A course with every lesson read no longer reloads without end, the reader offers the next lesson, and Recalculate in the editor stores the figure it computes.
Añadido
The lesson reader offers the next lesson, and only "Back" on the last one
Corregido
A course with every lesson read and a practical component still open renders once and names the blocker instead of reloading without end
Recalculate in the editor's status strip stores the monthly cost it computes, on frozen AS-IS versions as well, and the Versions panel shows the same figure
v3.12.0
Solutions Read Their Diagrams
A solution now takes its capabilities, skills, systems, duration and audience from the diagrams it links, and a workspace blueprint in the marketplace becomes a workspace with one click.
Añadido
Solutions derive capabilities, skills, occupations, systems with dependencies, duration, throughput and audience from their linked diagrams, per run variant split into provider and customer side
The solution form shows "From the process" beside "Added by you", locks derived audience types with their origin, flags additions that no linked diagram carries, and offers to adopt what the diagrams name
A pool without a workspace names one of the fourteen workspace types and, optionally, the capability whose team stands in it
A workspace blueprint in the marketplace is created as a new workspace, a team or a sub-workspace under a workspace you administer, and the workspace wizard accepts a preselected blueprint
"Learn ProcesOS" is a workspace blueprint: creating it gives a workspace with the eight workshop capabilities ready to be held
Cambiado
The three legacy pool categories are migrated to workspace types (consumer to person, business to organisation, government to municipality)
"Adopt into workspace" no longer appears on workspace blueprints, since it recorded an adoption without creating anything; the create action replaces it
The Continuity & Resilience product id is part of the shipped product map, so a dedicated instance needs the environment override only for its own Stripe account
v3.11.0
Continuity, Execution Governance & Passes
Ask what stands still when a system fails, keep agents inside their mandate at the moment of acting, and let every helper run their own pass of a process.
Añadido
Continuity & Resilience module: a per-system failure cascade over dependent systems, tasks, processes, capabilities and partner workspaces, in the cockpit Systems tab, the editor's analytics and Wizzy's stand sentence
Typed system dependencies (required or optional), stand-in systems, and the workspace that operates a system; a shared service names the systems it shares in both directions
Recovery targets as numbers on processes, systems and capabilities, with the cascade naming which system comes back later than a process can wait
Capabilities show a derived degraded state with the systems that cause it; the execution gate reports it to persons and refuses agents
Execution events: one append-only record per lane execution with a hashed input and the mandate it ran under, a pre-action gate, handover entries per pool boundary, and an oversight register in the cockpit
Passes: each participant runs a lane on their own, delivers rounds at the diagram's gate, is paid per confirmed round, and finds their passes in one list
A change process with a plan is executed as quests; the last lane's confirmation re-freezes the process as its next AS-IS
Handbook articles carry a review interval with a one-click reconfirmation; the cockpit lists the ones past it
A personal process can be confirmed lane by lane as its own status, distinct from validation
An accepted interview proposal rings the process owner, and an accepted "there is no system" converts the task on the server
Demo workspaces carry criticality, single points of failure, dependencies and recovery targets, so the cascade has something to show
Cambiado
The AI workspace briefing names special-category data objects by class only, and the provenance answer says what was withheld
Defining XP achievements and skill trees requires the workspace-management permission
The session list identifies devices by an opaque handle
Corregido
Lane names with special characters register under their real name in both lane parsers, and the credential gate for such a lane resolves its role
The federated public workspace list returns workspaces that share their location
A locked thread shows its status to the people who may see it
Template export carries system dependencies and integration endpoints as matching placeholders, without secret references
Editor documentation reflects the document import that shipped, and the billing designation says why it grants nothing
v3.10.0
Curriculum, Workspace Courses & Priced Change
A course for every maturity level, courses your workspace publishes itself, and a change decision that shows what it costs and when it pays off.
Añadido
Curriculum courses L0 to L5 with workshop diagrams, quizzes and a practice component that measures the learner's own diagram; L6 and L7 as an outlook
Practice mode in the validation wizard for rehearsing a sign-off on a course diagram
Operator seed for the whole curriculum, one click or one CLI command, and the "Learn ProcesOS" marketplace bundle of the eight workshop capabilities
Workspace courses: create, adopt from the catalogue and adapt, publish to the teams below, sell as a listing, or propose as a standard for the instance
Course completion credentials issued by the publishing workspace, and a course badge that names it
A course for Academy publishers, nine lessons with quiz
Change process per AS-IS → SHOULD-BE pair with a one-time change cost, a cached comparison, and the amortisation date
Decision surfaces show the same four figures: change cost, monthly cost before and after, and when the change pays for itself
Wizzy's review of a diagram as evidence on a quest attestation, and as feedback on a course practice diagram
Solution variant pickers offer agreed AS-IS processes, and submitting a variant requires one
Interview answers are reviewed by the process owner; accepting one writes it into the diagram, rejecting one records the reason
Data repairs in the admin panel: recompute maturity levels and remove forged AS-IS rows, each behind a dry run
API keys can be scoped to a workspace from the form
A first-time guest is greeted in the language their browser asks for
Cambiado
A change vote opens only once the fork is priced; an unpriced fork waits in "pricing open" and its creator is asked
The change cost is the whole price of a change; the earn-as-you-grow implementer share is retired
The L5 gate requires a priced and compared change; the L4 and L5 lessons and the docs say so
Learning capabilities are excluded from every maturity denominator
Members leave a workspace through ProcesOS's own exit; the framework's route is closed
The editor's state strip and analytics dialog show the level the server computed and its gaps
A membership still waiting for the governance body can read, and nothing else
Seeded template processes are validated through the real validation path, or stay drafts
Corregido
The validation server derives lane, tasks and quests from the diagram, so a session signs only what its lane owns
Sign-off snapshots merge per lane and detect in-place task edits; every save is compared with the snapshot
Every branch of a decision gateway asks for a probability in all four places, and inclusive gateways may total more than 100%
Manual AS-IS freezes ask "validated first", and the maturity ladder computes L4 to L7 live from the stored diagram
A marketplace bundle lists what is inside it, a prerequisite shows its title, and a quest states what it pays and in what rhythm
Every workspace permission is named and explained in the roles editor, and the legend beneath speaks the admin's language
Screen readers hear labels in the user's language; the Spanish settings page is in Spanish
Timespans are priced down to the second and the panel names each one
The wallet portfolio reports a missing network instead of failing
The delegated FAIR registrar reaches the admin shell
The acceptance progress card is reachable and knows all eight gates
Quiz answers appear at varied positions and shuffle per attempt
A markdown link onto an app route keeps its destination
Eliminado
Implementer share slider and the client-net-savings split in the ROI view
v3.9.1
Migration Hotfix
Schema migrations create the collection they index, so the 3.9.0 upgrade applies cleanly on every instance.
Corregido
Schema migrations create the collection they index when it does not exist yet, so an upgrade records every migration and the instance no longer reports itself degraded
The same guard reaches the foundation-skill slug index, so instances seeded by earlier tooling apply that migration cleanly too
v3.9.0
Wizzy in the Cockpit & Credly Badges
Wizzy reads your cockpit and speaks up, credentials become Credly badges, a process can start from a document or a conversation, and every template ships as a spec.
Añadido
Wizzy on every cockpit route: reads the areas you may see, names your standing, suggests only resolvable actions, and is metered and stamped
Cockpit notice: one computed sentence about what needs attention next, dismissable and never repeated
Credly integration at instance level: badge designs per credential kind, opt-in per person, mirror button, automatic issuance per design, revocation sync
Quest completions carry a stable badge kind and the quest builder can attach a Credly badge design
Create a process from a document: text layer first, OCR fallback, candidates with page citations, review, import through the pack importer
Process conversation: tell Wizzy a process, it asks along the workflow; "Analyze with Wizzy" builds the diagram with a source turn per element
A capability node shows which exchange solutions cover it, grouped by what each solution still needs
The Gaps tab lists real gaps and names why a dependency is missing
A skill certification can be issued by hand by the Head of Education
A published capability can be taken into an organisation's tree from the exchange
A workspace states its LEI; the register is asked and re-asked, and a DNS record binds the identity
The discussion of a process is reachable from the editor, with its message count
A solution listing has an address on the exchange, and register slugs link to the capability node
Cambiado
Feature tiers now bind server-side: a route refuses a workspace below the feature's tier, not only one without the module
Every workspace template, the Village, the demo and the blueprint scripts are built from process specs; no seed carries hand-written BPMN any more
Seeded lanes carry a rate with a time unit, start events carry tokens, meetings are groups — the figures stop reading as zero
Achievement suggestions come through a metered, stamped route and the rules table prices them; the AI skill-suggestion button is retired
One way to a new diagram, in the editor and on the overview; the last edit before "+ New" is saved
The Academy shows a plain sentence and the handbook links while the catalogue is empty; filters appear once there is something to filter
Governance and Versions tabs say why a button is unavailable, and stop offering what has already happened
The workspace creation wizard names its steps consistently, describes every module, counts parent workspaces and marks the irreversible choice
Meeting captions render in the reader's language from the stored facts
Reward grants and approval requests lead to the Rewards tab
Corregido
A credential revoke reaches only the workspace the caller is allowed to act in
The level-reward list answers members of the workspace only
A personal workspace admits nobody but its owner
Head-role designations and the workspace currency are read from the organisation row again, so designated heads count and cost bases show the set currency
A lane role's skill requirement is a minimum, and a minted certificate meets it
A workspace skill without an active flag counts as active for every reader
The validation round hands out its tasks again when a single person holds a lane
The structure delta and the walkthrough handle ad-hoc sub-processes on one level
The write path repairs capitalised BPMN tags and records what it repaired
A person's credential list loads on an instance without a chain
Seven properties-panel entries reach the screen, and one throwing entry no longer freezes the panel
The Soziale-Fahrten and Supply-Chain templates find their data objects in the library
The onboarding, the finish screen and the dashboard agree on what a complete profile is
A non-member who follows a shared workspace link lands on the public profile or the dashboard instead of a dead end
The instance node reaches active where the earlier migration could not
v3.8.0
Companion App and Personal Integrations
The phone signs in and gets notified, Notion and Google Drive connect to the person rather than the workspace, and a role offering becomes an engagement that pays out of what it improves.
Añadido
The companion app signs in with a bearer token issued from a browser session, and workspace API keys are refused on personal endpoints
A push channel to iOS and Android for the companion app, carrying the notification's group and its id and nothing else; an instance sends once the Apple and Firebase credentials are placed
Notion connected per person: pages as workspace knowledge, databases mapped onto resources with a dry run, pages and databases as dataroom sources
A Notion database bound to a start event counts the runs of a process, so the frequency behind every cost figure is measured instead of estimated
Google Drive connected per person, with a personal dataroom that can be bound into a workspace
Workspace members can be invited to a bound Drive folder through Google, and the workspace role now decides the Drive role
A role offering becomes a capability engagement, with the outcome share credited from the measured KPI difference
Quest bounties are recorded as payout credits in a ledger, with per-currency totals and a stated gap where no payment rail exists yet
The founder pack as a one-time offer: a consultation and a legal-form template pack delivered into the personal workspace
A workspace exports its own records as an archive, with a manifest naming what it contains and what it deliberately does not
Solution packs import as a zip with a manifest, a dry run first, a cost estimate and a funding request to the head of finance
Solutions carry the ESCO skills their lifecycle processes demand, the data flows between their systems, and the parts each cost figure is made of
A start event can carry a batch size, so a run that moves twenty-four items costs twenty-four items
The quest pane says what a quest is about, whether that is a capability, a solution or a resource
Odoo Documents folders as a dataroom source
Wizzy can create a data object and a data store, the store linked to the workspace CMDB, and can insert a step between two others by making room instead of hunting for it
A meeting drawn on a diagram carries its participants, duration and cadence, and is costed from the attendance of every lane in the room
Cambiado
Rearrange and Tidy up lay a diagram out on the same grid the spec builder uses, instead of a second arrangement
The eight collections that hold personal data have a class in the register and a step in the retirement cascade
Setup steps report their completion from the data behind them, and the systems step exists rather than counting as a placeholder
The register of the FAIR passport has an address, and three surfaces lead to it
Odoo handbook articles go through the same sanitizer as everything else, with one configuration instead of two
Seeded sample workspaces and the process-lifecycle handbook article read in the language the interface is set to
The six leadership roles are named in German on a German interface, each with a sentence saying what it does and whom it reaches, so the billing contact and the head of finance are told apart
The help panel lists the knowledge base and each workspace's handbook, and the global menu has an entry for it
Corregido
A re-keyed lane assignment keeps the workspace role it was vouched for, and the person saving the diagram is told when a rename could not be carried over
The account deletion reports what it removed and what it kept without a name, in sentences a person can read
Forking a frozen diagram asks the same credential gate the direct assignment asks
The cost view names a per-execution figure as such once a run carries more than one token
The editor toolbar fits its window: controls fold into a disclosure as the window narrows, so the title, the tabs and the buttons stay readable and separate from about 930 px upwards
The header names the workspace you are in, including one you just created
The closed state strip announces the frozen lock and the maturity level to a screen reader, not only to the eye
Opening the editor no longer leaves aborted view transitions as unhandled rejections in the console
v3.7.1
Walkthrough Fixes II
The German interface speaks with Du and one word for the workspace, the first screen after sign-in speaks once, and the remaining findings of the walkthrough are closed.
Añadido
Post-sign-in landing on the dashboard with one address at a time: cookie notice, tour offer, release banner
Leadership roles default to the workspace owner at creation; existing one-person workspaces are backfilled once
A FAIR register entry in the user menu and the landing footer
Quest listings show bounty, goal, deadline and the issuing workspace
Cambiado
German interface: Du everywhere except legal, invoice and privacy texts; one word for the workspace
Template figures carry a stamp until the first own change and are excluded from maturity; a seeded vote runs as the template
The maturity card names its profile and shows a medal only when more than half of the profile's dimensions are assessed
The head bar reads XP and notifications from one store per tab
Framework names follow the reader's language on every surface; the data-object register lists each open item once
The compass appears above a threshold of public workspaces and marks the one list; its reasons name what matches
Wizard and setup copy say what happens: Continue buttons, box placement, the irreversible choice named, entry counts measured, the clarification boxes shortened
Dates and numbers follow the reader's locale on the offerings page and invite links
The tour announces its continuation instead of starting it, every step highlights something or stands alone without darkening the canvas, a click beside Wizzy asks before it ends the tour, and the bubble waits for its anchor
Corregido
The working-languages field keeps what you type
Avatar initials skip brackets and digits
The sixth leadership role can be assigned in the workspace settings
Process tiles in the cockpit open the process and are reachable by keyboard
A quest without requirements no longer certifies that you meet them
Seeded data objects of the bakery template resolve to the library, so a new workspace starts without an Art. 30 gap
Level-gate promises that nothing enforced are gone from the product and the code
v3.7.0
Spec Builder & Datarooms
Every full page load renders again, a process is built from one spec, Notion and Odoo Documents mirror into datarooms, and forty defects from a full UI walkthrough are fixed.
Añadido
Spec builder as an application module: one call builds a laid-out diagram with readiness findings and a solution pack; the village template seeds through it
Wizzy builds a process from a spec (`build_process_from_spec`) behind the usual approval, and relays import warnings and pool or skill gaps
Diagram list imports several `.bpmn` files at once, each with an optional `.pack.json` that creates systems, data objects and token resources; ignored files are named
Wizzy points at the element he talks about, asks before walking a token, and looks at the diagram as a picture on an instance whose model can see
Notion: personal connection, sharing of a page or database into a workspace, and a search across the connected space
Datarooms mirror a Notion page or database or an Odoo Documents folder as metadata, with sync runs, a run history and a mirrored-entry count
Odoo Documents: the integration browses folders and files on Odoo 18 and reports whether the Documents module is present
Dashboard: three doors after the Core activation, the chain from the instance to you to your workspace as one picture, and the first quest one scroll away
Tour: the start names its reason, the wait is narrated, a locked tour names what would unlock it, and a skipped tour is never recorded as taken
Release images carry a version tag and OCI labels; the main branch publishes its own tag
Cambiado
Templates seed drafts with their quantities; they no longer seed validations, task confirmations or frozen AS-IS versions in the creating person's name
One process count on every cockpit tile, sentence and map; a SHOULD-BE fork is not a second process, and the two validation terms are named apart
Compliance rulebook explanations for LkSG, NIS2, GDPR, DORA and ISO 27001 read in the reader's language, with plurals by number
Numbers, currencies and relative times follow the reader's locale everywhere; the save pill and a language name speak the reader's language
Maturity exclusions read as sentences instead of internal codes, and capability nodes show their titles in governance blocks
AI readiness is answered once, for the About-Wizzy panel, the readiness bubble, the presentation and the interview; a workspace without a provider gets a sentence and a reference, never a bare error
The editor derives its workspace from the loaded diagram, the versions list follows the diagram, and Manage diagrams returns to that workspace's list
The billing overview shows the instance licence and no upgrade hint while the licence holds
The treasury lock distinguishes a role held by someone else from a role nobody holds, and links the step that assigns it
The personal onboarding screens say what to do, the Settings shell scrolls once, and locked tabs read as locked
The instance card on the journey page, the settings menu entries for data objects and artefacts, the tour's step about levels, and the Escape key in the workspace switcher behave as their words say
Admin, Foundation Skill Library: the sector tiles count the whole registry, the occupations are listed by ISCO major group, and the delete dialog opens as a dialog
The governance margin is profit over revenue, averaged over the processes that have revenue, and says over how many
Corregido
Every full page load with a session renders: refresh, Back button, bookmarks, links from email, the reload after a language or theme switch, and the 404 page
A federation identity that does not exist is an empty state, not an error
Failed requests carry a reference the person can quote: credentials, diagram import, presentation
Avatar initials skip brackets and symbols on every avatar
v3.6.1
Interview Voice Patch
Wizzy speaks one thing at a time in the interview, offers one dialog per system, and recognises a system named with words around it.
Cambiado
A mention that carries a known system name as whole words links to that system rather than offering a new one
Corregido
Wizzy reads the task sentence and the interview question as one utterance, and a newer utterance replaces one still being synthesised
A system named in the answer opens one confirmation dialog, and a name declined once is not asked again during the session
v3.6.0
Wizzy, the FAIR Register and AI Provenance
Wizzy guides the tour and drafts quests, the FAIR Passport gets a public register and a registrar desk, and every AI-written output says so.
Añadido
Wizzy guides the product tour as an animated figure with a pointing pose and a speech bubble; the tour is step one of the first quest "Wizzy shows you ProcesOS"
The editor walkthrough highlights, scrolls to and selects the current element on the canvas
A public register of FAIR Passports with facets, search and sort
The registrar worklist as an admin panel, with an application detail showing the trail, moves, passport status, revocation and the assessment lane
A case lane on the application detail: fee waiver, FFDE accompaniment and appeals, each with its refusal spelled out
The instance is a real, active node in every workspace tree, with a card on the journey naming the AI model and provider, the operator, the region, the licence, the federation identity and the data-centre certificates the operator enters
Wizzy presents the walkthrough: the figure moves to each element with the narration in its bubble, the interview question answered in place, and the text panel as the fallback for reduced motion and small screens
Framework agreements between a person and the operator or a workspace, on versioned templates per jurisdiction, with terms acceptance as the floor and money exchange locked until the agreement is active
A provenance stamp and badge on every AI-generated output: diagrams, mirrored comments, forum insights, process drafts, reports, quest drafts and Solution Package sections
Voice transcriptions name their provider and processing region
A five-step quest builder from the need to the publish, Wizzy drafting a quest from free text, and eleven partner standard quests one click away
Workspace type, solution portfolio and FAIR Passport as quest criteria; solution-targeted quests are suggested to the workspaces that carry the solution
The fulfiller's view of quests, with a balance that follows the scope and names the income nothing records
A frozen AS-IS sends you to a fork, and an accepted change vote makes it the next AS-IS
A validation quest per lane with a stepper in token-flow order, and what changed in the process on the page people vote from
One ballot with several candidates for one seat
A network template with a council, three sub-groups and one invite link
Federation peers by URL with a real handshake from the panel and incoming requests
Location once, as a jurisdiction code, with one classifier for the six EU sites
Four self-asserted person status artefacts as the placeholder for the EUDI wallet
Kind and exchange on personal offerings; legal standing as an activation requirement asked only when money is exchanged
Compliance shows the AI system per task and the governance owner's scope
A Forks filter in the diagram listing, off by default
Skills by life domain after a CV import, the profession step, and a way out of the data-room wall on the journey
A cacheable prompt prefix with a workspace briefing and a TOON delta, and a "From cache" column in token usage
The wizard prompt names every tool, and the TOON legend is generated from the code
OmniRoute as a speech provider with seconds from the gateway, a model-name capability map with grouped selects, OCR model suggestions, and the effective AI source with usage grouped by model and area on the admin page
ESCO 1.2.1 as the pinned skills release, with an operator runbook
Cambiado
Standard quests are the one path to a partner; the partner-request API is retired
The provider registry carries its own freshness check; the public CMDB scan without a caller is gone
A published listing keeps its contract terms; changes go through a new listing
A diagram's governance status moves only through the governance flow, never through a metadata edit
Internal quests are visible only to members of the publishing workspace
Wizard readiness counts confirmed members only
Corregido
The properties panel, the element type in its header, the save summary, the GTT capability shape and the Sustainable Impact evidence chips speak the reader's language
Structured AI answers arrive complete on gateways that stream by default
A governance promotion interrupted mid-way completes on the next run
Quest deadlines that arrive as text are stored as dates
The template picker asks the registry which sector a template is for
The admin persona travels with the wizard prompt, and the admin page shows which prompts are overridden
One compliance vocabulary across the editor tool, the panel and the maturity gates
Task and process compliance are recorded in the maturity snapshot
Icon buttons on the FAIR surfaces carry names for assistive technology
The Spanish FAIR catalogue is fully translated
v3.5.0
Confirmed Members
A governing body confirms who joins and issues a member credential, the operator can invoice and sell AI token packages, and ESCO skills reach the picker, solutions and life domains.
Añadido
Membership confirmation: a workspace with a governing body holds joins from links and join requests until a chair, vice-chair or operator confirms or declines them
Pending members read everything and change nothing, see a banner saying so, and receive a member credential from the body on confirmation
Payment requests with a Mod 97-10 checked reference, settled only by the ledger or the Stripe webhook, with part payment and overpayment named
AI token packages a workspace can buy once the operator configures them, credited as an addition to the monthly budget for the months bought
Fulfilment invoices behind the merchant-of-record switch, a printable invoice document, and an invoicing settings page for the operator
ESCO fetch as an admin action in the background, with progress, a job that survives a page reload, and a notice when a newer ESCO release is known
Skill groups and education fields as an axis on foundation skills, with labels in every shipped language, and group headings in the skill picker
Directed skill relations from ESCO, so a skill that is essential for another counts as its prerequisite
Workspace skills can be linked to a foundation skill, and linked skills satisfy capability requirements and quest criteria that name the ESCO skill
A solution's skill and occupation profile, derived from the capabilities it names, with rows the provider adds
ESCO skill groups, education fields and occupation groups mapped to the seven life domains as anchors, shown in the life-domain admin panel
Operator runbook for fetching, mounting, seeding and upgrading the ESCO dataset
Cambiado
A capability requirement on a skill nobody in the workspace can be evaluated against reads as not evaluable, with the reason named, rather than as unmet
The seed button in the life-domain panel is always offered, and the seed reports which anchors it added
The skill detail panel and the skill graph show the four ESCO relation types with their own labels
Corregido
The admin AI top-up grant is credited once per payment request, however many bank lines settle it
The ledger match form offers payment requests, so a short transfer marks the request part paid
v3.4.0
Quests From Process
A validated Setup process becomes a quest graph, a workspace elects its governing body with term limits, courses end in a certificate and a badge, and the operator's bank account is wired in.
Añadido
Quest from process: a validated Setup diagram generates a quest graph, one quest per lane, with dependencies, pre-assignment and credential gates
Six quest kinds (setup, run, change, retire, work, delivery), each with its own acceptance rule, and a typed target of capability, solution or resource
Recurring quests: run services and deliveries run in cycles that are delivered, confirmed or rejected, with the amount per cycle declared up front
Quest roll-up: when every lane quest is verified the capability is ready for validation, and activating it closes the parent quest
Governance body as a setup section: mandates with roles, seats, term length and rotation, and setup is not complete without it
Mandate votes: an owner, an admin or the acting chair opens a vote once setup is complete; the term starts at approval
Term end: holders are reminded before a mandate expires, with the succession vote prefilled and the rotation rule applied
Child workspaces inherit the parent's governance body, and the origin is shown
Invite from the network: a sub-workspace picks candidates from its ancestor workspaces, and a workspace can admit only members of its parent network
Shareable invite links with a role, an expiry and a quota, and a join page for them
Academy: a credential for every completed course, a quiz as completion requirement, evidence, certificate and badge on the course page, badges as profile achievements
A ProcesOS 3.0 course seeded from the rewritten platform and framework articles
Banking provider registry with Revolut Business: encrypted settings, a test endpoint and a signed webhook receiver
Operator ledger: transactions are ingested by webhook and catch-up, Stripe payouts are mirrored and reconciled, with an admin finance page
Payout accounts and payment orders with four-eyes approval, handed to the provider and completed through the ledger
Bundle products are unfolded into their parts at checkout and in the subscription webhook
LkSG rulebook with a framework entry and a supply-chain example template
Workspace type is chosen in the creation stepper
Cambiado
Quest projection reads the frozen AS-IS version the claim names rather than the working diagram
Publishing a quest sets it to published, so offers can be accepted right away
Status and tone colours come from declared theme tokens across the interface
Indexes on XP, skill progress and notifications keep those pages quick as they grow
Corregido
The audience hub shows its taglines
The sign-in panel scrolls on short viewports, and the quest bubbles on the login map keep clear of it
A capability in a terminal status carries no health warning, and gate redirects keep the request method
v3.3.0
Priced per Workspace
Per-workspace list prices, existing subscriptions keep their rate, a referral programme credits the people who bring a workspace in, and every landing page opens with the problem it solves.
Añadido
A referral programme: an initiator's code is entered at checkout, and 20 percent of the referred workspace's net plan price is credited to a workspace of the initiator for twelve months, never paid out and never combined with a founding place
A referral panel in the billing settings: the own code, where it pays into, the credits it has earned, and a code field on the upgrade with a plain explanation of who receives what
An operator ledger for referrals under Settings, with the rows that need a decision listed first and a one-way block for a code
An Advocate credential, minted once in the initiator's personal workspace on the first credit
A per-person view on the pricing page: what Team & Scale and the Pilot Set cost each month for 5, 20 and 50 people, divided from the list price
Founding places, ten per kind of workspace, with a live counter on the pricing page and an honest closed state
The Pilot Set: Professional plus four modules at 219 a month, next to the Full Platform at 290
The partner page names four kinds of partner, mappers, implementers, solution providers and initiators, with what each does, how they qualify and how they are paid, plus an illustrated flow with a video slot
The FAIR Passport explained on the academia page with a four-pillar switch, and a stewarded-ecosystems story told through one forester and one summer
The governance view rebuilt around a decision queue, coverage and attention, with AI systems staged by risk class and IT systems as first-class subjects
IT systems, data objects and resources as cockpit surfaces, with a signpost from the settings for personal workspaces
Personal data export and account retirement, and the RETIRE process of workspace_core that runs the deletion cascade
End-event completion credentials: a confirmed end event hands the lane's members a badge, confirmed only by the lane's responsible
Workspace OCR with your own key, next to the AI and voice keys
A process maturity fact on solutions, and a submission floor that keeps process-less listings readable as legacy IT systems
Cambiado
List prices raised to what the category charges. Subscriptions that already exist keep the rate they were signed at
AI Studio includes a fair-use quota of 500,000 tokens per workspace and month, with one notice at 80 percent. Workspaces with several members share the one budget, and a workspace answering with its own key is not metered
The Starter's three validated processes are a standing count: deleting or archiving a process frees its place again
Every amount the platform shows comes from one price list, and bundle savings are computed from it
Every audience landing page opens with the question it answers, links say where they lead, and no link drops a visitor into the editor or a sign-in unannounced
The ecosystem map and its detail panel share one stage, each actor's panel opens with a question, and a chosen actor is no longer remembered between visits
Landing copy across all pages rewritten to one thought per sentence, with jargon spelled out or dropped
The pricing page says how modules are bought: choose a workspace plan first, then add modules in that workspace's billing settings
The voice consent dialog names the chat model and its operator, not only the voice provider
Quest matching evaluates a candidate's language and location, and an empty profile field reads as not evaluable rather than unmet
A linked data object takes its name and fields from the library at render time, so a renamed object shows its current name in every diagram
Markdown renders through one canonical sanitizer everywhere it appears
Corregido
Team & Scale states the price of an additional workspace from the price list, so it cannot go stale in translation
Bundle cards show a saving only when the prices support it
Switching theme or language on a pricing anchor keeps the section in view
The marketing header stays on the Partners and Solutions pages
A draft or archived capability template is served only to its author and curators, on every sub-route
A provider's cost basis stays private to the provider, including for demo visitors of the cockpit
A pool without lanes reaches the governance tab as its own lane
A minted credential names the issuing workspace by its name
The Back button after a sign-out returns to a page rather than an error, and the error page offers a working sign-in link in every language
The editor shell fits the viewport on small screens, the toolbar folds, and dialogs stay reachable
Upload limits are announced at boot from the configured value
Blueprints open on the marketplace tab that exists
Eliminado
Governance Suite and Sustainability Pack, two narrow bundles whose discount had drifted to between 12 and 16 percent
The stand-alone blueprints page, which duplicated the marketplace
v3.2.0
Focus & Stewardship
Workspaces focus their own sectors' capabilities, stewards earn standing for curation work, relations get a hands-on editor, and linked datarooms become usable right from the forum.
Añadido
Workspace sector declaration with a focused capability tree: your sectors in the foreground, everything else dimmed but explorable
Domain segment health on the journey and workspace wheels — a named blocking capability with its standing duration, and an honest "nothing measured yet" state
Category stewards: the foundational and enabling catalogue layers can be assigned steward workspaces, with the same strict curation gate as sectors
Stewardship XP with a fixed published economy, and honorific per-scope stewardship credentials minted on first publish
A relation editor on the capability catalogue: typed add-relation dialog with evidence, drag-to-link on the tree, keyboard-accessible throughout
Forum-linked datarooms: upload from the thread, inline PDF viewing, and sanitized Markdown rendering under the dataroom's access policy
A licensed-instance workspace-creation flow: license-provided features instead of prices, and basics inherited from an admin-designated primary workspace
The business backoffice capability pack: ten seedable templates from bookkeeping to contract management, with ESCO-verified skills and a month-end-close blueprint
Cambiado
Withdrawing a capability relation deprecates it with full provenance — relations are never deleted
Cycle refusals in the relation editor quote the exact loop so the fix is obvious
Workspace connection requests reach the receiving side: admins are notified, the incoming request shows accept and decline where the receiving workspace looks, and a pending-requests banner appears on the cockpit
Connection notifications arrive in the reader's language instead of hardcoded English
The sector taxonomy admin panel and curation surfaces resolve stewards for every scope through one shared index
v3.1.0
Capability Graph & Sector Stewardship
The capability model becomes a curated graph: typed relations, sector-steward reviews for FAIR Passports, and personal career paths derived from ESCO occupations.
Añadido
Curated capability relations: all thirteen relation kinds as typed edges with ranks, qualifiers and references, editable through one guarded write path
JSON-LD publication of the capability catalogue under a versioned UCX namespace, with content negotiation on the catalogue, template and sector APIs
Personal starter catalogue: adoptable capabilities across all seven life domains, seeded per instance by an operator command
Sector fan-out on the personal journey: professions derived from ESCO occupations, adopt-to-curate shared catalogue entries, and a seven-rung responsibility ladder with nine worked professions
FAIR Passport sector reviews: steward queues, a changes-requested round trip with mandatory written reasons, resubmission from the solution page, and notifications on both sides
Quality, capacity and utilization conditions on capability instances, with capacity recorded as declared availability — never compared or scored
Domain wheels: one curated grouping axis per capability target type, from persons to nations, with sector-projected sub-segments
Five-value statement verdicts on personal capability requirements, so nearly-met setups read as what they are
A sixth global handbook article explaining who tends the capability catalogue
Cambiado
Exit and repatriation are sourcing options with their own panel on the template detail — no longer graph relations
Seeded catalogue entries carry a steward who can curate them; sector taxonomy upgraded to ISIC Rev. 5 with typed crosswalk predicates
The elemental grouping axis left the public capability model; the five roots continue as the community capability slice under forward-compatible aliases
Seed skill requirements resolve against the pinned ESCO release before anything is written — an unresolvable skill stops the seeder
The governance tab counts every stakeholder-validated maturity level from three upward and renders one honest legend
Login and network maps draw a self-contained stage, preparing fully self-hosted basemap tiles
Corregido
The workspace-creation wizard advances to the next step immediately after each answer is saved
Capability validation refusals surface their reason in the cockpit instead of failing silently, and the gtt:view / gtt:validate permissions are enforced on every route that declares them
An expired FAIR Passport also retires the solution's certification mark
A personal workspace can no longer be made the parent of another workspace
The cockpit tree tab reads its own workspace's tree with bounded queries
Workspace-scoped API keys act only within the workspace they are bound to when confirming taxonomy crosswalks
v3.0.1
Reachable Again
The app bar follows you onto workspace profiles instead of stranding you there, and you can finally create the personal dataroom the CV import always expected to find.
Añadido
Datarooms in personal settings: create and configure the encrypted rooms your evidence import has always expected, on any plan
Corregido
The app bar stays with you on public workspace profiles, so opening a workspace from the directory no longer strands you there
The app bar no longer overflows on medium windows, where its links were allowed to shrink out of the row instead of hiding
v3.0.0
The Personal Side
Every person gets a real place of their own: a capability journey along seven life domains, a first quest that ends in a genuinely activated capability, and solutions that travel on a FAIR passport.
Añadido
Your journey: a personal capability graph along seven curated life domains, with domain progress read from your real activity
The first quest: four honest steps from signup to your first activated capability, worth 425 XP across the arc — each milestone paid once, forever
Academy lesson player with per-lesson progress, and an eight-lesson orientation course in English and German, editable per instance
All ten capability activation requirements are now evaluable — experience, location, working languages, delivery mode, capacity and an NCTB-aligned identity floor included
Personal equipment: record your systems, machines and frameworks and bind them to your capabilities as honest self-declarations
Capability milestone XP: adopting pays 25, activating pays 150, through the same audited economy as everything else
Solutions declare their audience and their capability output — who they are for, and what they provide, improve, require, use or activate
FAIR passport machinery: tiers, applications, appeals with reminders, examiners, readiness, expiry and countersignature integrity
Workspace hierarchy: consent-guarded parent and child links, capabilities that spin out into sub-workspaces, bottom-up capability and cost rollups
AI stack: OmniRoute completion provider, document OCR, a speech provider per capability, and a provenance line naming who runs the model
Cambiado
FAIR is the passport status, not the entity name — the registry lists solutions, and the badge renders exactly when a passport is issued
The personal area is findable: diagrams live in the personal shell, the dashboard links your journey, and the first quest sits where a new person lands
Onboarding settles into three skippable steps with a handover screen, profile XP paid on facts, and a light-or-dark choice before the first paint
Four themes become two maintained themes plus the whitelabel CI, whose brand colour is derived to a readable contrast
Academy certifications are the evidence gate for skills: completing a course now issues the certificate a crossed skill-tree threshold promised
Corregido
Courses can actually be completed: the lesson player surfaces the completion path that existed server-side with no way to reach it
96 undeclared design tokens now resolve instead of rendering hard text-coloured borders, and a new test keeps the class of bug visible
The status palette uses one declared name per colour instead of five undeclared spellings
Capability nodes export correctly to SVG and PNG instead of leaving holes
Artifact updates are scoped to their workspace exactly like every sibling write
v2.20.0
Guided Setup, Incentives & Claims
Creating a workspace is now a linkable, resumable six-step flow. The XP economy moves into a cockpit Incentives area, and people can submit claims for verification across workspaces.
Añadido
Workspace creation runs as six linkable steps with its own routes, so a setup can be shared, left and resumed
Unfinished workspace setups are listed for 30 days with the step each stopped at, and can be picked up where they ended
Provisioning shows the phases it has completed and reports what the template actually created once it is done
Ecosystem roles are grouped by archetype during setup, and every template states how many documents it brings
Incentives is a cockpit area with five tabs — Rules, Achievements, Rewards, Impact and Skills
The rules tab makes the XP economy readable: what a bounty, a maturity level and a credential type are each worth
People can submit a confirmed claim to another workspace, carrying labels and types only
Workspace members with verification rights can decide a submitted claim, recorded as a separate result
Cambiado
Incentives moved out of the workspace settings and into the cockpit, next to the capability tree and the network graph
Skill statistics count people rather than progress records, so member totals, averages and top lists match the workspace roster
Averages are shown only where the group is large enough to support them, and always name the population they came from
Personal offerings can only be activated once their setup is validated, and are presented in three groups
Corregido
Every message catalogue that ships with a release is compiled into it, so newly added areas render their text on first load
A person working across several departments counts once towards a skill, with the level their combined experience earns
v2.19.1
Changelog Clarity
The release history now reads as release notes rather than as internal bug-tracker entries, with every date and technical detail left intact.
Cambiado
The fixed entries of releases v1.0.1 through v2.9.0 describe the behaviour that now holds, with their technical substance, magnitudes and publication dates unchanged
Three changelog entries with no observable effect on the product were removed
v2.19.0
Identity Assurance & Credential Verification
Identity assurance becomes its own axis I0-I4, credential claims can now be verified, and a failing index migration no longer blocks a deploy.
Añadido
Identity assurance ladder I0-I4 as its own axis, derived from append-only verification events so a revocation actually lowers it
Credential verification runs that record what was checked, and name the seven checks this instance cannot yet perform
A "what we did not check" block on verified credentials, so an absent check can never be mistaken for a passed one
The seven personal claim kinds now render as translated labels instead of raw slugs
Cambiado
Identity assurance is global to the person rather than workspace-scoped, so eligibility can be judged across workspaces
Migrations create indexes through a shared helper that matches on the key pattern and reports differing options instead of replacing them
Corregido
Schema migrations recognise an equivalent index that carries a different name, so an upgrade applies cleanly on instances whose collections were seeded by earlier tooling
v2.18.0
The FAIR Passport, and Capabilities That Know Who They Need
A complete FAIR Passport pipeline — four pillars, examiners, appeals, issuance — and capability nodes that can finally name the people, skills and occupations they require.
Añadido
FAIR Passport pipeline: four pillars, rubric as configuration, three scoring runs with the median per pillar, and run provenance
Examiner path: allocation with a conflict-of-interest block, counter-signing that holds up issuance, appeals with a named decision-maker and a deadline, and the FFDE role that edits evidence but never scores
Passport issuance with two-year validity, an expiry sweep and a public register; eligibility gate on TRL and four validated process views
Workspace Compass — questions, ranked results with their reasons, and a join request
Skill-tree builder with draft trees, node rewards, reward types and achievements
Workforce roles on a capability definition, mapped to ESCO occupations, with per-target overrides
Skill requirements suggested from a node's occupations — provenance-tagged, curator-decided, never applied automatically
Node card sections "Skills and credentials" and "Roles and authority", with skill names instead of identifiers in en/de/es
Person ↔ capability matcher with six named evidence states and no score
Workforce-transition map per capability, attachable as evidence for its workforce assessment
Capability-derived learning pathway: course draft, Setup and Run participation as components, Open Badges 3.0 export with ESCO alignment
ESCO occupation registry (~3 000 occupations with ISCO-08 groups and their essential and optional skills) and a runtime load path for the ESCO dataset
Assurance ladder A0–A4 on claims and evidence generally; ISIC / COFOG / SDG crosswalks on the sector taxonomy; distributional social-outcome fields on human-outcome statements
Cambiado
No composite score is shown without its breakdown — the FAIR transparency rule, applied to readiness as well
Readiness is a statement of named met / unmet / cannot-be-evaluated lists with blocking flags; the percentage is removed
Workspace skill checks honour each person's release level for their performance data; withheld data is reported as a count, never as a zero
Human capability requirements can name the skills they ask for, and every skill row on a capability records where it came from
The typed edge vocabulary between capabilities now matches the eleven Geneva relation types
The discussion list reads as a table, and a thread's pipeline moved into a header band
The workspace overview is three columns, with maturity shown next to the lever that moves it
Corregido
Skill requirements on a capability were permanently unsatisfiable — the check read fields nothing ever wrote and reported the result as "not earned yet"
Credential requirements on a capability never matched, because the check looked for the slug in a place credentials do not carry it
A capability that could not be evaluated no longer counts as one that failed
Achievements are granted again — the evaluator, the id space and a missing branch
Eliminado
The numeric readiness score and its breakdown
v2.17.0
Finding and Joining a Workspace
Workspaces can now be discovered, asked to join, and approved from the members list — and a new personal onboarding screen shows a first-time visitor where to start.
Añadido
Workspaces can appear in a public `/explore` directory and accept join requests, both opt-in per workspace
Join requests notify the people who can decide, and can be approved from the bell or from an approval queue in the members list
A personal onboarding screen for people who have just signed up
The capability detail panel shows required, optional, alternative and supporting dependencies, with blocking kinds kept apart from the rest
"Where do you want to go?" — pick a capability and see the missing prerequisites as an ordered route
A forum thread row shows whether the discussion was analysed, drafted or proposed, and marks the ones that have stalled
Setup, Run, Change and Retire processes are part of a capability's data model
The FAIR passport rubric is configuration rather than code
Cambiado
ProcesOS is now proprietary software; tech reform GmbH holds all rights
The network map follows the active theme and explains its pins, with the location form beside the map instead of below it
A manual FAIR score override can be removed, and the computed score stays visible underneath it
Both forum filter rows name the axis they filter, and every label goes through translation
Corregido
The thread analysis renders emphasis instead of printing the asterisks around it
`--bg-active` and its foreground are declared in every theme — the "you are here" background rendered nothing at all
Settings navigation groups are announced with the entries they head, and the current entry is marked as current
Five status colours that failed contrast on the light theme now use tones that hold on every theme
An industry no longer matches a sector because its name contains the word
v2.16.0
Capability Authoring & Access Control
Capabilities can now be created and adapted from the catalogue itself, and three surfaces that answered to a login alone now ask who is actually allowed.
Añadido
Create and adapt capability definitions directly from the catalogue and from any capability page, with category as a required choice
Filter the capability catalogue by category, and see it on each card
Curating the role-profile catalogue is now a separate, delegable permission rather than part of instance administration
A lane map beside the capability force graph, with the selection surviving the switch between the two
Workspace settings are grouped into five sections instead of one long list
Cambiado
Adapting a capability now links the processes that already referenced it, instead of waiting for each diagram's next save
Moving a diagram to another workspace takes its process-role links along, rather than leaving them behind in the old one
Saving in workspace settings names the section that was written, so two saves are no longer indistinguishable
Corregido
Certification submissions, estimates and partner requests could be read or raised for diagrams outside the caller's workspaces
Anyone signed in could add an entry to the global role-profile catalogue and publish it
The capability picker when publishing a marketplace listing was always empty
A capability could be created with an address that nothing could open afterwards
Listings could be published at a negative price
v2.15.0
Capabilities Meet Their Processes
A capability node now points at the diagrams that build and run it, validating one activates it, and the cost it carries is finally on screen instead of behind an endpoint nobody called.
Añadido
A capability's `uses` relation binds to the processes that build and run it, with the bound diagram openable from the properties panel and unbacked claims flagged during validation
Validating a capability's setup diagram activates the capability — a direct link no longer needs a blueprint
The capability cost basis is visible on the node, in its detail view and in the workspace cockpit, with an explicit recompute
Saving a diagram records which capabilities it touches, so the link between a process and a capability no longer has to be declared by hand
Walkthrough steps for capability nodes carry description, status and the systems behind them
A collapsed subprocess or call activity can reference another workspace diagram and open it
Confirming a claim now writes the assertion it derives
Cambiado
Writing to the global capability catalogue now requires the `gttTemplates:manage` permission
The five capability element colours come from one table, with a separate fill tone for surfaces carrying white text — measured against every theme surface rather than chosen by eye
The home page hero image loads eagerly; it is the element the page is judged on
Corregido
The readiness list names which dependency is missing instead of repeating "Missing dependency"
Capability nodes no longer sever the sequence graph in the walkthrough
Numeric entities written by the XML serializer are decoded in business-metric attributes, so a value round-trips as itself
v2.14.0
Personal Import & Cost Transparency
Bring a CV or Europass file into your own workspace on the free tier, trace what a process costs task by task, and reach every cockpit tab before a single process is validated.
Añadido
Personal Import page for Europass XML/JSON, LinkedIn CSV exports and plain-text CVs, with per-claim confirm, correct or discard
Internal datarooms on the free tier with a 500 MB quota, and pasted text stored as Markdown
Cost Breakdown tab in the analytics dialog showing the calculation task by task, with branch and execution weight
Editor command that opens the analytics dialog directly on the cost breakdown, reachable from the command palette
Workspace quest rows now show deadline, evidence type, scope and XP instead of only a slug and a price
Cambiado
All cost figures come from a single engine; the parallel implementation that never reached the editor's data model is gone
The cost view names its own blind spots — unresolved lane rates and truncated rework loops are stated rather than costed as zero
Corregido
A logged-in user with no membership could name another workspace and have its stored AI credentials used on their behalf
The cockpit no longer hides its tab bar and all ten tabs when a workspace has no validated process
Removing a treasury address is no longer blocked by unpaid internal work orders, which pledge nothing and never close
The ecosystem map is reachable again, and its anchor links work
Import and review routes refuse API-key authentication, which cannot be scoped to a single workspace there
Diagram SVG and PNG export now renders in the browser and reports a failure instead of quietly producing nothing
Long AI assistant conversations scroll inside their panel rather than pushing the editor out of shape
v2.13.0
Federated Events & Change Execution
Instances now exchange signed, ordered events. Changes can be forked, approved and promoted over HTTP. And the landing page finally shows the product.
Añadido
Federation exchanges signed events between instances: an append-only store with idempotency and ordering, an authenticated inbound route, and an outbound queue with its drainer
Revocation propagates across federated instances — by construction it can withdraw a grant but never issue one
The federation event queue is readable by an operator, so a stuck exchange can be diagnosed instead of guessed at
UCX Change Execution over HTTP: fork a process, approve it, promote it
Personal and household workspaces carry their own capability graphs
⌘K opens a command palette in the editor, filled with the editor's own verbs
Capability nodes participate in sequence flows, and the AI wizard can create and read them
Workspaces see their own quest drafts in the management tab
An admin panel names the registry entry the landing page exhibits — previously only reachable by editing the database
The landing page shows real product screenshots in all five frames: editor with the assistant, cost and path analysis, the exchange, and the workspace cockpit
Cambiado
Each quest row shows one readable status, derived from what the quest actually declares
Quest generation is locked across replicas, and generated rows say so
Corregido
The marketplace refuses self-offers on quests on the server, not only in the interface
A household with no members is reported as a defect instead of rendering as an empty one
An absent capability list is no longer read as an empty list
v2.12.0
Workspace Cockpit & Capability Flows
The workspace cockpit gains sovereignty and FAIR views, capability nodes join sequence flows in the editor, and the Academy opens its learner and author views.
Añadido
Workspace cockpit: sovereignty view across four jurisdictions, a FAIR matrix per system, and FAIR scale / jurisdiction buckets as token-bound bands
Capability nodes participate in sequence flows — splice them into a flow or append them from any task, event or gateway
Editor navigation in three levels (mode · view · action) with a process state strip in the toolbar
Academy: personal "for you" view with level gain and learning progress, plus an author view exposing the publish checklist
Jurisdiction stamps record where a process is compliant as-is, backed by a declarative compliance rulebook format
UCX lifecycle: handover packages, reopen triggers, and capability evidence rolled up from diagrams
Federation administration is separately delegable via new federation permissions
Wizzy, the assistant, has a real drawn figure
Cambiado
The theme picker offers the two maintained themes, and the theme cookie is validated instead of trusted
All themes gained the semantic tokens components were faking; marketplace surfaces no longer assume a dark theme
Every number on the marketplace states what it counts, using one shared label module
Stranded course enrollments are marked instead of deleted
Corregido
The employer's view of a member's level is workspace-isolated again
Ecosystem map edges meet the 3:1 contrast requirement where they are drawn
Admins can set which registry entry the landing page exhibits — the setting existed but had no UI
v2.11.0
Federation & a Rebuilt Front Door
Instances can now agree to work together under signed, scoped terms. And the public site was rebuilt from the ground up — nine chapters, two new explainer pages, one honest companion.
Añadido
Federation agreements between instances: mutual terms, key challenge, signed handshake, and an admin panel over the whole state
Inbound and outbound federated calls are gated on an active agreement, persisted and audited
`/capabilities` — a public explainer for the Universal Capability Exchange, with a shared status vocabulary bound to the product's own node states
`/ecosystem` — eleven actors on a map with their connections and a second view of who is accountable to whom
The registry chapter reads a real published solution: setup and run as a pair, six SC4 dimensions, verification level, and where each figure comes from
Orbit replaces the landing chat — read-only enforced server-side, with a ring that reports the knowledge actually used
Capability versioning: fork, approve and promote without destroying the previous state
Workspace sector curation, an incoming-steward worklist, and per-instance stewardship
A first-class workspace type axis, indexed, driving trial gates and licence lists
Academy articles carry translated prose through a locale sidecar
Cambiado
The landing page is driven by one ordered chapter array — adding a chapter is a single line, and numbering follows automatically
Typography, spacing, radii and motion are theme tokens; fonts are self-hosted with no third-party CDN request
The workspace overview was rebuilt as headline, metric strip and open points
The process map is now the default view of the diagram listing
Notification bodies render from typed payloads in the reader's own language
Wizzy's readiness check names consequences instead of deficiencies and no longer blocks the start
Wizzy's confirmation dialog shows a diff — target, before, after and consequence — and offers a per-turn undo
The wand signals a real mutation only; reads, searches and simulations never trigger it
Paraglide compiles per locale and the build is gated on a memory budget
Corregido
A logged-in user could read and write another workspace's resource library through a caller-supplied workspace id
SC4 environmental sustainability could never reach 5.0 and scalability silently saturated — every dimension now sums to the full scale, and scores from different weightings are never subtracted from one another
Unpublished academy articles were reachable, and workspace handbooks could enter the global knowledge index
Level rewards were counted across workspaces instead of the caller's own
Course completion XP was credited outside the real ledger
URL-localized routes were linked without their locale prefix, sending German visitors to the English page
Light theme muted text was green-tinted and below the WCAG AA threshold
Several cockpit counters were structurally wrong, and failing card queries took the whole page with them
A forked capability template did not resolve on the read path
The shipped env bundle was not covered by the ignore rules
v2.10.0
The Capability Catalogue
The Universal Capability Exchange arrives: a forkable catalogue of capability definitions, assessments across thirteen dimensions that never collapse into one score, and licence-wide module control.
Añadido
Universal Capability Exchange: a reference catalogue of capability definitions that nations, sectors and institutions can fork across five adaptation layers without mutating the common node
Capability type vocabulary — a stable classification of what a capability is, held separate from the node that defines it, so a national fork never breaks the shared vocabulary
Six mandatory human fields on every capability definition, including the judgement that must remain human and the outcomes that are never acceptable, carried as data in any language
Capability assessments across thirteen separate dimensions with supporting evidence, and eight red flags that route a capability to review or refusal regardless of how strong the rest of the picture looks
Fork write path: create a fork at a lower adaptation layer and override local metadata, with lineage fields refused rather than silently ignored
Module switches under an enterprise licence: disable a licensed module instance-wide or for a single workspace, without touching what was bought through Stripe
Cambiado
Marketplace acceptance now enforces credential and skill requirements instead of merely recording them
The Cardano escrow validator ships compiled with a script-hash drift tripwire, and mainnet operation is refused without an explicitly pinned escrow address
Testnet and mainnet signing keys are separated structurally, so a misconfiguration cannot quietly reach the wrong network
Corregido
Reference catalogue entries no longer count towards a workspace's capability maturity, dashboards or unlock cascades — publishing a catalogue no longer lowers everyone's score
Creating a template through the raw write path can no longer bypass the fork rules
The forum now keeps the active workspace in step with the thread being viewed
Under an enterprise licence the admin table showed workspaces as having no modules when they in fact had all of them; it now reports the effective set and where it comes from
v2.9.0
Shell, People and a Guided Start
A global bar above every view with notifications grouped by urgency, the Departments tab becomes a real People directory, and new workspaces get a guided setup instead of a modal.
Añadido
A global bar above every app view: my area, workspaces, marketplace, academy and forum, plus a workspace switcher, ⌘K command palette, level and notification bell
Notifications grouped by urgency with counted filters, each line naming the workspace it came from
People directory in the workspace cockpit: lanes resolved to people, contacts, process involvement and key-person risk
Three-step release levels for performance data — private, workspace or network — controlled by each person for themselves
Guided workspace setup: a resumable flow with credentials, invitations, process-map stubs and data-object capture
Instance-wide artifact registry with cost attribution per cost object and per licence line
Bulk invite and update of members from a spreadsheet
Marketplace browse-and-inspect layout with facet counts and a way out of an empty result
Cambiado
The personal dashboard is one screen without tabs; what waits for you is sorted by deadline across types, and workspaces are ordered by open items rather than alphabetically
A person's level is a number. Tier names no longer appear next to it, though the tier colour stays
Course XP is derived from the incentive table instead of being entered freely
Skill cards became rows, and the two values nobody could interpret are gone
Corregido
Draft courses are readable by slug, enrollable and publishable only once they carry at least one lesson
Custom credential gates can be satisfied — the credential slug is persisted with the gate
The Spanish translation gap is closed, with a guard against it reopening
Trial expiry is written compare-and-swap, so concurrent requests cannot clobber it
The vote board renders proposals that carry an ROI date
One live edge per workspace pair in the workspace graph, instead of one per workspace
Dataroom feature gates resolve through the licensed subscription
A failing migration is isolated so the rest still apply, and a duplicate migration id is refused rather than silently skipping one
Every sample workspace exports, and template references resolve
v2.8.0
A Seeded Ecosystem & Cross-Workspace Seals
Eight sample workspaces to adopt as templates, processes that carry a seal across workspace borders, and capabilities that now activate on Setup — where they are actually created.
Añadido
Eight connected sample workspaces seed as a working ecosystem — bakery, mobility association, self-sustaining village, stewarded ecosystem, solution provider, transformation consultancy, municipality and issuing authority — with cross-workspace adoption, a quest and a collaboration link between them
Four of the samples are adoptable workspace templates, so a new workspace can start from a solution provider or a municipality instead of an empty page
Cross-workspace process certification: request a seal from an issuing authority, which reviews the diagram in a shared collaboration space and certifies it against a named standard
Lane-staffing requests — a lane with a credential requirement must be staffed before a process can be certified, and an open request blocks the seal
Certification is a portable credential that travels with the process when its template is adopted
Lane roles carry their required credentials into exported templates, so an adopted process keeps its qualification bar
Administrators can seed the sample workspaces from the admin panel, including a reset that refreshes a demo instance
Soziale Fahrten licences can be bought through ProcesOS
Cambiado
Capabilities now activate when the Setup process is validated, not the Run process — a Run process cannot be validated for a capability that does not exist yet. Existing blueprints are migrated automatically, and anything ambiguous is left untouched and logged rather than guessed
Governance leads are seated in the shared collaboration workspace, so a head of compliance can actually review what their workspace was invited to
Exported templates keep the own pool and the partner pool distinguishable, so a two-party process survives adoption as a two-party process
Four eyes are enforced across workspace boundaries: whoever requests a certification cannot grant it
Corregido
Workspaces whose diagrams reference CMDB artifacts can be published as templates — the embedded database ids are rewritten into placeholders that resolve inside the manifest
A reference pointing at a record that was never exported is refused at publish time instead of shipping as a link to nothing
Every sample workspace exports cleanly through the anonymizer; random identifiers that leaked into exports were replaced with stable ones
VAT is requested during workspace checkout
The setup check degrades gracefully when the database is unreachable, instead of turning every route into a server error
v2.7.0
Languages Per Deployment & Voice Transparency
A deployment can now ship its own languages via LOCALES — declare generously, translate over time. And Wizzy shows which voice provider handles your audio before you opt in.
Añadido
Languages are configurable per deployment through a LOCALES environment variable — locales.config.mjs is the single source of truth and drives localized routes, the inlang project, and every locale list in the app
LOCALES travels the build path (GitHub Actions to Docker build argument), so an image carries the languages it was built for instead of falling back to the default set
Declared versus translated locales: a declared language reserves compiled capacity and gets AI narration and interview questions immediately, while the interface offers it only once its translations exist
Voice provider details before consent — provider name, who operates it, and how audio and text flow (speech-to-text discards audio, text-to-speech caches for 30 days), shown in the voice-interview consent dialog and behind an info trigger next to the voice controls
Voice configuration reports its scope, so you can see whether voice runs on your workspace's own provider or the instance-wide configuration
Cambiado
Accept-Language is parsed properly with quality values instead of matched against a whitelist
Language names appear as endonyms via the platform's display names (Kiswahili, Gikuyu, Dholuo); flags are reserved for the shipped languages, since a language is not a country
The language switcher, locale negotiation and the sitemap derive from the translated locale set; the AI narration and elicitation endpoints deliberately use the declared set
Corregido
Email templates fall back to the base locale for a language without its own templates, instead of failing outright
The sitemap emits URLs and hreflang alternates only for translated languages, so search engines are never pointed at English content under a foreign language code
v2.6.0
Whitelabel, Demo Mode & Verified Mandates
Instances can carry their own branding, open a public demo, and issue term-bounded committee mandates whose on-chain proof is actually verified — plus a broad security pass.
Añadido
Instance whitelabeling: name, logos, CI colors and a slim branded landing page, gated on the instance license
Governance-role credentials for committee mandates (chair, vice-chair, delegate, member, observer) with terms, appointing body and declared interests
Data-driven workspace structure for governance bodies, including sub-committees, cross-cutting bodies, an organisation workspace and one workspace per summit
On-chain verification of minted credentials against the chain, with the network always labelled and an outage never devaluing a genuine proof
Versioned sector taxonomy with crosswalks, and sector tagging for diagrams, blueprints, artifacts and capability nodes
API keys can be issued with a read-only scope for partner integrations
Datarooms can be gated on committee membership, role and appointing body
Cambiado
API keys are now strictly limited to the workspace they were issued for; key authentication is refused on admin and key-management endpoints
Credentials whose validity or mandate term has passed are now reliably treated as expired
Pricing pages show curated, localized plan features again instead of raw internal feature names
The release banner no longer mixes languages, and the mobile navigation header is decluttered
Corregido
AI-generated report HTML is sanitized before it is rendered, printed or copied
The session cookie keeps its httpOnly protection — the session object is no longer serialized into the page payload
Workspace member and dataroom routes reject non-string filter input (query injection)
Credential issuing via the Andamio import requires a write permission, and the mint endpoint enforces membership
Module gates added to compliance, CMDB and marketplace mutations that were only gated in the client
Rate limit and token bound on the AI completion endpoint, hard timeout on the thumbnail worker, URL validation for avatars and the Odoo endpoint
A repair migration normalizes invalid capitalized element names in stored diagram XML, restoring BPMN 2.0 schema validity for exports
v2.5.0
Own Voice, Own Storage
Wizzy's voice can run fully self-hosted or on your workspace's own provider, datarooms gain decentralized Storj storage with uploads, and the workspace handbook reads your Odoo knowledge base.
Añadido
Self-hosted voice provider (Speaches) with locale-dependent TTS voices — German, English and Spanish each speak with a fitting voice, fully on-instance
Workspaces can bring their own voice provider (AI Studio module): keys encrypted in the workspace vault, per-workspace audio caches
Admin voice settings list available models and voices live from the configured provider
Storj as decentralized dataroom storage: credential-gated listing, shared-link downloads, and direct uploads from ProcesOS into the bound folder
Workspace handbook: reading surface and dashboard widget combining workspace articles with a bound Odoo knowledge subtree (read-only proxy)
Cambiado
Wizzy's spoken output follows the app language — each locale gets its own cached audio
Dataroom error handling distinguishes 'no access' (request access) from 'workspace connection broken' (admin issue) consistently across providers
v2.4.0
Sovereign Licensing & Voice Interviews
Dedicated instances can run on a signed offline license instead of per-workspace billing, and Wizzy now conducts the process interview by voice — with consented transcripts to the forum.
Añadido
Instance license mode: signed offline license key replaces Stripe entitlements instance-wide, with an enterprise-mode switch and admin license panel
Voice interview: Wizzy speaks elicitation questions, accepts push-to-talk answers and spoken confirmations, and posts a consented Q&A transcript to the linked forum thread
Capability-node listings bundle their Setup+Run processes; CMDB artifact listings carry an ISMS evaluation profile and link to the capability nodes they enable
Capability nodes list the marketplace solutions that satisfy them, and adopted solutions arrive in your CMDB with their published ratings
Acquisition cost basis for capability nodes derived from Setup/Run processes, with normalized currency and rate units
Tasks can reference existing runbooks and automations directly from the BPMN properties panel
Cambiado
Marketplace categories renamed to the operating-layer vocabulary: Capability Node, CMDB Artifact, Workspace Blueprint; standalone process blueprints are retired from browsing
Blueprints gained a full lifecycle: workspace scoping, draft state, archiving — nothing is published forever by accident anymore
Business-metric fields are normalized and validated on diagram save (currencies, duration units, structured JSON fields)
Corregido
Workspace identity creation works on a fresh deployment — the signing library's ESM build is restored at install time
The AI diagram assistant reports what went wrong on large batch builds: invalid element types are rejected with clear feedback, broken connections abort early, and the model is told the reason
Adopting a capability creates its dependent nodes
A diagram cloned from an adapted capability carries its content
The changelog shows the running app version, and the voice settings panel opens in the admin dashboard
Wizzy gets a voice — provider-agnostic speech in the editor and dashboard. Google Drive datarooms are now free for every workspace, plus a licence-compliance pass.
Añadido
Wizzy voice layer — have answers read aloud and speak instead of typing, in both the editor assistant and the dashboard guide
Provider-agnostic voice configuration decoupled from the chat provider — Mistral (Voxtral) and any OpenAI-compatible endpoint, including self-hosted inference servers; configured under AI Settings and applied without a restart
Push-to-talk with hold-to-talk or click-to-toggle, capped at 90 seconds; the transcript lands editable in the composer and is never sent automatically
Voice usage metering per user and per workspace (characters spoken, seconds transcribed), with cached playback excluded from billing
OSS licence inventory plus a generator, so the dependency licence position can be audited rather than assumed
Cambiado
Google Drive datarooms are no longer a paid module — free tier at zero cost, toggleable per workspace by an admin
AGPL-licensed dependencies replaced, the bpmn.io watermark restored as the bpmn-js licence requires, and a NOTICE file now ships with the application
Spoken audio is never stored — only the resulting transcript is; synthesised speech is cached so repeat playback costs nothing
Corregido
Walkthrough interviews: answers write through, a declined or negative answer is remembered instead of being asked again, and questions respect the semantics of the task they belong to
Drive datarooms: folders are reachable, credential pickers show the workspace's real credentials, and forum links are scoped to the folder
The walkthrough's Back button is enabled whenever there is a step to return to
v2.2.0
Guided Walkthrough Mode, Google Drive Datarooms & Sovereign Hosting
Turn any diagram into a narrated walkthrough that also captures stakeholder data, back credential-gated datarooms with Google Drive, plus a landing overhaul and the move to sovereign self-hosting.
Añadido
Guided Walkthrough — Presentation mode: a read-only token stepper that walks a diagram element by element with one-sentence Wizzy narration (generated once per version, cached) and a plain-language data panel; you advance with Next and choose branches at gateways
Guided Walkthrough — Elicitation mode: the stepper becomes an interview with a deterministic gap engine and Wizzy Q&A; answers are captured as provenance-tagged, staged claims, never written silently
Guided Walkthrough — CMDB auto-capture: systems named in passing are fuzzy-matched against existing artifacts (match offers a binding, miss offers a draft); drafts are excluded from compliance/scope analysis until a steward confirms, merges, or deletes them
Google Drive as an external dataroom storage provider — connect a workspace Google account, back a credential-gated dataroom with a Drive folder, list and preview files under the same access policy (including lane-based gating)
Forum threads can link datarooms, carrying a credential-gated document space alongside the discussion
Featured login providers with a "more options" dropdown on the sign-in screen
URL-localized marketing routes (/de, /es) with hreflang
Cambiado
Landing page restructured around the Process-OS narrative with one canonical value proposition across en/de/es, plus brand-story videos on the business and government pages
ProcesOS now runs on sovereign, self-hosted EU infrastructure (website, application, and the Veridian/KERI identity agent) instead of a managed hosting provider
Corregido
Andamio integration validated and hardened
Comment requests raised from an element click carry the workspace id, so they resolve in the right workspace
An unverified email address is redirected to verification
v2.1.0
Wizzy on the Dashboard, hiop.io DataOps & a Dockable Assistant
Wizzy comes to the dashboard, a new hiop.io DataOps module ingests real process metrics, self-hosted OpenAI-compatible AI endpoints are supported, plus a dockable assistant and a security pass.
Añadido
Wizzy on the personal dashboard — a user-centric AI guide that reads your workspace context, role, open tasks, maturity standing and recommended next capabilities, with read-only tools scoped to your workspaces and quick-actions (What's on my plate / What to map next / How are my workspaces doing)
hiop.io DataOps workspace module (ingest MVP) — push real cost / duration / frequency / volume metrics to a workspace-scoped, API-key-authenticated ingest endpoint; measured values surface next to modeled estimates in process cost analysis
Mandatory DataObject classification on every hiop ingest binding — each transfer is GDPR-classified via the existing DataObject library; special-category bindings blocked, personal-data bindings flagged
Idempotent metric delivery (by delivery ID) plus an integration panel that generates a copy-paste hiop.io pipeline snippet
Resizable and dockable Wizzy chat panel in the editor
Support for self-hosted, OpenAI-compatible AI endpoints via a new AI_BASE_URL setting — run against your own model server instead of a hosted provider
Cambiado
The editor's Wizzy chat now bounds its height so long conversations scroll inside the panel instead of expanding the layout
Corregido
AI-generated pools and lanes are created through supported bpmn-js geometry, so participants and lanes render as expected
The admin user list reports each user's actual last login
The HIGH-severity findings of the July 2026 security audit are closed, including hardened Stripe webhook handling and tighter cross-tenant checks on federation collaboration endpoints
v2.0.2
Tidy-Up Layout, Save History & Workspace Invites
A gentle "Tidy up" layout mode with single-step undo, undo/redo buttons and a rolling save history in the editor, plus invites for not-yet-registered users and client-side diagram export.
Añadido
"Tidy up" layout mode in the editor — gentle align / grid-snap / edge-straighten that preserves your arrangement and reverts with a single undo
Undo / redo buttons in the editor toolbar
Rolling save history — up to 5 automatic snapshots per diagram (throttled ~1 per 5 min of editing, plus one before each auto-layout and AI change) with a preview-and-restore menu; restores are reversible
Full re-layout now offers a one-click Undo toast
Invite not-yet-registered users to a workspace by email — the invitation is applied when they sign up
Cambiado
The AI wizard's layout step now uses the gentle tidy-up instead of a full re-layout, keeping Wizzy's changes undoable
Corregido
Diagram SVG and PNG export renders in the browser and reports a failure instead of producing nothing
v2.0.1
Editor & Diagram-Listing Fixes
BPMN element coloring and single-lane naming restored, user-task forms save correctly, and the diagrams listing gains group-by, process metrics, and per-card forum links.
Añadido
Context-pad color picker for BPMN elements — recolor tasks, events, lanes and pools; colors persist through save/reload and XML export
Group-by toggle on the diagrams listing — folder, status, or folder-then-status with per-section counts and preserved sort order
Process-metrics card view on the diagrams listing — Lanes / Tasks / Paths / Systems / Maturity from the analytics snapshot, with a not-yet-analyzed state
Per-card forum link on the diagrams listing — open an existing linked thread or create-and-link a new discussion (workspace spaces only)
Lane Name field in the properties panel for single-lane pools
Corregido
BPMN element colouring runs through the bpmn-js renderer configuration, so themed defaults and custom colours both render
Form definitions built in the user-task dialog are persisted
A single-lane pool can be named from its properties panel, where the participant and lane label bands overlap on canvas
SVG and PNG export works for diagrams with no stored thumbnail
The landing page assistant answers from a maintained feature map rather than from the model's own assumptions
v2.0.0
The New Workspace Shell
A rebuilt workspace-centric UI with shell and switcher, Wizzy as public landing consultant with lead capture, a sharper six-pillar landing page, and Tresor as a new AI provider.
Añadido
Wizzy landing chatbot: a public, abuse-hardened AI consultant grounded in landing data, configurable from the admin panel
Lead capture with explicit consent — chat leads flow directly into the CRM
Tresor as a stateless OpenAI-compatible AI provider
Cambiado
Navigation rebuilt workspace-centric: manage view as home base, persistent workspace shell, fast workspace switcher, and a personal shell
Landing page consolidated around the six CPG pillars with a unified section design and localized badges
Corregido
Protected pages render directly on a cold load — the auth guard runs server-side
v1.9.0
Stewarded Ecosystems
Workspaces for natural entities with legal personhood: ecosystem health index, care quests with human attestation, plus ISO/IEC 42001 compliance and server-side module enforcement.
Añadido
Stewarded Ecosystem workspace template: guardian/ranger/ecologist/volunteer roles, natural-asset registry, stewardship capability branch, and a ready-to-publish cleanup quest
Ecosystem Health Index with cockpit tab: score gauge, component breakdown, pain points, and a one-click create-quest path
Human-attested quests: volunteers accept and submit evidence, guardians approve or reject under a four-eyes rule, rewards issue automatically
Ecosystem-stewardship branch in the Global Technology Tree (charter, inventories, monitoring, cleanup, assessment, restoration)
ISO/IEC 42001 control library with Statement-of-Applicability management in settings, cockpit, and ISMS reviews
New landing page for stewarded ecosystems at /for-ecosystems, wired into the audience hub and signup attribution
CPG-cycle brand video featured in the landing hero
Cambiado
Logging in now lands in the workspace overview with your main workspace preselected
Paid add-on modules (CMDB, GTT, ESG, Academy Publisher) are now enforced server-side on every mutating API route
Quest publishing supports bounty-free internal workspace tasks with human attestation
Corregido
The onboarding tour keeps its place when you navigate back from the level page
Governance lane assignment offers an "(any)" placeholder for lanes without a specific person
v1.8.0
The Process Maturity Ladder
Processes now climb a unified L1–L7 maturity ladder — computed from workspace state and surfaced from the editor's readiness checks all the way to the workspace cockpit.
Añadido
Unified L1–L7 process maturity ladder, computed from workspace state and persisted per process (recomputed on freeze)
Pre-validation checks in the editor are grouped by maturity level, showing current standing and what unlocks the next rung
Maturity level surfaced across the workspace cockpit — governance overview and process rankings now span all seven rungs
New ProcesOS cycle glyph and animated loader; the CPG governance loop and L4–L7 rungs share one lifecycle visual
New gated Process Lifecycle knowledge-base article in the Academy
Landing pages: per-audience social-preview images, a default showcase image, and an audience navigation dropdown
Cambiado
Process level widened from 1–3 to the full L1–L7 maturity scale (backwards compatible — levels 1–3 keep their meaning)
The ProcesOS logo now links back to the homepage
Corregido
Login hero logo and headings are legible on the always-dark map background
Audience landing pages show their own per-audience image
v1.7.0
ERP Sync & Process Intelligence
ProcesOS now syncs live ERP data into process cost analytics, consolidates duplicate process roles, and reveals each process's most valuable and greenest path — under a refreshed brand identity.
Añadido
Odoo ERP integration: connect a workspace, map products to resource categories, and sync them with real costs into process analytics — plus inventory levels, KPIs, and a dry-run preview
Process-role consolidation: merge duplicate roles across diagrams using name, shared-responsibility, and member-name suggestions, with diagram sync-back and credential retitling
Events now carry directed value and resource flows, revealing each process's golden path (highest business value) and green path (lowest footprint)
CMDB sovereignty scan: a scan button auto-fills hosting, technology, and FAIR maturity details for IT-system artifacts
Refreshed ProcesOS brand identity — logo, favicon, brand color, and per-audience social-preview images, plus a new For Academia landing page
After login you now land in your main workspace cockpit instead of a blank editor
Per-audience conversion funnel for the landing pages
Cambiado
Paid add-on routes (Odoo, CMDB scan) are now enforced on the server, not just hidden in the UI
Corregido
Theme switching completes without a server error
The stakeholder validation dialog scrolls on small screens
The Academy back button returns you where you came from
XOR gateway branch probabilities are validated to sum to 100%
Unexpected server errors are caught and logged with a reference id you can quote in a bug report
Signup notifications describe the current activation flow
The user-task form editor renders correctly
v1.6.0
Governance Lifecycle & CMDB-Driven Process Analytics
Validation now gates AS-IS freeze behind an ISMS review + promote vote. Process Analytics' Systems tab realigned onto the real CMDB with FAIR/ISMS ratings.
Añadido
ISMS Compliance Review stage — when all lane-responsibles validate, the workspace's Head of Compliance gets an attestation task listing CMDB Systems + Data Objects used in the process, with FAIR / contract / GDPR gap indicators
Promote-to-AS-IS Vote stage — after ISMS attestation, a governance vote opens to lane responsibles + Head of Processes + Head of Compliance with configurable quorum and 7-day expiry
Governance dashboard surfacing — ISMS reviews and promote-vote tasks appear on the user dashboard, in the notification bell, and inline in the validation wizard
CMDB IT-System view in Process Analytics — Systems tab, Overview chart, Monthly cost table, and per-lane/per-path tags all driven by the real CMDB inventory with FAIR scores
Per-system Data Object detail — each CMDB system shows the Data Objects attached to its tasks with classification, personal-data flag, special categories, and legal basis
Shared freezeProcessAsIs() helper — atomic CAS-freeze + AS-IS version insert with rollback on failure
Cambiado
Stakeholder validation no longer auto-freezes the process — completion now opens the ISMS review stage instead. The validation-complete toast was repurposed to "Validation complete — ISMS compliance review opened"
Tailwind dark variant is now bound to the app's CSS-variable theme (light / dark / midnight / amethyst), not the OS prefers-color-scheme setting
Process Analytics snapshot stores real CMDB system names (instead of BPMN task-type pseudo-names) — improves AS-IS / TO-BE delta accuracy and SC4 setup-cost matching going forward
package.json now carries an explicit license field; README has a license section pointing at the LICENSE file
Corregido
Path analysis follows sequence flows only, so KPIs and path costs reflect the real process — data associations and message flows previously turned a two-branch diagram into 72 paths
The forum's process context resolves the CMDB systems and data objects a diagram actually references
Cockpit overview cards are legible on the light theme
Forum credential, tag and status badges hold their contrast on every theme
v1.5.4
Parallel Gateway KPI Correctness
Process-level KPIs no longer overcount shared tasks across paths produced by parallel gateways. Critical-path analysis replaces sum-of-durations for parallel branches.
Cambiado
Process-level KPIs (`totalCostPerRun`, `monthlyCost`, `totalEffortHours`) now use task-based aggregation with effective execution probability instead of summing over paths — eliminates the parallel-gateway overcount
Total process duration uses critical-path analysis (max across parallel branches) instead of summing across all paths
Scoped KPIs in `scope-analysis.ts` follow the same task-based pattern
Corregido
Process cost KPIs count each task once however many parallel paths contain it — an 11-task diagram with a single parallel fork previously reported roughly five times its cost per run
Process duration through a parallel fork uses concurrent-execution semantics, taking the longest branch instead of the sum of all branches
CMDB sovereignty scanner (SSRF-hardened), US CLOUD Act exposure in FAIR scoring, IRB FAIR matrix estimator, BYOK setup wizard, and BPMN tools on Anthropic managed agents.
Añadido
CMDB Sovereignty Scanner — server-side scan of DNS / HTTP security headers / SSL-TLS / WHOIS-ASN / technology detection for `it_system` artifacts (feature-gated, CMDB add-on)
Provider Knowledge Base — workspace-aware registry of hosting / CDN / email / analytics providers with jurisdiction (EU / US / other / unknown), seeded with ~50 hand-curated providers and growing automatically via scan-discovery
EU Sovereignty Score (0-100 + A-E grade) per artifact, with category-weighted breakdown (hosting 40%, email/auth 25%, CDN 15%, analytics 10%, other 10%)
US CLOUD Act exposure surfacing on scan results + propagation into FAIR scoring
IRB FAIR Maturity Matrix estimator from scan signals — full level descriptions per dimension stored alongside the score
SSRF-hardened scanner core — `validateScanTarget()` rejects private / loopback / link-local / cloud-metadata IP ranges with TOCTOU-safe IP pinning
BYOK Setup Wizard — guided multi-step flow (provider → test → model dropdown → managed-agent create → token usage)
Anthropic managed-agent BPMN tool integration — all 22 BPMN custom tools registered on the agent alongside `agent_toolset_20260401`
System-prompt teaching for the managed agent — explicit ProcesOS tool round-trip + result shapes baked into the agent body
Cambiado
BYOK key save now fails loudly when `WORKSPACE_KEY_ENCRYPTION_SECRET` is missing or misconfigured — silent encryption failure path closed
BYOK model-load now receives the API key explicitly from the connection test (no more post-save race against `getWorkspaceSecret()`)
Anthropic console link in BYOK setup updated to `platform.claude.com` (new Anthropic URL)
Corregido
Managed agent updates carry the version field the API requires for concurrency control, with one automatic retry on conflict
Empty star ratings in the validation wizard are visible against the background
v1.5.2
Wizard, Billing & Cost-Math Fixes + AI Model Discovery
Wizzy chat unbroken, Stripe boot-crash fixed, monthly cost math now probability-weighted, validation flow hardened. Plus AI model discovery dropdowns and password reveal on auth screens.
Añadido
Provider-agnostic model discovery in Admin AI Settings + Workspace BYOK Settings (dropdown after API-key entry, supports Anthropic / OpenAI / Mistral)
Anthropic skill / managed-agent listing in Admin AI Settings
One-click "Wizzy erzeugen" creates an Anthropic Skill agent idempotently (existing skill is reused, not duplicated)
Password reveal toggle (eye icon) on login, setup, and reset-password screens — preserves `autocomplete` for password-manager compatibility, aria-label i18n in en/de/es
Discovery-call CTA on the landing page linking to Proton Meet booking
Anthropic managed-agents Sessions API spike script (`scripts/spike-managed-sessions.ts`) — foundation for future Wizzy-on-Sessions integration
Cambiado
Stripe price-ID resolution is now lazy (resolved on first use, not at module import) — missing env vars no longer block server boot
Wizzy API now requires `spaceId` and resolves the AI provider per workspace (BYOK key + provider, then global, then env-var fallback)
Validation start now archives prior `validation_invite` notifications via `read: true` instead of deleting — audit trail preserved
Validation `complete` action performs the all-responsibles-validated check server-side and creates the AS-IS freeze atomically via CAS — no client-side race condition
Corregido
The AI assistant resolves the diagram's workspace on every message, so chat works from inside the editor
The server boots without a complete Stripe configuration — price identifiers resolve on first checkout instead of at startup
Monthly costs in the Analyze view weight each path by its probability, so a diagram with unconfigured gateways reports the real figure rather than up to three times it
The stakeholder validation Start button is disabled while a session is running, so a round cannot be started twice
A validation task on the dashboard opens the wizard directly
A process freezes to AS-IS automatically once every responsible stakeholder has validated
Auth screen sidebars fill their full height
v1.5.1
Legal, Security & Brand Hardening
TTDSG cookie consent, Terms of Service, GDPR-hardened legal pages, HTTP security headers, env-driven Stripe config, and a consistent ProcesOS brand across the app.
Quest publish validator now checks `visibility`, `context`, `evidenceSpec.kind`, `targetArtifacts` consistency, and optional `rewardSpec` (credentialType + xp + foundation-skill existence)
Q1g acceptance loop guards against non-`validation_session` evidence and issues reward *before* close-CAS for bounty-free path (failure leaves quest at `verified` for retry)
Marketplace QuestPublishPane hides bounty and party-kind fields for non-marketplace contexts
Workspace-creation routes (`/api/spaces/+server.ts`, `/api/spaces/from-template/+server.ts`) seed the default FAIR quest template
Cockpit page-load triggers a lazy quest-refresh (debounced, fire-and-forget with `.catch()` to prevent SvelteKit unhandled-rejection crashes)
v1.4.0
Maturity Epic Sealed + Cockpit Systems Tab
Maturity Epic #104 sealed: all 12 profile-types covered, age-tier-cap, admin-tunable weights, history sparklines. Plus Cockpit Systems tab with FAIR/ISMS scoring and 3-tier cost analysis.
Añadido
Maturity profiles for the 7 remaining ecosystem-roles (`district`, `association`, `organisation`, `transform_consultant`, `agency`, `government`, `solution_provider`) — no more silent business-fallback
Workspace-age tier cap (silver under 3mo, gold under 12mo, unlimited ≥12mo) with would-be-tier display in Cockpit Maturity hero
Admin-tunable maturity weights via Cybernetic Core — per-profile, per-dimension override with 1.0 sum validation
Maturity history snapshots (`workspaceMaturitySnapshots` collection) with daily-deduped 4-hour scheduler over active workspaces
Inline sparkline trend in Cockpit Maturity hero — per-dimension and overall score
`GET /api/spaces/[id]/maturity/history?days=N` endpoint with 5-min client-side TTL cache
Cockpit **Systems** tab — CMDB-sourced view of every IT system with FAIR / ISMS / contract / ESG / AI metadata
FAIR dimension visualization (5-segment horizontal bars per dimension, color-coded by level)
Framework filter toggles on Systems tab (GDPR / NIS2 / DORA / ISO27001) with OR-semantics across multi-select
Sort options on Systems tab — sovereignty / FAIR-score / name / cost / criticality, with rated-first / unrated-last for sovereignty + FAIR
Header counter badges on Systems tab — `X low sovereignty · Y not assessed` for at-a-glance pain-point context
3-tier cost analysis with execution multipliers and time-window calculations (path / process / global metrics)
`src/lib/bpmn/cost-math.ts` — pure-math helpers extracted as testable module (21 unit tests)
Cambiado
Maturity engine `getProfileFor` async-resolves admin overrides via derived-config; sync `getDefaultProfile` exposed for tests; `getProfileFor` kept as `@deprecated` alias
Maturity engine `getProfileFor()` default branch now only catches `null` / `undefined` ecosystem-role; all 12 roles resolve to dedicated profiles
Corregido
The workspace age notice uses correct plurals in all three languages
v1.3.0
Treasury, Maturity, Audience Pages
Workspace Treasury sealed end-to-end. Maturity engine + 12 dimensions visible in Cockpit. Six audience-targeted landing pages live. Plus dashboard worldmap, listing hardening, cockpit hub.
Dashboard worldmap with workspace + federation-peer markers, Nominatim-backed address search
Cockpit Übersicht redesign — summary-card hub with deep-links to detail tabs
GET `/api/spaces/[id]/maturity` (auth-gated, 5-min client-side TTL cache)
GET `/api/spaces/[id]/treasury/obligations` (any workspace member, returns `{ count, totalLovelace }` for live workspace-funded quests)
GET `/api/user/me/treasuries` (returns spaces where current user holds Head-of-Finance + a verified treasury)
ADR-0001: rating-infrastructure decision for the role-experience-variance dimension
Cambiado
`/api/marketplace/listings` GET returns tiered responses based on caller auth (anonymous → identity-stripped, authed non-member → `kind` only, creator-space member → full payload). Single batched membership lookup avoids N+1.
Treasury DELETE handler shares the same `getOpenObligationsSum` helper as the new obligations endpoint — single source of truth for open-escrow precondition.
Marketplace `?creator=<spaceId>` filter param threads through to listings GET — used by the worldmap quest-badge deep-link.
v1.2.0
Quest Marketplace & Compliance Cockpit
Demand-side marketplace: workspaces publish capability bounties in ADA, fulfillers deliver via blueprints, acceptance auto-triggers on GTT activation. Plus compliance cockpit + voting view.
Añadido
Quest Marketplace (Epic #95): publish a capability-activation bounty with ADA locked in Cardano escrow; fulfillers offer, deliver, and get auto-accepted on GTT activation
Quest discovery tab at /marketplace?type=quest with bounty/deadline/urgency card, scope badge (U→U / U→W / W→U / W→W), archive toggle
Inline OfferToFulfilDialog — no detail page, one-click from frontier-pill or marketplace-card to offer-submit
GTT Frontier bounty chip: any unblockable capability with an open quest shows an accent ₳-pill that deep-links into the offer flow
Automatic quest acceptance loop: when the required GTT node flips to `active`, matching open quests auto-advance to `verified` with forensic evidence (non-fatal sweep, CAS-guarded against double-writes)
quest_fulfilment credential minted on offer-accept; space-scoped lookup so it survives individual member departures
Workspace Cockpit Compliance Tab: cross-diagram aggregation with min() semantics, per-framework/jurisdiction heatmap, pain-point hero card, gap click-through
Multi-dimensional Delta View (BPMN + cost + resource + GTT + compliance) extracted into its own reusable component
Voter View for change proposals with credential-gated voting + weighted tallies + on-acceptance bounty release
Workspace Treasury backend primitive: non-custodial CIP-30 signData ownership proof, Mongo-backed nonce store with atomic consume-once replay protection, rotate/unset endpoints that respect open-escrow immutability (UI lands v1.3.0)
Cambiado
Validated AS-IS BPMN diagrams are now immutable — PUT handler returns 409 `edits_disabled_after_validation` once a governance validation session has locked the process; proposals must flow through the voting view
Marketplace browse query filters out expired quests (no auto-cron for published → expired) and self-authored quests (no circular self-nudge)
Compliance analysis moved server-side via bpmn-moddle, with a 5-minute client-side cache on the aggregated workspace compliance store
QuestPayload's `questParties.quester` is the single source of truth for funder identity — open-escrow states (`published`, `in_progress`, `verified`, ...) exported as `OPEN_QUEST_STATES` for cross-module reuse
Eliminado
User-level subscription model — licensing is workspace-only now; personal spaces cascade-delete with their owner
Operating Layer epic complete: unified paid-escrow marketplace across all item types, capability activation loop, sovereign workspace identity via KERI AID, Forms linked to DataObjects.
Añadido
Unified paid-escrow marketplace across blueprints, GTT capabilities, artifacts and workspace templates
PublishListingDialog: five-step type-aware publish wizard with early-draft persistence
Creator Analytics dashboard at /marketplace/creator with totals, 30-day trend chart, acceptance rate
Blueprint.producesGttSlug hook: run-context validation auto-activates the referenced GTT capability
Editor action "Solution from selected artifacts" — promote artifact-bearing tasks into a workspace solution node
Durable audit log for admin-triggered GTT frontier snapshots, surfaced in the admin debug view
KERI AID support via KERIA integration — per-workspace identity with on-chain registration (Cardano metadata label 7743)
Public workspace profile at /w/[slug] with tokenize.it invest-widget integration
Head-of-Finance role with treasury:manage permission scope
Forms now link to DataObjects; AI heuristic infers GDPR categories from field keys and labels
DataObject settings: linked-forms section + read-only form preview on the GDPR tab
30-day Pro trial on every new workspace (pre-Stripe launch)
Vitest infrastructure as first repo-wide unit-test runner
In-app Bug Report dialog creates GitHub issues via server-side PAT — no repo access needed for users
Cambiado
WorkspaceCreateModal rewritten on top of a live marketplace picker — any published workspace_template listing appears automatically
FilterBar sector dropdown expanded to full FoundationSector enum; gains optional priceTier opt-out
MarketplacePublishSettings now dispatches to the unified PublishListingDialog with preset type
Tier-gate removed from workspace creation — every new workspace starts Pro-trialing
Frontier admin UI renders a compact timeline table instead of prose snapshot metadata
UserTask properties panel always offers a Create-form button, not just an Edit button for already-linked forms
Corregido
Inline label editing is legible on every theme, caret included
Spell-check underlines no longer appear on BPMN element labels
The "Add form" dialog opens when you ask for it, rather than on every load of a diagram that already has forms
The form editor renders on the first open of the dialog
The lane roles tab loads instead of spinning indefinitely
Docker images build cleanly with the credential signing dependencies
Form save errors surface as a notification, and the list refreshes once a save succeeds
The forum credential badge renders for the Head of Finance role
The editor route renders server-side without error
Eliminado
Legacy /api/marketplace/templates/* endpoint family (use /api/marketplace/listings/* instead)
PublishWorkspaceDialog component (superseded by PublishListingDialog)
Per-creation module-checkbox add-ins on WorkspaceCreateModal (Launch-Trial activates all modules)
Recommendation-tier match-badge UI (tier-gate no longer relevant with Launch-Trial)
"What's New" banner in the layout, tied to the latest published release version
App version and changelog link in the footer
Forgot password flow — password reset directly from the login screen
Form.js integration for UserTask form definitions in the editor
Self-sustaining village demo workspace template (~125 seed documents)
World events stream and resource flow panel on the login screen
ProcesOS brand definition with tagline typewriter in the hero section
/marketplace/how-it-works transparency page with links to validator and signer source
Cambiado
Lane roles auto-register workspace-wide on diagram save
Credential gate: hard for responsible, soft warning for contributor/viewer
Archived roles auto-reactivate when the same lane name reappears
Cardano NFT portfolio now queries by stake address for full HD wallet coverage
Corregido
Cardano network selection is explicit — an unconfigured network is refused rather than quietly falling back to preprod
Login map connection lines are subtler, and quest bubbles stay inside the viewport
v1.0.0
ProcesOS — The Process Operating System
Initial release of ProcesOS: a multi-tenant process management platform combining BPMN 2.0, DMN decision tables, AI assistance, process governance, and capability planning into a composable process execution language for organizations.
Añadido
BPMN 2.0 editor with bpmn-js — full diagram modeling, auto-save, translation overlays, auto-layout (ELK.js)
AI Wizard Assistant — multi-turn AI chat for diagram creation and modification (Anthropic, OpenAI, Mistral providers)
DMN Decision Tables — dmn-js integration linking BusinessRuleTask elements to reusable decision table definitions
Multi-tenant workspaces with subscription tiers (free, pro, team, enterprise) and feature gates
Process Governance — AS-IS/SHOULD-BE versioning, stakeholder validation wizard, change voting
Global Technology Tree (GTT) — 5-element capability planning (Fire/Water/Earth/Air/Aether) with status machine and unlock cascades
CMDB — IT systems registry with cost tracking, license management, FAIR assessment, and ESG data
Data Objects library with GDPR classification (personal data flags, legal basis, retention periods)
Resource tracking with carbon footprint analysis per process path
Cost & ROI analysis — per-task cost modeling, lane costs, process-level analytics with currency support
Compliance analysis — regulatory gap detection, DPIA/GDPR fields, EU AI Act properties (Art. 14, 26)
FAIR Score assessment for IT systems (Transparency, Accountability, Interoperability, Data Sovereignty, Human Oversight, Local Adaptability)
Discussion forum with credential-gated access, diagram linking, AI insights, and change proposals
Gamification — XP-based skill system with bronze-to-diamond tiers, foundation skill graph, and mastery levels