: source read at 1.17.1, not driven: api/models/agent.py:407 WorkflowAgentNodeBinding ties a roster agent to a workflow app node; api/controllers/console/agent/composer.py:54 agent-composer on a workflow node, :125 copy-from-roster; roster.py:474 published references listed on the agent's Access page ('Workflow access')
  • ag-capability-profile partial → yes: source read at 1.17.1, not driven: web/features/agent-v2/agent-detail/configure/components/orchestrate/ has model-config, prompt-editor, tools, skills, knowledge and files sections on the one Configure page; web/i18n/en-US/agent-v-2.json agentDetail.configure.tools/skills/knowledgeRetrieval/files
  • ag-delete unknown → yes: source read at 1.17.1, not driven: api/controllers/console/agent/roster.py:780 DELETE /agent/; api/services/app_service.py:1078 delete_app archives the backing agent and unbinds it; api/tasks/remove_app_and_related_data_task.py:90,632,681 deletes the app's triggers and WorkflowSchedulePlan rows so schedules stop; web/i18n/en-US/agent-v-2.json roster.deleteDialog 'web app, API access, and workflows that use it stop working'
  • ch-stream unknown → yes: source read at 1.17.1, not driven: api/controllers/web/completion.py:45-63 response_mode streaming (agent apps are streaming-only, :50); service API the same (api/controllers/service_api/app/completion.py); web chat renders SSE chunks (web/app/components/base/chat/chat-with-history/chat-wrapper.tsx)
  • ch-sessions unknown → yes: source read at 1.17.1, not driven: api/controllers/web/conversation.py:48 GET /conversations, :129 rename, :179 pin/unpin; web/app/components/base/chat/chat-with-history/sidebar lists past conversations to reopen
  • ch-session-delete unknown → partial: source read at 1.17.1, not driven: api/controllers/web/conversation.py:116 DELETE /conversations/; api/services/conversation_service.py:232 soft-delete flag then api/tasks/delete_conversation_task.py:105 purges related data. Searched 'restore|trash|bin|undelete' in api/services/conversation_service.py and api/controllers/web: no restore from a bin Note: delete only, no bin or restore
  • ch-tool-steps unknown → yes: source read at 1.17.1, not driven: web/app/components/base/chat/chat/answer/agent-content.tsx:15-38 renders each agent_thought with its tool call; answer/tool-detail.tsx tool input/output; agent v2 'Ran commands' activity in web/features/agent-v2/agent-detail/configure/components/preview/chat-conversation.tsx and answer/agent-roster-response-content.tsx
  • ch-attach unknown → partial: source read at 1.17.1, not driven: api/controllers/web/files.py:23 POST /files/upload and api/controllers/web/remote_files.py:102 upload by URL, enabled per app by web/app/components/base/features/new-feature-panel/file-upload; files go into the chat message. No picker for a document store such as Nextcloud Files: upload from the local device or a URL only Note: attach by upload or URL, not from Nextcloud
  • ch-feedback unknown → yes: source read at 1.17.1, not driven: api/controllers/web/message.py:107 POST /messages//feedbacks; web/app/components/base/chat/chat/answer/operation.tsx:123-144 like/dislike buttons on each answer
  • ch-companion unknown → partial: source read at 1.17.1, not driven: web/public/embed.js (461 lines) injects a floating chat bubble into any web page that includes the script; web/i18n/en-US/app-overview.json:47 points to a separate 'Dify Chatbot Chrome Extension' (not in this repo); nothing embeds the assistant across the Dify console itself or inside Nextcloud Note: a site owner can place the bubble on their pages; no Nextcloud integration
  • ch-object-leaf unknown → partial: source read at 1.17.1, not driven: web/public/embed.js:93-96 the host page passes config.inputs (e.g. a record id) into the embedded chat as app input variables; the agent only sees what the host page chooses to pass, no connector reads the record or its links from another app Note: a host page can hand context in, nothing looks the record up
  • ch-prompt-library unknown → partial: source read at 1.17.1, not driven: web/app/components/base/features/new-feature-panel/conversation-opener/modal.tsx:48,87 builder sets an opening statement and fixed suggested questions per app; web/app/components/base/chat/chat/answer/suggested-questions.tsx. No prompt library keyed to a record type Note: per-app starter questions only
  • ch-voice-in unknown → yes: source read at 1.17.1, not driven: api/controllers/web/audio.py:62 POST /audio-to-text; web/app/components/base/features/new-feature-panel/speech-to-text.tsx per-app switch; needs a speech2text model from a provider plugin
  • ch-voice-out unknown → yes: source read at 1.17.1, not driven: api/controllers/web/audio.py:119 POST /text-to-audio; web/app/components/base/features/new-feature-panel/text-to-speech (voice, autoplay) per app; needs a TTS model from a provider plugin
  • ch-smart-picker unknown → no: source read at 1.17.1, not driven: searched 'smart picker|reference provider|text field|browser extension' in web/ and api/: Dify is a standalone app, AI help inside text fields exists only for its own prompt editors (api/controllers/console/app/generator.py:327 instruction-generate); nothing inserts AI output into other applications' text fields
  • ch-text-tasks unknown → partial: source read at 1.17.1, not driven: a builder can make a Completion (text generator) app that summarises or translates (web/app/(shareLayout)/completion/[token]); no built-in one-click summarise/reformulate/translate action on arbitrary text Note: possible by building an app, not a ready one-click action
  • ch-image-gen unknown → partial: source read at 1.17.1, not driven: core builtin tools are only audio, code, time, webscraper (api/core/tools/builtin_tool/providers/); searched 'text2img|image_generation|generate image' in api/core and web/i18n/en-US: none in core. Image generation comes only from marketplace tool plugins Note: marketplace plugin only
  • ch-search-history unknown → partial: source read at 1.17.1, not driven: api/controllers/console/app/conversation.py:55,119-126 builders search one app's logs by keyword over queries and answers; the end-user chat sidebar (web/app/components/base/chat/chat-with-history/sidebar) has no search and api/controllers/web/conversation.py:48 lists without a keyword Note: admin log search per app, no search for the person across their own conversations
  • ch-citations unknown → yes: source read at 1.17.1, not driven: web/app/components/base/features/new-feature-panel/citation.tsx:44 per-app Citations switch; web/app/components/base/chat/chat/citation/popup.tsx:31,109 shows each source document and segment with a link to /datasets//documents/ (link shown to console users)
  • ch-share-link unknown → no: source read at 1.17.1, not driven: searched 'share conversation|shareConversation|conversation.*share' in web/i18n/en-US and api/controllers/web/conversation.py (list, delete, rename, pin only): the web app URL and QR code share the app (web/i18n/en-US/agent-v-2.json access.webApp.qrCode), no link to one conversation
  • sc-cron partial → yes: source read at 1.17.1, not driven: api/core/workflow/nodes/trigger_schedule/entities.py:10-19 Schedule Trigger start node with mode cron and cron_expression; api/schedule/workflow_schedule_task.py:18 poller (ENABLE_WORKFLOW_SCHEDULE_POLLER_TASK default true, api/configs/feature/init.py:1461); an agent runs on it as an Agent node in that workflow Note: the schedule belongs to a workflow app that holds the agent node, not to the agent itself
  • sc-interval partial → yes: source read at 1.17.1, not driven: api/core/workflow/nodes/trigger_schedule/entities.py:17,34-55 visual mode with hourly/daily/weekly/monthly frequency, on_minute, time, weekdays; api/services/trigger/schedule_service.py:257 visual_to_cron; web/i18n/en-US/workflow.json nodes.triggerSchedule.useVisualPicker Note: hourly is the finest visual step; 'every 15 minutes' needs cron
  • sc-once unknown → no: source read at 1.17.1, not driven: searched 'once|run_at|one-time|date' in api/core/workflow/nodes/trigger_schedule/entities.py and api/services/trigger/schedule_service.py: only recurring frequencies and a 5-field cron (api/libs/schedule_utils.py:33-39), which repeats yearly; no fire-once date
  • sc-nl unknown → no: source read at 1.17.1, not driven: searched 'natural language|describe|generate cron|text to cron' in web/i18n/en-US/workflow.json and api/services/trigger: the schedule node takes a visual picker or a cron string only (web/i18n/en-US/workflow.json nodes.triggerSchedule.*) Note: the workflow generator does not know the schedule node either: searched 'trigger-schedule|trigger_schedule|cron' in api/core/workflow/generator/, no hits
  • sc-timezone unknown → yes: source read at 1.17.1, not driven: api/core/workflow/nodes/trigger_schedule/entities.py:19 timezone per schedule; api/libs/schedule_utils.py:41-50 croniter evaluated in the pytz zone and converted to UTC, so fires follow local wall time across DST; web/i18n/en-US/workflow.json nodes.triggerSchedule.invalidTimezone
  • sc-run-now unknown → partial: source read at 1.17.1, not driven: api/core/trigger/debug/event_selectors.py:140-200 a schedule test run waits for the next computed slot, it does not fire at once; the same workflow can be run now only through a second User Input start node ('Choose the start node to run', web/i18n/en-US/workflow.json common.chooseStartNodeToRun) or the workflow run API Note: no 'run now' on the schedule itself
  • sc-pause unknown → yes: source read at 1.17.1, not driven: api/controllers/console/app/workflow_trigger.py:167,197 POST /apps//trigger-enable sets AppTriggerStatus ENABLED/DISABLED; api/schedule/workflow_schedule_task.py:55-78 the poller only picks ENABLED triggers
  • sc-webhook unknown → yes: source read at 1.17.1, not driven: api/controllers/trigger/webhook.py:59 /triggers/webhook/<webhook_id> any method starts the workflow; web/i18n/en-US/workflow.json blocks.trigger-webhook 'receives HTTP pushes from third-party systems'; configurable params, headers and response (nodes.triggerWebhook.*); the agent runs as a node in that workflow
  • sc-webhook-secret unknown → partial: source read at 1.17.1, not driven: api/services/trigger/webhook_service.py:966,994-1001 the random webhook_id in the URL is the only secret, generated once at node sync; no regenerate endpoint (api/controllers/console/app/workflow_trigger.py:94 is GET only); revoke by disabling the trigger (:167) or deleting the node. No HMAC/signature check Note: revoke yes, rotate no
  • sc-event unknown → partial: source read at 1.17.1, not driven: api/controllers/trigger/trigger.py:17 /triggers/plugin/<endpoint_id> receives events from trigger plugins with subscriptions (api/controllers/console/workspace/trigger_providers.py:191); the event sources (GitHub, Slack, etc.) come from marketplace trigger plugins. No internal event bus for Dify's own events, no Nextcloud source Note: marketplace plugin only
  • sc-manual-event-choice unknown → yes: source read at 1.17.1, not driven: a workflow chooses its start node(s): User Input, Schedule Trigger, Webhook Trigger or a plugin trigger (web/i18n/en-US/workflow.json blocks.trigger-schedule, blocks.trigger-webhook, onboarding.triggerDescription; common.chooseStartNodeToRun); api/controllers/console/app/workflow_trigger.py:128 lists an app's triggers Note: chosen per workflow app that wraps the agent
  • sc-retry yes → partial: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json nodes.common.retry.* per-node retry on failure with max retries and a fixed retry interval in ms (api/core/workflow/generator/prompts/builder_prompts.py:111 retry_config); fail branch / default value error handling (nodes.common.errorHandle.*). Searched 'backoff|exponential' in api/core/workflow: no growing waits, no whole-run retry Note: fixed interval, node level only
  • sc-dead-letter unknown → partial: source read at 1.17.1, not driven: api/controllers/console/app/workflow_app_log.py:27,121,150 run logs filter by status (failed) and web/app/components/app/workflow-log/filter.tsx; searched 'dead letter|dead_letter|quarantine|parked' in api/: no list that parks repeatedly failing runs Note: a failed-status filter per app, not a dead-letter list
  • sc-overlap unknown → no: source read at 1.17.1, not driven: api/schedule/workflow_schedule_task.py:94-114 _process_schedules advances next_run_at and dispatches every due schedule without checking for a running execution; searched 'overlap|already running|skip_if_running|concurrency' in api/schedule and api/services/trigger: nothing
  • sc-list unknown → partial: source read at 1.17.1, not driven: api/controllers/console/app/workflow_trigger.py:45-65,128 GET /apps//triggers lists one app's triggers with status, no next run or last result; next 5 run times only in the node panel (web/i18n/en-US/workflow.json nodes.triggerSchedule.nextExecutionTimes). No workspace-wide schedule list Note: per app, no next run or last result in the list
  • tl-files unknown → partial: source read at 1.17.1, not driven: core has no file-store tool (searched 'nextcloud|webdav' in api/, web/app, web/i18n: no hits; builtin tools are audio, code, time, webscraper in api/core/tools/builtin_tool/providers/). Official marketplace plugin langgenius/dify-official-plugins tools/nextcloud/tools/ has list_files, search_files, upload_file, download_file, create_folder, delete_file: no move Note: marketplace plugin only (official 'nextcloud' plugin, read on main not at a tag), and it cannot move files
  • tl-calendar unknown → partial: source read at 1.17.1, not driven: no calendar tool in core (api/core/tools/builtin_tool/providers/ has audio, code, time, webscraper). Marketplace: official langgenius/dify-official-plugins tools/google_calendar/tools/{list_events,create_event}.yaml, feishu/lark calendars, and a community CalDAV plugin langgenius/dify-plugins shaba/caldav that could point at a Nextcloud calendar Note: marketplace plugin only
  • tl-contacts unknown → partial: source read at 1.17.1, not driven: no contacts tool in core (api/core/tools/builtin_tool/providers/). Marketplace: official tools/google_contacts/tools/{search_contacts,get_contact}.yaml; community langgenius/dify-plugins shaba/carddav Note: marketplace plugin only
  • tl-deck unknown → partial: source read at 1.17.1, not driven: searched 'nextcloud|deck' in api/ and web/i18n: nothing in core. Marketplace kanban tools only for other products: official tools/trello/tools/{create_new_card_on_board,update_card}.yaml, monday, linear, jira Note: cards on Trello-like boards via plugins, not Nextcloud Deck
  • tl-mail unknown → partial: source read at 1.17.1, not driven: core email is only the Human Input node's delivery method (web/i18n/en-US/workflow.json nodes.humanInput.deliveryMethod.emailConfigure.*, api/services/feature_service.py:81 on for self-hosted). A generic send-email tool comes from the official tools/email/tools/send_mail.yaml plugin or gmail/outlook plugins Note: agent-callable email is marketplace plugin only
  • tl-talk unknown → partial: source read at 1.17.1, not driven: searched 'nextcloud|talk|spreed' in api/ and web/i18n: nothing in core. Marketplace chat tools for other products: official tools/slack/tools/send_message.yaml, tools/teams/tools/send_channel_message.yaml, discord, dingtalk, wecom Note: posts to Slack/Teams via plugins, not Nextcloud Talk
  • tl-tasks unknown → partial: source read at 1.17.1, not driven: no task tool in core (api/core/tools/builtin_tool/providers/). Marketplace: official tools/google_tasks/tools/{create_task,update_task}.yaml, microsoft_todo, todoist, feishu_task Note: marketplace plugin only
  • tl-unified-search unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|unified search|unified_search' in api/ and web/: nothing. The official marketplace nextcloud plugin (langgenius/dify-official-plugins tools/nextcloud/tools/search_files.yaml) searches files only, not everything Nextcloud search reaches
  • tl-web-search unknown → partial: source read at 1.17.1, not driven: core ships only a page reader (api/core/tools/builtin_tool/providers/webscraper); web search engines are marketplace plugins (official tools/duckduckgo, tavily, searxng, google, bing, brave, perplexity in langgenius/dify-official-plugins); web/i18n/en-US/agent-v-2.json tools.addMenu.tool 'like web search or integrations' Note: reading pages is core, searching needs a plugin
  • tl-register unknown → no: source read at 1.17.1, not driven: searched 'openregister' in api/ and web/app: no hits; no OpenRegister connector in core or in the official plugin list (langgenius/dify-official-plugins tools/). Only reachable by a hand-built custom OpenAPI tool or HTTP node
  • tl-mcp-client unknown → yes: source read at 1.17.1, not driven: api/controllers/console/workspace/tool_providers.py:1373 add an MCP server as a tool provider, :1501 MCP OAuth, :1577 list its tools; api/core/mcp/types.py:26 client negotiates protocol 2025-06-18; web/i18n/en-US/agent-v-2.json tools.toolTabs.mcp so agents pick MCP tools
  • tl-grants unknown → partial: source read at 1.17.1, not driven: tools are picked per agent (web/i18n/en-US/agent-v-2.json agentDetail.configure.tools.*; classic agent apps list tools in model config). But every Agent v2 run also gets a shell tool (dify-agent/src/dify_agent/layers/shell/layer.py:259,303 run) and 'Tools the agent installs in its sandbox won't appear here but stay available to it' (agent-v-2.json tools.tip) Note: explicit list for classic agents; Agent v2 always has a shell, so not 'nothing else'
  • tl-request-access unknown → no: source read at 1.17.1, not driven: searched 'request access|requestAccess|ask.*owner|tool request' in web/i18n/en-US and dify-agent/src: only static 'contact your Workspace Owner' tour text (web/i18n/en-US/common.json:624); no flow where an agent asks for a missing tool
  • tl-git unknown → yes: source read at 1.17.1, not driven: dify-agent-runtime/docker/Dockerfile:31-37 installs git and openssh-client in the agent sandbox; dify-agent/src/dify_agent/layers/shell/layer.py:303 the agent runs shell scripts there, secrets via the env editor (agent-v-2.json advancedSettings.envEditor); official github/gitlab plugins add PR and commit tools Note: through the generic shell, no dedicated git UI
  • tl-custom-tool partial → yes: source read at 1.17.1, not driven: api/controllers/console/workspace/tool_providers.py:685 add a custom tool from an OpenAPI schema (web/i18n/en-US/tools.json createTool.schema), :904 publish a workflow as a tool, :1373 add an MCP server; agent-v-2.json tools.cliDialog installs a CLI tool into the agent sandbox
  • tl-invocations-export unknown → partial: source read at 1.17.1, not driven: api/commands/retention.py:1591 export-app-messages CLI writes query, answer, inputs, sources and feedback (api/services/retention/conversation/message_export_service.py:53-62), no tool calls; api/controllers/console/workflow_run_archive.py:93-130 run-archive download is Cloud paid-plan only; tool spans reach Langfuse and other tracers (api/core/ops) Note: no community export of the tool-call list; old partial rested on the message export, which leaves tool calls out
  • tl-integrations-page unknown → partial: source read at 1.17.1, not driven: web/app/(commonLayout)/integrations/[[...slug]]/page.tsx and web/app/components/integrations/routes.ts:2-11 one page for model providers, builtin tools, MCP, custom tools, workflow tools, data sources, endpoints, triggers, agent strategies, extensions, each showing Authorized/Unauthorized (web/i18n/en-US/tools.json auth.authorized, auth.unauthorized) Note: shows whether a connection is authorised, not a live health check
  • me-long-term unknown → partial: source read at 1.17.1, not driven: api/models/agent.py:126-131 Agent v2 working directories are owned per conversation, workflow run or build draft, so end-user runs do not carry facts into the next conversation; only builder-applied persistent files and the build note (agent-v-2.json workingDirectory.persistentFilesTooltip) carry over. Learned memory comes from marketplace plugins (official bailian_memory; community mem0, zep in langgenius/dify-plugins) Note: marketplace plugin for learned memory; plugins not read
  • me-user-profile unknown → partial: source read at 1.17.1, not driven: searched 'user profile|user_memory|remember' in dify-agent/src and api/core/memory (token_buffer_memory.py only): no per-person memory in core; conversation variables are per conversation (api/controllers/console/app/conversation_variables.py:88). Per-user memory only via marketplace memory plugins (community mem0, zep) Note: marketplace plugin only, plugin behaviour not read
  • me-view-edit unknown → partial: source read at 1.17.1, not driven: builders see and edit the agent's persistent files and generated build note (web/i18n/en-US/agent-v-2.json agentDetail.configure.files., files.buildNote, workingDirectory.) and conversation variables per conversation (api/controllers/console/app/conversation_variables.py:88); there is no learned-memory store to inspect Note: the agent's files are editable, but there is no memory of learned facts to review
  • me-consolidate unknown → no: source read at 1.17.1, not driven: searched 'consolidat|dedupe memory|stale|forget' in dify-agent/src and api/core: dify-agent/src/dify_agent/runtime/compaction.py only compacts the current run's context; nothing merges or prunes stored memory
  • me-context unknown → partial: source read at 1.17.1, not driven: an agent's Files are kept in its persistent working directory and available in every run (web/i18n/en-US/agent-v-2.json agentDetail.configure.files.*, workingDirectory.persistentFilesTooltip; api/models/agent.py:218 AgentHomeSnapshot); knowledge retrievals attach per agent. No named bundle of files and records that can be reused across agents Note: per-agent files, not a named reusable context bundle
  • me-compression unknown → yes: source read at 1.17.1, not driven: dify-agent/src/dify_agent/runtime/compaction.py:16-44 TieredCompaction clears old tool results then SummarizingCompaction keeps the last 20 messages and summarises older ones, wired in dify-agent/src/dify_agent/runtime/runner.py:365,402 Note: Agent v2 only; classic apps use a token window (api/core/memory/token_buffer_memory.py) without summarising
  • me-knowledge-graph unknown → no: source read at 1.17.1, not driven: searched 'knowledge.?graph|graph_rag|graphrag' in api/core/rag and web/i18n/en-US: no hits; retrieval is vector, full-text, hybrid and parent-child chunks (api/core/rag/retrieval). A neo4j query tool exists only as an official marketplace plugin (tools/neo4j)
  • me-object-grounding unknown → no: source read at 1.17.1, not driven: searched 'record|object context|linked records' in api/core/app and dify-agent/src: an answer is grounded only in knowledge retrieval and inputs the caller passes (web/public/embed.js:93 inputs); nothing resolves the record on screen or follows its links
  • me-external-kb unknown → yes: source read at 1.17.1, not driven: api/controllers/console/datasets/external.py:153,339 connect an external knowledge API as a dataset; api/controllers/console/datasets/data_source.py:228,417 Notion import and sync in core; website crawl datasets/website.py:32; SharePoint and Confluence via official datasource plugins (langgenius/dify-official-plugins datasources/sharepoint_datasource, confluence_datasource) Note: SharePoint itself is a marketplace plugin; Notion wiki and the external-KB API are core
  • sk-catalog unknown → yes: source read at 1.17.1, not driven: web/app/(commonLayout)/skills/page.tsx workspace Skills library; api/controllers/console/workspace/skills.py:296 list with search by name or description and tags (web/i18n/en-US/skill.json skillManagement.searchPlaceholder, tags); agents add from it (agent-v-2.json skills.addMenu.workspace 'Add from library') Note: a workspace library, not a public catalogue
  • sk-install unknown → yes: source read at 1.17.1, not driven: api/controllers/console/workspace/skills.py:811 /workspaces/current/agents/<agent_id>/skills binds library skills to an agent; web/i18n/en-US/agent-v-2.json skills.addMenu.workspace 'Add from library' and skills.addMenu.upload 'Upload skill.zip' (embedded), limit of 20 library skills per agent (skills.workspaceSelector.limitReached)
  • sk-format unknown → yes: source read at 1.17.1, not driven: web/i18n/en-US/skill.json emptyAction.importDescription 'Bring a .zip with SKILL.md, in the agentskills.io format', errors.missingSkillMd; api/controllers/console/workspace/skills.py:385 import and :494 export of the package; agent-v-2.json skills.upload.warning.specification 'must follow the Agent Skills specification'
  • sk-self-improve unknown → partial: source read at 1.17.1, not driven: in Build mode the agent edits its own skills and files from the build conversation and holds them as a build draft to Apply (agent-v-2.json skills.tip 'In Build mode, the agent can set these up for you'; api/controllers/console/agent/roster.py:876,941); the Skill Builder rewrites a skill on request (api/controllers/console/workspace/skills.py:516 assist/messages). Nothing proposes improvements from production runs Note: improves from the builder's build chat, not from what it learned in runs
  • sk-draft-review unknown → partial: source read at 1.17.1, not driven: web/features/agent-v2/agent-detail/configure/components/orchestrate/build-draft-changes-panel.tsx lists changed sections as Updated/Rewritten with Apply or Discard (build-draft-bar.tsx; roster.py:932 DELETE build-draft, :941 apply); skill drafts publish or restore (skills.py:678,703). Searched 'diff|compare' in web/i18n/en-US/skill.json and agent-v-2.json: no side-by-side difference Note: accept or reject yes, a visible diff no
  • sk-auto-create unknown → partial: source read at 1.17.1, not driven: agent-v-2.json skills.tip 'In Build mode, the agent can set these up for you': the agent writes skills while the builder chats in Build mode (roster.py:846 build-draft/checkout); searched 'auto.?create|learn|after solving' in dify-agent/src: no path where an agent writes a skill on its own after a production run Note: only inside a builder-driven Build session
  • sk-curator unknown → no: source read at 1.17.1, not driven: searched 'curator|merge skill|duplicate skill|archive unused|stale' in api/services/skill_management_service.py, api/schedule and web/i18n/en-US/skill.json: only manual duplicate and delete (api/controllers/console/workspace/skills.py:474, skill.json deleteDialog); no scheduled merge or archive
  • sk-maturity unknown → no: source read at 1.17.1, not driven: searched 'maturity|proven|rating|success rate|eval' in web/i18n/en-US/skill.json and api/services/skill_management_service.py: a skill shows only draft/published state, version number and 'Used by N agents' (skill.json detail.referencedBy_one, referenceCount); no maturity or proof signal Note: usage count is the only trust hint
  • sk-versions unknown → partial: source read at 1.17.1, not driven: api/controllers/console/workspace/skills.py:743,758 versions list and detail, :703 restore a version to draft; web/i18n/en-US/skill.json detail.versions, versionPublishNote, restoreVersion. Searched 'compare|diff' in skill.json: no comparison of two versions Note: history and rollback yes, compare no
  • sk-github unknown → no: source read at 1.17.1, not driven: api/controllers/console/workspace/skills.py:385-409 import takes only an uploaded zip (request.files['file']); searched 'github|repository|publish to' in api/services/skill_management_service.py and skill.json: no GitHub discovery, install or publish
  • sk-learnings unknown → no: source read at 1.17.1, not driven: searched 'lesson|learning|rule' in dify-agent/src, api/services/skill_management_service.py and web/i18n/en-US/skill.json: no mechanism that turns repeated run lessons into skill rules; the build note (agent-v-2.json files.buildNote) records build-session setup only
  • sk-export unknown → yes: source read at 1.17.1, not driven: api/controllers/console/workspace/skills.py:494 /workspaces/current/skills/<skill_id>/export returns the skill package; single files downloadable (web/i18n/en-US/skill.json detail.downloadFile)
  • sk-install-source unknown → no: source read at 1.17.1, not driven: api/controllers/console/workspace/skills.py:385-409 the only import path is a multipart zip upload; searched 'url|source address|remote' in the skill import payload and skill.json: no install from an outside address
  • sk-evals unknown → no: source read at 1.17.1, not driven: searched 'evaluation|eval_set|test case' in api/controllers and web/i18n/en-US: only tracing-provider blurbs (web/i18n/en-US/app.json:220-258 Langfuse, Arize, Phoenix 'evaluation') and dataset hit testing; no run of a skill against cases with and without it
  • mo-providers yes → partial: source read at 1.17.1, not driven: api/controllers/console/workspace/model_providers.py:148,200 provider list and credentials; web/i18n/en-US/common.json:378-379 'Please install a model provider first ... from the Marketplace': core ships no provider, OpenAI, Anthropic, Mistral etc. are official plugins (langgenius/dify-official-plugins models/openai, anthropic, mistralai, ...) Note: every provider is a marketplace plugin run by the plugin daemon; old yes rested on a feature line
  • mo-local yes → partial: source read at 1.17.1, not driven: no local runtime in core (web/i18n/en-US/common.json:378 install a provider first); official plugins models/ollama, localai, xinference, openllm, triton_inference_server, huggingface_tei in langgenius/dify-official-plugins Note: marketplace plugin only
  • mo-openai-compat unknown → partial: source read at 1.17.1, not driven: official plugin langgenius/dify-official-plugins models/openai_api_compatible adds any OpenAI-compatible endpoint; core only provides the provider framework (api/controllers/console/workspace/model_providers.py:148) Note: marketplace plugin only
  • mo-nc-assistant unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|task processing|taskprocessing' in api/ and web/: no hits; models come only from Dify provider plugins
  • mo-provide-text2text unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|task processing|text2text provider' in api/ and web/: nothing registers Dify apps as a provider for another platform's AI task framework; apps are reachable only through Dify's own service API (api/controllers/service_api/app/completion.py) and MCP (api/controllers/mcp/mcp.py:44)
  • mo-tenant-policy unknown → yes: source read at 1.17.1, not driven: providers and credentials are per workspace (api/controllers/console/workspace/model_providers.py:148,200); api/controllers/console/workspace/models.py:519-545 enable/disable individual models for the workspace so its apps cannot pick them Note: per workspace; per-role model rights (permission-keys.json plugin.model_config) need enterprise RBAC
  • mo-per-feature unknown → yes: source read at 1.17.1, not driven: api/controllers/console/workspace/models.py:205 default-model per model type (system reasoning, embedding, rerank, speech2text, tts) and :633 models by type; every app, node, knowledge base and generator picks its own model, so summaries and triage can run on different providers
  • mo-failover unknown → partial: source read at 1.17.1, not driven: api/core/model_manager.py:440-477,1003-1066 load balancing rotates credentials of the same model and cools down one on rate-limit or connection errors; off by default (api/configs/feature/init.py:813 MODEL_LB_ENABLED=False). A second provider only by wiring a fail branch to another LLM node (web/i18n/en-US/workflow.json nodes.common.errorHandle.failBranch) Note: same-model credential failover, not provider fallback
  • mo-sensitivity-routing unknown → no: source read at 1.17.1, not driven: searched 'sensitiv|classification|pii|route.*model' in api/core/model_manager.py, api/core/moderation and dify-agent/src: no routing of data by sensitivity; only content moderation (api/core/moderation) that blocks or replaces text
  • mo-cli-runner unknown → no: source read at 1.17.1, not driven: searched 'claude code|claude cli|anthropic cli' in api/, dify-agent/src and dify-agent-runtime: model turns go through provider plugins (dify-agent/src/dify_agent/layers/dify_plugin/llm_layer.py); no runner that drives the claude command line tool
  • mo-key-broker partial → yes: source read at 1.17.1, not driven: model keys live once per workspace provider, encrypted, with named credentials and switching (api/controllers/console/workspace/model_providers.py:200,291; models.py:342,495); agents and apps reference the provider, never hold the key; api/models/credential_permission.py:1-35 limits which members may use a credential Note: per-member credential access needs enterprise RBAC (permission-keys.json credential.use)
  • mo-personal-key unknown → no: source read at 1.17.1, not driven: searched 'personal credential|per.?user credential|end.?user.*credential' in api/core/tools, api/services/tools and web/i18n/en-US: credentials are workspace-level (api/controllers/console/workspace/model_providers.py:200) and runs use the app's configured credential; api/models/credential_permission.py only restricts who may use a shared credential
  • dl-talk unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|talk|spreed' in api/ and web/: no hits; no official plugin for Nextcloud Talk in langgenius/dify-official-plugins tools/ (only slack, teams, discord, dingtalk, wecom, telegraph)
  • dl-talk-bridge unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|talk|spreed' in api/ and web/: no hits; chat-app bridges exist only as plugin endpoints for other messengers (api/controllers/console/workspace/endpoint.py), none for Nextcloud Talk
  • dl-talk-grouping unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|talk|spreed|room' in api/ and web/: no Talk integration, so no agent-room grouping
  • dl-webhook-out unknown → partial: source read at 1.17.1, not driven: a workflow HTTP Request node posts an agent's output to any URL with API-Key, Basic, Bearer or custom header auth (web/i18n/en-US/workflow.json:510-518 nodes.http.authorization.*); searched 'hmac|signature|sign' in workflow.json and the http node: no payload signing Note: outbound webhook yes, signed no
  • dl-notification unknown → partial: source read at 1.17.1, not driven: when a run needs a person, the Human Input node emails workspace members or externals (api/tasks/mail_human_input_delivery_task.py; workflow.json humanInput.deliveryMethod.emailConfigure.allMembers); api/controllers/console/notification.py:43 is only product announcements. Searched 'run finished|run completed|notify' in api/tasks and web/i18n/en-US: no notice when a run finishes Note: email when input is needed, nothing on completion, no in-app notification
  • dl-target-pref unknown → no: source read at 1.17.1, not driven: searched 'delivery target|default delivery|preferred channel' in api/ and web/i18n/en-US: delivery is wired per workflow node (HTTP, tool plugins, Human Input delivery methods); no per-person default delivery setting
  • dl-messengers unknown → partial: source read at 1.17.1, not driven: api/controllers/console/workspace/endpoint.py plugin endpoints host chat bots; official extensions slack_bot and wecom_bot, triggers slack_trigger and telegram_trigger (langgenius/dify-official-plugins extensions/, triggers/), community microsoft-teams (langgenius/dify-plugins); nothing for Signal found Note: marketplace plugin only
  • dl-digest unknown → partial: source read at 1.17.1, not driven: a Schedule Trigger workflow (api/core/workflow/nodes/trigger_schedule/entities.py:10) can end in a chat-posting tool node, but the posting tools are marketplace plugins (official tools/slack/tools/send_message.yaml, teams send_channel_message.yaml) Note: schedule is core, the chat delivery is a plugin
  • dl-dedupe unknown → no: source read at 1.17.1, not driven: searched 'dedup|collapse|identical|duplicate report' in api/core/workflow, api/services and web/i18n/en-US: no collapsing of repeated outputs into one with a count
  • dl-dashboard-widget unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|dashboard widget' in api/ and web/: no widget that shows agent output on another product's dashboard; the app Overview/Monitoring pages (web/i18n/en-US/app-overview.json, agent-v-2.json monitoring.*) show usage metrics, not output
  • dl-transcribe unknown → yes: source read at 1.17.1, not driven: api/core/tools/builtin_tool/providers/audio/tools/asr.py speech-to-text tool usable in workflows and agents; api/controllers/web/audio.py:62 audio-to-text for voice messages in chat Note: needs a speech2text model from a provider plugin
  • dl-embed-web unknown → yes: source read at 1.17.1, not driven: web/public/embed.js floating chat bubble script and iframe embed chosen in web/i18n/en-US/app-overview.json:50-52 'Choose the way to embed chat app to your website', with pre-filled hidden inputs; agents have 'Embed Into Site' on their Access page (agent-v-2.json access.webApp.actions.embedIntoSite)
  • ov-approval-inbox unknown → no: source read at 1.17.1, not driven: human input forms are reached one by one by token link (api/controllers/web/human_input_form.py:141, console/human_input_form.py:70 /form/human_input/<form_token>); searched 'inbox|pending forms|awaiting' in web/i18n/en-US and api/controllers: no list of everything awaiting me
  • ov-approval-context unknown → partial: source read at 1.17.1, not driven: the Human Input form shows builder-written Form Content with inserted run variables (web/i18n/en-US/workflow.json:609-612 nodes.humanInput.formContent.*), and in Agent v2 the agent writes the question and fields itself (dify-agent/src/dify_agent/layers/ask_human/schema.py AskHumanToolArgs); nothing derives what the action touches automatically Note: context is what the builder or the model chooses to show
  • ov-risk-threshold unknown → partial: source read at 1.17.1, not driven: no risk scoring; a builder can route only some cases to a Human Input node with an IF/ELSE or classifier node, and the Agent v2 ask_human tool is called at the model's discretion (dify-agent/src/dify_agent/layers/ask_human/layer.py:56-78 prompt hint). Searched 'risk|threshold' in dify-agent/src and api/core/workflow: none Note: hand-built branching, no risk threshold setting
  • ov-talk-reaction unknown → no: source read at 1.17.1, not driven: searched 'nextcloud|talk|reaction' in api/ and web/: no Talk integration; approvals are answered only through the form link (api/controllers/web/human_input_form.py:141)

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 5 of 8

dify (continued)

  • ov-draft-hold partial → yes: source read at 1.17.1, not driven: a workflow can put a Human Input node between the LLM/Agent node and the reply so a person reviews, edits input fields and picks an action before the answer is sent (web/i18n/en-US/workflow.json nodes.humanInput.formContent.*, user actions; api/tasks/mail_human_input_delivery_task.py email delivery to staff) Note: built per workflow; chat apps with webapp delivery show the form to the end user instead
  • ov-kill-switch unknown → no: source read at 1.17.1, not driven: searched 'kill switch|disable all|pause all|emergency stop' in api/controllers/console and web/i18n/en-US: no workspace-wide stop; each app's web app and API are toggled separately (api/controllers/console/agent/roster.py:1013)
  • ov-kill-agent unknown → partial: source read at 1.17.1, not driven: api/controllers/console/app/completion.py:327 /agent//chat-messages/<task_id>/stop and workflow.py:1188 stop one running task; roster.py:1013 and web-app-access-card.tsx:254 switch the agent's surfaces off. No single control that stops all of one agent's running work at once Note: stop per run plus switch off per surface
  • ov-guardrail-input unknown → partial: source read at 1.17.1, not driven: api/core/moderation/input_moderation.py with keywords, openai_moderation and api providers (api/core/moderation/{keywords,openai_moderation,api}); api/core/moderation/base.py:10-20 DIRECT_OUTPUT blocks with a preset reply, OVERRIDDEN lets a custom API extension return rewritten inputs. No built-in PII or secret detector Note: blocking is built in; redaction only through a self-built API extension
  • ov-guardrail-output unknown → yes: source read at 1.17.1, not driven: api/core/moderation/output_moderation.py moderates the streamed answer; web/i18n/en-US/app-debug.json:93-104 feature.moderation 'Moderate OUTPUT Content' with preset replies, keyword list, OpenAI moderation or API
  • ov-tool-risk unknown → no: source read at 1.17.1, not driven: searched 'risk|dangerous|destructive|sensitive tool' in api/core/tools, dify-agent/src and web/i18n/en-US/tools.json: tools carry no risk class and no extra checks per class
  • ov-egress unknown → partial: source read at 1.17.1, not driven: docker/ssrf_proxy/squid-agent.conf.template routes the agent sandbox through Squid, denying private networks but 'External internet is allowed' (http_access allow all); docker/ssrf_proxy/squid.conf.template does the same for HTTP nodes and tools. No per-agent allowlist of web addresses in the UI Note: blocks internal addresses, not a public-web allowlist; an admin can hand-edit the Squid config
  • ov-anonymise unknown → no: source read at 1.17.1, not driven: searched 'anonymi|presidio|redact|pii' in api/core and web/i18n/en-US: only redaction of the agent backend request in logs (api/core/app/apps/agent_app/runtime_request_builder.py:34); no document anonymisation before the model reads it, and none in the official tool list (langgenius/dify-official-plugins tools/)
  • ov-automation-bias unknown → no: source read at 1.17.1, not driven: searched 'automation bias|rubber.?stamp|approval rate|approve all' in api/ and web/i18n/en-US: no tracking of how reviewers answer Human Input forms
  • ov-tool-oversight unknown → partial: source read at 1.17.1, not driven: tool calls are visible per message and per run in the logs (web/app/components/base/chat/chat/answer/agent-content.tsx:31-38, workflow run detail via api/controllers/console/app/workflow_run.py) and a reviewer can mark answers with admin feedback or annotations (api/controllers/console/app/annotation.py); searched 'misuse|flag tool' in api/: no tool-level flagging Note: review yes, flagging misuse per tool no
  • co-audit-log unknown → partial: source read at 1.17.1, not driven: every run, node execution and agent thought is stored (api/models/workflow.py node executions, message agent thoughts) but rows are deletable by retention jobs (api/services/retention/conversation/messages_clean_service.py:566); audit events are emitted as log lines for the Enterprise OTel exporter only (api/controllers/openapi/_audit.py:1-6; api/enterprise/telemetry/README.md 'only available in ENTERPRISE') Note: records exist, not tamper-proof; audit stream is enterprise-licensed
  • co-retention unknown → yes: source read at 1.17.1, not driven: api/configs/feature/init.py:1425 ENABLE_CLEAN_MESSAGES and :1623-1624 WORKFLOW_LOG_CLEANUP_ENABLED / WORKFLOW_LOG_RETENTION_DAYS; api/schedule/clean_messages.py:17-23 'Self-hosted editions delete all messages within the configured time range'; api/schedule/clean_workflow_runlogs_precise.py Note: instance-wide environment settings, off by default, no per-workspace or per-agent setting in the UI
  • co-ai-register unknown → no: source read at 1.17.1, not driven: searched 'register|risk class|ai act|inventory' in api/models, api/services and web/i18n/en-US: no register of AI features with a risk class
  • co-risk-class unknown → no: source read at 1.17.1, not driven: searched 'risk|ai act|high.?risk|classification' in api/models/agent.py, api/models/model.py and web/i18n/en-US: agents and apps carry no risk level field
  • co-dpo-ack unknown → no: source read at 1.17.1, not driven: searched 'dpo|data protection officer|sign.?off|go.?live approval' in api/ and web/i18n/en-US: publishing an agent needs only edit/publish permission (api/controllers/console/agent/roster.py:815), no sign-off step
  • co-control-packs unknown → no: source read at 1.17.1, not driven: searched 'iso 42001|42001|control framework|ai act' in api/ and web/i18n/en-US: nothing checks the organisation against a framework; web/i18n/en-US/common.json:124-125 only lists Dify's own vendor certificates (GDPR DPA, ISO 27001)
  • co-factsheet unknown → no: source read at 1.17.1, not driven: searched 'fact ?sheet|model card|system card' in api/ and web/i18n/en-US: no generated fact sheet of an agent's model, data and purpose; the closest is DSL export of its configuration (web/features/agent-v2/agent-detail/sidebar-actions.tsx:52)
  • co-compliance-export unknown → no: source read at 1.17.1, not driven: api/controllers/console/billing/compliance.py:28-49 and api/services/compliance_download_service.py only hand out Dify's own vendor documents (GDPR DPA, ISO 27001, web/i18n/en-US/common.json:124-127) to paid Cloud plans; no compliance report about the organisation's own agents Note: the 'compliance' download is the vendor's certificate, not the customer's report
  • co-incident unknown → no: source read at 1.17.1, not driven: searched 'incident|impact|postmortem' in api/models, api/services and web/i18n/en-US: no AI incident record
  • co-authority-notify unknown → no: source read at 1.17.1, not driven: searched 'authority|regulator|serious incident|notify' in api/services and web/i18n/en-US: no incident record and no authority notification
  • co-access-review unknown → no: source read at 1.17.1, not driven: searched 'access review|attest|recertif|periodic review' in api/ and web/i18n/en-US: no periodic owner or need review of agents
  • co-transparency unknown → partial: source read at 1.17.1, not driven: api/controllers/console/app/site.py:49-57 each web app can show a description, privacy policy link and custom disclaimer to its users; no generated plain-language register or explanation of the agents employees deal with Note: per-app description and disclaimer only
  • co-residency unknown → no: source read at 1.17.1, not driven: searched 'residency|region|data location|processing location' in api/ and web/i18n/en-US: providers show no processing location per feature
  • co-disable-dept unknown → no: source read at 1.17.1, not driven: searched 'department|group.*disable|ai off' in api/ and web/i18n/en-US: community has no departments; enterprise RBAC per-agent access policies (web/features/agent-v2/permissions.ts:37, api/configs/enterprise/init.py:38) grant access but there is no switch that turns AI off for a group with proof
  • ob-trace partial → yes: source read at 1.17.1, not driven: workflow run detail with a TRACING tab listing each node in order with inputs, outputs, status, time and tokens (web/i18n/en-US/run-log.json tracing, meta.*; web/app/components/workflow/run/node.tsx:89); chat messages show each agent thought and tool call (web/app/components/base/chat/chat/answer/agent-content.tsx:31-38); agent logs per conversation (api/controllers/console/agent/roster.py:1172)
  • ob-replay unknown → partial: source read at 1.17.1, not driven: in the draft canvas a node can be re-run with its Last Run values from the variable inspector (web/i18n/en-US/workflow.json:272 debug.lastRunTab; api/controllers/console/app/workflow_draft_variable.py); searched 'replay|rerun|run again' in web/i18n/en-US and api/controllers/console/app: no replay of a logged production run (only a Re-run in RAG pipelines, pipeline.json:12) Note: node re-run in the editor, not replay of a past run
  • ob-dry-run unknown → no: source read at 1.17.1, not driven: searched 'dry.?run|mock|simulat' in web/i18n/en-US/workflow.json, agent-v-2.json and api/core/workflow: draft debug runs and Agent v2 Build mode execute tools and the sandbox for real (agent-v-2.json build.empty.communityEditionTip 'changes made to the file system happen in real time'); only webhook triggers can be simulated (workflow.json:291) Note: test runs are separate from the published version but still act
  • ob-cost-per-run unknown → partial: source read at 1.17.1, not driven: web/app/components/workflow/run/meta.tsx:91-97 total tokens per run and web/app/components/workflow/run/node.tsx:89 tokens per node; money cost appears only in aggregate token-cost charts (api/controllers/console/app/statistic.py:232, web/app/components/app/overview/app-chart.tsx) Note: tokens per run and step, cost only in totals
  • ob-budget unknown → no: source read at 1.17.1, not driven: searched 'budget|spend limit|spending|hard stop' in web/i18n/en-US and api/services: none for self-hosted; hosted-credit quotas (api/services/credit_pool_service.py, quota_service.py) apply to Dify Cloud's own trial credits, not a user-set budget with warning and stop
  • ob-estimate unknown → no: source read at 1.17.1, not driven: searched 'estimate|expected cost|cost preview' in api/controllers/console/app and web/i18n/en-US: the only estimate is document indexing cost for knowledge bases (api/controllers/console/datasets/datasets_document.py:706 indexing-estimate), none for an agent or workflow run
  • ob-fail-alert unknown → no: source read at 1.17.1, not driven: searched 'alert|on failure notify|failed run email' in api/tasks, api/schedule and web/i18n/en-US: failures show only in logs and the editor toast (web/i18n/en-US/workflow.json:242 common.scheduleTriggerRunFailed); api/schedule/queue_monitor_task.py alerts admins about Celery queue length, not run failures Note: alerting only by wiring an external tracer or OTel collector
  • ob-drift unknown → no: source read at 1.17.1, not driven: searched 'drift|regression|quality trend|anomal' in api/ and web/i18n/en-US: no drift detection; satisfaction rate chart (api/controllers/console/app/statistic.py:286) is the nearest signal
  • ob-metrics unknown → yes: source read at 1.17.1, not driven: api/extensions/ext_app_metrics.py:20,28,54 /health, /threads and /db-pool-stat endpoints; api/configs/observability/otel/otel_config.py:10-25 ENABLE_OTEL exports traces and metrics over OTLP to a monitoring system; api/celery_healthcheck.py for workers Note: OTel metrics off by default
  • ob-reports unknown → no: source read at 1.17.1, not driven: searched 'report|weekly|monthly digest|usage report' in api/schedule, api/tasks and web/i18n/en-US: no periodic usage report; usage is only on the live Overview/Monitoring charts (api/controllers/console/app/statistic.py)
  • ob-feedback-stats partial → yes: source read at 1.17.1, not driven: api/controllers/console/app/statistic.py:286 user-satisfaction-rate per app; agent Monitoring 'User Satisfaction Rate: Percentage of agent replies that users rated with a like' (web/i18n/en-US/agent-v-2.json monitoring.metrics.userSatisfactionRate); logs show user and operator rating per conversation (agent-v-2.json logs.table.userRate, operationRate)
  • fl-subagent unknown → partial: source read at 1.17.1, not driven: an agent can call a published workflow as a tool (web/i18n/en-US/agent-v-2.json tools.toolTabs.workflow; api/controllers/console/workspace/tool_providers.py:904) and that workflow can hold another Agent node; searched 'sub.?agent|handoff|delegat' in dify-agent/src: no direct agent-to-agent handoff Note: indirect, through workflow-as-tool
  • fl-branch unknown → yes: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json:13 blocks.if-else and :26 blocks.question-classifier branch a flow on conditions or on an LLM classification; fail branches on node errors (nodes.common.errorHandle.failBranch)
  • fl-run-history partial → yes: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json:240,245,254 common.runHistory / showRunHistory / viewRunHistory in the canvas editor, opening each run's tracing on the canvas; published-run logs per app (api/controllers/console/app/workflow_app_log.py:121)
  • fl-seed-flows partial → yes: source read at 1.17.1, not driven: api/constants/recommended_apps.json ships 22 templates (workflow, chatflow, agent-chat, e.g. 'Text Summarization Workflow', 'Email Assistant Workflow'); api/controllers/console/explore/recommended_app.py:96,126 serve them; web/app/(commonLayout)/templates/[[...category]] create from template Note: default source is remote tmpl.dify.ai (api/configs/feature/hosted_service/init.py:444), builtin as fallback mode
  • fl-n8n unknown → no: source read at 1.17.1, not driven: searched 'n8n' in api/, web/app and web/i18n: no hits, and none in langgenius/dify-official-plugins tools/ or langgenius/dify-plugins; only a hand-built HTTP Request node or custom OpenAPI tool could call an n8n webhook
  • fl-code-step partial → yes: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json:6 blocks.code, Python or JavaScript run in the dify-sandbox service (docker/docker-compose.yaml sandbox); nodes.code.syncFunctionSignature
  • fl-subflow unknown → yes: source read at 1.17.1, not driven: Snippets are reusable node groups inserted into workflows (api/controllers/console/snippets/snippet_workflow.py; web/i18n/en-US/snippet.json); a published workflow can be used as a tool in other apps (web/i18n/en-US/workflow.json:257-258 common.workflowAsTool)
  • fl-validate unknown → yes: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json:997-1000 panel.checklist 'Resolve the following issues before publishing', :207 needConnectTip for unconnected steps, per-node checks such as :361 nodes.agent.checkList.strategyNotSelected; agent composer validate endpoint api/controllers/console/agent/composer.py:167
  • re-store unknown → yes: source read at 1.17.1, not driven: web/app/(commonLayout)/explore and templates/[[...category]] browse ready-made apps including agents (api/constants/recommended_apps.json 'Investment Analysis Report Copilot', 'SVG Logo Design' in agent-chat mode); api/controllers/console/explore/recommended_app.py:96,126; one click creates a copy in the workspace Note: templates are Dify-curated, fetched from tmpl.dify.ai by default
  • re-template-from-agent unknown → partial: source read at 1.17.1, not driven: an agent can be duplicated (api/controllers/console/agent/roster.py:961 copy), exported as DSL (web/features/agent-v2/agent-detail/sidebar-actions.tsx:52), and an inline workflow agent saved to the shared roster (api/controllers/console/agent/composer.py:239 save-to-roster). Searched 'publish as template|insert-explore-apps' in api/controllers: no way to add it to the Explore template list Note: reuse by roster, copy and file; publishing a template for others goes through the Marketplace Creator Center, an outside service (web/i18n/en-US/plugin.json:230,305), not an in-product action
  • re-template-github unknown → partial: source read at 1.17.1, not driven: api/services/app_dsl_service.py:174 import accepts yaml_url (web/i18n/en-US/app.json:115-116 'From URL'), so a raw GitHub DSL link installs; searched 'github' in api/services/app_dsl_service.py and web/i18n/en-US/app.json: no discovery or publish to GitHub Note: install by URL only
  • re-template-approve unknown → no: source read at 1.17.1, not driven: searched 'approve template|template review|pending template' in api/ and web/i18n/en-US: no approval step for templates; Explore templates come from a remote or builtin catalogue (api/configs/feature/hosted_service/init.py:444)
  • re-agent-versions unknown → partial: source read at 1.17.1, not driven: api/controllers/console/agent/roster.py:1266,1282,1302 list versions, view one, restore it; api/models/agent.py:327,363 AgentConfigSnapshot and AgentConfigRevision; workflow version history with restore (web/i18n/en-US/workflow.json:1079-1081). Searched 'compare|diff' in agent-v-2.json and workflow.json: no version comparison (only the workflow generator's change summary, :1110) Note: versions and rollback yes, compare no; Community Edition does not version the agent's file system (agent-v-2.json build.empty.communityEditionTip)
  • re-evals unknown → no: source read at 1.17.1, not driven: searched 'evaluation|test case|expected answer|dataset eval' in api/controllers and web/i18n/en-US: no agent test sets; evaluation is delegated to external tracers (web/i18n/en-US/app.json:220-258) and dataset hit testing only checks retrieval (api/controllers/console/datasets/hit_testing.py)
  • re-baseline unknown → no: source read at 1.17.1, not driven: searched 'compare|baseline|a/b|prompt version' in web/i18n/en-US/app-debug.json, agent-v-2.json and workflow.json: classic apps can debug several models side by side on one prompt (web/app/components/app/configuration/debug/debug-with-multiple-model), but no run of a new prompt version against the old one before publishing Note: multi-model debug compares models, not prompt versions
  • re-community unknown → yes: source read at 1.17.1, not driven: web/app/(commonLayout)/marketplace in-product Dify Marketplace with community Plugins and Templates, creator profiles and trending by real usage (web/i18n/en-US/plugin.json:210-240 marketplace.home.templates, creatorProfile.*); skills and agent strategies ship through it too
  • re-template-cross-tenant unknown → yes: source read at 1.17.1, not driven: an app or agent exports as DSL YAML (web/features/agent-v2/agent-detail/sidebar-actions.tsx:52; api/services/app_dsl_service.py:723) and imports into another workspace or instance by file or URL (api/services/app_dsl_service.py:174; web/i18n/en-US/app.json:115); snippets export and import the same way (web/i18n/en-US/snippet.json importFromDSLUrl) Note: credentials and plugin dependencies must be set up again in the target (web/app/components/workflow/plugin-dependency)
  • re-course-recs unknown → no: source read at 1.17.1, not driven: searched 'course|learner|curriculum' in api/ and web/i18n/en-US: only Dify's own product onboarding lessons (api/controllers/console/explore/recommended_app.py:111 learn-dify; web/i18n/en-US/common.json stepByStepTour.*), no learner recommendations
  • op-airgap unknown → partial: source read at 1.17.1, not driven: offline is possible but not default: MARKETPLACE_ENABLED can be false with plugins uploaded as local packages (docker/.env.example:251; api/controllers/console/workspace/plugin.py:746 upload/pkg), templates in builtin mode (api/configs/feature/hosted_service/init.py:444 default remote), CHECK_UPDATE_URL (docker/.env.example:37) and community telemetry (api/configs/feature/init.py:839-850, ext_celery.py:285) must be switched off Note: every model needs a local provider plugin loaded by hand
  • op-multi-tenant yes → partial: source read at 1.17.1, not driven: workspaces keep apps, data, providers and members apart (api/controllers/console/workspace/workspace.py:229,289 list and switch; tenant_id on every model, e.g. api/models/agent.py:163); creating workspaces is off by default (api/configs/feature/init.py:1599 ALLOW_CREATE_WORKSPACE=False) and LICENSE:5-6 forbids running a multi-tenant service without a commercial licence Note: works technically, licence-gated for serving several organisations
  • op-tenant-quota unknown → no: source read at 1.17.1, not driven: api/services/feature_service.py:24-31 per-workspace limits (members, apps, vector space, upload quota, api/services/entities/feature_entities.py:152-161) are filled only from the Cloud billing API; self-hosted community has no per-workspace quota setting Note: Dify Cloud plans only
  • op-tenant-ops unknown → no: source read at 1.17.1, not driven: searched 'tenant management|all workspaces admin|operations page' in api/controllers/console and web/app: /all-workspaces (api/controllers/console/workspace/workspace.py:238) lists the caller's own workspaces; workspace-wide switches come from the separate Enterprise service (api/services/system_feature_service.py:106-112, 160-197), not a page in this repo
  • op-credential-vault partial → yes: source read at 1.17.1, not driven: tool, model, datasource and trigger credentials are stored encrypted per workspace (api/core/helper/encrypter.py, provider_encryption.py) and referenced by agents, not typed into agent settings (api/controllers/console/workspace/tool_providers.py, model_providers.py:200); api/models/credential_permission.py limits who may use each credential Note: an encrypted store in the Dify database, not an external vault such as HashiCorp
  • op-agent-credential unknown → yes: source read at 1.17.1, not driven: api/controllers/console/agent/roster.py:1032,1062 per-agent service API keys (create, list, revoke); per-agent secret environment variables injected only at runtime (web/i18n/en-US/agent-v-2.json advancedSettings.envEditor.scopeSecret, tools.cliDialog.securityTip); each tool on an agent picks which workspace credential it uses (agent-v-2.json tools.credential.authOne)
  • op-admin-settings yes → partial: source read at 1.17.1, not driven: Dify is set up in its own workspace settings and Integrations page (members api/controllers/console/workspace/members.py, model providers, plugins, web/app/(commonLayout)/integrations) plus environment variables (docker/.env.example); searched 'nextcloud' in api/ and web/: no Nextcloud admin settings panel Note: own settings, not Nextcloud's
  • op-setup-wizard yes → partial: source read at 1.17.1, not driven: api/controllers/console/setup.py:42,65 first-run admin account setup (web/app/install); api/controllers/console/onboarding.py:56 and web/app/components/step-by-step-tour a checklist tour pointing to Integrations, Knowledge, Studio and Learn Dify lessons (web/i18n/en-US/common.json:643-662); web/i18n/en-US/common.json:378 'Please install a model provider first'. No wizard that configures the first provider and agent end to end Note: a tour of pages, not a guided setup of provider plus agent
  • op-health unknown → partial: source read at 1.17.1, not driven: api/extensions/ext_app_metrics.py:20,28,54 /health, /threads, /db-pool-stat JSON endpoints and api/celery_healthcheck.py for machine checks; searched 'health|status page|system status' in web/app and web/i18n/en-US: no page showing chat and dependency health Note: endpoints only, no page
  • op-flat-cost unknown → partial: source read at 1.17.1, not driven: the self-hosted Community Edition carries no seat or message fee in code (api/services/feature_service.py:24-31 billing limits only for CLOUD); enterprise licences carry a member limit (api/services/entities/feature_entities.py:161 workspace_members LicenseLimitationModel) and Cloud plans limit apps and members (:152-157) Note: community is free; paid editions are limited by members or plan, pricing itself not in code
  • op-scale partial → yes: source read at 1.17.1, not driven: docker/docker-compose.yaml:227,306,353,660 separate api, Celery worker, beat and agent_backend services; docker/.env.example:57,66-67 SERVER_WORKER_AMOUNT, CELERY_WORKER_AMOUNT, CELERY_AUTO_SCALE; dify-agent/src/dify_agent/runtime/run_scheduler.py schedules concurrent agent runs; schedules dispatched in parallel groups (api/schedule/workflow_schedule_task.py:108)
  • op-outside-agent unknown → partial: source read at 1.17.1, not driven: api/controllers/openapi/oauth_device.py:103-129 RFC 8628 device flow issues bearer tokens that act as the approving account, scoped by api/libs/oauth_bearer.py:60-65 (apps:run, apps:read, workspace:*); clients allowed only via env OPENAPI_KNOWN_CLIENT_IDS (api/configs/feature/init.py:639-646, default difyctl); per-app API keys (api/controllers/console/apikey.py:236) and MCP server per app (api/controllers/mcp/mcp.py:44) Note: no UI to register an outside agent; scope is per-app or coarse token scopes, not a per-tool allowlist
  • op-preferences unknown → no: source read at 1.17.1, not driven: api/controllers/console/workspace/account.py:376,394,412 account settings are only interface language, theme and timezone; searched 'custom instruction|personal instruction|about you|user preference' in web/i18n/en-US, api/controllers and dify-agent/src: only conversation variables that a builder defines per conversation (web/i18n/en-US/workflow.json:113) Note: no per-person settings for how agents behave
  • ag-identity unknown → partial: source read at 1.17.1, not driven: api/core/agent/entities.py:19 each agent tool carries a credential_id the builder picks; api/models/tools.py:121 credential visibility, web/i18n/en-US/plugin.json:27 an OAuth credential is 'only for you or shared with all workspace members'. So a tool runs as the builder's or a shared workspace credential; searched 'on_behalf|end_user credential|user_credential' in api/core/tools and api/core/plugin: no run-as-the-asking-person Note: owner or shared credential only, no per-caller identity and no service-account concept
  • ch-shared-session yes → no: source read at 1.17.1, not driven: api/services/conversation_service.py:56-57,179-180 every conversation is filtered to one from_end_user_id or from_account_id; api/controllers/web/conversation.py lists, renames, pins and deletes only the caller's own conversations; the Collaboration feature is live co-editing of the workflow canvas (api/controllers/console/socketio/workflow.py, web/i18n/en-US/workflow.json:118,986 collaborator cursors) Note: old yes rested on the Collaboration beta, which is shared canvas editing for builders, not a shared chat
  • ch-intake unknown → partial: source read at 1.17.1, not driven: web/i18n/en-US/app.json:2 web app access 'Anyone with the link'; api/controllers/web/passport.py:53-72 issues a token to an anonymous end-user session, so a resident chats without an account; filing the request needs a builder-built HTTP Request node or custom tool (web/i18n/en-US/workflow.json:11,45); no ready-made intake to a case or request system in core Note: anonymous chat is core; the filing target has to be wired by hand
  • tl-connectors yes → partial: source read at 1.17.1, not driven: core ships only audio, code, time and webscraper tools (api/core/tools/builtin_tool/providers/); connectors come from the in-product Dify Marketplace: about 149 official tool plugins (langgenius/dify-official-plugins tools/, e.g. slack, jira, notion, gmail, salesforce, nextcloud) plus about 1,290 community packages (langgenius/dify-plugins), installed from web/app/(commonLayout)/integrations; MCP client too Note: rated partial only by the brief's plugin rule; the catalogue is well over a hundred ready-made connectors, one click from the core UI. The lane keeps partial under the plugin rule (ruling 2026-09-26).
  • me-rag-files yes → partial: source read at 1.17.1, not driven: knowledge bases from uploaded files (api/controllers/console/datasets/datasets_document.py:384) and datasource plugins; official datasources are S3, Azure, Box, Dropbox, Google Drive, OneDrive, SharePoint, Confluence, Notion, GitHub, GitLab and others, no Nextcloud (langgenius/dify-official-plugins datasources/); only the official nextcloud tool plugin can download_file at run time (tools/nextcloud/tools/download_file.yaml) Note: old yes rested on generic RAG; Nextcloud Files is not a knowledge source, only a plugin tool fetch
  • me-permissions unknown → partial: source read at 1.17.1, not driven: api/models/dataset.py:163,184-187 dataset permission (only_me, all_team, partial_members) governs which builders may attach a knowledge base, not what the end user may see; retrieval does not check the asking person. A builder can hand-build a manual metadata filter bound to a variable (api/core/workflow/nodes/knowledge_retrieval/entities.py:46-48, knowledge_retrieval_node.py:312-327 convert_template) Note: no document ACL trimming; only a hand-built metadata filter per flow
  • sk-share-tenants unknown → partial: source read at 1.17.1, not driven: api/models/skill.py:62,66 skills are unique per tenant_id (workspace); api/controllers/console/workspace/skills.py:494 export and :385 import (web/i18n/en-US/skill.json:224 '.zip with SKILL.md, agentskills.io format') copy a skill into another workspace; searched 'share' in skill.json and skills.py: no live cross-workspace sharing Note: copy by export/import only, updates do not follow
  • co-algoritmeregister unknown → no: source read at 1.17.1, not driven: searched 'algoritme|algorithm.?regist|register|ai act' in api/, web/app and web/i18n/en-US: no hits for an algorithm register or any export to one; apps and agents carry no register fields (api/models/agent.py, api/models/model.py)
  • co-dpia unknown → no: source read at 1.17.1, not driven: searched 'dpia|impact assessment|fundamental rights|privacy assessment' in api/, web/app and web/i18n/en-US: no hits; agents have name, description, role and icon only (api/controllers/console/agent/roster.py:706), no field or link for an assessment
  • fl-parallel unknown → yes: source read at 1.17.1, not driven: web/i18n/en-US/workflow.json:152,217 'Add Parallel Node' parallel branches on the canvas; :684-702 Iteration node Parallel Mode with maximum parallelism over list items; api/configs/feature/init.py:949 MAX_SUBMIT_COUNT thread pool for parallel node execution; Agent nodes (blocks.agent-v2, api/core/workflow/nodes/agent_v2) can sit on each branch or inside the iteration Note: fan-out is designed in the flow; an agent cannot spawn parallel sub-agents itself at run time (see fl-subagent)
  • op-languages unknown → partial: source read at 1.17.1, not driven: web/i18n-config/languages.ts:158-162 nl-NL 'Nederlands' marked supported; web/i18n/nl-NL has all 37 namespaces, but about 3,800 of 5,947 values are identical to en-US (e.g. workflow.json 921 of 1161, dataset-documents.json 258 of 260 untranslated), while agent-v-2, permission and skill are translated Note: Dutch is selectable, roughly two thirds of the UI still shows English

n8n: every rating change (before → after, evidence)

  • ag-create unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub-agent.entity.ts:45,51,69 personal agent has name, description, systemPrompt; chat-hub.controller.ts:451 POST /chat/agents; packages/frontend/@n8n/i18n/src/locales/en.json:492 'Instructions' field in the Chat agent editor; the opt-in Agents module adds packages/cli/src/modules/agents/agents.controller.ts:29 POST with en.json:7867,7878 Name and Instructions Note: Chat hub is a default module, so creating a named agent with instructions works out of the box.
  • ag-list unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/agents-list.controller.ts:17 GET /agents/v2 across projects; agents.service.ts:358-364 scoped to projects the user is a member of, so an admin does not see every agent; packages/frontend/editor-ui/src/features/agents/components/AgentCard.vue:203-220 card shows name, updated, created and a Published badge, no owner Note: No organisation-wide list and no owner column. Agents module is shipped but off by default: packages/@n8n/backend-common/src/modules/module-registry.ts:44 defaultModules omits 'agents' (enable with N8N_ENABLED_MODULES=agents).
  • ag-detail unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/module.descriptor.ts:60-91 agent page with builder, preview, sessions and session-detail children; en.json:8172-8178 tabs Build, Knowledge, Sessions, Settings, Memory, Evals; en.json:8112 Schedules and 8044 Skills sections in the builder Note: Configuration, schedules and skills sit on the Build tab, runs on the Sessions tab of the same agent page. Agents module is shipped but off by default: packages/@n8n/backend-common/src/modules/module-registry.ts:44 defaultModules omits 'agents' (enable with N8N_ENABLED_MODULES=agents).
  • ag-model partial → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/agents/Agent/V3/AgentV3.node.ts:46 AI Agent node requires a chat model sub-node (26 provider nodes under nodes/llms/); packages/cli/src/modules/chat-hub/chat-hub-agent.entity.ts:107 model per chat agent; packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:446 provider/model string per agent; en.json:7870 Model field Note: Old partial rested on a credential-test release line; the code picks a model per agent everywhere.
  • ag-quota unknown → partial: source read at n8n@2.40.7, not driven: per-run caps only: packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:518 maxIterations 1-200 per run, packages/@n8n/nodes-langchain/nodes/agents/Agent/agents/ConversationalAgent/execute.ts:58 maxIterations default 10, packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/LmChatOpenAi.node.ts:401 maxTokens per call; searched 'budget|quota' in packages/cli/src/modules/agents: no per-agent run or token budget Note: Caps one run, not an agent's total runs or tokens.
  • ag-enable unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/workflows/workflows.controller.ts:475 POST /:workflowId/deactivate turns off an agent workflow's triggers without deleting it, en.json:4567 'Deactivate workflow'; packages/cli/src/modules/agents/agent-publish.controller.ts:45 unpublish, en.json:7775 unpublish stops production executions until republished
  • ag-owner unknown → partial: source read at n8n@2.40.7, not driven: ownership sits with a project, not a person: packages/cli/src/services/user.service.ts:616 shared workflow role 'workflow:owner' held by a project; packages/cli/src/modules/agents/entities/agent.entity.ts:13-18 agent belongs to projectId; only chat agents carry a person, packages/cli/src/modules/chat-hub/chat-hub-agent.entity.ts:74 ownerId Note: A personal project maps to one person; a team project has no named accountable human per agent.
  • ag-offboard unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/services/user.service.ts:593-610 deleting a user can transfer their personal project's resources to another user or project (en.json:3856 'Transfer their workflows, credentials and data tables'); workflow move at packages/cli/src/workflows/workflows.controller.ts:646 PUT /:workflowId/transfer; but packages/cli/src/services/ownership-transfer/ownership-transfer.manifest.json:59-60 says agents are dropped via FK cascade on transfer Note: Workflow-based agents move to a new owner; Agents-module agents are lost when their owner is deleted (the code's own manifest says so).
  • ag-nl-builder unknown → yes: source read at n8n@2.40.7, not driven: Instance AI ('n8n Agent') is a default module (packages/@n8n/backend-common/src/modules/module-registry.ts:79) enabled by default (packages/cli/src/modules/instance-ai/instance-ai-settings.service.ts:287-288) and builds workflows from chat (packages/@n8n/instance-ai/src/workflow-builder/); packages/frontend/editor-ui/src/features/agents/views/NewAgentView.vue:58-83 a new agent opens in an Instance AI thread that builds it Note: Needs a model set up in Instance AI first (useInstanceAiReady).
  • ag-app-slug unknown → partial: source read at n8n@2.40.7, not driven: an agent is addressable by id, not bound to a consuming app: packages/cli/src/modules/agents/entities/agent.entity.ts:39-40 availableInMCP flag, packages/cli/src/modules/agents/agent-mcp-access.controller.ts:26 toggle; workflow agents are called by webhook path (packages/nodes-base/nodes/Webhook) or Execute Workflow; searched 'appId|consumer app|slug' in packages/cli/src/modules/agents: no app binding Note: An app can call an agent by id, URL or MCP; there is no registry tying an agent to the app it serves.
  • ag-capability-profile unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/components/AgentCapabilitiesSection.vue:534-695 one Capabilities section with rows for tools, workflows, skills and sub-agents (en.json:8340 'Capabilities: What this agent can do'); knowledge files and vector stores on the Knowledge tab (en.json:7923,7956) Note: Data sources sit on the neighbouring Knowledge tab. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • ag-delete unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/agents.service.ts:386-432 delete removes the agent, disconnects its channels and calls AgentTaskService.requestReconcile to stop its schedules; entities/agent-task.entity.ts:33 tasks cascade on agent delete; en.json:8128 'This schedule will stop running'; for workflow agents, archiving/deleting a workflow deactivates its Schedule Trigger (packages/cli/src/workflows/workflows.controller.ts:475)
  • ag-import-export unknown → yes: source read at n8n@2.40.7, not driven: en.json:7613-7619 agent builder 'Export JSON' and 'Import agent JSON' modal (packages/frontend/editor-ui/src/features/agents/components/AgentJsonImportModal.vue); workflows export/import as JSON in the editor (en.json:1933 'From file') and by CLI packages/cli/src/commands/export/workflow.ts and packages/cli/src/commands/import/workflow.ts Note: Moves to another n8n instance (no Nextcloud target). Workflow JSON is complete; the Agents-module export (packages/frontend/editor-ui/src/features/agents/views/AgentBuilderView.vue:1466-1475) writes the config, where skills are only {type, id} references (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:189-198).
  • ch-chat partial → yes: source read at n8n@2.40.7, not driven: Chat hub is a default module (packages/@n8n/backend-common/src/modules/module-registry.ts:60); packages/frontend/editor-ui/src/features/ai/chatHub/module.descriptor.ts:108-113 route /home/chat with a full-page 'chat' layout for models, personal agents and workflow agents; packages/cli/src/modules/chat-hub/chat-hub.controller.ts:168 POST /chat/conversations/send Note: Old partial rested on a release line about chat hub tools; the chat hub is a default full-page chat.
  • ch-stream unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-stream.service.ts:160-191 sendChunk pushes content chunks to the user with reconnection replay; packages/@n8n/nodes-langchain/nodes/trigger/ChatTrigger/ChatTrigger.node.ts:129-131 'streaming' response mode, AI Agent node enableStreaming (nodes/agents/Agent/V3/AgentV3.node.ts:141-145); Agents module SSE in packages/cli/src/modules/agents/agent-sse-stream.ts
  • ch-sessions unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub.controller.ts:95 GET /chat/conversations and :110 GET one conversation; en.json:694-697 sidebar 'New chat' and 'Load more' sessions (packages/frontend/editor-ui/src/features/ai/chatHub/components/ChatSidebar.vue); agent memory keyed by session in memory nodes (nodes/memory/MemoryBufferWindow)
  • ch-session-delete unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub.controller.ts:388-397 DELETE /chat/conversations/:sessionId returns 204; en.json:686-690 'Are you sure you want to delete this conversation?'; searched 'archiv|restore|deletedAt|trash' in packages/cli/src/modules/chat-hub: no conversation bin or restore (hits are archived helper workflows and memory restore) Note: Delete is permanent; no bin and no restore.
  • ch-tool-steps unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/components/AgentChatToolSteps.vue:33-51 renders each tool call in the agent chat (en.json:7671-7675 tool names); in workflows the chat Logs panel lists the AI Agent's tool sub-node runs with inputs, outputs and tokens (packages/frontend/editor-ui/src/features/execution/logs/components/LogsOverviewPanel.vue, ChatMessagesPanel.vue, LogsViewConsumedTokenCountText.vue)
  • ch-attach unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub.controller.ts:120 message attachments; en.json:594 'Attach' and 565 'Drop files here to attach' upload from the local device; searched 'nextcloud|webdav' in packages/frontend/editor-ui/src/features/ai/chatHub: no picker for files held in Nextcloud (a Nextcloud node exists only as a workflow step) Note: Uploads a local file; cannot pick a file from Nextcloud in chat.
  • ch-feedback unknown → partial: source read at n8n@2.40.7, not driven: rating exists only in two narrower places: n8n's own builder assistant (packages/frontend/editor-ui/src/features/ai/instanceAi/useResponseFeedback.ts, instanceAi.api.ts:73-86 POST /instance-ai/feedback) and eval review rows (en.json:8317-8318 thumbs up/down); searched 'thumb|feedback|rating' in packages/frontend/editor-ui/src/features/ai/chatHub and features/agents chat components: no rating on a user agent's live answer Note: No thumbs on answers from agents people build.
  • ch-companion unknown → partial: source read at n8n@2.40.7, not driven: an assistant side panel follows the user across the n8n editor (packages/frontend/editor-ui/src/features/ai/assistant/chatPanel.store.ts, components/AssistantsHub.vue) and the canvas chat panel (features/ai/chatHub/components/CanvasChatHubPanel.vue); searched 'nextcloud' in packages/frontend: no integration into Nextcloud pages Note: Available on every n8n page, not inside Nextcloud or other apps.
  • ch-object-leaf unknown → partial: source read at n8n@2.40.7, not driven: no host-app record context for user agents (searched 'record context|objectId|current page' in packages/cli/src/modules/agents and chat-hub: none); only n8n's own assistant can read the user's open browser tab through the AI Browser Bridge extension (packages/@n8n/mcp-browser/README.md:3-6, packages/@n8n/computer-use/README.md Browser tools) Note: Only n8n's builder assistant, through a local browser bridge; agents people build cannot see the record on screen.
  • ch-prompt-library unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub-agent.entity.ts:62-63 suggestedPrompts per chat agent, en.json:527 'Suggestions' in the agent editor (packages/frontend/editor-ui/src/features/ai/chatHub/components/SuggestedPromptsEditor.vue, ChatSuggestedPrompts.vue); searched 'record type|prompt library' in packages/cli/src/modules/chat-hub: no organisation prompt library bound to a record type Note: Ready-made prompts are per agent and set by its owner, not per record type.
  • ch-voice-in unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/ai/chatHub/components/ChatPrompt.vue:4,53 useSpeechRecognition turns speech into the prompt; en.json:599 'Voice input' and 571-573 microphone prompts; audio transcription also shipped as a node, packages/@n8n/nodes-langchain/nodes/vendors/OpenAi/v2/actions/audio/transcribe.operation.ts Note: Browser speech recognition, so it depends on the browser supporting it.
  • ch-voice-out unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/ai/chatHub/components/ChatMessageActions.vue:17-19,64,72 'Read aloud' action on AI messages via browser speech synthesis (en.json:650); speech generation node packages/@n8n/nodes-langchain/nodes/vendors/OpenAi/v2/actions/audio/generate.operation.ts
  • ch-smart-picker unknown → partial: source read at n8n@2.40.7, not driven: the same kind of thing exists only on n8n's own surface: 'Ask AI' writes code into the Code node's field (packages/@n8n/constants/src/index.ts:39 feat:askAi, licence-gated) and the builder assistant fills node parameters; searched 'smart picker|nextcloud' in packages/frontend and packages/cli/src: no way to call it from a Nextcloud text field Note: Missing Nextcloud part: any text field in Nextcloud. Rewritten under the lane ruling of 2026-09-26 (was no).
  • ch-text-tasks unknown → partial: source read at n8n@2.40.7, not driven: text tasks ship as workflow nodes, not one-click actions: packages/@n8n/nodes-langchain/nodes/chains/ChainSummarization (summarise), nodes/vendors/OpenAi/v2/actions/audio/translate.operation.ts, nodes-base DeepL node (packages/nodes-base/nodes/DeepL); searched 'summarize|translate|rephrase' in packages/frontend/editor-ui/src/features/ai/chatHub: no one-click text actions Note: Needs a workflow built around a node or a typed chat request.
  • ch-image-gen unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/vendors/OpenAi/v2/actions/image/generate.operation.ts image generation operation; Google Gemini vendor node image actions (nodes/vendors/GoogleGemini); both usable in a workflow or as an agent tool
  • ch-search-history unknown → no: source read at n8n@2.40.7, not driven: packages/cli/src/modules/chat-hub/chat-hub.controller.ts:95-107 GET /chat/conversations takes only limit, cursor, type (packages/@n8n/api-types/src/chat-hub.ts:491-495), no query; searched 'search' among chatHub i18n keys (en.json:539-677): only agent, tool and model search; agent sessions list has status/origin filters only (packages/frontend/editor-ui/src/features/agents/components/AgentSessionsFilter.vue:25-34)
  • ch-citations unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/agent-knowledge-retrieval.ts:199,276 knowledge search returns file and line citations to the model (tools/knowledge/search-knowledge.tool.ts:215) and the chat shows 'Read file'/'Search text' tool steps (en.json:7672-7674); searched 'citation|sources' in packages/frontend/editor-ui/src/features/ai/chatHub and features/agents: no linked source list under an answer Note: The model gets citations, the answer UI shows no source links. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • ch-share-link unknown → partial: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/components/AgentPreviewMoreMenu.vue:159-172 'Copy link' copies the session route (en.json:8223), which opens only for users with agent:read in the project; chat hub conversations are private to their user (packages/cli/src/modules/chat-hub/chat-hub.controller.ts:110 getConversation by req.user.id); searched 'share' in chat-hub.controller.ts: no share endpoint Note: A link works for project colleagues on agent sessions; no public or chat-hub share link. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sc-once unknown → partial: source read at n8n@2.40.7, not driven: no one-shot trigger: packages/nodes-base/nodes/Schedule/ScheduleTrigger.node.ts:81-106 only recurring rules; inside a running workflow the Wait node can hold until a date (packages/nodes-base/nodes/Wait/Wait.node.ts:329 resume 'specificTime'); agent schedules are recurring only (packages/cli/src/modules/agents/builder/skills/target-tasks.skill.ts:10 'Not for one-off requests') Note: A one-off run needs a workflow that starts then waits until the date.
  • sc-nl unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/builder/skills/target-tasks.skill.ts:5-20 the agent builder assistant turns a request for a recurring schedule into create_tasks/update_task calls; Instance AI (default module) builds Schedule Trigger workflows from plain prompts, e.g. en.json:1271 'Every morning, scan Gmail ...' suggestion Note: Through the AI builder, which needs a model configured.
  • sc-timezone unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Schedule/ScheduleTrigger.node.ts:501-532 rules evaluated in the workflow/instance IANA timezone with moment-timezone; agent schedules carry their own zone, packages/cli/src/modules/agents/scheduling/task-timezone.ts:10-18 and agent-task-job-registrar.ts:190-195 cron planned in that zone
  • sc-run-now unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/agent-tasks.controller.ts:98-99 POST /:agentId/tasks/:taskId/run, en.json:8155 'Run schedule'; workflows with a Schedule Trigger run on demand from the editor's execute button (packages/cli/src/workflows/workflows.controller.ts manual run)
  • sc-pause unknown → yes: source read at n8n@2.40.7, not driven: en.json:8122 per-schedule 'Enabled' switch in the agent task editor, packages/api-types agent-json-config.schema.ts:200-210 task enabled flag; whole workflows pause and resume with packages/cli/src/workflows/workflows.controller.ts:441 activate and :475 deactivate
  • sc-webhook-secret unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Webhook/description.ts:91-95 basic, header and JWT auth on the webhook, each backed by a stored credential; the secret is rotated or revoked by editing or deleting that credential (packages/cli/src/credentials/credentials.controller.ts:243 PATCH, :450 DELETE) Note: No dedicated rotate button; rotation is a credential edit.
  • sc-event yes → partial: source read at n8n@2.40.7, not driven: 103 trigger nodes in packages/nodes-base/nodes (Trigger.node.ts), e.g. file-upload triggers for Google Drive and Dropbox; searched 'nextcloudtrigger' in packages/nodes-base/nodes: none, so a Nextcloud event reaches n8n only as a call to a generic Webhook node (packages/nodes-base/nodes/Webhook) Note: Event triggers are rich for other apps; nothing listens to Nextcloud directly. Old yes rested on the generic webhook line.
  • sc-manual-event-choice unknown → yes: source read at n8n@2.40.7, not driven: each workflow picks its start: Manual Trigger, Schedule Trigger, Webhook or one of 103 app trigger nodes (packages/nodes-base/nodes/*Trigger.node.ts); Agents module agents combine chat, channel triggers and schedules per agent, en.json:8342-8343 'Triggers: Where and when this agent runs'
  • sc-retry yes → partial: source read at n8n@2.40.7, not driven: packages/core/src/execution-engine/workflow-execute.ts:1799-1814 node 'Retry On Fail' clamps maxTries to 2-5 and waitBetweenTries to at most 5000 ms, :2346-2347 same wait every attempt (en.json:2378-2408); failed executions can be retried by hand (en.json:1577 'Retry execution') Note: Retries stop after a limit, but the wait is fixed, not growing. Old yes rested on a generic error-handling line.
  • sc-dead-letter unknown → partial: source read at n8n@2.40.7, not driven: the executions list filters failed runs (en.json:1429 'Error' status) with manual 'Retry execution' (en.json:1577-1579), and an Error Workflow can route failures elsewhere (workflow settings errorWorkflow); searched 'dead letter|deadLetter|parked' in packages/cli/src: no dedicated queue for runs that keep failing Note: Failed runs are findable by status, not parked in their own list.
  • sc-overlap partial → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/agent-task.service.ts:529-558 takes a per-task run lock (entities/agent-task-run-lock.entity.ts:6-35) and returns 'skipped-active' when the previous run still holds it; scheduling/agent-task-task-handler.ts:59-60 skips that tick Note: Agent schedules only (opt-in Agents module); workflow Schedule Triggers can overlap and have only the instance-wide N8N_CONCURRENCY_PRODUCTION_LIMIT (packages/@n8n/config/src/configs/executions.config.ts:25).
  • sc-list unknown → partial: source read at n8n@2.40.7, not driven: per agent only: en.json:8119-8123 'Next run', 'Last run', 'Schedule status' in the agent's Schedules section (packages/frontend/editor-ui/src/features/agents/components/AgentSchedulesRow.vue); searched 'schedule' list views in packages/frontend/editor-ui/src/features: no instance-wide schedule overview for workflows or agents Note: No single list of every schedule.
  • tl-files unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/NextCloud/NextCloud.node.ts:35 usableAsTool, so an AI Agent can call it; :82-143 file resource with copy, delete, download, move, share, upload and :163-188 folder create, list, move; authenticated by Nextcloud access token or OAuth2 (:40-70) Note: Needs a workflow with an AI Agent node and the Nextcloud tool attached.
  • tl-calendar unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Google/Calendar/GoogleCalendar.node.ts:57 usableAsTool, event get/getAll/create as an AI Agent tool; Microsoft Outlook node has calendar events (packages/nodes-base/nodes/Microsoft/Outlook/v2); searched 'caldav' in packages/nodes-base/nodes: none, so a Nextcloud calendar needs a hand-built HTTP Request tool Note: Google and Microsoft calendars; no CalDAV or Nextcloud Calendar node.
  • tl-contacts unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Google/Contacts/GoogleContacts.node.ts:35 usableAsTool with contact get/getAll; searched 'carddav' in packages/nodes-base/nodes: none, so Nextcloud Contacts is only reachable by a hand-built HTTP Request tool Note: Google Contacts; no CardDAV or Nextcloud Contacts node.
  • tl-deck unknown → partial: source read at n8n@2.40.7, not driven: card boards of other products as agent tools: packages/nodes-base/nodes/Trello/Trello.node.ts:42 usableAsTool (card create/update), Asana and Jira nodes; searched 'deck' in packages/nodes-base/nodes/NextCloud: the Nextcloud node has only file, folder and user resources (NextCloud.node.ts:82-91) Note: Cards on Trello-like boards, not Nextcloud Deck.
  • tl-mail unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/EmailSend/v2/EmailSendV2.node.ts:32 usableAsTool sends SMTP mail; packages/nodes-base/nodes/Google/Gmail/v2/GmailV2.node.ts:54 usableAsTool with send
  • tl-talk unknown → partial: source read at n8n@2.40.7, not driven: team chat tools for other products: packages/nodes-base/nodes/Slack/V2/SlackV2.node.ts:75, Mattermost/v1/MattermostV1.node.ts:19, Microsoft/Teams/v2/MicrosoftTeamsV2.node.ts:21 all usableAsTool; searched 'talk|spreed' in packages/nodes-base/nodes: no Nextcloud Talk node Note: Posts to Slack, Mattermost or Teams, not Nextcloud Talk.
  • tl-tasks unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Google/Task/GoogleTasks.node.ts:29, Microsoft/ToDo/MicrosoftToDo.node.ts:33 and Todoist/v2/TodoistV2.node.ts:61 are usableAsTool with create and update (complete) task operations Note: No Nextcloud Tasks (CalDAV) node.
  • tl-unified-search unknown → no: source read at n8n@2.40.7, not driven: searched 'unified search|unifiedsearch|nextcloud search' in packages/nodes-base/nodes, packages/@n8n/nodes-langchain/nodes and packages/cli/src/modules/agents: no tool that searches across a Nextcloud instance; the Nextcloud node covers files, folders and users only (packages/nodes-base/nodes/NextCloud/NextCloud.node.ts:82-91)
  • tl-web-search unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/tools/ToolSerpApi/ToolSerpApi.node.ts:25 'SerpApi (Google Search)' and nodes/tools/ToolSearXng agent tools; Agents module web search setting with native, Brave or SearXNG providers (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:80-84, en.json:7884-7895); pages read with the HTTP Request tool (nodes/tools/ToolHttpRequest)
  • tl-register unknown → no: source read at n8n@2.40.7, not driven: searched 'openregister' in packages/nodes-base/nodes, packages/@n8n/nodes-langchain/nodes and packages/cli/src: no hits; only reachable by a hand-built HTTP Request tool against its API
  • tl-grants unknown → yes: source read at n8n@2.40.7, not driven: an AI Agent node can call only the tool sub-nodes wired to it (packages/@n8n/nodes-langchain/nodes/agents/Agent/utils.ts:31-59 typed inputs incl. ai_tool); Agents module lists tools per agent and filters MCP tools with allow/exclude (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:266-282, :461); skills narrow further with allowedTools (en.json:8053)
  • tl-request-access unknown → no: source read at n8n@2.40.7, not driven: searched 'request access|request_tool|requestTool' in packages/cli/src/modules/agents and packages/@n8n/agents/src: a running agent cannot ask its owner for a missing tool; ask_credential exists only for the builder assistant while editing an agent (packages/cli/src/modules/agents/builder/prompts/config-mutation.prompt.ts:31,103), and 'Suggest a tool' (en.json:7800-7801) is feedback from the builder to n8n Note: The builder asks the human for credentials while building; the agent at runtime cannot.
  • tl-code-exec partial → yes: source read at n8n@2.40.7, not driven: Code node and Custom Code Tool (packages/@n8n/nodes-langchain/nodes/tools/ToolCode/ToolCode.node.ts) run JS or Python in task runners, Python in a sandbox (packages/@n8n/task-runner-python/src/_sandbox_callables.py; runner mode config packages/@n8n/config/src/configs/runners.config.ts:16-17); Agents module custom tools run in V8 isolates (packages/cli/src/modules/agents/runtime/agent-secure-runtime.ts:5,23) Note: Default runner mode is 'internal' (a child process); the external runner container gives stronger isolation.
  • tl-git unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Git/Git.node.ts:90 usableAsTool with operations add, clone, commit, pull, push (:136-184); GitHub and GitLab nodes for remote repositories (packages/nodes-base/nodes/Github, Gitlab) Note: Git node works on the n8n host's filesystem; needs a workflow with an AI Agent node.
  • tl-invocations-export unknown → partial: source read at n8n@2.40.7, not driven: tool calls sit inside execution data, exportable per run through the public API packages/cli/src/public-api/v1/handlers/executions/spec/paths/getExecutions.generated.yml:18 includeData; one agent session exports to LangSmith (packages/cli/src/modules/agents/agent-threads.controller.ts:53-65); searched 'export' in packages/frontend/editor-ui/src/features/agents and execution logs: no export of an agent's tool-call list Note: No single export of every tool call; assemble from execution data or per session.
  • tl-integrations-page unknown → partial: source read at n8n@2.40.7, not driven: the Credentials page lists every outside connection (en.json:1178-1182) and a credential is tested when saved (packages/cli/src/credentials/credentials.controller.ts:147 POST /test), but the list shows no live health; per agent, packages/cli/src/modules/agents/agent-integrations.controller.ts:89-104 channel status report and en.json:8554 'Not running' badge Note: No single page with live status of every dependency.

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 6 of 8

n8n (continued)

  • me-long-term unknown → yes: source read at n8n@2.40.7, not driven: Agents module episodic memory stores source-backed facts across conversations (packages/@n8n/agents/src/runtime/memory/episodic-memory.ts, packages/cli/src/modules/agents/entities/agent-memory-entry.entity.ts, en.json:7918-7919); workflows keep chat history across runs in persistent memory nodes keyed by session (packages/@n8n/nodes-langchain/nodes/memory/MemoryPostgresChat, MemoryRedisChat, MemoryZep) Note: Fact memory needs the opt-in Agents module; workflow memory nodes keep conversation history, not distilled facts.
  • me-user-profile unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/agents/utils/agent-memory-scope.ts:1-60 memory is scoped per resource: per n8n user (draft-chat:), per chat-platform user (integration::) and per task; memory entries indexed by agentId and resourceId (entities/agent-memory-entry.entity.ts:8-17) Note: Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • me-view-edit unknown → partial: source read at n8n@2.40.7, not driven: workflow chat memory can be read, overwritten or deleted with the Chat Memory Manager node (packages/@n8n/nodes-langchain/nodes/memory/MemoryManager/MemoryManager.node.ts:127-183 load, insert, override, delete); the Agents module Memory tab only configures memory (packages/frontend/editor-ui/src/features/agents/components/AgentMemoryPanel.vue:225-316) and searched 'memory' in packages/cli/src/modules/agents/*.controller.ts: no endpoint to list or edit remembered facts Note: Facts an agent remembers cannot be seen or corrected in the UI.
  • me-consolidate unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/agents/src/runtime/memory/observation-log-reflector.ts:76,123-160 a reflector model merges observations and marks superseded ones; memory-lifecycle.ts:1-12 active, superseded, dropped states; reflector model chosen in en.json:8034-8035 'Memory model' Note: Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • me-kb-upload unknown → yes: source read at n8n@2.40.7, not driven: Chat hub agents take knowledge files with semantic search (packages/cli/src/modules/chat-hub/chat-hub.controller.ts:484 POST /chat/agents/:agentId/files, en.json:515); Agents module knowledge base for CSV, PDF, Markdown, TXT (packages/cli/src/modules/agents/agent-knowledge.controller.ts:48, en.json:7925); workflows load documents into vector stores (packages/@n8n/nodes-langchain/nodes/vector_store/) Note: Chat hub PDF upload needs semantic search configured by the owner.
  • me-context unknown → partial: source read at n8n@2.40.7, not driven: per-agent knowledge files and instructions travel with the agent (packages/cli/src/modules/agents/agent-knowledge.controller.ts:36-48, en.json:7925); the instance-wide Context settings page ships only Preferences, with 'Sources' and 'Skills' marked 'Coming soon' (packages/frontend/editor-ui/src/features/settings/context/views/SettingsContextView.vue:68-77, en.json:3229-3233) Note: No named, reusable bundle of files and records to attach to several agents.
  • me-compression unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/agents/src/runtime/memory/memory-orchestrator.ts:615-650 observations stand in for older messages once an observer model has summarised them (observation-log-observer.ts:166 runObservationLogObserver, thresholds in packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:42-51); workflows only window history (packages/@n8n/nodes-langchain/nodes/memory/MemoryBufferWindow) Note: Summarising needs the opt-in Agents module; workflow memory nodes truncate instead.
  • me-knowledge-graph unknown → no: source read at n8n@2.40.7, not driven: searched 'knowledge graph|graph|relation' in packages/cli/src/modules/agents, packages/@n8n/agents/src and packages/@n8n/nodes-langchain/nodes: no graph of related records for agents to follow (agent-dependency-index.service.ts tracks config dependencies, not data); no Neo4j or graph store node in packages/nodes-base/nodes
  • me-object-grounding unknown → no: source read at n8n@2.40.7, not driven: searched 'record context|objectId|current record|on screen' in packages/cli/src/modules/agents, chat-hub and packages/frontend/editor-ui/src/features/ai: agents get no host-app record or its linked records; grounding is only in uploaded knowledge files or vector stores
  • me-external-kb unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Microsoft/SharePoint/v2/actions/versionDescription.ts:26 and packages/nodes-base/nodes/Notion/v2/VersionDescription.ts:26 usableAsTool, Confluence node (packages/nodes-base/nodes/Confluence); Agents module connects outside vector stores Pinecone, Qdrant, Supabase, Postgres (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:305-371, en.json:7956-7958)
  • sk-catalog unknown → no: source read at n8n@2.40.7, not driven: skills exist per agent only (packages/cli/src/modules/agents/agents-skills.controller.ts:21-82 CRUD under one agent); the shared place for skills is a placeholder, packages/frontend/editor-ui/src/features/settings/context/views/SettingsContextView.vue:68-71 'Skills' row with 'Coming soon' (en.json:3231-3232); searched 'catalog|marketplace|registry' in agents-skills.controller.ts and agent-skills.service.ts: none Note: Skills can be written or imported per agent, but there is nothing to browse.
  • sk-install unknown → yes: source read at n8n@2.40.7, not driven: en.json:8062-8063 'Upload SKILL.md' and 'Upload folder' in the agent's Skills section (packages/frontend/editor-ui/src/features/agents/composables/useAgentSkillImport.ts), saved by packages/cli/src/modules/agents/agents-skills.controller.ts:40 POST /:agentId/skills Note: Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-format unknown → partial: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/composables/useAgentSkillImport.ts reads SKILL.md with YAML frontmatter name and description plus markdown references (en.json:8064-8080), but :56-57 rejects a scripts/ folder, en.json:8070 'Scripts aren't supported for skills yet' Note: Imports agentskills.io-style SKILL.md without scripts. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-self-improve unknown → partial: source read at n8n@2.40.7, not driven: improvement runs through the builder assistant on request: en.json:653,657 'Fix with Assistant' sends failed tool calls from a preview to the builder, and eval reviews 'Send feedback to assistant' (en.json:8313); searched 'improve|propose' in packages/cli/src/modules/agents and packages/@n8n/agents/src/runtime/skills: no agent proposing skill revisions from its own runs Note: A person triggers the fix; the agent does not propose skill updates itself. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-draft-review unknown → partial: source read at n8n@2.40.7, not driven: builder edits land in a draft; the owner can preview, publish or 'Revert changes' to the published version (en.json:7765, packages/cli/src/modules/agents/agent-publish.controller.ts:21-111 publish, revert, versions); searched 'diff' in packages/frontend/editor-ui/src/features/agents: no side-by-side diff of a skill change Note: Accept or reject happens at agent level by publishing or reverting, without a diff. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-auto-create unknown → no: source read at n8n@2.40.7, not driven: skills are created by the builder assistant only when a person asks (packages/cli/src/modules/agents/builder/skills/target-skills.skill.ts:9-19 create_skills; builder/agents-builder-prompts.ts:215); searched 'create_skills|write_skill' in packages/@n8n/agents/src: no runtime tool letting an agent write its own skill after a task
  • sk-curator unknown → no: source read at n8n@2.40.7, not driven: searched 'curator|archive|merge|unused' in packages/cli/src/modules/agents/agent-skills.service.ts, agents-skills.controller.ts and packages/@n8n/agents/src/runtime/skills: no scheduled merging of duplicate skills or archiving of unused ones
  • sk-maturity unknown → no: source read at n8n@2.40.7, not driven: searched 'maturity|proven|usage count|success rate' in packages/cli/src/modules/agents/agent-skills.service.ts, agents-skills.controller.ts and packages/frontend/editor-ui/src/features/agents/components/AgentSkill*.vue: a skill has name, description, instructions, allowed tools and references only
  • sk-versions unknown → partial: source read at n8n@2.40.7, not driven: skills live inside the agent config, so they ride the agent's publish history: packages/cli/src/modules/agents/agent-publish.controller.ts:87-111 revert-to-version and GET versions, en.json:7780-7797 'Publish history', 'Revert to this version'; searched 'diff|compare' in packages/frontend/editor-ui/src/features/agents: no comparison of two versions and no per-skill history Note: Roll back yes, compare no, and only at agent level. Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-github unknown → no: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/agents/composables/useAgentSkillImport.ts imports a local SKILL.md file or folder only (en.json:8062-8063); searched 'github' in that file and in packages/cli/src/modules/agents/agents-skills.controller.ts: no GitHub search, install or publish
  • sk-learnings unknown → no: source read at n8n@2.40.7, not driven: lessons from runs go into episodic memory, not into skill rules (packages/@n8n/agents/src/runtime/memory/episodic-memory.ts, observation-log-reflector.ts); searched 'learning|lesson|rule' in packages/cli/src/modules/agents/agent-skills.service.ts and packages/@n8n/agents/src/runtime/skills/active-skills.ts: nothing writes back to a skill
  • sk-export unknown → no: source read at n8n@2.40.7, not driven: the agent's 'Export JSON' (packages/frontend/editor-ui/src/features/agents/views/AgentBuilderView.vue:1413,1466-1475) writes the agent config, in which a skill is only a {type:'skill', id} reference (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:189-198); searched 'export|download' in AgentSkillViewer.vue and AgentSkillModal.vue: no skill file export
  • sk-install-source unknown → no: source read at n8n@2.40.7, not driven: skill import reads files the user selects (packages/frontend/editor-ui/src/features/agents/composables/useAgentSkillImport.ts, en.json:8062-8065); searched 'url|fetch(' in that file and 'source' in packages/cli/src/modules/agents/agents-skills.controller.ts: no install from an outside address
  • sk-evals unknown → partial: source read at n8n@2.40.7, not driven: test-case runs exist for workflows (packages/cli/src/evaluation.ee/test-runs.controller.ee.ts, Evaluation nodes in packages/nodes-base/nodes/Evaluation) and for Agents-module agents (packages/cli/src/modules/agent-evals/agent-evals.controller.ts, gated per user by PostHog flag in agent-evals-flag-gate.ts:17-24); searched 'with and without|baseline|skill' in packages/cli/src/modules/agent-evals: no with/without-skill comparison Note: Workflow evaluations count against the licence quota quota:evaluations:maxWorkflows (packages/@n8n/constants/src/index.ts:73); agent evals are an opt-in module behind a rollout flag.
  • mo-local unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/llms/LMChatOllama and LMChatLemonade chat model nodes, EmbeddingsOllama for local embeddings; Ollama vendor node packages/@n8n/nodes-langchain/nodes/vendors/Ollama
  • mo-openai-compat unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/credentials/OpenAiApi.credentials.ts:35-36 'Base URL' field, :80 baseURL taken from it, so the OpenAI chat model node talks to any OpenAI-compatible server; OpenRouter and Vercel AI Gateway nodes too (nodes/llms/LmChatOpenRouter, LmChatVercelAiGateway)
  • mo-nc-assistant unknown → partial: source read at n8n@2.40.7, not driven: n8n's own centrally set-up models can be reused: chat hub providers configured once by an admin (packages/@n8n/api-types/src/chat-hub.ts:574-585, packages/cli/src/modules/chat-hub/chat-hub.settings.controller.ts:59) and 'Included in n8n' credit models (en.json:5450); searched 'nextcloud|taskprocessing' in packages/@n8n/nodes-langchain/nodes and packages/cli/src/modules: no provider backed by Nextcloud AI task processing Note: Missing Nextcloud part: TaskProcessing as a model source. Rewritten under the lane ruling of 2026-09-26 (was no).
  • mo-provide-text2text unknown → partial: source read at n8n@2.40.7, not driven: agents are offered to the rest of n8n: workflows call Agents-module agents (session origin 'Workflow', en.json agentSessions.origin.workflow) and outside tools reach them through the MCP call_agent tool (packages/cli/src/modules/mcp/mcp-scopes.ts:73); searched 'chat/completions' as a served route in packages/cli/src: none, so nothing registers with Nextcloud task processing Note: Missing Nextcloud part: registering as a TaskProcessing text provider. Rewritten under the lane ruling of 2026-09-26 (was no).
  • mo-tenant-policy unknown → partial: source read at n8n@2.40.7, not driven: Chat hub admin settings restrict providers and models instance-wide (packages/@n8n/api-types/src/chat-hub.ts:574-584 enabled and allowedModels per provider, packages/cli/src/modules/chat-hub/chat-hub.settings.controller.ts:59 GlobalScope chatHub:manage); per-project node type policies can block model nodes (packages/cli/src/modules/type-availability-policies/type-availability-policy-project.controller.ts:19-24, @licensed NODE_TYPE_POLICIES) Note: Instance-wide for chat; per-project blocking is enterprise-licensed and in a module not loaded by default; no organisation tenancy.
  • mo-per-feature unknown → yes: source read at n8n@2.40.7, not driven: every AI node chooses its own model: Summarization Chain, Text Classifier, Information Extractor and AI Agent each take a separate chat model sub-node (packages/@n8n/nodes-langchain/nodes/chains/ChainSummarization, chains/TextClassifier, agents/Agent/utils.ts:46-59); Instance AI has its own model setting (packages/cli/src/modules/instance-ai/instance-ai-model.service.ts)
  • mo-failover unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/agents/Agent/V3/AgentV3.node.ts:37-40,118-119 'Enable Fallback Model' adds a second model input used when the primary fails
  • mo-sensitivity-routing unknown → partial: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/ModelSelector/ModelSelector.node.ts:73-124 routes to a model by rules on workflow data, and the Guardrails node detects PII (packages/@n8n/nodes-langchain/nodes/Guardrails); searched 'sensitiv|classification' in packages/cli/src/modules/agents: no built-in data-class-to-model policy Note: Must be hand-built from a Guardrails check plus Model Selector rules.
  • mo-cli-runner unknown → no: source read at n8n@2.40.7, not driven: searched 'claude-code|claude code|claude-agent-sdk' in packages/cli/src, packages/@n8n/nodes-langchain/nodes, packages/@n8n/agents/src and packages/@n8n/instance-ai/src: none; Anthropic is reached only through its API (packages/@n8n/nodes-langchain/nodes/llms/LMChatAnthropic)
  • mo-personal-key unknown → yes: source read at n8n@2.40.7, not driven: Chat hub lets each user pick a provider credential they own, checked per user (packages/cli/src/modules/chat-hub/chat-hub-credentials.service.ts:25-31 findCredentialForUser; packages/frontend/editor-ui/src/features/ai/chatHub/components/DynamicCredentialsDrawer.vue); workflows can resolve a credential per executing user with dynamic credentials (packages/cli/src/modules/dynamic-credentials.ee, feat:dynamicCredentials) Note: Per-user resolution in workflows is enterprise-licensed.
  • dl-talk unknown → partial: source read at n8n@2.40.7, not driven: output goes to team chats of other products through Slack, Mattermost and Teams nodes (packages/nodes-base/nodes/Slack/V2/SlackV2.node.ts, Mattermost/v1, Microsoft/Teams/v2); searched 'talk|spreed' in packages/nodes-base/nodes and packages/cli/src/modules/agents/integrations: no Nextcloud Talk target Note: Delivery into a team chat works; Nextcloud Talk is not a target.
  • dl-talk-bridge unknown → partial: source read at n8n@2.40.7, not driven: Agents module chat channels let people chat with an agent from Slack, Telegram, Discord and Linear with replies in place (packages/cli/src/modules/agents/agents.module.ts:81-96 registry; integrations/platforms/); workflows do the same with Slack or Telegram triggers; searched 'talk|spreed|nextcloud' in integrations/: no Talk adapter Note: Works in other chat apps (opt-in Agents module or hand-built workflows), not in Nextcloud Talk.
  • dl-talk-grouping unknown → partial: source read at n8n@2.40.7, not driven: on its own chat surfaces an agent gets its own space: in Slack each agent is its own app with its own direct messages (packages/cli/src/modules/agents/agent-slack-integrations.controller.ts:26-150 app creation and install; en.json:8408 'Agent name' shown in Slack), and n8n's chat lists agents under their own sidebar links (en.json:695-696); searched 'talk|spreed|nextcloud' in packages/cli/src/modules/agents/integrations: no Nextcloud Talk Note: Missing Nextcloud part: Talk rooms. Rewritten under the lane ruling of 2026-09-26 (was no).
  • dl-webhook-out unknown → partial: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/HttpRequest sends a run's output to any URL (also as the Respond to Webhook node); signing is hand-built with the Crypto node's HMAC (packages/nodes-base/nodes/Crypto); searched 'signature|hmac' in packages/nodes-base/nodes/HttpRequest: no built-in request signing Note: Outbound webhook yes; the signature must be wired by hand.
  • dl-email unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/EmailSend/v2/EmailSendV2.node.ts SMTP send and Gmail/Outlook send operations (packages/nodes-base/nodes/Google/Gmail/v2/GmailV2.node.ts) deliver an agent's output by email
  • dl-notification unknown → partial: source read at n8n@2.40.7, not driven: run alerts are hand-built: packages/nodes-base/nodes/ErrorTrigger starts a workflow when another fails, which can mail or post to chat; the push channel only refreshes open editors (packages/cli/src/modules/agents/agent-execution-update-broadcaster.ts:43); searched 'notification' in packages/nodes-base/nodes/NextCloud: none, the node has no notifications resource Note: No Nextcloud notification and no in-app inbox; an alert needs a workflow built for it.
  • dl-target-pref unknown → no: source read at n8n@2.40.7, not driven: searched 'default delivery|deliveryTarget|preferred channel' in packages/cli/src/modules/agents, chat-hub and packages/@n8n/api-types/src/agents: no per-user default delivery target; each workflow or agent names its own destination node or channel
  • dl-messengers unknown → yes: source read at n8n@2.40.7, not driven: Agents module channels for Slack, Telegram, Discord and Linear (packages/cli/src/modules/agents/agents.module.ts:81-96, en.json:8476-8477 Slack/Telegram help texts); workflows also start from Telegram, WhatsApp, Discord, Slack and Teams trigger nodes (packages/nodes-base/nodes/Telegram, WhatsApp, Discord, Slack, Microsoft/Teams) Note: Teams and Signal are not Agents-module channels; Teams works through workflow trigger nodes, Signal not at all.
  • dl-digest unknown → yes: source read at n8n@2.40.7, not driven: an Agents-module schedule runs an objective on cron (en.json:8112-8113 'Objectives the agent runs on a schedule') and a connected Slack or Discord channel gives the agent a send_channel_message action (packages/cli/src/modules/agents/integrations/integration-tool-definitions.ts:278); workflows do the same with Schedule Trigger plus Slack node Note: Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • dl-dedupe unknown → partial: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/Transform/RemoveDuplicates/v2/RemoveDuplicatesV2.description.ts:11-13 'Remove items processed in previous executions' drops repeats across runs, and the Summarize node counts groups (packages/nodes-base/nodes/Transform/Summarize); searched 'dedupe|collapse' in packages/cli/src/modules/agents: no built-in collapse of identical reports into one with a count Note: Must be wired by hand in a workflow.
  • dl-dashboard-widget unknown → no: source read at n8n@2.40.7, not driven: searched 'dashboard widget|nextcloud dashboard' in packages/nodes-base/nodes/NextCloud and packages/cli/src: no Nextcloud Dashboard widget; n8n's own Insights dashboard (packages/cli/src/modules/insights) shows execution counts, not agent output
  • dl-transcribe unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/vendors/OpenAi/v2/actions/audio/transcribe.operation.ts transcribes audio files to text; chat hub voice input turns speech into text (packages/frontend/editor-ui/src/features/ai/chatHub/components/ChatPrompt.vue:53)
  • dl-embed-web unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/trigger/ChatTrigger/ChatTrigger.node.ts:408-452 'public' chat with an embeddable widget or hosted chat page; packages/frontend/@n8n/chat/README.md:1-3 embeddable chat window with CORS allowed origins
  • ov-approval-inbox unknown → partial: source read at n8n@2.40.7, not driven: waiting runs are findable with the executions list 'Waiting' status (en.json:1621); Agents-module approvals appear as cards inside each conversation (en.json:7676-7684); searched 'inbox|pending approvals' in packages/frontend/editor-ui/src/features: no single inbox of actions awaiting my approval Note: Approvals are scattered across chats, channels and waiting executions.
  • ov-approval-context unknown → partial: source read at n8n@2.40.7, not driven: the approval card names the tool and opens its arguments (en.json:7677 'The agent wants to run the {toolName} tool', 7682 'View tool details'); send-and-wait approval messages carry whatever the builder writes into them (packages/nodes-base/nodes/Telegram/hitl/descriptions.ts:4-47); searched 'reason|impact|affects' in packages/frontend/editor-ui/src/features/agents/components/RichInteractionCard.vue and AgentConfirmationModal.vue: no stated reason or affected objects Note: Shows what will run and with which inputs, not why or what it touches.
  • ov-risk-threshold unknown → yes: source read at n8n@2.40.7, not driven: approval is chosen per tool: packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:382,408,429 requireApproval on custom, workflow and node tools and :283-293 MCP approval 'selected' tools (en.json:7846 'Ask selected'); in workflows only tools wired through a human-in-the-loop node are gated (packages/core/src/execution-engine/node-execution-context/utils/get-input-connection-data.ts:64-77) Note: Static per-tool choice, no risk scoring.
  • ov-talk-reaction unknown → partial: source read at n8n@2.40.7, not driven: one-tap approval inside chat apps other than Talk: packages/nodes-base/nodes/Telegram/hitl/descriptions.ts:4,31 approval buttons in Telegram, packages/nodes-base/nodes/Slack/V2/SlackHitlWebhook.ts Slack approvals; searched 'talk|spreed' in packages/nodes-base/nodes: no Nextcloud Talk Note: Approve from Slack or Telegram, not from Talk.
  • ov-draft-hold unknown → yes: source read at n8n@2.40.7, not driven: a sending tool can require approval before it runs (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:429 requireApproval on node tools such as Gmail or Send Email), and workflow agents can route replies through a Send and Wait approval node before the send step (packages/nodes-base/nodes/Slack/V2/SlackHitlWebhook.ts, packages/nodes-base/nodes/Telegram/hitl/) Note: Configured per tool or wired per workflow.
  • ov-kill-switch unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/commands/unpublish/workflow.ts:8-29 'n8n unpublish:workflow --all' deactivates every workflow from the server shell; packages/cli/src/executions/executions.controller.ts:118 POST /stopMany stops running executions; the chat hub and Instance AI have admin on/off switches (packages/cli/src/modules/chat-hub/chat-hub.settings.controller.ts:73 PUT /enabled) Note: No single UI switch that stops every agent, and Agents-module agents are not covered by the CLI command.
  • ov-kill-agent unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/executions/executions.controller.ts:102-110 POST /:id/stop halts a running execution and :475 of packages/cli/src/workflows/workflows.controller.ts deactivates the workflow; Agents module: packages/cli/src/modules/agents/agent-chat.controller.ts:248 DELETE /:agentId/chat/runs/:runId stops a run and agent-publish.controller.ts:45 unpublishes
  • ov-guardrail-input unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/Guardrails/description.ts:71-72 'Sanitize Text' operation with PII (:138-156, all or selected entities) and secret-key detection (:174-200, strict/balanced/permissive), actions/checks/pii.ts and secretKeys.ts; placed before the AI Agent node in a workflow Note: A shipped node, placed by the builder in front of the agent.
  • ov-guardrail-output partial → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/Guardrails/description.ts:65-66 'Check Text for Violations' with keywords, jailbreak, NSFW, PII, topical alignment and URL checks (:99-273; actions/checks/*.ts), routing passing and failing text to separate outputs Note: Old partial rested on a Bedrock guardrail-version line; the Guardrails node checks output directly.
  • ov-tool-risk unknown → partial: source read at n8n@2.40.7, not driven: tools can be marked 'Require approval' one by one (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:382,408,429; en.json:7840-7841); searched 'risk|riskLevel|dangerous' in packages/cli/src/modules/agents and packages/@n8n/api-types/src/agents: no risk classes for tools and no stronger checks tied to a class Note: Per-tool approval, no risk classification.
  • ov-egress unknown → partial: source read at n8n@2.40.7, not driven: packages/@n8n/config/src/configs/ssrf-protection.config.ts:91-146 SSRF protection (off by default) blocks private IP ranges and N8N_SSRF_BLOCKED_HOSTNAMES instance-wide; credentials can restrict HTTP Request domains (packages/workflow/src/credential-domain-restrictions.ts:10-20 allowedHttpRequestDomains); searched 'allowlist|egress' in packages/cli/src/modules/agents: no per-agent list of allowed web addresses Note: Instance-wide blocking and per-credential domains; nothing per agent.
  • ov-anonymise unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/Guardrails/description.ts:71-72,138-156 'Sanitize Text' replaces detected PII in text before it reaches a model; document text comes from the Extract From File node (packages/nodes-base/nodes/Files/ExtractFromFile) Note: Works on extracted text; wired in the workflow before the model step.
  • ov-ai-oversight unknown → partial: source read at n8n@2.40.7, not driven: past runs can be reviewed in the executions list and per-run logs (packages/frontend/editor-ui/src/features/execution/executions, logs/components/LogsPanel.vue) and in Agents-module session timelines (packages/frontend/editor-ui/src/features/agents/views/AgentSessionTimelineView.vue); searched 'oversight|review decision' in packages/frontend/editor-ui/src/features: no page that gathers AI decisions for review Note: Run history exists; there is no oversight page for AI decisions.
  • ov-automation-bias unknown → no: source read at n8n@2.40.7, not driven: searched 'automation bias|rubber|approval rate|approve all' in packages/cli/src/modules/agents, packages/frontend/editor-ui/src/features/agents and packages/core/src/execution-engine/node-execution-context/utils/get-input-connection-data.ts: approvals are recorded per call only, with no warning about approving without looking
  • co-audit-log unknown → partial: source read at n8n@2.40.7, not driven: runs are stored as executions and AI tool calls emit 'n8n.ai.tool.called' events (packages/cli/src/eventbus/event-message-classes/index.ts:16,35); the append-only copy lives outside n8n only when log streaming is on, packages/cli/src/modules/log-streaming.ee/log-streaming.controller.ts:46 @licensed('feat:logStreaming'); executions are prunable and deletable (packages/@n8n/config/src/configs/executions.config.ts:106-111) Note: Local history can be deleted or pruned; a tamper-evident trail needs the enterprise-licensed log streaming to an outside store.
  • co-audit-export unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/modules/log-streaming.ee/destinations/ streams audit and AI events to syslog, webhook or Sentry, licence-gated at log-streaming.controller.ts:46,57 @licensed('feat:logStreaming'); executions can be exported per run through the public API (packages/cli/src/public-api/v1/handlers/executions/spec/paths/getExecutions.generated.yml:18) Note: Enterprise-licensed; no one-file audit export for an auditor.
  • co-retention unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/config/src/configs/executions.config.ts:106-126 EXECUTIONS_DATA_PRUNE (on by default), EXECUTIONS_DATA_MAX_AGE 336 hours and max count 10,000 with a hard-delete buffer; agent checkpoints expire after N8N_AGENTS_CHECKPOINT_TTL (packages/@n8n/config/src/configs/agents.config.ts:38-39) Note: Set by the operator in environment variables, not in the UI.
  • co-ai-register unknown → no: source read at n8n@2.40.7, not driven: searched 'ai register|risk class|AI Act|inventory' in packages/cli/src and packages/frontend/editor-ui/src: no register of AI features with a risk class
  • co-risk-class unknown → no: source read at n8n@2.40.7, not driven: searched 'AI Act|42001|risk class|DPIA|data protection officer|incident|factsheet|algoritme' in packages/cli/src, packages/frontend/editor-ui/src and packages/frontend/@n8n/i18n/src (only hit: an onboarding survey option 'Incident response', en.json:2768): no EU AI Act risk classification of agents
  • co-dpo-ack unknown → partial: source read at n8n@2.40.7, not driven: workflow reviews let an author request named reviewers (packages/@n8n/db/src/entities/workflow-review-request-reviewer.ee.ts) and block publishing while a review is open or changes are requested (packages/cli/src/modules/workflow-reviews.ee/workflow-review-publish-guard.service.ts:8-22), licence-gated by feat:workflowReviews (packages/@n8n/constants/src/index.ts:58); searched 'data protection officer|DPIA|high-risk' in packages/cli/src: no DPO role or risk trigger Note: A DPO can be named as reviewer by hand; nothing ties sign-off to high-risk features. Enterprise-licensed.
  • co-control-packs unknown → no: source read at n8n@2.40.7, not driven: searched 'AI Act|42001|risk class|DPIA|data protection officer|incident|factsheet|algoritme' in packages/cli/src, packages/frontend/editor-ui/src and packages/frontend/@n8n/i18n/src (only hit: an onboarding survey option 'Incident response', en.json:2768); the security audit checks instance hygiene (packages/cli/src/security-audit/risk-reporters/ credentials, database, filesystem, instance, nodes), not a control framework
  • co-factsheet unknown → no: source read at n8n@2.40.7, not driven: searched 'AI Act|42001|risk class|DPIA|data protection officer|incident|factsheet|algoritme' in packages/cli/src, packages/frontend/editor-ui/src and packages/frontend/@n8n/i18n/src (only hit: an onboarding survey option 'Incident response', en.json:2768): no generated fact sheet for an agent's model, data and purpose
  • co-compliance-export unknown → partial: source read at n8n@2.40.7, not driven: packages/cli/src/commands/audit.ts:27 'Generate a security audit report for this n8n instance' and public API packages/cli/src/public-api/v1/handlers/audit/audit.handler.ts return one risk report (packages/cli/src/security-audit/risk-reporters/: credentials, database, filesystem, instance, nodes); searched 'AI Act|42001|compliance report' in packages/cli/src: no AI compliance report Note: A one-shot security risk report, not an AI compliance report.
  • co-incident unknown → no: source read at n8n@2.40.7, not driven: searched 'AI Act|42001|risk class|DPIA|data protection officer|incident|factsheet|algoritme' in packages/cli/src, packages/frontend/editor-ui/src and packages/frontend/@n8n/i18n/src (only hit: an onboarding survey option 'Incident response', en.json:2768): no record of AI incidents, impact or follow-up
  • co-authority-notify unknown → no: source read at n8n@2.40.7, not driven: searched 'authority|regulator|attest|access review|transparency|residency|data location' in packages/cli/src and packages/frontend/editor-ui/src: no incident register and no notification to an authority
  • co-access-review unknown → no: source read at n8n@2.40.7, not driven: searched 'authority|regulator|attest|access review|transparency|residency|data location' in packages/cli/src and packages/frontend/editor-ui/src: no periodic review in which owners attest that an agent is still needed; user and project membership pages exist but carry no review cycle
  • co-transparency unknown → no: source read at n8n@2.40.7, not driven: searched 'authority|regulator|attest|access review|transparency|residency|data location' in packages/cli/src and packages/frontend/editor-ui/src: no published plain-language explanation of agents for employees
  • co-residency unknown → no: source read at n8n@2.40.7, not driven: searched 'authority|regulator|attest|access review|transparency|residency|data location' in packages/cli/src and packages/frontend/editor-ui/src: no view of where each AI feature processes data; a model credential only holds its endpoint (packages/nodes-base/credentials/OpenAiApi.credentials.ts:35-36 Base URL)
  • co-disable-dept unknown → partial: source read at n8n@2.40.7, not driven: a project's node type policy can block AI node types for that project (packages/cli/src/modules/type-availability-policies/type-availability-policy-project.controller.ts:19-24), licence-gated in type-availability-policies.module.ts:10-12 licenseFlag NODE_TYPE_POLICIES and not in the default module list; the chat hub has only an instance-wide switch (packages/cli/src/modules/chat-hub/chat-hub.settings.controller.ts:73) Note: Per project (as a department) with an enterprise licence and an opt-in module; proof is the policy itself, no report.
  • ob-trace partial → yes: source read at n8n@2.40.7, not driven: the Logs panel shows each node, model call and tool call of a run in order with inputs and outputs (packages/frontend/editor-ui/src/features/execution/logs/components/LogsOverviewPanel.vue, LogDetailsPanel.vue, LogsViewRunData.vue); Agents-module session timeline with tool calls and token use per message (packages/frontend/editor-ui/src/features/agents/views/AgentSessionTimelineView.vue, en.json:1435 'Token Usage') Note: Old partial rested on a generic execution-history line; logs show every step in order.
  • ob-analytics unknown → partial: source read at n8n@2.40.7, not driven: Insights shows production executions, failure rate, time saved and average run time (en.json:6750-6755; packages/cli/src/modules/insights), the full dashboard behind feat:insights:viewDashboard (packages/@n8n/constants/src/index.ts:46); searched 'cost|tool use' in packages/cli/src/modules/insights: no cost or tool-use metrics across agents Note: Success and speed per workflow; no cost or tool use; dashboard is enterprise-licensed.
  • ob-cost-per-run unknown → yes: source read at n8n@2.40.7, not driven: Agents-module sessions show token usage and cost per message (en.json:1435 'Token Usage', 1492 'Cost'; cost from the model catalog, packages/@n8n/agents/src/sdk/catalog.ts:215-217 and runtime/loop/agent-runtime.ts:1234, recorded in packages/cli/src/modules/agents/execution-recorder.ts:472); workflow Logs panel shows tokens per model call (packages/frontend/editor-ui/src/features/execution/logs/components/LogsViewConsumedTokenCountText.vue) Note: Cost only in the opt-in Agents module; workflow runs show tokens, not cost.
  • ob-budget unknown → no: source read at n8n@2.40.7, not driven: searched 'budget|spend limit|hard stop' in packages/cli/src/modules/agents, chat-hub and packages/@n8n/agents/src: no user-set spending budget; the only budget is n8n's own AI gateway credit quota from the licence (packages/cli/src/services/frontend.service.ts:600 quota:aiGatewayBudget)
  • ob-estimate unknown → no: source read at n8n@2.40.7, not driven: searched 'estimate|estimated cost|forecast' in packages/cli/src/modules/agents, packages/@n8n/agents/src and packages/frontend/editor-ui/src/features/agents: cost is recorded after a run (packages/cli/src/modules/agents/execution-recorder.ts:472), never predicted before it starts; Insights 'time saved' estimates (en.json:6745) concern time, not cost
  • ob-fail-alert unknown → yes: source read at n8n@2.40.7, not driven: packages/nodes-base/nodes/ErrorTrigger starts a chosen error workflow whenever a workflow fails (set per workflow in its settings as errorWorkflow), which then mails or posts the alert with any node; Agents-module channel failures show as 'Not running' (en.json:8554) Note: The alert channel is whatever the error workflow sends to.
  • ob-drift unknown → no: source read at n8n@2.40.7, not driven: searched 'drift|regression|anomal' in packages/cli/src/modules/agents, agent-evals, insights and packages/@n8n/agents/src: no watch on result quality over time; evaluations run only when started
  • ob-metrics partial → yes: source read at n8n@2.40.7, not driven: packages/@n8n/config/src/configs/endpoints.config.ts:8 N8N_METRICS enables a Prometheus /metrics endpoint (packages/cli/src/metrics/prometheus/, event-bus-metrics.service.ts) and /healthz health checks for monitoring Note: Old partial rested on a /healthz bug fix; Prometheus metrics and health endpoints ship.
  • ob-external-tracing unknown → yes: source read at n8n@2.40.7, not driven: packages/cli/src/modules/otel (default module, packages/@n8n/backend-common/src/modules/module-registry.ts:70) exports workflow and agent spans over OTLP (otel.config.ts:9-21 endpoint, protocol, headers), agent spans toggled by N8N_AGENTS_TRACING_ENABLED (packages/@n8n/config/src/configs/agents.config.ts:49-50); LangChain nodes honour LANGCHAIN_TRACING_V2 and agent sessions export to LangSmith (packages/cli/src/modules/agents/agent-session-langsmith-export.service.ts:29) Note: Langfuse is reached through its OTLP endpoint, not a named integration.
  • ob-reports unknown → no: source read at n8n@2.40.7, not driven: searched 'report|digest|weekly' in packages/cli/src/modules/insights and agents: no periodic usage report for people; packages/cli/src/modules/instance-reporting.ee/instance-reporting.module.ts sends daily billable execution numbers to a monitoring receiver, opt-in and not a report about agent use
  • ob-feedback-stats unknown → partial: source read at n8n@2.40.7, not driven: ratings exist only on evaluation runs: en.json:8317-8318 thumbs up/down per case and en.json:8301 '{reviewed} of {total} reviewed' in the agent's Evals tab (packages/cli/src/modules/agent-evals/agent-eval-rating.service.ts); searched 'feedback|rating' in packages/cli/src/modules/chat-hub and insights: no per-agent statistics of how people rated live answers Note: Only test-case reviews in an opt-in, flag-gated module.
  • fl-subagent unknown → yes: source read at n8n@2.40.7, not driven: packages/@n8n/nodes-langchain/nodes/agents/Agent/AgentTool.node.ts:10-11 'AI Agent Tool' lets one agent call another as a tool; Agents-module sub-agents with 'use when' hints and delegation (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:132-173, en.json:7996-7997)
  • fl-run-history partial → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/execution/executions/views/WorkflowExecutionsView.vue the workflow's Executions tab lists its runs and opens each one on the canvas with the data each node produced Note: Old partial rested on a generic execution-history line; runs open on the canvas.
  • fl-seed-flows unknown → yes: source read at n8n@2.40.7, not driven: packages/frontend/editor-ui/src/features/workflows/readyToRun/workflows/aiWorkflow.ts ships a ready-to-run AI workflow (ReadyToRunButton.vue); the template library loads from packages/@n8n/config/src/configs/templates.config.ts:10-11 N8N_TEMPLATES_HOST https://api.n8n.io/api/ (features/workflows/templates/) Note: Most templates come from n8n's online library, so an offline instance sees only the bundled one.
  • fl-n8n unknown → yes: source read at n8n@2.40.7, not driven: this row describes n8n itself: an AI Agent calls another workflow through the Call n8n Workflow Tool (packages/@n8n/nodes-langchain/nodes/tools/ToolWorkflow), and Agents-module agents attach published workflows as tools (packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:401-420, en.json:7820-7829)
  • fl-validate unknown → yes: source read at n8n@2.40.7, not driven: the canvas flags node issues before a run, e.g. en.json:4502-4504 'Credentials for {type} are not set'; Agents module validates the whole agent (packages/cli/src/modules/agents/agents-config.controller.ts:40-55 GET /:agentId/validation) and blocks preview or publish with named issues (en.json:7734-7763)
  • re-store unknown → yes: source read at n8n@2.40.7, not driven: en.json:4462 'Workflow templates' gallery with en.json:4445-4446 'Try template' and 'Use this workflow' (packages/frontend/editor-ui/src/features/workflows/templates/, setupTemplate.store.ts), fed by api.n8n.io (packages/@n8n/config/src/configs/templates.config.ts:10-11) and including AI agent workflows Note: Online library; an offline instance loses it.
  • re-template-from-agent unknown → partial: source read at n8n@2.40.7, not driven: an agent can be duplicated within its project (en.json:7721 'Duplicate', packages/frontend/editor-ui/src/features/agents/views/AgentsListView.vue:136-174) or exported as JSON (en.json:7613); searched 'publish template|create template' in packages/cli/src and packages/frontend/editor-ui/src/features/workflows/templates: no way to publish one's own agent or workflow as an in-instance template Note: Reuse by copy or file, not a template others browse.
  • re-template-github unknown → partial: source read at n8n@2.40.7, not driven: workflows sync to a Git repository with source control (packages/cli/src/modules/source-control.ee, feat:sourceControl at packages/@n8n/constants/src/index.ts:22); searched 'github' in packages/frontend/editor-ui/src/features/workflows/templates: templates come only from api.n8n.io, no GitHub discovery or install Note: Git sync is enterprise-licensed and is not template search or publishing.
  • re-template-approve unknown → no: source read at n8n@2.40.7, not driven: searched 'template approv|approve template' in packages/cli/src and packages/frontend/editor-ui/src: none; workflow reviews (packages/@n8n/constants/src/index.ts:58 feat:workflowReviews, packages/frontend/editor-ui/src/features/workflow-reviews/) approve changes to a workflow, not templates for the organisation
  • re-baseline unknown → yes: source read at n8n@2.40.7, not driven: workflow evaluation runs compare side by side with Cases, Outputs, Metrics and 'Workflow diff' tabs (en.json:6521-6524; packages/frontend/editor-ui/src/features/ai/evaluation.ee/components/Compare/CasesTable.vue:113-174 delta vs best, WorkflowDiffTab.vue), so a changed prompt is scored against the previous version before publishing Note: Evaluations are quota-limited by licence (packages/@n8n/constants/src/index.ts:73).
  • re-template-cross-tenant unknown → partial: source read at n8n@2.40.7, not driven: a workflow moves to another project with packages/cli/src/workflows/workflows.controller.ts:646 PUT /:workflowId/transfer, or to another instance by JSON export/import (packages/cli/src/commands/export/workflow.ts, import/workflow.ts); projects are not isolated client organisations (see op-multi-tenant) Note: Moves between projects or instances; no tenant concept.
  • re-course-recs unknown → no: source read at n8n@2.40.7, not driven: searched 'course|learner|curriculum|recommend' in packages/cli/src and packages/frontend/editor-ui/src: no learning features; out of n8n's domain
  • op-airgap unknown → partial: source read at n8n@2.40.7, not driven: outbound calls can be switched off: packages/@n8n/config/src/configs/diagnostics.config.ts:17 N8N_DIAGNOSTICS_ENABLED, version-notifications.config.ts:6, templates.config.ts:6 N8N_TEMPLATES_ENABLED, packages/cli/src/modules/community-packages/community-packages.config.ts:11,15 own npm registry; local models via LMChatOllama; but instance AI setup, AI credits and licence activation and renewal reach the licence server (packages/cli/src/license.ts:73-98) Note: Workflows with local models run offline; enterprise licence activation and the managed AI features need the internet.
  • op-multi-tenant unknown → partial: source read at n8n@2.40.7, not driven: projects separate workflows, credentials and agents with project roles (packages/cli/src/modules/agents/entities/agent.entity.ts:13-18, packages/@n8n/permissions/src/roles/scopes/project-scopes.ee.ts); team projects are limited by the licence quota quota:maxTeamProjects (packages/@n8n/constants/src/index.ts:67); users, SSO, models and settings stay instance-wide Note: Group separation inside one organisation, not tenants with their own admins and settings.
  • op-tenant-quota unknown → no: source read at n8n@2.40.7, not driven: searched 'quota' per project in packages/cli/src/services/project.service.ee.ts and packages/cli/src/modules: quotas come from the instance licence (packages/@n8n/constants/src/index.ts:63-74), none can be set per project or organisation
  • op-tenant-ops unknown → no: source read at n8n@2.40.7, not driven: searched 'tenant|organisation|organization' in packages/cli/src/controllers and packages/frontend/editor-ui/src/features/settings: no operations page that sets switches, quotas and retention per organisation; retention is instance-wide by environment variable (packages/@n8n/config/src/configs/executions.config.ts:106-111)
  • op-admin-settings yes → partial: source read at n8n@2.40.7, not driven: n8n is configured in its own Settings pages (packages/frontend/editor-ui/src/features/settings/: users, sso, apiKeys, communityNodes, chat hub providers at en.json:3665-3668) and environment variables (packages/@n8n/config/src/configs/); searched 'nextcloud' in packages/frontend/editor-ui/src: no Nextcloud admin integration Note: Own settings, not Nextcloud's.
  • op-setup-wizard unknown → yes: source read at n8n@2.40.7, not driven: n8n Assistant onboarding walks an admin through connecting a model (en.json:5358-5365 'Get started', 'Connect a model'; setup state checked in packages/frontend/editor-ui/src/features/ai/instanceAi useInstanceAiReady), and a new agent then opens in that assistant to be built (packages/frontend/editor-ui/src/features/agents/views/NewAgentView.vue:58-83)
  • op-flat-cost unknown → partial: source read at n8n@2.40.7, not driven: the self-hosted community edition runs without seat or message metering; licensed plans carry quotas such as quota:users and quota:activeWorkflows (packages/@n8n/constants/src/index.ts:63-65) and report billable execution counts daily (packages/cli/src/modules/instance-reporting.ee/instance-reporting.module.ts) Note: Free self-hosting is flat; paid tiers meter users and executions. Pricing itself is not in the code.
  • op-scale partial → yes: source read at n8n@2.40.7, not driven: queue mode spreads executions over worker processes (packages/@n8n/config/src/configs/executions.config.ts:90-91 EXECUTIONS_MODE, packages/cli/src/commands/worker.ts, packages/cli/src/scaling/job-processor.ts); several main instances need a licence (packages/cli/src/scaling/multi-main-setup.ee.ts, feat:multipleMainInstances) Note: Workers are free; multi-main high availability is enterprise-licensed. Old partial rested on a bug-fix line.
  • op-outside-agent unknown → yes: source read at n8n@2.40.7, not driven: outside agents connect to the instance MCP server with an API key or OAuth client (packages/cli/src/modules/mcp/mcp-api-key.service.ts, packages/cli/src/modules/oauth-server) and act as the user who issued it; packages/cli/src/modules/mcp/mcp-scopes.ts:13-50 grantable scopes limit which tools they may call (workflow:read, workflow:write, workflow:execute, agent:read ...), and workflows or agents opt in to MCP one by one (agent.entity.ts:39-40 availableInMCP)
  • op-preferences unknown → partial: source read at n8n@2.40.7, not driven: Settings > Context > Preferences holds per-user or shared guidance (en.json:3234-3258, scope 'Just you' or 'Everyone'), used by the n8n Assistant and connected AI tools, and shown only when a PostHog flag is on (packages/frontend/editor-ui/src/features/settings/context/context.utils.ts:20-25); searched 'preference' in packages/cli/src/modules/agents: agents people build do not read them Note: Preferences steer n8n's own assistant, behind a rollout flag.
  • ch-shared-session unknown → partial: source read at n8n@2.40.7, not driven: in the opt-in Agents module a Slack or Discord thread is one shared conversation whose memory belongs to the thread, not the author (packages/cli/src/modules/agents/utils/agent-memory-scope.ts:9-20); chat hub conversations are private to one user (packages/cli/src/modules/chat-hub/chat-hub.controller.ts:110 by req.user.id) Note: Shared only through a chat platform channel, not in n8n's own chat.
  • ch-intake unknown → partial: source read at n8n@2.40.7, not driven: a public chat page or embedded widget needs no n8n account (packages/@n8n/nodes-langchain/nodes/trigger/ChatTrigger/ChatTrigger.node.ts:408-452 'public', packages/frontend/@n8n/chat), and the agent behind it can file a request with any tool node; the filing flow has to be built as a workflow Note: The anonymous chat is shipped; the request filing is hand-built.
  • me-rag-files unknown → partial: source read at n8n@2.40.7, not driven: the Nextcloud node downloads files (packages/nodes-base/nodes/NextCloud/NextCloud.node.ts:124-125 download) that a Default Data Loader and a vector store insert node index (packages/@n8n/nodes-langchain/nodes/document_loaders/DocumentDefaultDataLoader, nodes/vector_store/), then a vector store tool grounds the agent (nodes/tools/ToolVectorStore); searched 'nextcloud' in packages/cli/src/modules/agents and chat-hub: knowledge upload takes local files only Note: Works as a hand-built ingestion workflow; no Nextcloud source in the agent's knowledge settings.
  • me-permissions unknown → no: source read at n8n@2.40.7, not driven: searched 'permission|acl|access' in packages/cli/src/modules/agents/agent-knowledge-retrieval.ts, tools/knowledge/ and packages/@n8n/nodes-langchain/nodes/vector_store/shared: retrieval returns whatever the agent's store holds, with only static metadata filters (packages/@n8n/agents/src/sdk/vector-store-filter.ts:5-19); nothing trims results to what the asking person may see
  • me-context-docs unknown → yes: source read at n8n@2.40.7, not driven: Agents-module skills carry markdown reference files next to their instructions (en.json:8077-8084 'References', 'Markdown reference'; packages/frontend/editor-ui/src/features/agents/components/AgentSkillFileNav.vue) and agents search uploaded Markdown or PDF knowledge files (en.json:7925) Note: Agents module is opt-in (not in module-registry.ts:44 defaultModules).
  • sk-share-tenants unknown → no: source read at n8n@2.40.7, not driven: skills are stored inside one agent (packages/cli/src/modules/agents/entities/agent.entity.ts:35-36 skills column); searched 'share' in packages/cli/src/modules/agents/agents-skills.controller.ts and agent-skills.service.ts: no sharing of a skill with other projects or organisations; the shared Skills area is 'Coming soon' (en.json:3231-3232)
  • co-algoritmeregister unknown → no: source read at n8n@2.40.7, not driven: searched 'algoritme|algorithm register|algoritmeregister' in packages/cli/src, packages/nodes-base/nodes and packages/frontend/editor-ui/src: no connection to the Dutch Algoritmeregister
  • co-dpia unknown → no: source read at n8n@2.40.7, not driven: searched 'DPIA|IAMA|fundamental rights|impact assessment' in packages/cli/src, packages/@n8n/api-types/src/agents and packages/frontend/editor-ui/src: no link from an agent or workflow to an assessment record
  • fl-parallel unknown → yes: source read at n8n@2.40.7, not driven: Agents-module sub-agents run in parallel up to a set number (en.json:8010-8011 'Max parallel sub-agents', packages/@n8n/api-types/src/agents/agent-json-config.schema.ts:151-159 maxChildren) with tool calls in parallel (:517 toolCallConcurrency, en.json:7906); background sub-agents that outlive the turn need N8N_AGENTS_BACKGROUND_TASKS_ENABLED (packages/@n8n/config/src/configs/agents.config.ts:79-80, default false) Note: Agents module is opt-in; in workflows an AI Agent can call several AI Agent Tool nodes, and branches run in sequence.
  • op-languages unknown → no: source read at n8n@2.40.7, not driven: packages/frontend/@n8n/i18n/src/locales/ holds only en.json; packages/@n8n/config/src/index.ts:253-254 N8N_DEFAULT_LOCALE defaults to 'en' with no Dutch locale shipped Note: Agents answer in Dutch if prompted in Dutch; the product UI is English only.

open-webui: every rating change (before → after, evidence)

  • ag-create unknown → yes: source read at v0.11.4, not driven: an agent is a workspace Model: src/lib/components/workspace/Models/ModelEditor.svelte:789 name, :962 description, :1055 system prompt, :856 base model; backend/open_webui/routers/models.py:285 POST /models/create; backend/open_webui/models/models.py:111 model table (id, user_id, base_model_id, params, meta)
  • ag-list unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Models.svelte:808 owner name per row, :899 Enabled/Disabled switch; backend/open_webui/routers/models.py:162 GET /models/list (admins see all with BYPASS_ADMIN_ACCESS_CONTROL, :198), :245 GET /models/all admin; admin Settings > Models lists every model (src/lib/components/admin/Settings/Models.svelte)
  • ag-detail unknown → partial: source read at v0.11.4, not driven: src/lib/components/workspace/Models/ModelEditor.svelte:1194-1275 config, knowledge, tools, skills, filters, capabilities on one page; schedules live apart in /automations (src/routes/(app)/automations/[id]/+page.svelte) keyed by model_id (backend/open_webui/models/automations.py:73) and per-model chats in admin analytics (routers/analytics.py:285, :343) Note: no single page joins an agent's config with its schedules and runs
  • ag-model unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Models/ModelEditor.svelte:856 'Base Model (From ...)' selector; backend/open_webui/models/models.py:118 base_model_id = upstream model; providers are the Ollama/OpenAI-compatible/Anthropic connections (routers/ollama.py, routers/openai.py, utils/anthropic.py)
  • ag-visibility partial → yes: source read at v0.11.4, not driven: src/lib/components/workspace/common/AccessControl.svelte:19 principal_type user|group|anyone; ModelEditor.svelte:600 AccessControlModal; backend/open_webui/routers/models.py:1035 POST /model/access/update; models/access_grants.py grants read/write per user or group; config.py sharing.public_models permission gates 'whole organisation' Note: old partial rested on a feature-row line; the code has private, per-user, per-group and public grants
  • ag-enable unknown → yes: source read at v0.11.4, not driven: backend/open_webui/models/models.py:122 is_active soft-disable; routers/models.py:881 POST /model/toggle; src/lib/components/workspace/Models.svelte:899 Enabled/Disabled switch per model, :353 Enable All / Disable All
  • ag-owner unknown → yes: source read at v0.11.4, not driven: backend/open_webui/models/models.py:117 user_id owner; src/lib/components/workspace/Models.svelte:802-808 owner name and email shown per model, 'Deleted User' when the owner is gone; routers/models.py:948 only owner, write grantee or admin may update Note: owner is always the creator; there is no field to name a different accountable person
  • ag-offboard unknown → partial: source read at v0.11.4, not driven: searched 'transfer|reassign|owner' in backend/open_webui/routers and models: no ownership transfer; models/users.py:847 delete_user_by_id leaves models orphaned (Models.svelte:808 'Deleted User'); workaround: routers/models.py:1035 write grant to another user or group so they can keep maintaining it
  • ag-nl-builder unknown → no: source read at v0.11.4, not driven: searched 'generate|describe|builder|magic' in src/lib/components/workspace/Models/ModelEditor.svelte and backend/open_webui/routers/models.py: model presets are built by hand; the only natural-language builder is /skills:create for skills (backend/open_webui/utils/skills.py:81), not agents
  • ag-app-slug unknown → partial: source read at v0.11.4, not driven: src/lib/components/workspace/Models/ModelEditor.svelte:836 stable Model ID that other programs pass as 'model' to the OpenAI-compatible /api/chat/completions (backend/open_webui/main.py:1118 model_id lookup); no binding of an agent to a consuming app and no per-app discovery Note: an app can call an agent by its id, but nothing ties the agent to that app
  • ag-capability-profile unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Models/ModelEditor.svelte:1194 Knowledge, :1198 ToolsSelector, :1202 SkillsSelector, :1206 filters/actions, :1245 Capabilities, :1262 BuiltinTools, :1268 TerminalSelector, all on the model edit page
  • ag-delete unknown → partial: source read at v0.11.4, not driven: backend/open_webui/routers/models.py:1111 POST /model/delete removes the model only; automations store model_id (backend/open_webui/models/automations.py:73) and routers/models.py has no Automations call, so a schedule keeps firing and fails with 'Model not found' at main.py:1128 Note: schedules are not stopped with the agent
  • ag-import-export unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/models.py:381 GET /models/export, :441 POST /models/import (ownership check :515); src/lib/components/workspace/Models.svelte:109 Import JSON, :115 Export JSON; permissions workspace.models_import/models_export in config.py DEFAULT_USER_PERMISSIONS Note: JSON file moves an agent to another Open WebUI instance
  • ch-sessions unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/chats.py:249 GET /chats/list, :774 POST /chats/new, :1325 GET /chats/{id}; sidebar chat list src/lib/components/layout/Sidebar.svelte reopens earlier chats at /c/[id]
  • ch-session-delete unknown → partial: source read at v0.11.4, not driven: backend/open_webui/routers/chats.py:1568 DELETE /chats/{id} permanent, :1909 POST /{id}/archive toggles archive, :1061 GET /archived; src/lib/components/chat/Settings/ArchivedChats.svelte restores; searched 'trash|recycle|restore|bin' in en-US translation.json: no bin Note: archive is the only undo; a deleted chat cannot be restored

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 7 of 8

open-webui (continued)

  • ch-tool-steps unknown → yes: source read at v0.11.4, not driven: src/lib/components/chat/Messages/StructuredOutputRenderer.svelte:116 renders each tool call with src/lib/components/common/ToolCallDisplay.svelte:233-246 ('Executing {{NAME}}', 'View Result from {{NAME}}', 'Denied {{NAME}}'), expandable arguments and result
  • ch-attach unknown → partial: source read at v0.11.4, not driven: src/lib/components/chat/MessageInput/InputMenu.svelte:209 Upload Files, :322 Attach Notes, :353 Attach Knowledge, :399 Google Drive, :692 OneDrive/SharePoint; backend/open_webui/routers/files.py upload then RAG; searched 'nextcloud|webdav' in backend/open_webui and src/lib: no Nextcloud Files source Note: attaching files works, but not from Nextcloud
  • ch-companion unknown → no: source read at v0.11.4, not driven: searched 'companion|floating|spotlight|nextcloud' in src/lib/components and src/routes: the chat is its own web app; the Spotlight-style chat bar is a separate desktop app repo (README.md:100 open-webui/desktop), not core, and nothing embeds into Nextcloud pages
  • ch-object-leaf unknown → no: source read at v0.11.4, not driven: searched 'nextcloud|record|object context' in backend/open_webui/utils/middleware.py and src/lib/components/chat: no integration that passes the record open in another app; closest is the iframe postMessage 'input:prompt' handler at src/lib/components/chat/Chat.svelte:1470 which only pre-fills text
  • ch-prompt-library unknown → partial: source read at v0.11.4, not driven: backend/open_webui/routers/prompts.py:71 prompt list with access grants (:441), :384 versioning; src/lib/components/chat/MessageInput/Commands/Prompts.svelte '/' picker; per-model suggestion prompts ModelEditor.svelte:1183; no binding of prompts to a record type Note: org prompt library exists; not scoped to record types
  • ch-smart-picker unknown → no: source read at v0.11.4, not driven: searched 'smart picker|reference provider|nextcloud' in backend/open_webui and src/lib: Open WebUI is standalone and offers no picker inside other apps' text fields; in-app only via note AI menu (src/lib/components/notes/AIMenu.svelte:42)
  • ch-text-tasks unknown → partial: source read at v0.11.4, not driven: src/lib/components/notes/AIMenu.svelte:42 one-click 'Enhance' on a note; NoteEditor.svelte:154-157 suggested 'Summarize this note.', 'Rewrite the selected text.'; src/lib/components/chat/ContentRenderer/FloatingButtons.svelte:26 Ask, :33 Explain on selected text; searched 'translate' in those components: no one-click translate Note: only inside notes and chat selections, no one-click translate
  • ch-search-history unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/chats.py:865 GET /chats/search over title and message content with snippet (:178 chat_search_snippet); src/lib/components/layout/SearchModal.svelte 'Search Chats'; agent-side tool tools/builtin.py:1512 search_chats
  • sc-cron yes → partial: source read at v0.11.4, not driven: schedules are iCalendar RRULE, not cron: backend/open_webui/models/automations.py:76 rrule; utils/recurrence.py:37 _parse_rule (dateutil rrulestr); src/lib/components/automations/ScheduleDropdown.svelte:33 'Custom' free-text field with placeholder RRULE:FREQ=DAILY;BYHOUR=9 (:223); searched 'cron' in backend/open_webui/utils and routers/automations.py: none Note: same power as cron via RRULE, but no cron syntax
  • sc-once unknown → yes: source read at v0.11.4, not driven: src/lib/components/automations/ScheduleDropdown.svelte:28 'Once' builds DTSTART + RRULE:FREQ=DAILY;COUNT=1 (:69, detection :110); backend/open_webui/utils/recurrence.py:106 validate_rrule requires DTSTART with COUNT
  • sc-nl unknown → yes: source read at v0.11.4, not driven: backend/open_webui/tools/builtin.py:3709 create_automation built-in tool: the chat model turns 'every weekday at eight' into an RRULE (docstring examples :3723-3728), plus :3817 update_automation and :3921 list_automations, gated by features.automations permission
  • sc-timezone unknown → yes: source read at v0.11.4, not driven: backend/open_webui/models/automations.py:319-330 claim_due fetches each owner's User.timezone and reschedules with it; utils/recurrence.py:128 next_run_ns evaluates the rule on local wall-clock time then attaches ZoneInfo (:137), so 08:00 stays 08:00 across DST
  • sc-run-now unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/automations.py:334 POST /automations/{id}/run; src/lib/components/automations/AutomationItemHeaderActions.svelte:33 'Run now', AutomationMenu.svelte:96 'Run Now'; src/routes/(app)/automations/+page.svelte:196 runAutomationById
  • sc-webhook unknown → partial: source read at v0.11.4, not driven: inbound channel webhooks only post a message: backend/open_webui/routers/channels.py:2005 POST /channels/webhooks/{id}/{token} does not call model_response_handler (:976, only invoked at :1244 for user posts); another system can start a model turn only by calling the OpenAI-compatible API with an API key (routers/auths.py:1529, main.py:1118) Note: no webhook trigger bound to an agent; API call is the only machine start
  • sc-webhook-secret unknown → partial: source read at v0.11.4, not driven: channel webhook token is minted once (backend/open_webui/models/channels.py:937 secrets.token_urlsafe) with no regenerate endpoint; revoke only by deleting the webhook (routers/channels.py:1963); the API key used for machine starts can be regenerated or deleted (routers/auths.py:1529 POST, :1554 DELETE /api_key) Note: no agent webhook; nearest secrets can be revoked, only the API key rotated
  • sc-event unknown → partial: source read at v0.11.4, not driven: backend/open_webui/events.py:1103 dispatch_event_functions runs admin-installed 'event' Functions on every published event (file.uploaded, knowledge.file.added, chat.created, ...; catalog class EventDefinitions events.py:42); an agent start must be hand-coded inside such a Function, searched 'trigger' in routers/automations.py and models/automations.py: automations are time-only (:73) Note: event hook exists for plugin code, no no-code event trigger for an agent
  • sc-manual-event-choice unknown → partial: source read at v0.11.4, not driven: an automation runs on its RRULE (backend/open_webui/models/automations.py:76) and can be run by hand (routers/automations.py:334 /run); a model is also started by hand in chat; there is no event option per agent (searched 'trigger|event' in models/automations.py and src/lib/components/automations: none) Note: schedule or manual, no event trigger to choose
  • sc-retry unknown → no: source read at v0.11.4, not driven: searched 'retry|backoff|attempt' in backend/open_webui/utils/automations.py, models/automations.py, routers/automations.py: execute_automation (utils/automations.py:345) catches the error, records status 'error' (:617 _record_run) and waits for the next RRULE slot; no automatic retry
  • sc-dead-letter unknown → partial: source read at v0.11.4, not driven: failed runs are kept per automation in automation_run with status and error (backend/open_webui/models/automations.py:43-50), listed in src/lib/components/automations/AutomationEditor.svelte:212 getAutomationRuns; automation.run_failed event can go to a webhook (events.py AUTOMATION_RUN_FAILED); no cross-automation list of failing runs Note: per-automation run history, no parked-failures list
  • sc-overlap unknown → no: source read at v0.11.4, not driven: backend/open_webui/models/automations.py:289 claim_due only prevents double claiming of one slot (next_run_at advanced, SKIP LOCKED); utils/automations.py:112 asyncio.create_task(execute_automation) with no check that the previous run finished; searched 'running|in_progress|overlap|lock' in utils/automations.py: none
  • tl-files yes → partial: source read at v0.11.4, not driven: agents read uploaded and knowledge files via built-in tools backend/open_webui/tools/builtin.py:2750 view_file, :2413 list_chat_files, :2453 grep_chat_files; create and move files only inside an attached Open Terminal filesystem (utils/middleware.py:1286 write_file / run_command); searched 'nextcloud|webdav' in backend/open_webui: no Nextcloud Files Note: file work happens in the Open Terminal sandbox, not in Nextcloud Files
  • tl-contacts unknown → no: source read at v0.11.4, not driven: searched 'contacts|carddav|address book' in backend/open_webui and src/lib/components: no contacts store or tool; only the user directory used for sharing
  • tl-deck unknown → no: source read at v0.11.4, not driven: searched 'deck|kanban|board' in backend/open_webui (py): no board tool or integration
  • tl-mail unknown → no: source read at v0.11.4, not driven: searched 'smtp|send_email|sendmail|mail' in backend/open_webui: no mail sending anywhere in core; outbound messages go only to webhooks (utils/webhook.py:30) Note: only possible through a community Tool
  • tl-talk unknown → partial: source read at v0.11.4, not driven: an automation can target an Open WebUI channel (backend/open_webui/models/automations.py:68 AutomationTarget type 'channel', utils/automations.py:250 _execute_channel_automation) and models answer @mentions in channels (routers/channels.py:976); channel built-in tools are read-only (tools/builtin.py:1763-1957); no Nextcloud Talk Note: posting is to Open WebUI's own channels, only via automation target or mention reply
  • tl-tasks unknown → partial: source read at v0.11.4, not driven: backend/open_webui/tools/builtin.py:3593 create_tasks and :3643 update_task keep a checklist inside the chat message (status pending|in_progress|completed); searched 'todo|caldav|vtodo' in backend/open_webui: no task app to create or complete tasks in Note: in-chat progress checklist only
  • tl-unified-search unknown → partial: source read at v0.11.4, not driven: separate built-in search tools over Open WebUI's own stores: backend/open_webui/tools/builtin.py:1512 search_chats, :1127 search_notes, :865 search_memories, :1763 search_channels, :2104 search_knowledge_bases, :4151 search_calendar_events; no single cross-app search tool and no Nextcloud unified search Note: agent can search each store, not one unified index
  • tl-register unknown → no: source read at v0.11.4, not driven: searched 'openregister|register' in backend/open_webui/tools and utils/tools.py: no OpenRegister or record-store tool; reachable only through a custom OpenAPI or MCP tool server
  • tl-mcp-server unknown → no: source read at v0.11.4, not driven: searched 'FastMCP|mcp.server|/mcp' in backend/open_webui (py): the only MCP code is the client (utils/mcp/client.py); Open WebUI exposes an OpenAI-compatible REST API, not an MCP server
  • tl-catalog unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Tools.svelte lists custom tools with descriptions (routers/tools.py); src/lib/components/workspace/Models/BuiltinTools.svelte:14-51 each built-in tool category with label and description; tool servers listed in chat/ToolServersModal.svelte
  • tl-request-access unknown → no: source read at v0.11.4, not driven: searched 'request access|request_access|missing tool' in backend/open_webui and src/lib/components: no flow for an agent to ask its owner for a tool; the ask_user tool (tools/builtin.py:518) asks the chat user a question, not for a grant
  • tl-git yes → partial: source read at v0.11.4, not driven: no git tool in core (searched 'git' in backend/open_webui/tools and utils/tools.py); an agent can run git only through an attached Open Terminal via run_command (utils/tools.py:1439, utils/middleware.py:1287), which is a separate first-party server (README.md:96 open-webui/open-terminal) Note: old yes; git works only with the separate Open Terminal server
  • tl-invocations-export unknown → partial: source read at v0.11.4, not driven: tool calls live inside each message's output items (utils/tool_approval.py:43 function_call entries) and leave only through chat JSON export (src/lib/components/chat/Settings/DataControls.svelte:93 exportChats, admin routers/chats.py:1049 /all/db) or chat stats export (:609); no dedicated tool-invocation log or export
  • tl-integrations-page unknown → partial: source read at v0.11.4, not driven: admin Settings tabs Connections, Integrations (tool servers), Code Execution, External Knowledge (src/lib/components/admin/Settings/*.svelte) list outside connections, each with a verify or test action at add time (AddToolServerModal.svelte:206 verifyToolServerConnection, AddTerminalServerModal.svelte:246, ExternalKnowledge.svelte:295); no standing status view showing whether each still works
  • me-user-profile partial → yes: source read at v0.11.4, not driven: memory is kept per person: backend/open_webui/models/memories.py:22 user_id, :23 type 'user' for durable facts about the user; utils/memory.py:528 background review writes 'user' facts; src/lib/components/chat/Settings/Personalization/MemoryModal.svelte:97 'Add a preference, fact, or instruction about you' Note: old partial; memory is per user across all models, not per agent
  • me-consolidate unknown → yes: source read at v0.11.4, not driven: backend/open_webui/utils/memory.py:410 review_memory_after_turn every N turns (memories.review_interval_turns) asks the model for add/replace/move/remove operations and tells it to prefer replace/remove over duplicates (:528 prompt), applied via routers/memories.py:234 update_memories Note: off by default: ENABLE_MEMORY_BACKGROUND_REVIEW (config.py:428)
  • me-context unknown → yes: source read at v0.11.4, not driven: per-agent bundle: ModelEditor.svelte:1194 Knowledge (knowledge bases, files, notes) stored in ModelMeta.knowledge (backend/open_webui/models/models.py:81) and injected every chat; per-project bundle: folders carry system_prompt and files applied to every chat in them (backend/open_webui/utils/middleware.py:2591-2602)
  • me-knowledge-graph unknown → no: source read at v0.11.4, not driven: searched 'graph|relation|link' in backend/open_webui/retrieval and tools/builtin.py: retrieval is vector plus BM25 hybrid search over chunks; no entity or record relationship graph an agent can walk
  • me-object-grounding unknown → no: source read at v0.11.4, not driven: searched 'record|object|linked' in backend/open_webui/utils/middleware.py and tools/builtin.py: there is no record model or 'record on screen' context; grounding is only on attached files, knowledge and notes
  • me-external-kb yes → partial: source read at v0.11.4, not driven: backend/open_webui/routers/knowledge.py:697 external knowledge connections to existing Qdrant, Milvus or pgvector collections (src/lib/components/admin/Settings/ExternalKnowledge.svelte:469-471); OneDrive/SharePoint and Google Drive only as one-time file pickers (chat/MessageInput/InputMenu.svelte:399, :707); live SharePoint/wiki sync is the separate oikb project (README.md:98) Note: no live SharePoint or wiki connector in core
  • sk-catalog unknown → yes: source read at v0.11.4, not driven: src/routes/(app)/workspace/skills/+page.svelte and src/lib/components/workspace/Skills.svelte list every skill the user can read, with search, enable state and owner; backend/open_webui/routers/skills.py:63 GET /skills/list with access grants Note: org-internal catalogue; no public skill store link like the one for models and tools
  • sk-install unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Models/ModelEditor.svelte:1202 SkillsSelector attaches a skill to an agent in one pick; users can also pull a skill into one chat with the '$' mention (src/lib/components/chat/MessageInput/Commands/Skills.svelte, backend/open_webui/utils/skills.py:23 extract_skill_ids_from_messages)
  • sk-format unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Skills.svelte:272 import accepts .md, :306-312 parses SKILL.md frontmatter; backend/open_webui/utils/terminals.py:247 get_terminal_skill reads .agents/skills//SKILL.md directories with resources (:276); utils/skills.py:37 authoring standards (name, description frontmatter, scripts/ references/ assets/) Note: DB skills are single-file; full skill folders only through Open Terminal
  • sk-self-improve unknown → partial: source read at v0.11.4, not driven: backend/open_webui/utils/skills.py:35 SKILLS_CREATE_RE '/skills:create' makes the model distill the current chat into a SKILL.md and save it (:81-115), which can rewrite an existing skill; it runs only when a user types the command and needs an Open Terminal (:133); searched 'improve|propose|revision' in utils/skills.py and routers/skills.py: no agent-initiated proposals
  • sk-draft-review unknown → no: source read at v0.11.4, not driven: searched 'draft|diff|review|version|history' in backend/open_webui/routers/skills.py and models/skills.py: skills are edited in place (routers/skills.py:274 update); no proposed-change queue, diff or accept/reject (prompts have versions at routers/prompts.py:384, skills do not)
  • sk-auto-create unknown → partial: source read at v0.11.4, not driven: backend/open_webui/utils/skills.py:81 _build_skill_create_prompt, default request 'the workflow we just went through in this conversation ... distill them into a reusable skill' (:84-86); triggered only by the user's /skills:create command and saved to the Open Terminal (:108), not on the agent's own initiative
  • sk-curator unknown → no: source read at v0.11.4, not driven: searched 'curator|merge|archive|dedupe|unused' in backend/open_webui/routers/skills.py, models/skills.py, utils/skills.py and utils/automations.py: no scheduled job that merges or archives skills
  • sk-maturity unknown → no: source read at v0.11.4, not driven: searched 'maturity|usage count|rating|verified|stable' in backend/open_webui/models/skills.py, routers/skills.py and src/lib/components/workspace/Skills*: a skill has name, description, content, meta, is_active (models/skills.py:20-32), no maturity or proof signal
  • sk-versions unknown → no: source read at v0.11.4, not driven: searched 'version|history|rollback' in backend/open_webui/models/skills.py and routers/skills.py: updates overwrite content (routers/skills.py:274); version history exists only for prompts (routers/prompts.py:384, workspace/Prompts/PromptHistoryMenu.svelte)
  • sk-github unknown → no: source read at v0.11.4, not driven: searched 'github|url' in backend/open_webui/routers/skills.py: no URL or GitHub install and no publish; GitHub raw loading exists only for tools and functions (routers/tools.py:247 github_url_to_raw_url, :264 /tools/load/url)
  • sk-learnings unknown → no: source read at v0.11.4, not driven: searched 'learning|lesson|rule' in backend/open_webui/utils/skills.py, utils/memory.py and routers/skills.py: run lessons go to per-user memory (utils/memory.py:410), never into a skill's rules
  • sk-export unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/skills.py:123 GET /skills/export; src/lib/components/workspace/Skills/SkillMenu.svelte:16 per-skill Export, Skills.svelte:91 Export JSON (permission workspace.skills_export) Note: exports JSON, not SKILL.md
  • sk-install-source unknown → partial: source read at v0.11.4, not driven: skills import from a local .md or .json file (src/lib/components/workspace/Skills.svelte:272) and are read live from an attached Open Terminal's .agents/skills folder (backend/open_webui/utils/terminals.py:263 GET {terminal}/skills/{name}); searched 'url|load' in routers/skills.py: no install from an outside address
  • sk-evals unknown → no: source read at v0.11.4, not driven: searched 'eval|test case|benchmark' in backend/open_webui/routers/skills.py, utils/skills.py and routers/evaluations.py: evaluations compare models by user feedback and arena ELO (routers/evaluations.py:222 leaderboard), nothing runs a skill against test cases with and without it
  • mo-providers partial → yes: source read at v0.11.4, not driven: backend/open_webui/routers/openai.py:129 native Anthropic model listing and :485 anthropic-version headers (utils/anthropic.py), :208 Azure AD auth, :890 Azure; any OpenAI-compatible provider such as OpenAI, Mistral, Groq, OpenRouter (README.md:28); admin UI src/lib/components/admin/Settings/Connections/OpenAIConnection.svelte Note: old partial rested on a feature row; the code connects OpenAI, Anthropic natively and Mistral through the compatible API
  • mo-nc-assistant unknown → no: source read at v0.11.4, not driven: searched 'nextcloud|taskprocessing|task_processing' in backend/open_webui: no connection to Nextcloud AI task processing
  • mo-provide-text2text yes → partial: source read at v0.11.4, not driven: backend/open_webui/main.py:898 GET /api/v1/models and :1109 POST /api/v1/chat/completions (OpenAI-compatible), :2003 /api/v1/messages (Anthropic-compatible) expose every agent, custom models included, to outside clients with an API key; no Nextcloud TaskProcessing provider Note: old yes; any OpenAI-compatible client can use the agents, but nothing registers them inside Nextcloud
  • mo-per-agent unknown → yes: source read at v0.11.4, not driven: each workspace model has its own base_model_id and params (backend/open_webui/models/models.py:118-120; ModelEditor.svelte:856); automations pick a model per task (models/automations.py:75 model_id, src/lib/components/automations/ModelDropdown.svelte)
  • mo-tenant-policy unknown → partial: source read at v0.11.4, not driven: model access is per user or group through access grants (backend/open_webui/utils/models.py:465 check_model_access, main.py:1151; admin/Settings/Models access control); searched 'tenant|organization' in backend/open_webui/routers and models: no tenant scope Note: group-level model allow-lists only; no organisation or tenant concept
  • mo-per-feature unknown → yes: source read at v0.11.4, not driven: backend/open_webui/config.py:2180 TASK_MODEL and :2182 TASK_MODEL_EXTERNAL for titles, tags, queries and autocomplete, set in src/lib/components/admin/Settings/Interface.svelte:180; separate engines per feature in admin Settings Audio, Images, Documents (embedding, reranker), WebSearch
  • mo-failover unknown → partial: source read at v0.11.4, not driven: backend/open_webui/main.py:1137-1147 ENABLE_CUSTOM_MODEL_FALLBACK (env.py:1035, off by default) swaps to the first default model only when a custom model's base model is missing; Ollama spreads requests over URLs (routers/ollama.py:863 random.choice) but does not retry another provider on an error; searched 'failover|retry' in routers/openai.py: none Note: no runtime failover when a provider call fails
  • mo-sensitivity-routing unknown → no: source read at v0.11.4, not driven: searched 'sensitiv|classification|pii|confidential' in backend/open_webui/utils/middleware.py, utils/models.py and main.py: routing follows the chosen model only; no data-classification based model selection
  • mo-cli-runner unknown → no: source read at v0.11.4, not driven: searched 'claude|subprocess|cli' in backend/open_webui/utils and routers: Anthropic is called over HTTP (utils/anthropic.py:15 ANTHROPIC_VERSION); no runner that shells out to the claude CLI in a container
  • mo-key-broker unknown → yes: source read at v0.11.4, not driven: provider keys live once in admin connection config (backend/open_webui/routers/openai.py:360 get_openai_connection by url_idx, config.py:2829 openai.api_keys), set in src/lib/components/admin/Settings/Connections.svelte; agents reference a base model id, never a key (models/models.py:118); tool-server OAuth tokens Fernet-encrypted (utils/oauth.py:269) Note: central config store, not an external vault
  • mo-personal-key unknown → yes: source read at v0.11.4, not driven: src/lib/components/chat/Settings/Connections.svelte:66 per-user Direct Connections (own endpoint and key), enabled by admin 'direct.enable' (backend/open_webui/config.py:230 ENABLE_DIRECT_CONNECTIONS); main.py:1164 _set_direct_model routes the user's runs through it Note: direct connections run from the browser session and are refused for sub-agents (utils/subagents.py:334)
  • dl-talk unknown → partial: source read at v0.11.4, not driven: automation output can go to an Open WebUI channel: backend/open_webui/models/automations.py:68 AutomationTarget type 'channel', utils/automations.py:250 _execute_channel_automation, src/lib/components/automations/DestinationDropdown.svelte; searched 'talk|spreed|nextcloud' in backend/open_webui: no Nextcloud Talk Note: delivers to its own channels, not Talk
  • dl-talk-bridge unknown → partial: source read at v0.11.4, not driven: in Open WebUI channels a member @mentions a model and the reply lands in the room or thread: backend/open_webui/routers/channels.py:976 model_response_handler, :1244; src/lib/components/channel/MessageInput/MentionList.svelte; no Nextcloud Talk bridge Note: own channels only
  • dl-talk-grouping unknown → no: source read at v0.11.4, not driven: searched 'agent room|bot room|category' in backend/open_webui/models/channels.py and src/lib/components/channel: channels have types group/dm/standard, no marking or grouping of agent rooms apart from human ones
  • dl-webhook-out yes → partial: source read at v0.11.4, not driven: admin event webhooks (backend/open_webui/events.py:1034 dispatch_webhook_event, filters :707) and per-user notification webhooks (utils/notifications.py:264 chat.finished payload with the answer text and link) post output to another system; utils/webhook.py:30 post_webhook sends plain JSON; searched 'hmac|signature' in utils/webhook.py, events.py, utils/notifications.py: unsigned Note: old yes; webhooks exist but carry no signature
  • dl-email unknown → no: source read at v0.11.4, not driven: searched 'smtp|email|sendmail' in backend/open_webui/utils/notifications.py, utils/webhook.py, events.py and routers: notification targets accept type 'webhook' only (utils/notifications.py:34)
  • dl-target-pref unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/notifications.py:56 add target, :84 PUT /targets/{id}/default; utils/notifications.py:213 set_default_target; per-user settings in src/lib/components/chat/Settings/Notifications.svelte
  • dl-messengers unknown → partial: source read at v0.11.4, not driven: outbound only: utils/webhook.py:44-55 formats Slack, Google Chat, Discord and Microsoft Teams webhooks; searched 'telegram|signal|whatsapp|slack bot|bot token' in backend/open_webui: no inbound messenger adapter; chatting from Telegram or WhatsApp is the separate Open WebUI Computer project (README.md:94) Note: can post to Teams or Slack, cannot be reached from them
  • dl-dedupe unknown → no: source read at v0.11.4, not driven: searched 'dedup|duplicate|collapse|count' in backend/open_webui/utils/notifications.py, events.py and utils/automations.py: each run and event is delivered separately; no collapsing of identical reports
  • dl-dashboard-widget unknown → no: source read at v0.11.4, not driven: searched 'dashboard|widget' in src/lib/components and src/routes: src/routes/(app)/home/+page.svelte is an empty shell, admin Analytics is usage stats; no widget showing agent output and no Nextcloud dashboard integration
  • dl-embed-web unknown → no: source read at v0.11.4, not driven: searched 'embed|widget|anonymous|guest|public chat' in src/lib/components and backend/open_webui/routers/auths.py: every chat needs a signed-in user; the only embedding hook is an iframe postMessage handler for a logged-in session (src/lib/components/chat/Chat.svelte:1457 'Confirm Prompt from Embed') Note: no anonymous chat window for public websites
  • ov-approval unknown → yes: source read at v0.11.4, not driven: src/lib/components/chat/MessageInput/InputMenu.svelte:62 'Ask for approval': 'Stop before each tool call until you allow or deny it.'; backend/open_webui/utils/middleware.py:3613 pause_for_tool_approval holds the call; src/lib/components/common/ToolCallDisplay.svelte:250-271 Allow/Deny; utils/tool_approval.py:20 resolve_tool_call_output resumes or rejects
  • ov-approval-inbox unknown → no: source read at v0.11.4, not driven: searched 'requires_approval|pending approval|needsApproval' in src/routes and src/lib/components/layout: pending calls are shown only inside the chat message that raised them (common/ToolCallDisplay.svelte:244); no cross-chat approval inbox
  • ov-approval-context unknown → partial: source read at v0.11.4, not driven: the pending call shows tool name and its decoded arguments (src/lib/components/common/ToolCallDisplay.svelte:147 arguments, :246 'Allow {{NAME}}?'); the reasoning is whatever the model wrote before the call; searched 'reason|impact|touches' in utils/tool_approval.py and ToolCallDisplay.svelte: no statement of what the action touches or why Note: what and with which arguments, not why or blast radius
  • ov-risk-threshold unknown → no: source read at v0.11.4, not driven: tool_approval_mode is 'full' or 'ask' for all tool calls in a chat (src/lib/components/chat/MessageInput/InputMenu.svelte:54-64; backend/open_webui/utils/middleware.py:5934); searched 'approv|risk' in utils/tools.py and routers/tools.py: no per-tool or risk-based approval rule
  • ov-talk-reaction unknown → no: source read at v0.11.4, not driven: searched 'reaction' with 'approv' in backend/open_webui/routers/channels.py and utils/tool_approval.py: channel reactions (events message.reaction_added) do not resolve tool calls; approval is only via the Allow/Deny buttons or POST /api/v1/chats/{id}/messages/{mid}/resolve (main.py:1893)
  • ov-draft-hold unknown → no: source read at v0.11.4, not driven: searched 'draft|hold|review before' in backend/open_webui/utils/automations.py, routers/channels.py and utils/middleware.py: answers are written straight to the chat or channel (utils/automations.py:250 channel post); only tool calls can be held (utils/middleware.py:3613)
  • ov-kill-switch unknown → partial: source read at v0.11.4, not driven: admin 'Disable All' models (src/lib/components/workspace/Models.svelte:365, routers/models.py:881 toggle each) and the global automations switch (src/lib/components/admin/Settings/General.svelte:377 ENABLE_AUTOMATIONS, checked at utils/automations.py:105) stop new runs; running tasks are stopped one by one (main.py:2128 /api/tasks/stop/{id}, admin) Note: no single action that also halts in-flight runs
  • ov-kill-agent unknown → yes: source read at v0.11.4, not driven: backend/open_webui/routers/models.py:881 POST /model/toggle sets is_active false and utils/models.py:210 drops inactive custom models from the served list; in-flight turns stop via main.py:2160 POST /api/tasks/chat/{chat_id}/stop and admin main.py:2128 /api/tasks/stop/{task_id}; automations pause at routers/automations.py:306
  • ov-guardrail-input unknown → partial: source read at v0.11.4, not driven: mechanism only: Filter functions run an inlet() on every request (backend/open_webui/utils/filter.py:212 process_filter_functions, global or per model via ModelEditor.svelte:1210 FiltersSelector); searched 'pii|presidio|redact|secret' in backend/open_webui: no shipped PII or secret filter, those are community Functions from openwebui.com Note: community Function, not core
  • ov-guardrail-output unknown → partial: source read at v0.11.4, not driven: Filter functions also run outlet() and stream hooks on answers (backend/open_webui/utils/filter.py:212, filter_type 'outlet'); searched 'moderation|guardrail|content rule' in backend/open_webui: none shipped, blocking rules must be written as or installed from community Functions Note: community Function, not core
  • ov-tool-risk unknown → no: source read at v0.11.4, not driven: searched 'risk|danger|sensitive' in backend/open_webui/models/tools.py, routers/tools.py, utils/tools.py and utils/tool_approval.py: tools carry no risk class; approval mode is uniform per chat (utils/middleware.py:5934)
  • ov-anonymise unknown → no: source read at v0.11.4, not driven: searched 'anonymi|pseudonym|redact|presidio|pii' in backend/open_webui (routers, utils, retrieval): documents are extracted and embedded as-is (routers/retrieval.py); anonymising needs a community Filter function
  • ov-ai-oversight unknown → partial: source read at v0.11.4, not driven: admins browse any model's conversations and messages: backend/open_webui/routers/analytics.py:285 /models/{id}/chats, :125 /messages, src/lib/components/admin/Analytics/AnalyticsModelModal.svelte; user feedback review in admin Evaluations (Feedbacks.svelte); no decision log with review status or sign-off Note: transcript browsing, not a structured oversight workflow
  • ov-automation-bias unknown → no: source read at v0.11.4, not driven: searched 'bias|rubber|approve all|approval rate' in backend/open_webui/utils/tool_approval.py, utils/middleware.py and src/lib/components/common/ToolCallDisplay.svelte: approvals are not counted or analysed per reviewer
  • ov-tool-oversight unknown → partial: source read at v0.11.4, not driven: per-user 'Most used tools' in src/lib/components/chat/Settings/Usage.svelte:472 (routers/chats.py:307 /stats/usage); admins read tool calls inside any conversation (routers/analytics.py:125 /messages, :285 model chats); searched 'flag|misuse|report' in routers/analytics.py and routers/tools.py: no flagging Note: tool use is visible, misuse cannot be flagged
  • co-audit-log unknown → partial: source read at v0.11.4, not driven: backend/open_webui/utils/audit.py:36 AuditLogEntry middleware writes HTTP requests (with user, path, body up to MAX_BODY_LOG_SIZE) to DATA_DIR/audit.log via utils/logger.py:200 with rotation; off by default (env.py:1236 AUDIT_LOG_LEVEL 'NONE'); plain rotating file, not tamper-evident, and tool calls are only inside chat records Note: request-level audit, not immutable, off by default
  • co-audit-export unknown → partial: source read at v0.11.4, not driven: the audit trail is the file at env.py:1226 AUDIT_LOGS_FILE_PATH (utils/logger.py:200) that an operator can copy; searched 'audit' in backend/open_webui/routers and src/lib/components/admin: no export endpoint or UI; chat data export exists (routers/chats.py:1049 /all/db admin)
  • co-retention unknown → no: source read at v0.11.4, not driven: searched 'retention|older_than|prune|expire|ttl' in backend/open_webui/routers, models/chats.py and config.py: no chat or run retention period; ENABLE_KNOWLEDGE_FILE_RETENTION (config.py:985) only keeps files when removed from a knowledge base; temporary chats that are never stored can be enforced per user ('temporary_enforced' permission)
  • co-ai-register unknown → no: source read at v0.11.4, not driven: searched 'register|risk class|ai act|inventory' in backend/open_webui/models and src/lib/components/admin: no register of AI features with a risk class
  • co-risk-class unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; models carry no risk-level field (backend/open_webui/models/models.py:74 ModelMeta)
  • co-dpo-ack unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; publishing a model is immediate on save (routers/models.py:285), no sign-off step
  • co-control-packs unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; no control framework checks anywhere in admin settings
  • co-factsheet unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; the nearest artefact is the model JSON export (routers/models.py:381) and the description field (ModelEditor.svelte:962), not a generated fact sheet
  • co-compliance-export unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; exports cover models, chats, feedback and config (routers/models.py:381, routers/evaluations.py:354, routers/configs.py:118), none is a compliance report
  • co-incident unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; the event catalogue (events.py:42) has no incident type
  • co-authority-notify unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; no incident record to notify from
  • co-access-review unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; models keep their creator as owner forever (backend/open_webui/models/models.py:117) with no review date or re-attestation
  • co-transparency unknown → partial: source read at v0.11.4, not driven: each agent has a user-facing, localisable description (backend/open_webui/models/models.py:78 'User-facing description of the model.', ModelEditor.svelte:962) shown in the model selector, and admins can post banners (src/lib/components/admin/Settings/Interface/Banners.svelte); no published page explaining the agents employees deal with Note: short per-agent descriptions only
  • co-residency unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpo|data protection officer|iso 42001|ai act|incident|factsheet|model card|residency|attestation|access review|algoritmeregister|dpia|impact assessment' in backend/open_webui, src/lib/components and src/routes: no matches; connections record a URL but no location, and no view maps AI features to where they process data (src/lib/components/admin/Settings/Connections.svelte)
  • co-disable-dept unknown → partial: source read at v0.11.4, not driven: group permissions switch features and model access per group (src/lib/components/admin/Users/Groups/Permissions.svelte:44-51, backend/open_webui/routers/groups.py:401); permissions are additive and a default user permission 'will remain enabled' (Permissions.svelte:78), and there is no proof view that AI is off for a group Note: can narrow a group only when defaults are off; no evidence it is off
  • ob-runs yes → partial: source read at v0.11.4, not driven: scheduled runs: backend/open_webui/routers/automations.py:388 GET /{id}/runs with status, time and error (models/automations.py:43-50), shown in src/lib/components/automations/AutomationEditor.svelte:355-400; interactive turns are chats with no status list; no list across all agents Note: old yes; run history exists only per automation
  • ob-trace unknown → yes: source read at v0.11.4, not driven: each run is a chat whose assistant message keeps ordered output items (function_call, function_call_output, reasoning, text; backend/open_webui/utils/tool_approval.py:43, utils/middleware.py:5925); src/lib/components/chat/Messages/StructuredOutputRenderer.svelte:116-176 renders them in order; automation runs link to their chat (models/automations.py:46 chat_id)
  • ob-replay unknown → partial: source read at v0.11.4, not driven: a past turn can be re-run with 'Regenerate' (src/lib/components/chat/Messages/ResponseMessage.svelte, permission chat.regenerate_response) and a chat cloned or forked (backend/open_webui/routers/chats.py:1775 /clone, :1672 /fork); tool results are not recorded for deterministic replay, so it is a fresh run
  • ob-dry-run unknown → no: source read at v0.11.4, not driven: searched 'dry run|dry_run|simulate|sandbox mode' in backend/open_webui/utils/middleware.py, utils/tools.py and routers: no mode that lets an agent run while blocking side effects; the closest is per-chat 'Ask for approval' (utils/middleware.py:5934)
  • ob-cost-per-run unknown → partial: source read at v0.11.4, not driven: per-message token usage stored (backend/open_webui/utils/middleware.py:3737 merge_usage) and shown in src/lib/components/chat/Messages/ResponseMessage.svelte:1209-1213; searched 'cost|price' in routers/analytics.py and utils/middleware.py: no cost, and no per-step split
  • ob-budget unknown → no: source read at v0.11.4, not driven: searched 'budget|spend|limit|price' in backend/open_webui/routers/analytics.py, utils/middleware.py, routers/openai.py and config.py: no spending budget, warning level or hard stop
  • ob-estimate unknown → no: source read at v0.11.4, not driven: searched 'estimate|cost|price' in backend/open_webui/main.py, routers/analytics.py and src/lib/components/chat/MessageInput.svelte: main.py:1933 /api/v1/messages/count_tokens counts input tokens for Anthropic-style clients and MessageInput.svelte:1837 shows context usage, but nothing predicts a run's cost
  • ob-fail-alert unknown → yes: source read at v0.11.4, not driven: backend/open_webui/utils/automations.py:526 publish_event AUTOMATION_RUN_FAILED routed to admin event webhooks (events.py:1034); chat.failed is a user notification event (events.py:669, utils/notifications.py:287) with browser and webhook delivery (src/lib/components/chat/Settings/Notifications.svelte:37 'Chat failed')
  • ob-drift unknown → no: source read at v0.11.4, not driven: searched 'drift|anomaly|regression|baseline' in backend/open_webui/routers/analytics.py, routers/evaluations.py and utils: no monitoring of result quality over time beyond the feedback leaderboard history (routers/evaluations.py:268)
  • ob-metrics unknown → yes: source read at v0.11.4, not driven: backend/open_webui/main.py:2963 GET /health, :3009 /health/db for probes; utils/telemetry/metrics.py:151 setup_metrics with request counter, duration histogram and user gauges exported over OTLP (env.py:1267 ENABLE_OTEL_METRICS, :1271 endpoint) Note: metrics are pushed over OTLP, not a Prometheus scrape endpoint
  • ob-external-tracing unknown → yes: source read at v0.11.4, not driven: backend/open_webui/env.py:1266 ENABLE_OTEL_TRACES, :1270 OTEL_EXPORTER_OTLP_ENDPOINT, utils/telemetry/setup.py and instrumentors.py send traces to any OTLP collector (Langfuse accepts OTLP); direct Langfuse hooks exist only as community pipeline filters Note: OTLP in core; native Langfuse only via community pipelines
  • ob-reports unknown → no: source read at v0.11.4, not driven: searched 'report|digest|weekly' in backend/open_webui/routers/analytics.py, utils/automations.py and events.py: analytics are on-demand dashboards (src/lib/components/admin/Analytics/Dashboard.svelte); no periodic usage report
  • fl-canvas unknown → no: source read at v0.11.4, not driven: searched 'canvas|workflow|flow editor|node' in src/lib/components and src/routes: @xyflow/svelte (package.json:89) is used only for the chat message-tree overview (src/lib/components/chat/Overview/Flow.svelte); multi-step logic lives in Python Pipe functions or the external Pipelines server (backend/open_webui/routers/pipelines.py)
  • fl-agent-node unknown → no: source read at v0.11.4, not driven: searched 'canvas|workflow|flow editor|node' in src/lib/components and src/routes: @xyflow/svelte (package.json:89) is used only for the chat message-tree overview (src/lib/components/chat/Overview/Flow.svelte); multi-step logic lives in Python Pipe functions or the external Pipelines server (backend/open_webui/routers/pipelines.py); no flow to put an agent step in
  • fl-approval-step unknown → no: source read at v0.11.4, not driven: searched 'canvas|workflow|flow editor|node' in src/lib/components and src/routes: @xyflow/svelte (package.json:89) is used only for the chat message-tree overview (src/lib/components/chat/Overview/Flow.svelte); multi-step logic lives in Python Pipe functions or the external Pipelines server (backend/open_webui/routers/pipelines.py); approval exists only for tool calls in a chat (utils/middleware.py:3613)
  • fl-subagent unknown → partial: source read at v0.11.4, not driven: backend/open_webui/tools/builtin.py:1680 delegate_task hands a focused task to a sub-agent and returns its summary (utils/subagents.py:270 delegate, max_iterations and max_output :298-301), admin toggle src/lib/components/admin/Settings/Subagents.svelte; the sub-agent is a copy of the current model and tools (subagents.py:317 'model_id': current), it cannot pick another configured agent Note: delegates to a clone of itself, not to a different agent
  • fl-branch unknown → no: source read at v0.11.4, not driven: searched 'canvas|workflow|flow editor|node' in src/lib/components and src/routes: @xyflow/svelte (package.json:89) is used only for the chat message-tree overview (src/lib/components/chat/Overview/Flow.svelte); multi-step logic lives in Python Pipe functions or the external Pipelines server (backend/open_webui/routers/pipelines.py); conditions can only be coded inside a Pipe or Filter function
  • fl-run-history unknown → no: source read at v0.11.4, not driven: no flow feature to hold it (searched 'canvas|workflow|flow' in src/lib/components and src/routes; @xyflow/svelte only draws the chat overview, src/lib/components/chat/Overview/Flow.svelte)
  • fl-seed-flows unknown → no: source read at v0.11.4, not driven: no flow feature to hold it (searched 'canvas|workflow|flow' in src/lib/components and src/routes; @xyflow/svelte only draws the chat overview, src/lib/components/chat/Overview/Flow.svelte); the app ships no example flows or agents, community presets live on openwebui.com (src/lib/components/workspace/Models.svelte:947)
  • fl-n8n unknown → no: source read at v0.11.4, not driven: searched 'n8n' in backend/open_webui and src: no n8n integration in core; an n8n workflow can only be called through a custom Tool, OpenAPI or MCP server or a community Pipe
  • fl-code-step yes → partial: source read at v0.11.4, not driven: custom Python runs in the request pipeline as Filter (inlet/outlet) or Pipe functions (backend/open_webui/routers/functions.py:48, src/routes/(app)/admin/functions/create/+page.svelte, utils/filter.py:212) and on the external Pipelines server (routers/pipelines.py); searched 'canvas|workflow|flow' in src/lib/components: no flow to place the step in Note: old yes; code steps exist in the chat pipeline, not in a flow
  • fl-subflow unknown → no: source read at v0.11.4, not driven: no flow feature to hold it (searched 'canvas|workflow|flow' in src/lib/components and src/routes; @xyflow/svelte only draws the chat overview, src/lib/components/chat/Overview/Flow.svelte)
  • fl-validate unknown → no: source read at v0.11.4, not driven: no flow feature to hold it (searched 'canvas|workflow|flow' in src/lib/components and src/routes; @xyflow/svelte only draws the chat overview, src/lib/components/chat/Overview/Flow.svelte); the only pre-run check is RRULE validation for schedules (backend/open_webui/utils/recurrence.py:106 validate_rrule)
  • re-store unknown → partial: source read at v0.11.4, not driven: src/lib/components/workspace/Models.svelte:945-950 'Discover a model' links to openwebui.com/models when enable_community_sharing is on; the community page posts the preset back into src/routes/(app)/workspace/models/create/+page.svelte:77 (COMMUNITY_ORIGINS check) to prefill a new model Note: the store is an outside website, not an in-app catalogue
  • re-template-from-agent unknown → yes: source read at v0.11.4, not driven: src/lib/components/workspace/Models.svelte:221 shareModelHandler posts the full model to openwebui.com, :214 Clone, per-model Export JSON (routers/models.py:381); public read grant makes it usable org-wide (common/AccessControl.svelte:19 'anyone')
  • re-template-github unknown → no: source read at v0.11.4, not driven: searched 'github|load/url' in backend/open_webui/routers/models.py: model presets import only from a JSON file or openwebui.com; GitHub URL loading exists for tools and functions only (routers/tools.py:247, routers/functions.py:107)
  • re-template-approve unknown → no: source read at v0.11.4, not driven: searched 'approve|review|publish' in backend/open_webui/routers/models.py and src/lib/components/workspace/Models*: a model is shared the moment its access grants are saved (routers/models.py:1035); no approval gate
  • re-agent-versions unknown → no: source read at v0.11.4, not driven: searched 'version|history|rollback' in backend/open_webui/models/models.py and routers/models.py: updates overwrite the row (routers/models.py:932); versioning with history menu exists only for prompts (routers/prompts.py:384, workspace/Prompts/PromptHistoryMenu.svelte)
  • re-evals partial → no: source read at v0.11.4, not driven: backend/open_webui/routers/evaluations.py:222 leaderboard and arena models (admin/Settings/Evaluations/ArenaModelModal.svelte) rank models from blind user votes; searched 'expected|test case|dataset|golden' in routers/evaluations.py: no case sets with expected answers Note: old partial; arena voting is not a test set
  • re-baseline unknown → no: source read at v0.11.4, not driven: searched 'baseline|compare|promote|a/b' in backend/open_webui/routers/prompts.py, routers/models.py and routers/evaluations.py: prompt versions can be set live (routers/prompts.py:384) but no side-by-side run of old versus new before promotion; arena compares models, not prompt versions
  • re-community unknown → yes: source read at v0.11.4, not driven: openwebui.com community library of model presets, tools, functions and prompts reached from src/lib/components/workspace/Models.svelte:947, Tools.svelte:639 and admin/Functions.svelte (common/CommunityDiscover.svelte 'Made by Open WebUI Community'); import back via postMessage (routes/(app)/workspace/tools/create/+page.svelte:58) Note: no community channel for skills
  • re-template-cross-tenant unknown → partial: source read at v0.11.4, not driven: automations export and import as JSON (src/routes/(app)/automations/+page.svelte:91-96 Import/Export JSON, :438) and models likewise (routers/models.py:381, :441), so an automation can be moved to another instance; searched 'tenant|organization' in backend/open_webui/models: no client-organisation concept to move between
  • re-course-recs unknown → no: source read at v0.11.4, not driven: searched 'course|learner|lesson|curriculum' in backend/open_webui and src/lib/components: no learning domain
  • op-multi-tenant unknown → no: source read at v0.11.4, not driven: searched 'tenant|organization|org_id|workspace_id' in backend/open_webui/models and routers: the only hits are vector-store multitenancy modes (retrieval/vector/dbs/qdrant_multitenancy.py, milvus_multitenancy.py) that partition collections; users, groups and config are instance-wide
  • op-tenant-quota unknown → no: source read at v0.11.4, not driven: searched 'tenant|organization|org_id|workspace_id' in backend/open_webui/models and routers: the only hits are vector-store multitenancy modes (retrieval/vector/dbs/qdrant_multitenancy.py, milvus_multitenancy.py) that partition collections; users, groups and config are instance-wide; only per-user automation limits (routers/automations.py:69)
  • op-tenant-ops unknown → no: source read at v0.11.4, not driven: searched 'tenant|organization|org_id|workspace_id' in backend/open_webui/models and routers: the only hits are vector-store multitenancy modes (retrieval/vector/dbs/qdrant_multitenancy.py, milvus_multitenancy.py) that partition collections; users, groups and config are instance-wide; admin settings are one instance-wide panel (src/lib/components/admin/Settings)
  • op-sso partial → yes: source read at v0.11.4, not driven: OAuth/OIDC with group mapping (backend/open_webui/utils/oauth.py, config.py:2582 ENABLE_OAUTH_GROUP_MANAGEMENT), LDAP/AD (config.py:2788), trusted header SSO (env.py:802), SCIM 2.0 provisioning (routers/scim.py, env.py:907) Note: old partial rested on a feature row; code covers OIDC, LDAP, SCIM and group sync
  • op-credential-vault unknown → partial: source read at v0.11.4, not driven: outside keys are kept centrally in the config table (admin Connections, tool servers) and plugin valves are Fernet-encrypted (backend/open_webui/utils/valves.py:21 encrypt_valves), OAuth tool tokens encrypted (utils/oauth.py:269); searched 'vault|keyring|secret manager' in backend/open_webui: no external vault integration
  • op-agent-credential unknown → no: source read at v0.11.4, not driven: backend/open_webui/utils/automations.py:389 an automation run gets a short-lived token for its owner ({'id': user.id, 'typ': 'automation'}), so it acts with the owner's full rights; tool-server auth is set per connection or per user OAuth (src/lib/components/AddToolServerModal.svelte:313); searched 'agent credential|service account|scoped token' in backend/open_webui: no credential per agent
  • op-admin-settings unknown → partial: source read at v0.11.4, not driven: full setup in Open WebUI's own admin panel (src/routes/(app)/admin/settings/[tab]/+page.svelte: General, Connections, Models, Documents, WebSearch, CodeExecution, Integrations, Audio, Images, Subagents, Events); not inside Nextcloud admin settings Note: own admin UI, no Nextcloud integration
  • op-setup-wizard unknown → no: source read at v0.11.4, not driven: src/lib/components/OnBoarding.svelte:82-118 is a welcome screen ('Welcome to your AI home.', 'Get started', 'Read the docs') before the first admin signs up (src/routes/auth/+page.svelte:216); searched 'wizard|setup step|first provider' in src/lib/components: no guided provider or agent setup
  • op-health unknown → partial: source read at v0.11.4, not driven: backend/open_webui/main.py:2963 GET /health and :3009 GET /health/db return JSON for probes; admin connection verify buttons only at edit time (AddToolServerModal.svelte:206); searched 'health|status page' in src/lib/components/admin: no page showing chat and dependency health
  • op-scale unknown → yes: source read at v0.11.4, not driven: backend/open_webui/env.py:381 REDIS_URL and :382 REDIS_CLUSTER for multi-worker socket and task state; models/automations.py:308 FOR UPDATE SKIP LOCKED so several instances share scheduled runs; utils/subagents.py:298 max_concurrent sub-agents; README.md:80 horizontal scalability
  • op-outside-agent unknown → partial: source read at v0.11.4, not driven: an outside agent can use a user's API key (backend/open_webui/routers/auths.py:1529) limited to listed endpoints by auth.api_key.endpoint_restrictions and allowed_endpoints (utils/auth.py:522-543), acting as that user; searched 'client registration|agent registry|service account' in backend/open_webui: no registry of outside agents or per-agent identity Note: restriction is instance-wide per key type, identity is always a human user
  • op-preferences unknown → yes: source read at v0.11.4, not driven: src/lib/components/chat/Settings/General.svelte:29 personal system prompt, :80 saved to user settings, model parameters (settings.personal.general.modelParameters), language; Personalization.svelte memory on/off; Notifications.svelte delivery; InputMenu.svelte:54 default tool-approval mode
  • ag-identity unknown → partial: source read at v0.11.4, not driven: interactive runs act as the asking user (main.py:1118 with user from the session); automation runs act as the owner with a minted token (backend/open_webui/utils/automations.py:389 'typ': 'automation', re-gated at :366); searched 'service account|run as|impersonat' in backend/open_webui: the rights holder cannot be chosen Note: fixed by trigger type, no service-account option
  • ch-shared-session partial → yes: source read at v0.11.4, not driven: Channels put colleagues and models in one timeline: backend/open_webui/routers/channels.py:976 model_response_handler answers @mentioned models (:1244) in rooms and threads; src/lib/components/channel/Channel.svelte, Thread.svelte, MessageInput/MentionList.svelte; group and member channel types (translation 'A collaboration channel where people join as members') Note: old partial; shared agent conversations happen in channels
  • ch-intake unknown → no: source read at v0.11.4, not driven: searched 'anonymous|guest|public chat|intake' in backend/open_webui/routers/auths.py, routers/chats.py and src/routes: every chat requires an account (utils/auth.py get_verified_user); no anonymous assistant that files a request
  • tl-connectors unknown → partial: source read at v0.11.4, not driven: outside services connect through generic MCP and OpenAPI tool servers (src/lib/components/AddToolServerModal.svelte:43, utils/mcp/client.py) and community Tools from openwebui.com (workspace/Tools.svelte:639); searched 'connector' in backend/open_webui: no shipped catalogue of ready-made connectors Note: ready-made connectors are community Tools, not core
  • me-rag-files yes → partial: source read at v0.11.4, not driven: RAG over uploaded files and knowledge bases: backend/open_webui/routers/retrieval.py (hybrid BM25 + vector, reranking), tools/builtin.py:3151 query_knowledge_files, :2509 query_chat_files; sources are uploads, Google Drive and OneDrive pickers (chat/MessageInput/InputMenu.svelte:399, :692); searched 'nextcloud|webdav' in backend/open_webui: no Nextcloud Files source Note: old yes; grounding works but not on Nextcloud Files
  • me-context-docs unknown → yes: source read at v0.11.4, not driven: backend/open_webui/utils/terminals.py:189 get_terminal_agents_md loads AGENTS.md from the attached Open Terminal and :239 add_terminal_agents_md injects it; notes can be attached as documents (chat/MessageInput/InputMenu.svelte:322 Attach Notes); folder system prompt and files (utils/middleware.py:2591)
  • sk-share-tenants unknown → no: source read at v0.11.4, not driven: skills are shared by access grants to users, groups or everyone on one instance (backend/open_webui/routers/skills.py:357 access update); searched 'tenant|organization' in backend/open_webui/models: no organisations to share across
  • co-algoritmeregister unknown → no: source read at v0.11.4, not driven: searched word-bounded 'algoritmeregister|algorithm register|register' in backend/open_webui/routers and src/lib/components/admin: no publication to the Dutch Algoritmeregister
  • co-dpia unknown → no: source read at v0.11.4, not driven: searched word-bounded 'dpia|impact assessment|fundamental rights' in backend/open_webui and src/lib/components: models have no field or link for an assessment (backend/open_webui/models/models.py:74 ModelMeta)

@rubenvdlinde

Copy link
Copy Markdown
Contributor Author

Rating change log, part 8 of 8

open-webui (continued)

  • fl-parallel unknown → yes: source read at v0.11.4, not driven: backend/open_webui/tools/builtin.py:1680 delegate_task 'Delegate focused work to a parallel sub-agent', foreground bounded by a semaphore (utils/subagents.py:370 max_concurrent, default 20) and background runs (:364 max_async); admin limits in src/lib/components/admin/Settings/Subagents.svelte
  • op-languages unknown → yes: source read at v0.11.4, not driven: src/lib/i18n/locales/nl-NL/translation.json: 3432 of 3518 keys translated; language picker in src/lib/components/chat/Settings/General.svelte (settings.personal.general.language); 60+ locales in src/lib/i18n/locales

@rubenvdlinde
rubenvdlinde merged commit a5cb70f into development Sep 26, 2026
38 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/hermiq @ 9189629

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-specs ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
check-bundle-budget ✅
composer ✅ ✅ 123/123
npm ✅ ✅ 843/843
app:check-code ⏭️
info.xml ✅
REUSE ❌
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-26 21:16 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant