This release adds 5 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Summary
AI summaryAdds customs clearance, SOX audit, and pharmacovigilance hard‑gap verticals with full kits.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds customs clearance vertical with licensed broker signing entry of record. Adds customs clearance vertical with licensed broker signing entry of record. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Adds SOX ITGC audit vertical with CPA/engagement partner signing ICFR opinion. Adds SOX ITGC audit vertical with CPA/engagement partner signing ICFR opinion. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Adds pharmacovigilance vertical with QPPV/physician signing before safety report filing. Adds pharmacovigilance vertical with QPPV/physician signing before safety report filing. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Adds browser push notifications to signer's console when a case lands in queue. Adds browser push notifications to signer's console when a case lands in queue. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Adds physical multi‑tenant isolation storing each tenant's data in separate <base>/<tenant>/<id>.json directories. Adds physical multi‑tenant isolation storing each tenant's data in separate <base>/<tenant>/<id>.json directories. Source: llm_adapter@2026-06-07 Confidence: high |
— |
Full changelog
3 new hard-gap verticals (research-backed US markets), each a full kit (flow + connectors + compliance reviewer + pack/command/TM + golden eval), all Tier-0 wired and passing --validate:
- customs — Customs clearance ($4.6B); a licensed customs broker signs the entry of record. Reuses live OFAC/sanctions-screen for denied-party.
- audit — SOX ITGC audit ($15–25B); a CPA / engagement partner signs the ICFR opinion.
- pharma — Pharmacovigilance ($1.65B outsourced); a QPPV / drug-safety physician signs before a safety report is filed. Reuses live ehr-fhir.
Plus operational hardening of the end-to-end service (Layer D):
- 🔔 Browser push to the signer — the autopilot console subscribes the licensed human's browser (VAPID); a real push fires when a case lands in their queue (incl. the next gate of a multi-gate flow).
- Physical multi-tenant isolation — runs live under
<base>/<tenant>/<id>.json; one tenant's directory never holds another's.
19 verticals, 270 lib tests, all passing the durable run → inbox → sign → write loop.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About great_cto
Engineering-management layer of 34 specialist AI agents covering the full SDLC (architect, PM, senior-dev, reviewer, QA, security, devops, L3-support + 18 archetype-specific reviewers) with auto-detected archetypes and compliance gates (PCI-DSS, HIPAA, FedRAMP, GDPR, EU AI Act). Runs in Claude Code, Cursor, Codex CLI, Aider, and Continue via AGENTS.md + MCP. MIT.
Related context
Related tools
Earlier breaking changes
- v2.72.2 Removes Autopilot sidebar item and Operate topbar button from dev board.
- v2.55.0 Hard-gates the Build board; redirects invite sessions to Operate for operators.
- v2.43.0 Runtime now blocks autonomous execution of irreversible actions without prior human checkpoint.
- v2.43.0 Adds reversible and blastRadius fields to every flow step.
- v2.32.0 Removed AgentShield scanner and its CLI commands.
Beta — feedback welcome: [email protected]