Skip to content

Week of September 14 -- 20, 2026

Cross-project agent messaging was the week’s flagship delivery — a 7-phase feature enabling agents to communicate across project boundaries with policy-controlled authorization, multi-target fan-out, and full UI controls. In parallel, native chat received its largest overhaul to date (context menus, drag-and-drop threads, layout density, optimistic send, and jump-to-message search), A2A standalone infrastructure reached production-grade HA with durable PostgreSQL task state and authenticated gRPC transport, and the release pipeline matured into a three-channel model with nightly automation and CLI version checking.


Agents can now message across project boundaries, governed by a three-control authorization system: a hub-wide agent messaging mode, a per-project inbound policy (none/members/any), and a non-escalation grant guard. The feature landed in seven phases — from mode-matrix characterization and policy store through typed authorization evaluation with stable denial codes, target resolution and capabilities APIs, full UI controls (hub settings toggle, project inbound policy, agent hub-mode in create/configure/detail, messageability indicators), multi-target DM fan-out with group/broadcast/plugin boundary enforcement, and comprehensive documentation with cross-project decision tables. Live UAT testing on September 20 resolved five integration defects spanning CLI addressing, inter-agent visibility, attachment authorization, and conversation send dispatch.

Chat’s interaction model was rebuilt from the ground up. Right-click context menus replaced the hover toolbar (net −500 lines), threads gained drag-and-drop reorder with named collapsible groups, and a layout density chooser (dense/comfy) replaced 160 CSS values across 13 files. Optimistic send clears the composer on Enter and restores text on failure. Jump-to-message from search fetches around the target via a new around history parameter with highlight-flash animation. Typing responsiveness improved dramatically — synthetic 500-message updates dropped from ~34ms to under 1ms — and DM unread dots and Seen receipt expiry were overhauled with sub-millisecond precision timestamp ordering.

The Agent-to-Agent bridge reached production-grade high availability with four major components: Google credential exchange into short-lived Hub user tokens with Gemini Enterprise JSON-RPC compatibility, PostgreSQL-backed A2A SDK tasks with authoritative ownership and execution leases with atomic crash reap, fail-closed gRPC auth with refreshable Google credentials and TLS/mTLS support, and deterministic multi-process integration tests with a Hub/two-bridge/PostgreSQL topology. Companion work added an Agent Registry lifecycle hooks example for auto-registering Scion agents as A2A endpoints in Google Cloud.

The release pipeline evolved from a two-channel model into a full nightly/preview/stable system. Release management scripts (cut-preview.sh, bump-preview.sh, promote-stable.sh) shipped with dry-run mode and interactive confirmation. A LATEST.json manifest at repo root tracks all three channels, a daily 2 AM UTC nightly build cron skips no-commit days and runs 14-day cleanup, and scion version --check queries update availability against the manifest. The nightly workflow was hardened to invoke build-release directly via workflow_call and prevent execution on forks.


  • Bidirectional mention translation (#1672): Mention format automatically translates between @firstname-lastname (chat) and @email (agents), with autocomplete dedup via normalized slug matching.
  • Emoji icons for spaces (#1672): Optional per-space emoji icons stored in project annotations and rendered in the space rail.
  • Members sidebar filter and sort (#1701): All/Unread toggle and sort dropdown (Alphabetical/Recent Activity) with agent activity tracked by lastActivityEvent.
  • Set-default-agent context menu (#1692): Right-click “Make this agent thread default” on agent messages, with a “thread default” label in the members sidebar.
  • Auto-convert large pastes to attachments (#1714): Pastes exceeding 1,000 characters automatically become text file attachments; image paste takes precedence.
  • Chat conversation export (#1636): Download as Markdown, print/save as PDF, and copy to clipboard with HTML-escaped content.
  • Reply message infrastructure (#1723, #1694, #1728, #1704): New reply message type with metadata pass-through that routes to the sender agent rather than the thread default. Reply context parsed from history backfill with reply_context promoted to a top-level DeliveryEnvelope field.
  • Send/receive polish (#1730, #1736, #1719): Double message flash eliminated via idempotency key tracking, agent-recipient header preserved during SSE reconciliation, optimistic thread creation without sidebar flash, and thread group rendering fixes.
  • Self-sent unread and cross-channel DM (#1703): Self-sent messages no longer mark threads unread; non-web messages (Discord) now touch DM activity via canonical key.
  • File preview vs edit size limits (#1640): Separates read-only preview limit (100 MB) from edit limit (1 MB) with a mode=preview parameter.
  • SPA routing for chat URLs (#1702): Browser refresh on /chat/space/uuid no longer returns 404.

🤝 Conversation & Cross-Project Infrastructure

Section titled “🤝 Conversation & Cross-Project Infrastructure”
  • Conversation CLI and participant management (#1671, #1678, #1686): Surface-agnostic scion conversation command with hub API endpoints — list, messages, get, create, set-default, participants, join, leave, catch-up — all added to the agent-mode allowlist.
  • scion conversation get-message (#1737): New subcommand with participant-based authorization and IDOR protection.
  • Native group conversation routing (#1729): Empty ExternalRef on native conversations no longer causes a hard 500; native conversations route by ConversationID.
  • Auto-register group conversation participants (#1697): Agents and users auto-registered on send and receive paths using idempotent EnsureParticipant.
  • Chat member resolution (#1669): People section replaced legacy group lookup with ListProjectMembers(), fixing @mention resolution for non-creator members.
  • Per-user session revocation (#1590): session_generation counter on the User model with admin API and UI action to force re-authentication, enforced by per-request middleware.
  • Break-glass admin promote (#1589): Emergency admin promote CLI command for access recovery; AdminEmails is now authoritative and all-or-nothing.
  • Session secret removed from /proc (#1602): --session-secret flag removed from systemd ExecStart — resolveSessionSecret() reads from EnvironmentFile instead.
  • Helm credential guard fixes (#1624): assertNoCredentialTree now covers map keys, and the URL password pattern allows slashes.
  • Agent creation permissions (#1754, #1753, #1756): ComputeScopeCapabilities reports agent.create across all granting projects, scope capabilities keyed per resource type, and the project picker lists by capability instead of owner-only.
  • Preview/stable release channels (#1596): Two-channel release model with SemVer tag triggers, automatic channel detection, and branch updates on each release.
  • Release management scripts (#1631): cut-preview.sh, bump-preview.sh, promote-stable.sh with dry-run mode, interactive confirmation, and bash 3.2 compatibility.
  • Release manifest and nightly channel (#1761): LATEST.json at repo root with nightly/preview/stable channels and daily 2 AM UTC cron builds.
  • Version update checking (#1760): scion version --check with text and JSON output against the release manifest.
  • CI custom linter framework (#1606): hack/LINT-CONVENTIONS.md, check-custom Makefile target, and CI workflow for project-specific linting.
  • Individual image build targeting (#1619): Build specific images by step ID with --continue-on-error for partial failures.
  • Bounded GCP observability and native harness telemetry (#1792): Five-phase metrics work adding bounded OTLP admission/delivery, GCP metric identity and cadence, native harness telemetry configuration, privacy controls, diagnostics, and runbook.
  • Cloud Run sandbox log observability (#1616, #1610, #1611): Host-side entrypoint log tailer with per-agent goroutine cleanup, dead-sandbox log serving with source labels, and log preservation across restarts via rotation.
  • Codex reasoning effort key (#1763): Provisioner now writes model_reasoning_effort (matching codex CLI expectations) and expands mapping from 3 buckets to 4 quartiles.
  • Code-quality sweeps (#1592, #1630): ~80 commits across two batches removing obsolete routes, centralizing Hub/runtime/CLI paths, and embedding five behavior-affecting fixes including cross-project runtime fallback prevention and resource import authorization.
  • Workspace-mode label backfill (#1653): Boot-time migration stamps per-agent mode on pre-August-31 git projects that were incorrectly returning shared-plain.
  • Group hierarchy BFS → recursive CTEs (#1639): Four N+1 BFS query functions replaced with single WITH RECURSIVE CTE queries for PostgreSQL and SQLite.
  • pgx UUID type registration (#1787): google/uuid.UUID registered with the pgx type system, resolving uuid = text operator errors on the delegation-ceiling check.
  • Harness-config cache invalidation (#1762): Co-located brokers no longer serve stale harness configs after hub re-bootstrap; ResolveWithHash verifies against the hub.
  • Harness-config hash threading (#1777): HarnessConfigID and HarnessConfigHash flow through the full StartAgent call chain for hash-verified resolution.
  • Hub agent defaults cascade (#1734, #1724, #1696): Harness-config fallback now cascades project → hub → hardcoded instead of using a hardcoded value. Default harness changed from antigravity to claude.
  • Web asset build-time enforcement (#1660): Compile-time sentinel embed catches missing web builds, preventing blank pages.
  • Container image build wizard (#1725): Single-node-VM deploy script gains interactive wizard for registry path or local image builds.
  • Single-node-vm live-deployment fixes (#1655): Nine blockers resolved from live testing — systemd, releases fallback, IAP tunnel, SA parameterization, health checks, and SSH capture.
  • Opencode hook bridge plugin (#1620): Hook bridge plugin and dialect enabling the opencode harness to communicate with the Scion hub.
  • Opencode resume with synthetic prompt (#1638): Agents no longer exit within ~15 seconds after suspend/resume; synthetic prompt injected for task-flag harnesses.
  • grok-build Vertex AI compatibility (#1778, #1776, #1774): Provisioner sets api_backend = "chat_completions" for Vertex AI, --disallowed-tools x_search removes unsupported hosted tools, and --trust suppresses the directory trust prompt.
  • Unified template authoring UX (#1665): Shared resource-list and resource-import components replace standalone 700-line profile-templates.ts.
  • A2A bridge multi-turn and artifact text (#1676): Preserves artifact reply text, fixes multi-turn subscriptions, raises HTTP write timeout. (Zainab Ahmed Safeer)
  • Telegram sender ID resolution (#1232): Resolves registered sender’s Hub user ID for outbound SenderID. (Juan Pablo Urzua)
  • Claude model upgrade dialog suppression (#1663): CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST=1 suppresses the blocking “Newer Opus model available” dialog at agent startup.
  • Cross-project messaging design docs (#1779): Four design documents (1,555 lines) covering full design spec, current behavior analysis, 7-phase delivery plan, and confirmed decisions.
  • Messaging authorization reference (#1786): Full Starlight reference page covering message modes, decision tables, piercing rules, quarantine, 7 denial codes, API endpoints, and CLI commands.
  • Release process documentation (#1759): Three-channel model, branch taxonomy, operator runbook, manifest format, and CI/CD workflow architecture.
  • Single-node VM guide and Developer Hub rebrand (#1652): Deployment guide for single-node-vm tier, choosing-a-mode comparison doc, starter-hub rebranded to Developer Hub.
  • Agent Registry lifecycle hooks example (#1791): Auto-register Scion agents as A2A endpoints using lifecycle hooks.
  • Conversation platform skill (#1738): New scion-conversation skill documenting all 10 subcommands with cross-links to scion-messaging.