Agent activity becomes easier to supervise and trace, with clearer sharing, retained work records, and native iPhone/iPad views.
Agents, activity and provenance
Keep Agents as the default tab, with Activity for work needing attention, running agents and today's sessions, and Provenance for searchable actions.
Filter oversight by person while keeping personal spend scoped to Mine.
Show subagents beneath their parent and trace a turn's commands, paths, URLs and stored output back to its messages.
Open Show provenance from agent messages, images and supported artifacts.
Bundle Volta Agent 0.1.5 with foreground subagents and preserve scheduled-turn activity attribution in the ACP harness.
Keep agent creation in one flow and Sharing in the agent's Sharing tab. Export saves PNG or JSON files; the misleading non-sending Send action is gone.
Conversations and storage
Keep thread replies when their root message is deleted, with an explicit placeholder and retained activity provenance.
Separate retained activity records from expiring large payloads, expose the community retention setting and storage usage, and bound local search storage.
Preserve existing records: this release does not retroactively trim old encrypted activity or mass-archive conversations.
Keep narrow channel headers usable and improve composer, navigation, unread state and current-flow regression coverage.
Turn off the legacy steps chip and remote-agent provider UI for this release; shared compute is removed, while explicit remote-compute jobs remain separate.
Native iPhone and iPad
Replace Flutter iOS with the native SwiftUI client, including phone navigation, adaptive iPad layout, profiles, boards, conversation tools, files and Galvani.
Add essential Activity views on iPhone and the fuller Activity/Provenance experience on iPad, with turn provenance sheets for supported message/image entry points.
Keep attachment actions usable with the keyboard open and restore Galvani navigation after reopening the app.
Keep session titles, deleted triggers and expired approval attention current.
Prepare the native shipping identity separately from Debug Preview; Flutter/Android remains paused and its metadata is unchanged.
Pair again when installing the native replacement. Existing Flutter credentials, drafts and pending messages are not migrated into native storage. Native huddle joining remains unavailable; artifact authoring/export remains on desktop. The native parity ledger tracks remaining work. Native runtime console warnings remain unresolved. Android is not released in this cycle.
Packaging and release evidence
Package the same pinned Volta Agent on Windows and macOS and verify packaged GitHub sign-in configuration.
Sign native macOS agent resources before sealing the app; require notarized, stapled app/DMG and signed updater archives.
Keep Windows native title-bar controls for this release; the integrated title-bar redesign is deferred.
Acceptance and distribution record
Dependency policy: the two PDF-exporter maintenance exceptions for rustybuzz (RUSTSEC-2026-0206) and ttf-parser (RUSTSEC-2026-0192) were renewed specifically for 0.7.0 on 2026-09-17 (recorded in deny.toml and commit d45fcc6ea). Replacement remains tracked in #109; this release introduces no new advisory waiver.
Human smoke: Harrison reported on 2026-09-25 that he had smoke-tested the release's features, including the Windows canary, and authorized completing the release without intermediate approval stops once the test gates pass.
macOS and Windows: final same-source installers and signed updater artifacts are required before publication; their exact source, hashes and verification results belong in the published release evidence manifest.
Native TestFlight: Harrison took ownership of mobile distribution on 2026-09-26. This desktop release does not upload or deliver a TestFlight build. Native source is prepared for 0.7.0 build 28; the mobile handoff must check App Store Connect for a build-number collision, archive signing, processing, internal availability, and physical-device/push behavior before delivery. Public App Store submission remains outside this release.
Source validation: PR #111 passed all applicable CI lanes, with full iPhone and iPad iOS 27 suites each passing 92/92. Desktop smoke passed with 1,534 passed, 11 skipped and one test passing on its configured retry; that flake is not claimed fixed. Exhaustive iOS 26.5 coverage remains explicitly deferred. The release integration preserves the validated source; final release CI and package evidence are recorded separately.
These candidate notes do not certify pending tests, artifacts or deployment. The final release record must state the actual distribution outcomes, not convert pending work or earlier isolated passes into final acceptance.
Shared conversations, project task boards, and collaborative artifacts bring people and agents into the same workspace. This release also repairs packaged GitHub sign-in and Windows project paths.
Conversations and agents
Share agent sessions while keeping owner controls separate from conversation access.
Edit agent settings on the computer that owns the runtime, including before a chat starts.
Preserve one-on-one history, streamed answers, drafts, and return navigation.
Keep agent identities and team deletion state consistent across computers.
Refine composers, agent colors, sidebar labels, scrollbars, and message activity.
Keep branch titles readable at the minimum desktop window width.
Preserve focus in channel creation menus while the dialog opens.
Tasks and artifacts
Manage shared project boards with assignments, priorities, and agent pickup of authorized Ready tasks.
Work with Design and Galvani setup discussions as ordinary collaborative threads.
Publish interactive HTML and editable slide decks beside conversations, with editing leases and PDF/PowerPoint export.
Create source-based study guides, mind maps, quizzes, flashcards, and tables from HTML starters.
Discover shared artifacts through Files and search while preserving the current thread and draft.
Keep artifact previews and presentation inside the conversation pane; remove fullscreen artifact controls.
Galvani
Export retained reports, forum, literature, scores, evidence, and available researcher session archives.
Track multiple metrics and eligibility gates independently, with clearer charts and authoritative scoring evidence.
Share Analyzer review discussion and preserve the boundary between conversation access and privileged controls.
Improve setup navigation, naming, and run review workflows.
GitHub and packaging
Require both GitHub OAuth application values for Mac and Windows builds and verify them in packaged apps.
Preserve drive-letter and UNC project paths on Windows.
Rebuild and verify packaged agent tools, including boards, artifacts, and paper operations.
Support exact-version Windows release builds through GitHub Actions with updater signing kept on the release Mac.
Platform decisions
Dependency policy: Harrison authorized exceptions for the rustybuzz (RUSTSEC-2026-0206) and ttf-parser (RUSTSEC-2026-0192) unmaintained-library notices on 2026-09-12, limited to 0.6.1. Both come through the PDF exporter; replacement and removal of these exceptions before the next release are tracked in #109.
macOS: human installation, launch, GitHub sign-in/private-clone, and feature smoke explicitly waived by Harrison on 2026-09-12. Artifact and automated verification remain required.
Windows: installer and updater are included; human installation, launch, GitHub sign-in/private-clone, and feature smoke explicitly waived by Harrison on 2026-09-12. Artifact and automated verification remain required.
iOS: smoke and release intentionally skipped by Harrison on 2026-09-12. Mobile product source is unchanged since 0.6.0; the version/build metadata advances to 0.6.1+27 without a TestFlight upload.
Galvani gains a shared literature survey, reviewed research submissions, and a private Analyzer. One-on-one conversations are easier to reopen and continue.
Galvani
Four librarians prepare a cited survey before researcher time begins. Researchers can read and extend the literature throughout their work.
Structured mini-papers are reviewed before grading. Published findings show the exact reviewed submission and authoritative score.
The private Analyzer provides run analysis with configurable model, thinking level, and monitoring interval. Its conversation stays inside Galvani instead of appearing in Direct Messages.
Setup exposes run duration, per-agent submission limits, research iteration limits, and research model settings.
GPU jobs support independent researcher and GPU hosts, fresh Slurm allocations, and already held capacity. Verification checks the selected GPU environment and researcher tools.
Results, Forum, Literature, researcher boxes, submissions, and records share clearer navigation, timing, and contributor labels.
Score charts format axis labels automatically and preserve exact scores in details.
Conversations and controls
Reopen one-on-one conversations with their history intact. Closing the panel hides the conversation; Stop interrupts the current turn.
Continue chatting after Galvani setup handover, with shared composer controls and clearer Analyzer presentation.
Improve thread responsiveness, attachment controls, agent model settings, and deferred thinking-level changes.
Preserve link previews when metadata arrives during Send, and dismiss stale channel suggestions when an edit is cleared.
Keep Galvani setup progression correct when retrying a rejected answer.
Preserve spaces when inserting a mention before existing draft text.
Offer updates for agent adapters and retain supported model and thinking controls.
Release validation
Cleanup integration: full CI passed, including desktop, mobile, backend, relay, and both desktop integration shards. Browser smoke: 1,473 first-attempt passes, one passing retry, and one existing skip.
Candidate artifacts: both desktop installers were built from aaa70f29e402ed4b153b2e5f789380655f7c8e3c; the full local CI gate passed on that source.
Candidate hosted CI: all required jobs passed, including 1,474 browser smoke passes, one existing skip, and no failures or retries.
macOS: signed, notarized, and stapled 0.6.0 installer verified, including the mounted app and signed updater archive. Human candidate smoke accepted by Harrison on 2026-09-08: "It's good." This answers the handoff covering installation, launch, sign-in, and Analyzer chat checks.
Windows: 0.6.0 x64 installer verified, with a stored-only updater archive and cryptographically verified signature. Human candidate smoke accepted by Harrison in the same 2026-09-08 desktop handoff: "It's good."
iOS: intentionally skipped by Harrison because mobile app behavior is unchanged since 0.5.0; the mobile diff contains only a comment and the version/build bump to 0.6.0+26.
Channel composers show the agents currently working, while threads retain a dedicated participant attachment surface with per-agent activity visibility.
Thread attachments are explicit and durable: selected agents use leading attachment chips, survive navigation and sending, and remain independent of ordinary mentions.
Thinking and permission menus fit their full labels and remain editable when an agent is stopped; the agent activity default is configurable in Settings.
Projects and sidebar
Project rooms use normal channel typography, a compact fixed color palette, and consistent expanded, collapsed, hover, border and inset treatments.
Projects can be reordered directly in the sidebar, with the per-user order synchronized across devices and retained for hidden projects.
Sidebar sections share subtle reduced-motion-aware disclosure transitions, while scrolling no longer reserves a visible scrollbar gutter.
Galvani
Experiment packs can define their own grader program, executed in a closed grader box with held-out answers, reserved attempt budgets and durable ledger accounting.
Galvani can launch, verify and resume researcher boxes through Apptainer, including the warden and process lifecycle needed on Slurm compute nodes.
Platform outcomes
macOS: 0.5.2 signed, notarized and stapled build is included; human install/launch smoke intentionally skipped for this rushed release.
Windows: 0.5.2 x64 NSIS installer and signed updater archive are included; human install/launch smoke intentionally skipped for this rushed release.
iOS/TestFlight: intentionally skipped because this release has no mobile changes; the mobile version remains 0.5.0+25.
Hosted CI and local code/test checks were intentionally skipped by explicit release authorization. Packaging and publication still perform their required artifact-integrity and live-feed readback gates.
Agent pills replace the old attach bar with a compact, thread-aware surface for attaching, watching and steering agents.
Thinking effort and permission mode can be chosen at creation and are shown from the applied session configuration, while lightweight seen marks replace noisy reaction acknowledgements.
Message actions now offer two learned quick reactions, including custom emoji, while preserving the full reaction picker and existing reply/link actions.
Runtimes, projects and Galvani
Google Antigravity is available as a built-in agent runtime with its own discovery, readiness, model selection and branding.
Project rooms now share one consistent sidebar identity, color and branch treatment across project navigation.
Galvani labs can be archived without deleting provenance, and remote runs gain executable connection-route preflight before durable setup begins.
Reliability and operator safeguards
Agent session configuration, thread provenance and reconnect behavior retain the state needed to explain how a turn actually ran.
The Buzz CLI refuses empty message bodies and accidental literal \\n text, preventing accepted-but-blank collaboration messages.
Platform outcomes
macOS: 0.5.1 signed, notarized and stapled build is included; human install/launch smoke intentionally skipped for this rushed release.
Windows: intentionally skipped. The configured Windows build host is unavailable for this rushed release.
iOS/TestFlight: intentionally skipped because this release has no mobile changes; the mobile version remains 0.5.0+25.
Labs and setup-scoped runs now form one usable research surface, including local supervised launches and coordinate-only remote starts.
Run records expose the conditions needed to compare researchers: population, model and typed effort, box contract, siting, network posture, baselines, scored-submission allowance, spend, crashes, transcripts and workspaces.
Run-room filtering, bounded relay reads and strict canonical-record handling keep search results and run summaries truthful when records are incomplete.
Mobile is part of this release
Mobile Huddles add live voice conversations, participant controls and agent voice-turn state handling.
Profiles can be edited on-device, with camera, image and animated-avatar capture plus safer identity export behind device authentication.
Community invites, open-channel discovery, channel details, threads, composer behavior, message actions, emoji interactions and navigation have been substantially expanded and repaired.
Relay recovery now handles stale or shuffled messages without presenting an incomplete timeline as current.
Conversations, agents and storage
Agent addressing persists across composer sends, while mention handling, search highlighting, message editing, thread loading and image navigation are more reliable.
GIF search, improved message actions and corrected lightbox zoom round out the desktop conversation surface.
Storage reporting now accounts for channel-file bytes and other major partitions with durable rollups instead of hiding them under “other.”
Platform outcomes
macOS: 0.5.0 signed, notarized and stapled build passed human smoke.
Windows: 0.5.0 installer and signed updater archive are included; human install/launch smoke intentionally skipped for this rushed release.
iOS/TestFlight: included as 0.5.0+25; the human archive and upload to TestFlight completed from this release candidate before publication.
Windows is now an explicit desktop release platform in the canonical runbook, candidate and publisher skills, and release checklist.
Publication fails before tagging when the Windows installer/updater archive is missing, unless the canonical notes record an intentional Windows skip.
The live updater feed is read back after publication to verify the Windows entry and archive URL.
Platform outcomes
macOS: signed, notarized, and stapled artifact required; repeat human smoke waived because product behavior is unchanged from the smoke-tested 0.4.8 build.
Windows: installer and signed updater archive built from the 0.4.9 candidate; human install/launch and release-flow smoke passed on nyx.
iOS: 0.4.9+24 intentionally skipped for TestFlight; product behavior is unchanged from 0.4.8.
Channel files replace notebook sources as the shared material agents and people work from.
Type $ in the composer to find and reference a channel file; sent references open as the file itself.
Agents can list and read channel files, and their generated artifacts can be opened or kept directly from any channel.
File indexing now covers both new sends and earlier channel history, with removal support when a file or message is deleted.
Agents are easier to steer and configure
Managed agents now keep one continuous conversation while preserving the channel, thread, and project-room context of each turn.
Late steering keeps its provenance, and single-worker controls prevent duplicate concurrent work.
Model and thinking-level controls now share one consistent editor for personal agents and team members, including values that are not present in the current catalog.
Faster, clearer conversations and projects
Long threads page replies progressively and window the visible list, reducing work as conversations grow.
Project navigation now treats papers as the project workspace entry, with cleaner per-project hover and visibility behavior.
File references, artifact cards, and non-image attachments render more clearly and avoid duplicate previews.
Mobile
mobile/pubspec.yaml is at 0.4.8+23. TestFlight publication was explicitly skipped for this release after the macOS DMG passed human smoke testing.
Release checks
Mobile hooks use and report the repository-pinned Flutter toolchain instead of inheriting a global SDK.
Remote-compute adapter tests no longer depend on the launching session's configured hosts.
The tracing-state assertion runs in an isolated process, and release pull requests compare changed paths against their real base so substantive CI jobs cannot silently skip.
The Tectonic fetcher rejects empty or non-executable cache entries instead of shipping an incomplete paper-compilation sidecar.
An installed Windows copy could not apply an update: it failed with unsupported Zip archive: Compression method not supported. The updater archive was built with deflate, and the reader inside the app has no deflate backend compiled in. The archive is now stored uncompressed, which every build of that reader can open — so copies already installed can update to this release, without a manual reinstall.
Sidebar and projects
Projects can be turned on and off in the sidebar without going silent.
A project group now shows the name its owner set, instead of the GitHub name.
A project header gets a ⋯ menu as well as its right-click menu.
Projects have their own sort key, and every section gets one header.
Agents and channels
The inline activity bar says who is working rather than reciting what they are doing.
Every agent's attach "eye" starts closed.
An agent's answer goes back to the thread its question was asked in.
Other fixes
A huddle that auto-ends says so, instead of going quietly unremovable.
The desktop dev server serves a browser the mock backend rather than a loading screen forever.
Mobile
iOS/TestFlight was not shipped for this release — deliberately skipped. mobile/pubspec.yaml is at 0.4.7+22; no archive was uploaded.
Teams have roles now, and agents can call each other in.
Roles
A team is no longer a flat list of agents. It has roles — Manager, Implementer, Reviewer — and each role carries its own instructions, its own seat count, and its own look. Fill a seat by making somebody new or by moving somebody you already have; either way they arrive wearing the role.
A member's prompt is now a stack rather than one field: the base prompt, then whatever is theirs alone, then the team's instructions, then the role's. Their own prompt says who they are; the role says what the job is, so the same agent can be an Implementer on one team and something else on another without being rewritten.
Start a team from a template — Circuit, Lattice, or Grid — and the roles, seats, and entry points come with it.
The delegating roles now carry explicit scope discipline: a Manager is told to hold the boundary it was given and to hand back a smaller thing rather than a bigger one. Scope growth is the standard failure of delegated work, and it now has a named owner in the prompt.
An agent knows its own team
Every agent on a team is now given its roster at startup — who its teammates are, what role each holds, which one is itself, and each one's full key. It could not previously find this out: the relay knows team members by an internal id, not by anything an agent can address. So an agent that wanted a colleague had to guess a name and hope. Now it can simply mention them.
Agents can wake each other
Mentioning an agent has always started it. That only worked when you did the mentioning — an agent that mentioned another agent was talking to a room where nobody was listening, and the message sat there.
Now any agent you own, or that has been shared with you, comes up when it is mentioned by anyone in that same circle. Ask a manager for something and it can bring in its own team; the four of them wake, work, and answer.
Harnesses
The Default harness in Settings now actually reaches the agents that get made for you — team-minted agents silently ran the fallback harness before, whatever Settings said. Beyond the default, a role can specify which harness its seats are minted with, and any individual seat can differ, so one team can run Claude Code and Codex side by side.
Smaller things
A deleted or archived agent now leaves the channels it was in, instead of lingering in the member list forever. Agents retired before this release are swept out on first launch. Their messages stay.
The base prompt's buzz reactions example named flags the command does not take, so an agent following it hit a usage error.
Volta now builds, installs, and updates itself on Windows. The installer is on this release; once installed, the app checks the same update feed macOS uses and installs new versions from inside the app.
Windows builds are unsigned for now, so Windows shows a SmartScreen prompt on first download, and a "Unknown publisher" prompt each time an update installs. Both are expected and neither indicates a problem — a code signing certificate is a separate piece of work.
macOS is unchanged: same signed, notarized, stapled DMG, same auto-update.
Under the hood
Volta's CI now runs on hardware we own rather than billed cloud runners. The last recurring cloud job moved to a dedicated always-on machine, along with the lint, web, security and cross-compile lanes. Nothing about the app changed as a result; builds are simply no longer billed and no longer wait on a laptop being awake.
One real bug surfaced while proving the Windows build: the LaTeX toolchain Volta bundles for paper compilation was extracted with a tool that misreads Windows paths as network addresses. Fixed — it affected any Windows build, not just ours.
A notebook is a shared research workspace: you add sources — PDFs, documents, web pages — and their text is extracted once and shared with everyone in the notebook. Ask a question in the notebook's room and an agent answers from those sources, citing the passage it used rather than recalling something plausible.
Add a source from a file, a link, or a message someone already posted. Extraction happens once, on the relay, so everyone reads the same text.
Ask, and get citations. Answers point back at the exact passage. Clicking a citation opens the source at that spot.
Studio turns the sources into a study guide, a mind map, a data table, a quiz, or flashcards. Output is added back as a source, so it can be read and cited like anything else.
A notebook belongs to a project and inherits its access — everyone in the project, and nobody else. There is no separate member list to grant or forget to revoke.
buzz notebook covers the same ground from the CLI: list, sources, search, read, add-source.
The sidebar says what each room is
A project's rooms used to arrive as one flat list, where nothing told a paper's room apart from a branch except recognising the name — and a notebook's room was not shown at all.
Each project now groups its rooms by what they are: Repo, Papers, Notebooks. Each block is labelled, collapses on its own, and is hidden entirely when it has nothing in it. The separate top-level Notebooks section is gone; a notebook hangs off its project exactly as a paper does, so it lives there. The tree is also a level shallower than before.
Panes you can actually resize
The notebook's sources rail and Studio pane both drag, and each remembers its width for the session.
The conversation can no longer be squeezed out of existence by dragging both rails inward — it keeps a minimum, and the rails give up width first.
The same protection turned out to be missing in the paper editor, where the editor could be reduced to half its documented minimum width. Fixed.
Every right-hand pane now remembers its own width. Previously the paper editor, the channel thread panel, Agents, Pulse and Home shared one, so resizing any of them resized all of them.
Agents know which room they woke up in
An agent in a repository's room now sees the repository and branch that room is, and a paper's room names its paper. Before, a project room and #general looked identical apart from the name, so an agent had no way to know a checkout was already in front of it — and would clone the repository again or ask which one was meant. It now works in the checkout the room already has.
Fixes
A newly created notebook now appears immediately — and so does a newly created paper. Previously the room was created but the app never heard about it, which also meant the person who had just created a notebook was offered no way to rename or delete it.
Notebook source search works. It was returning nothing for every query on any relay that had ever stored an event, and the empty result was indistinguishable from "the sources do not say that". Relays now report which content they index, so an empty result means what it says.
Deleting a notebook removes it from every surface, including its rooms.
Platforms
macOS only. iOS/TestFlight was deliberately skipped for 0.4.4: the sole change under mobile/ since v0.4.3 is a comment in nostr_models.dart explaining why Volta's own 500xx event kinds are absent there, so a TestFlight build would carry no functional difference. Notebooks, the sidebar grouping and the pane work are all desktop surfaces; mobile has no screen for any of them yet. mobile/pubspec.yaml still carries the version bump, so the next mobile release picks up from 0.4.4.
For operators
This release needs a relay carrying migrations through 9016. Full-text search over notebook sources additionally requires scripts/maintenance/nip_rs_search_allowlist.sql to have been run against the relay's database — new installs get it automatically; existing ones do not.
The patch promised in v0.4.2's known issue. Desktop only — iOS skipped again.
The audience control on the Agents screen now changes the agent
In v0.4.2 you could open an agent, set Who can send instructions to Selected people, pick someone, save, reopen it, and see Selected people — while the person you picked still saw nothing. Restarting the agent did not help.
Nothing was lying to you. The dialog read back exactly what it wrote; it just wrote to the wrong record. Volta stores an agent's audience in two places:
the persona — the template you create agents from, and
the agent — the running thing that actually answers.
The Agents settings screen edits the persona. The persona's audience was only ever read once, at the moment an agent is created from it. Change it afterwards and the running agent kept the audience it was born with, so no access was granted and no activity became visible.
Saving now writes the audience through to every agent made from that persona, republishes it, and issues the access that follows from it. One save, one result.
This also repairs agents that were already out of step: the first save of any persona that states an audience re-asserts it onto its agents, so an agent stranded on an old audience by v0.4.2 or earlier is corrected without you having to recreate it.
Correction to v0.4.2's release notes
The known issue was described as Selected people not surviving a round trip through the editor — the dialog appearing to forget your list. That is not what was happening. The dialog remembered correctly; the value simply never reached the agent. Only me and Anyone were affected in the same way and for the same reason, not unaffected as stated. Anyone who set an audience on an existing agent under v0.4.2 should open it and save once after updating.
Not included
iOS/TestFlight was skipped for this release. Mobile is unchanged.
Hotfix release so a shared agent's work is actually visible to the people it is shared with. Desktop only — iOS was deliberately skipped.
Talking to an agent and watching it are now one permission
Before this, an agent had two independent access controls that nothing kept in step: Who can send instructions decided who could drive it, and a separate mechanism decided who could see what it did. You could hand someone an agent and have them able to drive it while staring at an empty activity panel — which is exactly what happened, and it was not recoverable from the sharing UI in v0.4.1.
There is one control now, and it answers both questions:
Setting
Who may drive
Who may watch
Only me
you and your agents
the same
Selected people
the people you pick
the same
Anyone
anyone in a shared channel
the same
Under Selected people, saving the agent publishes the activity grants for the people you chose. Under Anyone, the agent grants each person the first time they actually instruct it — not merely for being in the room.
Narrowing the setting is the revocation: there are no revoke events to send and no list for your laptop to enumerate. The relay stops resolving what the agent issued the moment the policy that allowed it no longer holds.
The bug that made every earlier fix invisible
An agent shared with you was hidden by default, and acquiring the grant is what hid it — so each previous fix landed correctly behind a client that had already decided not to show the agent. Shared agents are now watched by default and appear in the attach bar with their activity visible.
Also in this release
The status line under the composer no longer announces your own prompt back to you, and no longer describes the previous turn's work while a new turn is still thinking.
Activity frames arriving while a grant is being re-read are no longer dropped, and a thread loaded before the grant arrives is refetched once it lands.
The access copy now says plainly that a grantee sees the agent's work in the channels they share with it — including turns you and other people drove, and work done before they arrived — and that narrowing access later cannot erase what someone already received.
Known issue
Selected people does not survive a round trip through the agent editor. Opening an agent whose audience is Selected people shows "Only me (default)", and saving from that dialog writes the narrowed value back and drops your list. The stored policy itself is correct — grants derive from it properly — but avoid re-saving such an agent until the fix ships. Anyone and Only me are unaffected. A 0.4.3 patch follows shortly.
Volta now knows what the agent tools it runs actually are — what each harness is called, which adapter version it needs, which permission modes it offers, and what its tool calls mean. Alongside that: agents you address in a thread are addressed the way you wrote it, and setting up a project tells you what it is doing to which folder.
Agent harnesses
No more empty "Thinking". Claude Code turns opened a Thinking heading over nothing. The adapter sends thought frames with no text — Volta was faithfully rendering nothing at all. Nothing is drawn where there is nothing, and the reasoning still keeps its place in the transcript when it does arrive.
Outdated adapters say so. A harness declares the adapter versions it runs on, and an adapter below that floor offers a reinstall instead of silently behaving worse. The floor names the npm package it measures, so Zed's claude-code-acp is not judged by claude-agent-acp's version line.
Permission mode is a control. The mode an agent runs under was fixed when it launched. It is now the adapter's own list, offered live per session — and only where the adapter declared one, so a runtime that offers none is never handed a control that would crash it.
Tool calls read as what they are. Every ACP tool kind an adapter declares — read, edit, delete, move, search, execute, think, fetch, switch mode — now has a reading. They used to collapse into "Ran tool".
The setup card calls a harness what it calls itself.
Agents in a thread
Every agent gets a colour, so a thread with several of them reads as several voices rather than one column. An emoji avatar already carries the colour its owner chose; a picture avatar takes an outline instead.
The bar says who is here. A pill shows when its agent is mid-turn in another conversation, so a message that will wait behind that turn says so before you send it.
Deleting an agent retires it without unnaming its work. Its past messages keep the name and colour they were written under; the agent leaves pickers, autocomplete and the composer bar, and its work stays switch-off-able behind an Archived disclosure.
Addressing works the way you wrote it. An @-mention re-aims the command that follows it, one message can carry several, and a bare /command in a DM offers the popup it always ran.
Projects
Setting a project up offers only answers that can succeed, reports the folder it is actually looking at, and refuses a move before offering it rather than after.
A source directory is no longer mistaken for a project's container, and the folder you picked is the folder that gets moved.
Fixes
h2 0.4.16 clears the advisory that blocked any Cargo.lock change.
A git worktree's E2E suite gets its own preview port, so two checkouts no longer serve each other's tests.
---
Platforms: macOS desktop only. iOS/TestFlight was deliberately skipped this cycle — no mobile changes since v0.4.0.
Until now, watching an agent work meant leaving the conversation to do it: the activity panel displaced the thread, showed only agents running right now, and lost everything the moment you reloaded. You could read the work or read the room, never both.
From this release an agent's work is read in the thread that asked for it, attaching to an agent is a real per-thread choice, and what an agent did is a durable record rather than a live feed you had to be present for.
Attach mode
Work lands under the message that caused it. Placement is causal — every row hangs off the message that triggered its turn, never off a clock — so a turn reads as one unit even though thread replies render in tree order.
Attach is a (thread, agent) pair, in DMs and threads. A regular channel's top-level composer is untouched.
Activity survives a reload. Agent activity is a thread-anchored durable record, not an ephemeral frame you had to be watching to see.
Share an agent, and see what it did — a grant now reaches the person you shared with live, not only on their next reload.
Turns say where they came from and where they went. Sessions are per channel, so consecutive turns routinely share one model context across different threads. A turn marks the context it imported and the messages it posted elsewhere, instead of presenting each thread as hermetic.
A mid-turn send queues by default, with a composer control to escalate a single send to a steer.
Effort in passing — change an agent's effort from its bubble, see the model it is running as, and how much of its context window is left.
What a thread shows
A thread and the agent panel are different surfaces, and this release stops treating them as one. The panel is a monitor and shows everything; a thread is a record and shows the work.
An edit shows the change. Claude Code's adapter reports edits as structured diffs, a shape the renderer did not know — so an edit arrived as a title with nothing under it. Edits render as diffs now, in the panel too.
No raw JSON parameters in a thread. The row's title already names the file or the command.
The answer appears once, rather than as a published reply plus an unattributed copy directly above it.
Scrollback, not the status line. Mode, token usage, the advertised command list and the system prompt are terminal chrome, and no longer render as thread rows — nor leave an empty "No ACP activity yet" card where a turn had nothing to show.
Slash commands
**The / menu works before you have said anything.** Adapters only advertise their commands once a session exists, and sessions were created lazily on the first message — so the menu was empty exactly when you reached for it. The harness now collects the repertoire at startup, and Volta remembers it across runs.
Commands render as chips, the way @ mentions do.
An agent that has not reported yet says "Starting up agent…" instead of showing you an empty list.
The popup offers the whole repertoire rather than the first eight.
Liquid Glass composer (macOS)
Real WebKit system materials behind the composer, with a legible edge.
Glass opacity rides the appearance slider; non-mac keeps the plain blur.
The glass survives dock resizes, remounts and page-visibility changes, and the bottom-left corner mask paints over it correctly again.
Also in this release
just volta comes up as your real Volta account, agents and all.
A launch-restored agent tells the UI it is running.
A dev build hands a key to agents that arrive after migration.
An agent's log can say what its harness advertised.
For the record
macOS: signed, notarized and stapled DMG — both the app and the DMG carry their own notarization tickets.
iOS: skipped for this release. No mobile changes landed since v0.3.11, so nothing was archived or uploaded to TestFlight. mobile/pubspec.yaml still advanced to 0.4.0+15 so the next upload gets an increasing build number.
A sync release. Two upstream desktop releases — 0.5.10 and 0.5.11 — arrive together, because 0.5.10 was never taken on its own. Volta adds no features of its own here; almost everything below is upstream's work, kept or reshaped where Volta's product differs, plus one fix of ours and a documentation reorganisation you will never see.
The headline is speed. Upstream spent both releases chasing input latency on a real profile, and the fixes are additive.
Speed
Clicking back into the app no longer stalls. Waking the window used to fan a refetch out across every query at once, on the main thread, before the first frame had painted. Resume work now waits for the window to actually be live and for a frame to land, and relay recovery is coalesced instead of run per-subscriber.
Bursts of replies stop rewriting the whole activity buffer. Every incoming thread reply serialized a ~600 KB blob to local storage — once per event. A burst now collapses into a single debounced write. Read-state persistence got the same treatment: it was rewriting all three of its blobs synchronously on every change.
Channel lists load from a cached fingerprint. The channel snapshot now carries a hash, so an unchanged list is recognised rather than rebuilt, and get_channels itself got materially cheaper. Upstream traced multi-second stalls, slow boots and intermittent lockups introduced in their 0.5.9 to three independent causes plus this one; all four are fixed.
Search
One scope, and you can take it off. Cmd+K and a channel's Cmd+F now share a single removable channel-or-conversation scope chip rather than being two different searches. People and channels match fuzzily while exact matches still sort first, a one-character scoped query returns a complete result set, and up to 40 results scroll.
Appearance
Glass is now a preference, not a side effect of your theme. Volta's translucency used to switch on only under a first-party theme. It is now an explicit opt-in with its own opacity slider, in Settings → Appearance, and it previews live as you change themes. Volta's Spectrum gradient still overrides it — the two were rewired to the new switch rather than left fighting.
Channel settings and profiles were rebuilt around shared parts. Channel settings collapse into detail, member, canvas and action sections; human and agent profiles now use the same rows, segmented tabs and top-level actions.
Chat
Live timelines are no longer replaced by their own first event. A live subscription starts at the current second, which left a gap — and an unresolved, pageless channel window could overwrite a populated timeline with the single event it had. Both are fixed.
Typing straight after sending to an agent no longer corrupts the mention. Restoring the persistent @Agent prefix ran it back through the Markdown parser, which ate its trailing space and left the caret inside the mention.
Sent link previews show their thumbnail and favicon again when the media is hosted on the relay. Buzz entity cards — the ones that name a pull request or a repository inline — were rebuilt on what Volta actually publishes; upstream's version reads relay-hosted git state, which Volta does not have.
Paper
A comment on a sentence you just typed no longer vanishes. Posting a comment publishes your pending edit first, deliberately, so the comment's position accounts for it. But both events carry whole-second timestamps, and a same-second tie was broken by a random event id — so about half the time your own edit was replayed over your own comment, pushing it past the end of the file. The comment, and the entire margin column with it, silently failed to appear. Your own edits are no longer ordered against your own comments by chance.
Agents
Agents see the channel description in their prompt context.
A long answer is no longer truncated as harshly, and an agent gets three recovery attempts rather than one.
Woken lazy pools go back to sleep when they go idle again instead of staying up.
Databricks OAuth can be launched from passive model discovery.
Operators
Deleting a community actually deletes it. Upstream added a durable whole-community deletion that discovers community-scoped tables by scanning the catalog and fails closed on any table it does not recognise — which meant Volta's own forge tables had to be declared to it, or every deletion path would error and a purge would report success while leaving rows behind. They are declared and fenced now.
Security
webbrowser bumped to 1.2.4 for RUSTSEC-2026-0257.
Mobile
Hydrated threads settle on the latest reply.
---
Upgrading: if you are on 0.3.9 or later, Check for Updates in Settings. A DMG download is only needed for a fresh install.
**iOS/TestFlight: shipped as 0.3.11 (14)** [HARRISON, 2026-08-15] — unlike 0.3.10, this release has mobile content (the hydrated-thread fix above), so it went to TestFlight Internal rather than being skipped. The next mobile upload must start above build 14.
The first release where updating actually works end to end, and the first whose DMG installs a fully notarized app.
Paper
Additions and removals now look like one diff. Removed lines gained the - marker their added counterparts always had, both markers sit in one gutter column, and both repeat down a line long enough to wrap. Removals are tinted as whole lines rather than glyph-by-glyph, so a wrapped removal reads as one block instead of striped bands — and a proposed line now wraps inside the text column instead of running off the right edge.
Suggested insertions no longer overlap the text below them. A proposed line long enough to wrap was reserved as a single line's worth of space, so the extra lines painted straight over the document. Both halves of a diff now occupy the room they actually take, and shrink again when a wider pane un-wraps them.
A cleared cache now says so. macOS may empty the cache a compiled PDF is written to; the record naming that file lives elsewhere and survives. The paper tab used to surface the result as pdf.js's transport text — Unexpected server response (404) while retrieving PDF "asset://…" — which reads like a broken app rather than a deleted file. It now says the cache was cleared, that your source is untouched, and to press Compile again. Which is all it ever needed.
A rebuilt PDF appears without switching tabs. Once the preview pane hit an error it stayed there, because the failure replaced the very thing that would have reported success. A new build now clears it.
Updates
Check for Updates works. v0.3.9 shipped the updater but its first real update failed to unpack: macOS tar had written AppleDouble ._ side-files into the archive, invisible to the tool that made it and fatal to the one that reads it. The archive is now built without them and verified by a different implementation than the one that wrote it.
Signing
The DMG now installs a stapled app. Every Volta DMG before this one carried a notarization ticket on the disk image but not on the app inside it, because the image was sealed around the app before the app was stapled. That left a DMG-installed copy needing to reach Apple on first launch. The app is now notarized and stapled before the image is built around it, and a new check opens the finished DMG and validates the app inside rather than inspecting the container.
Updating from 0.3.9 was never affected — that path always carried the ticket.
---
Upgrading: if you are on 0.3.9, Check for Updates in Settings. A DMG download is only needed for a fresh install.
iOS/TestFlight: deliberately skipped [HARRISON, 2026-08-14] — this release contains no mobile changes. mobile/pubspec.yaml carries 0.3.10+13, so the next mobile upload starts from a fresh, increasing build number.
Every Volta before this one told you the truth when you opened Settings → Software Updates: "Automatic updates aren't available on this build." It had nowhere to look for an update and no way to verify one if it found it. Getting a new version meant being handed a DMG.
From this release, Volta checks hub.verenalabs.com on launch and every six hours, and Check for Updates fetches, verifies, installs and relaunches.
What that means for you
This release is still a manual install — an updater only runs in a build that contains one, so v0.3.8 has no button to press. v0.3.9 is the last DMG you have to go and get. From here Volta offers you the next one.
An update is only installed if it is signed by Volta's key. A build accepts updates signed by the one key it was compiled against and refuses everything else, so a replaced download is inert rather than dangerous.
Also in this release
Settings → Software Updates said it kept Buzz up to date, and its manual-download link pointed at Buzz's releases — a different product, whose builds this app would refuse anyway. Both now point at Volta.
For the record
Updates are served as static files from hub.verenalabs.com/updates, next to the account portal. Not from a public GitHub repository: reading a private one would mean shipping a token inside the app, and anyone holding the app would hold the token.
The archive an update installs is built from the notarized and stapled app — not from the bundle the build produces earlier — and the release refuses to publish one that is not. An archive without that ticket produces an install that has to reach Apple before it will launch and fails closed when it cannot, which looks like the update having broken the app rather than like a packaging mistake.
The paper editor grows a modal keymap, a file tree that behaves like one, one image/PDF viewer instead of three — and the whole app starts remembering where you were.
Helix mode
The paper editor's keymap is now a choice of three: default, Vim, or Helix.
Helix is selection-first — you select, then act, and every motion is a selection — and it is native multi-cursor, which is the reason it fits here at all. The full space and g menus are implemented rather than a motions subset: pickers for files, buffers, symbols, changed files and diagnostics, a jumplist, g . to the last edit, g w jump labels over the visible lines, : command mode, and space ? — a command palette built from those same menus, so nothing is reachable only by a chord you have to remember.
Two of its parts are worth having whether or not you ever turn Helix on:
**g d means something in LaTeX.** On a \ref{} it goes to the \label{}; on a \cite{}, to the bibliography entry; space s lists the paper's sections and labels. That comes from an index over the paper's files rather than from a language server.
Compile errors are editor markers. Tectonic's log is parsed into file:line diagnostics, so a failed build underlines the line that failed instead of leaving you to read the log.
Bindings that have no referent in a paper editor say so once, plainly, rather than failing silently.
The paper tab, generally
Four complaints, all of them fixed together.
One viewer, not three
Figures, uploaded PDFs and the compiled build were three separate viewers. An uploaded PDF was handed to the webview's own reader, so the app shipped two unrelated PDF readers a screenshot could not tell apart.
They are one viewer now, and pinch-zoom does what pinch-zoom does everywhere else: it centres on the point between your fingers and leaves the content where you put it when the gesture ends. Scroll position is remembered per document — close a paper mid-page and it opens mid-page.
The file tree does a file tree's two jobs
Save to… on any file, figure or source, hands it to the ordinary macOS save dialog. And files drag between folders — including back out to the root, which is what the blank space below the rows is for.
Comments have somewhere to be
The margin beside the text now holds only live threads. Everything else — every resolved thread, every thread whose passage was deleted, and every thread in the files you do not have open — is in a Comments tab beside PDF and History: the whole paper's conversation in one list, filtered Open / Resolved / Detached, with Open-in-file, Reply and Resolve/Reopen on each.
The collapsed "resolved" shelf v0.3.7 introduced is gone with the drawer it sat in. It was better than a margin full of settled arguments, and worse than having somewhere to put them.
That work turned up a real bug it had been hiding: a comment on a sentence you typed in the same session never anchored. The card had nothing to sit beside, so it filed itself under "detached" and read as a design choice. Comments now anchor to what you just wrote.
It looks like the rest of the app
Three panes, three chrome bands, three different heights — one screen drawing three horizontal rules at three different places, which is what made this tab read as an IDE bolted into the app rather than part of it. One band now, at the height the Projects tab strip already uses.
Everything remembers where you were
Leaving a tab and coming back used to mean starting over: the Papers list, the channel root, the projects list.
Paper reopens on the paper, the file and the line you left.
A channel reopens on the thread you were reading.
Projects reopens on the project, and the part of it, you were in.
Each is remembered per community, so switching communities never resumes into something the new one has never heard of.
Security
Picks up webbrowser 1.2.4 for RUSTSEC-2026-0257.
Mobile
Skipped this release. Nothing in 0.3.8 changes the mobile app, so no TestFlight build was archived or uploaded. pubspec.yaml sits at 0.3.8+11, so whenever mobile does ship next it starts from a build number App Store Connect has not seen. Recorded explicitly rather than omitted — a release that says nothing about mobile is how the build number drifted to 0.0.0+1 for two releases running.
For contributors
The upstream watch is now enforced rather than remembered. UPSTREAM_WATCH.md asked for an entry whenever we changed block/buzz's own code; nothing made that happen, so an Upstream watch CI lane now asks every PR for either an entry or a Watch: trailer, and a backfill walked six sync eras to record the divergence already there — 23 entries to 71. No effect on the app; see AGENTS.md § Touching a file upstream owns.
Install
Download the DMG below, open it, drag Volta to Applications.
Updating still means downloading by hand. Volta cannot yet update itself; that is the next release.
Three changes to Paper, one of which fixes text loss.
Editing a paper together no longer deletes the other person's work
Two people editing one paper could destroy each other's writing. Not a merge conflict and not a warning — paragraphs silently disappearing, and the file getting shorter each time anyone saved.
The editor used to hand the whole file back on every change and work out what you had done by comparing it against the shared document. Alone that is correct: the only person who changed anything is you. With someone else in the file, the copy being compared is missing whatever they have just written — so their paragraph looks like text you deleted, and that deletion gets saved, signed with your name, as a real edit.
The editor now sends what you actually changed instead of the whole file. There is nothing left to guess at, so there is no way to guess wrong.
Two smaller repairs came with it: files written on Windows no longer get mangled when two people open them at once, and text containing mathematical symbols or emoji no longer breaks when the editor catches up with the document.
Resolved comments get out of the way
A resolved comment stayed in the margin forever, greyed out. Finish enough work and the margin fills with settled arguments — it got worse the more you got done.
Resolved threads now collapse into a "N resolved" shelf at the foot of the column. The count stays visible, reopening still works from inside, and nothing is deleted. Replying is only offered on threads that are still open, since a reply into a collapsed shelf is a reply nobody would ever see.
The comment margin gets out of the way properly
Comments live in a column beside the text, and that column held its width whether or not anything was in it — so a paper with one settled comment gave up the same strip of the editor as a paper mid-argument.
The column now collapses to a narrow rail, handing its width back so the text runs right up to the edge of the editor. The rail keeps the count, and the commented passages stay marked in the document itself, so nothing becomes hard to find. The choice is remembered, and it is yours alone — a co-author does not inherit it.
Suggestions survive accepting other suggestions
When an agent proposed several edits at once, accepting the first moved the text underneath all the rest. The later ones then pointed at the wrong place — sometimes refusing, sometimes offering to replace a passage nobody meant.
A suggestion now anchors to the document itself rather than to a character count, so accepting one leaves the others pointing exactly where they were written. Suggestions from the CLI and from the desktop anchor identically, and older suggestions made before this release keep working the way they always did.
buzz paper suggestions also reports where a passage is now rather than where it was when proposed, with an anchored field saying which you are looking at.
Mobile
iOS was skipped this release — the changes are desktop-only. pubspec.yaml carries 0.3.7+10; the next upload needs a build number above 10.
Install
Download the DMG below, open it, drag Volta to Applications.
Updating still means downloading by hand. Volta cannot yet update itself; that is the next release.
A hotfix. One user-visible change, plus a relay-side fix that is already live and needs no app update.
Compiling a paper with a figure now works
Any paper carrying a figure failed to compile, reporting
Could not fetch asset "figs/model_diagram.pdf": server returned 401 Unauthorized
Figures live on the relay's media store, whose reads require a signed credential. The compiler was fetching them without one, so every figure came back 401 and the compile refused before Tectonic ever ran. It now signs those fetches the same way the rest of the app signs media reads.
The error message itself was doing its job — it named the asset and the real reason rather than letting Tectonic report a confusing "missing graphics" later. What was missing was the credential.
Already fixed on the relay — no update needed for this one
Typing in a paper, and accepting an agent's suggested edits, could stall with saves timing out. Every event a client publishes was charged against a per-minute quota sized for chat messages (60/min), but a document editor emits collaboration traffic continuously — roughly 200 edit batches and 400 cursor updates a minute. About six seconds of typing exhausted a minute's budget, after which edits were dropped without an acknowledgement, so the app waited on saves that were never going to complete.
Collaboration traffic now has its own budget on the relay, separate from the chat quota. This shipped as a relay deployment and is live for every build, including v0.3.5 — it is listed here only so the change is recorded somewhere.
Mobile
iOS was deliberately skipped this release. The fix is desktop-only Tauri Rust, so an archive would have shipped an identical app under a new build number. mobile/pubspec.yaml carries 0.3.6+9; the next upload needs a build number above 9.
Not in this release
v0.3.6 is deliberately a hotfix: apart from the compile fix, its desktop binary is identical to v0.3.5. Archiving resolved paper comments, durable suggestion anchoring, and the update button are the next release.
Install
Download the DMG below, open it, drag Volta to Applications.
Updating still means downloading by hand — Volta cannot yet update itself. That is being built next.
Two upstream syncs in one release — desktop-v0.5.8 and desktop-v0.5.9 — plus the removal of the agent trading cards.
Agent trading cards are gone
The feature minted a collectible card PNG for an agent through an OpenAI Responses call and embedded an encrypted agent snapshot in the artwork. It came from upstream and is not part of Volta.
A locked card someone already holds still imports and unlocks — that is the snapshot system, not the card system. Only the ability to mint new ones is gone, along with the "Create card" action, the card gallery, and the OpenAI key plumbing they needed.
The ordinary agent card on the Agents page is untouched; it only shares the name.
Fixes you will notice
Adding an agent to a branch room works again. Mentioning an agent that is not yet in a branch room publishes a request to add it; a rule change from upstream had started refusing that for anyone who was not an owner or admin, which meant the mention silently dead-ended. Any project member can do it again, on desktop and on mobile.
Mobile no longer overwrites your desktop theme. Desktop and mobile share one theme record. Mobile could not read a record written by a desktop on the default Volta accent, ignored it, and then replaced it with its own — so a theme set on desktop would quietly disappear. Both clients now speak the same accent vocabulary.
Your accent stops drifting. A signed-out launch read the stored accent in one numbering and wrote it back in another, so the colour advanced by one position every cold start. Signed-out appearance now has its own storage slot.
Paper PDFs render again. A new content security policy from upstream did not know about the two mechanisms Paper uses to show a compiled PDF, so the panel would have failed at runtime.
Onboarding says Volta. Several first-run screens had picked up upstream's product name.
From upstream
The desktop quiesces its polling while hidden or unfocused, which should show up as lower idle CPU. Stale local caches are now swept on a timer and nine unbounded caches got limits. Search surfaces exact short profile names. Overlapping member mentions resolve correctly. Channel updates take a --visibility flag in the CLI. Plus the usual dependency and toolchain bumps.
Security
nostr and nostr-relay-pool in the desktop build were carrying live RUSTSEC advisories — that lockfile sits in its own workspace, which the dependency-policy check does not read. Both are bumped. The gap in the check itself is recorded as owed work.
Platforms
macOS (Apple silicon), signed and notarized. iOS ships to TestFlight as build 0.3.5+8, archived and uploaded by Harrison.
Under the hood
Both syncs are recorded in full, including everything declined and why:
A paper fix release. Two defects made agent collaboration on a paper quietly unreliable — one hid papers you had deleted, the other hid suggestions you were trying to accept — and both had been shipping since Paper landed.
Suggestions you could not accept or reject
An agent's suggestion would render its proposed text with nothing to click: the green + lines were there, the Accept and Reject controls were not. This was the common shape of an agent edit — propose a sentence, a citation, a paragraph — because it turned out two separate things had to go right for a suggestion to be settleable, and neither always did.
A suggestion that took nothing away produced no decoration at all, and the margin card is placed from a decoration's reported position. The added lines still drew, because insertions reach the editor by a different route entirely, which is exactly why the symptom looked like a rendering glitch rather than a missing control.
Separately, a suggestion was matched to its decoration by text offset, but the decoration covers a whole line while the anchor is wherever the proposer pointed. Those agree only when a suggestion happens to begin exactly at the start of a line, so anything anchored mid-line was dropped too.
Both are fixed, and every pending suggestion is now anchored — including ones whose anchor no longer lands on any text, which previously stranded them with no way to resolve them from any client or CLI. The one case still not anchorable is a suggestion pending against a file emptied of all its text; that is recorded rather than papered over.
Accepting one suggestion no longer breaks the rest of the batch
An agent proposes several suggestions at once, all worked out against the document as it stood at that moment. A suggestion records positions — "replace characters 14130 through 17820" — so accepting any one of them moved the text under all the others, and the rest could no longer be accepted at all. On a real paper, one accept grew the file by 5012 characters and stranded the three suggestions after it; their passages were still there, word for word, five thousand characters further down.
The tell was that rejecting always worked and accepting didn't — rejecting applies no text, so it never checks a position.
A suggestion now looks for where its text actually went instead of giving up. If that text appears exactly once, it applies there. If it appears more than once, it still declines and says so, because guessing which one was meant could rewrite a passage nobody proposed changing.
If you are used to working around this by accepting from the bottom of the document upwards, you no longer need to.
An accept that was refused now says why
Accepting a suggestion could report "Could not record that decision" and leave the edit unapplied, with no indication of what went wrong or what to do.
The refusal was correct. A suggestion records the offsets it was proposed against and the exact text it anchored to; when that passage has since moved, applying it by those offsets would rewrite something the proposer never saw, so it declines. What was wrong is that the reason — already written, and naming the remedy — was replaced by a generic line. You now get it verbatim: "This suggestion's anchored text has changed since it was proposed. Reject it and re-propose against the current text."
This matters more because of the anchoring fix above, not less: that fix makes drifted suggestions visible again, and drifted suggestions are exactly the ones this refusal fires on.
Papers you deleted came back
Deleting a paper removed its room but left its identity events on the relay, and the papers list builds a card from those alone — so a deleted paper kept its card indefinitely, with no room behind it and no files in it.
The client was meant to notice by checking the deletion log, but that check could not be made reliable: it searches only the most recent deletions of every kind, and ordinary message deletions push a paper deletion out of range within days. One affected community had 886 deletion events, 863 of them ordinary message deletes.
The relay now retires a paper's identity events when the paper is deleted, so the answer comes from the relay instead of being re-derived by each client. That closes the same hole in the agent tooling, where buzz paper list had no deletion check at all and could resurrect a deleted paper by writing to it.
A migration retires deletions already on record. Papers whose owner is an agent are deliberately left alone — re-issuing the deletion from any client clears those.
This half requires the relay to be updated; it does not ship inside the desktop app.
Also
Project-room constraint now survives schema generation, with a lint to keep it that way, so CI and migrated databases enforce the same rule.
Paper end-to-end specs get a real project to attach to, and two specs catch up with product rulings that had already landed.
Concurrent CI toolchain installs stop corrupting each other.
Two unmaintained transitive dependencies acknowledged in the advisory allowlist (smallstr via the paper CRDT, nostr-relay-pool dev-only).
Platforms
macOS (Apple silicon). iOS/TestFlight was deliberately skipped for this release — nothing here touches the mobile app. The mobile manifest is at 0.3.4+7; that build number is unused and remains available for the next upload.
Two changes to the paper editor, both about seeing what you are looking at.
A suggestion now reads as a diff
An agent's proposed edit used to open as a card laid over the passage it was about — covering the very text you were being asked to judge. And what it showed was not a diff: the whole anchored passage struck through, the whole replacement printed beneath it, with nothing compared. A one-word change inside a paragraph appeared as the paragraph deleted and the paragraph added again, and finding the actual change was left to you.
Now:
The card moved to the margin, beside comments, carrying the proposer's case and the Accept / Decline controls and nothing else.
The change itself is a unified diff in the document. Removed lines stay real lines — numbered and syntax-highlighted as always — tinted with a - in the gutter. Added lines appear directly beneath them with a +, in the editor's own font.
Lines that do not change are left alone, which is the whole reason a diff is readable. A one-word edit marks one line.
Suggestion and comment cards share a single stack, so one can no longer land on top of the other when they are anchored near the same passage.
Figures pinch to zoom
An image opened from the file tree can be pinched to zoom and dragged to pan. A figure still opens exactly as before at 1× — zoom scales the fitted size rather than replacing it — and panning drives the pane's own scrolling, so the scrollbars keep telling the truth.
---
Verification
Verified by hand against a real paper before release: suggestions on main.tex, and figures in an image tab.
just ci green. 4723 desktop tests, including 8 new ones for the diff itself and one for the case that motivated it — a middle line changing while its neighbours stay unmarked.
The shipped Volta.app was checked for its agent surface and for this release's own code, rather than assumed from a successful build.
Windows and Linux are untested. Repository CI cannot acquire GitHub-hosted runners, so those jobs have not run — on this release or on any release before it. Tracked as PLAN.md § 12.1.
CI was not green for this release, and has not been green on main for some time. Released on local evidence because CI could not offer a better answer. Also § 12.1.
No iOS/TestFlight build. No mobile changes in this release. mobile/pubspec.yaml carries the candidate's build bump but nothing was archived or uploaded.
"Check for Updates" still does not work. Automatic updates are not wired up in any build to date, so this release must be installed by hand like every one before it. Tracked as PLAN.md § 12.
PDF viewers are unchanged. Only image tabs gained pinch-zoom and pan; PDF tabs still use the system viewer, and the compiled-PDF sidebar keeps its existing pinch. The three are not yet one system.
Note on versioning
There is no v0.3.2. This release follows v0.3.1 directly.
A patch release about one thing: an agent in a project room can now see the project it is in. Three separate-looking bugs turned out to share a shape — the relay knew something and never said it on the channel the listener was actually using.
An agent no longer guesses which repository it is in
Asked "what repo is this?", an agent in a project room could only infer. The channel API returned an id, a name, a description and a timestamp — so the answer came from matching channel names against branch names. It got the repo right and the branch wrong, editing an old layout on a branch that mapped to no channel at all.
The relay had published the answer the whole time. A project room's metadata carries its repository, branch, project anchor, and whether the room is archived; the CLI kept four fields and dropped the rest. channels list, get and search now share one projection that keeps them.
**Archived rooms are hidden from channels list by default** (--include-archived to opt back in). A branch room is archived the moment its branch is deleted on the forge, so listing one beside live channels read as "this branch still exists" — which is how a deleted branch stayed on an agent's map of a repository long after it was gone.
**worktree_for_branch accepts the owner/repo a project room publishes.** It previously knew only owner--repo and the bare repository name, so the canonical form matched nothing at any casing and an agent had to guess a directory name.
A linked worktree beside its checkout is no longer an ambiguity. Two directories sharing a git common directory are one repository, and the primary checkout is the answer.
The agent base prompt now states it plainly: read the room's binding rather than inferring it, never assume a checkout is on the right branch, don't edit a project's default-branch room, and expect to share a working tree with a human.
A new agent is no longer deaf to a project's branch rooms
Adding an agent to a project told it about the project's anchor room and nothing else, because a branch room's membership is derived — there is no membership row to fire a notification from. The desktop was unaffected (it re-reads channel discovery), but an agent harness reads that once at startup and afterwards learns of new rooms only from membership notifications. The symptom was a newly created agent seeing nothing in a project's branch rooms until Volta was quit and reopened, at which point all of them appeared at once.
Adding a member, removing one, and creating a branch room now notify across the whole project. Removal mattered most: eviction already acted on the whole project, so an agent was being cut off from rooms it was never told it had lost.
The relay owns its own identity
Channel metadata is addressed by its signer, so when a relay changes keys its old announcements are not replaced — a second set appears beside them and both stay live. A relay now adopts what a previous identity announced when it starts: re-announce under the current key, then retire the old records, in that order so a client listing mid-swap never loses the channel. An announcement whose channel no longer exists is retired rather than left advertising something that isn't there.
The development keypair — whose private half is published in the source — now refuses to start against a database holding another identity's announcements, rather than re-signing every channel with a key anyone can sign for.
Relay-key rotation is now an operation the relay completes by itself.
Paper editor
The editor scrolls under the wheel.
Lines are numbered.
The PDF panel pinches to zoom.
---
Verification
The relay changes were deployed to production before this release and the identity repair ran itself there: nine channels re-announced under the current key, one stale announcement retired for a channel that no longer exists.
Local gate green (just ci), 819 Postgres-backed relay tests, and each new test confirmed to fail without its fix.
The shipped Volta.app was checked for its agent surface and for this release's own changes, rather than assumed from a successful build.
Windows and Linux are untested. Repository CI cannot acquire GitHub-hosted runners, so those jobs have not run — on this release or on v0.3.0. Tracked as PLAN.md § 12.1.
CI was not green for this release, and has not been green on main for some time. It was merged and released on local evidence because CI could not offer a better answer. Also § 12.1.
The smoke test was performed on a pre-release local build of the same code, not on this signed DMG.
No iOS/TestFlight build. Deliberately skipped with Harrison's explicit permission — there are no mobile changes in this release. mobile/pubspec.yaml carries 0.3.1+5 from the candidate bump but nothing was archived or uploaded.
"Check for Updates" still does not work. Automatic updates are not wired up in any build to date, so this release must be installed by hand like every one before it. That is the whole of PLAN.md § 12, scheduled for 0.3.2 — and 0.3.2 will be the first release capable of updating anything, whichever release introduces it.
The Paper release, plus the first upstream sync since 0.2.0.
Paper
A paper is a collaborative LaTeX document that lives in its project's room — not a file on anyone's disk, and not a git repo.
Write together. A collaborator's edits and cursor arrive live, the header shows who else has the paper open, and figures preview inline.
A real file tree. Add files, upload figures, drop in a .zip to import an existing paper. Text files and binary assets are handled differently and deliberately: text becomes editable history, figures go to media storage.
Compile to PDF with a bundled Tectonic — no LaTeX install. View it inline with zoom, or open it externally.
History and Restore. Every edit is an event, so the document's history is the log. Restore a file to an earlier state from the History tab.
Comments and suggestions. Leave a margin comment on a passage, or propose a find/replace edit that a named human accepts or rejects.
Vim mode in the editor, and Paper has its own settings tab.
Agents can work on papers
buzz paper gives an agent the surface it needs, registered identically as CLI subcommands and MCP tools so both harnesses see the same thing:
list / show / files / read — find a paper and read it.
checkout — materialise the whole paper locally (text replayed from history, figures downloaded). A snapshot, not a live mount.
upload — add a NEW file, e.g. a generated figure into figs/.
suggest / comment — propose a change to existing text, or annotate it.
An agent suggests; a named human accepts. There is no direct-edit path for an agent, by design — authorship of the words stays with the author. Uploads are the exception, because a new file touches nobody's words.
Upstream sync — Buzz 0.5.3 → 0.5.5
38 fixes and 26 features from block/buzz, including:
Buzz Term — a real terminal in the channel header (⌘J).
Agent trading cards — mintable card PNGs from an agent's profile, with an optional NIP-44 lock.
Kubernetes backend — run an agent in a cluster instead of on this machine.
Entity links — repo, PR and issue links render as preview cards.
Encrypted key backup in onboarding, and a redesigned Huddle experience.
Reconnect gaps that previously needed ⌘R now heal themselves.
Upstream's multi-repo NIP-MP project model (kind 30621) was deliberately not adopted: in Volta a project is its repository, and PRs and issues come from GitHub or GitLab rather than the relay.
Projects
Projects and Paper graduated out of Experiments — both are on by default.
Who may add a project to a community is now a community setting the relay enforces, rather than a client-side convention.
Connecting a project is one action, and disconnecting one actually disconnects: the webhook is retired and its branch rooms are archived.
Fixes worth naming
Every previous DMG shipped stale agent binaries. The release lane bundled whatever sat in the sidecar directory rather than building it, and signing refreshed the timestamps so nothing looked wrong — agents were running a CLI from before buzz paper existed. The lane now builds them, and verify-bundle.sh runs the shipped binaries and asks what they can do.
buzz repos list lists repositories you are part of, not just ones you announced.
buzz upload accepts PDFs, and strips image metadata itself instead of refusing a figure any plotting library produces.
An agent with no relay profile no longer shows as a raw pubkey to everyone.
A project member can add a bot to a branch room again.
On a hosted relay, the workspace icon stays admin/owner-only even when a community has no steward row.
A relay restart no longer strands a session behind the reconnect card.
Two features and a new face. Volta can now run work on machines that are not your laptop, and a branch on GitHub becomes a place to talk about that branch.
Remote compute
Point Volta at a machine over SSH and hand work to it.
Compute targets are configured in Settings and resolved through your own ~/.ssh/config, so an alias that already works in a terminal works here. Volta probes a host before trusting it and tells you what it found.
Agents can see what a cluster offers — partitions, limits, what is idle — and generate an sbatch script rather than being told the syntax.
Jobs detach. Start one, close the laptop; the record is waiting when you come back.
File staging preserves structure, so a job that expects a directory tree gets one, into a scratch root rather than scattered across $HOME.
Every finished job leaves a signed record in the room it belongs to (kind 39200), so "what ran, where, and what came back" is answerable later by someone who was not there.
**volta-mcp** exposes Volta's tools to Claude Code without duplicating primitives it already has.
Branch as room
Push a branch, get a room for it. Delete the branch, the room goes read-only and keeps its history.
Connecting a repository registers its webhook for you, sets the three settings people got wrong by hand, and mints rooms for the branches that already exist — rather than looking connected and doing nothing until someone pushes.
Branch rooms group under their repository in the sidebar. The group is derived from what the repository has, so it is not something to organise, rename or lose.
A project has one member list. Adding someone anywhere in a project adds them everywhere, and the control says so and confirms before it fires. There is no per-branch access control, because anyone who can clone has every branch's bytes after one command.
Members can be managed from the project page, not only from the room that happens to be the default branch.
Open in editor from a branch room: Volta keeps a git worktree per branch, so switching rooms does not disturb what you have checked out.
Projects collapse under one parent — all of them at once, or each on its own. Right-click a project (long-press on mobile) to choose which branches you see: a repository with two thousand branches must not destroy a sidebar. That choice follows you between devices, and a project showing a subset says so rather than quietly omitting rows.
The Volta face
The Verena stack replaces the Buzz bee throughout — app icon, menu bar glyph, and the thinking animation, which now resolves a ring into the stack instead of looping three marks. Mobile gets the new icon too.
Fixes worth naming
A repository rename used to kill its webhook silently, forever. Hooks are now pinned to the forge's immutable id.
A connection that refused every delivery looked identical to one nobody had pushed to. Projects now say which.
Deleting a project made its name permanently unusable — every attempt to recreate it reported success and stayed invisible. A NIP-09 deletion is now scoped the way the spec says, matching what the relay always did.
The project page's branch list is maintained by the relay, so it stops disagreeing with the sidebar about what branches exist.
Branches that exist only in your clone, or only in a closed pull request, no longer masquerade as branches on the forge.
The mobile app could lose its connection without noticing. On iOS a websocket goes half-open routinely — backgrounding, a wifi/cell handoff, a NAT timeout — and the app went on reporting itself connected while messages silently stopped arriving. Force-quitting was the only recovery. It now pings, tears the socket down when no pong comes back, and reconnects and replays.
Security
nostr 0.44.7 clears six advisories: credentials in debug output, unauthenticated wallet event parsers, and resource exhaustion in the NIP-44 v2, NIP-04, NIP-98 and NIP-50 paths.
Mobile
The iOS build ships with this release rather than trailing it.
Branch rooms group by project, with the same Projects parent and the same branch picker as the desktop — structure the phone never had.
Notification groundwork, not notifications. Permission, an APNs device token, and a settings row that names what is missing. Wakes still do not arrive: that needs a push gateway deployed with an Apple key, which is not part of this release. The row says so plainly, rather than looking healthy and delivering nothing.
Known open
The relay maintains repo state incrementally; a reconnect restates the whole set. Two pushes to different branches at the same instant can drop one ref until the next push to it.
A forge branch read that fails is currently indistinguishable from a repository with no branches.
Two repositories with the same name under different owners produce two identically named sidebar groups.
Upstream
Three bugs found in block/buzz code and fixed downstream, each recorded in UPSTREAM_WATCH.md with a check to run on the next sync: a sidebar section title 2rem off-axis, the NIP-09 coordinate match, and a closed pull request's deleted branch lingering in the branch picker.
A bug-fix release. The headline is that agents you share with other people can finally be talked to by them.
Agents you share are now mentionable by other people
If you opened an agent up in Advanced Options — "anyone", or an allowlist of specific people — and added it to a channel, nobody but you could actually use it. The agent never appeared in anyone else's @ menu, and if they typed its name anyway, nothing happened. No error, no reply, no sign anything had gone wrong. The agent could read the whole conversation; it just was never woken.
Two things were wrong, and neither was the sharing setting itself:
The mention picker only ever offered agents your own machine runs, a check no one else's computer can pass. So a shared agent was filtered out before the sharing setting was even consulted.
Waking an agent requires the message to carry a hidden reference to it, and that reference is only attached when you pick the agent from the menu. No menu entry meant no reference, which meant the message never reached the agent at all — which is exactly why it failed silently.
Now an agent that has been added to a channel is offered to the people its sharing setting allows: anyone means any member of that channel, an allowlist means only the people on it, and owner-only stays yours alone.
Nothing about your privacy settings changed — an agent you have not shared is still invisible to everyone else.
Paper and Evolve tabs (preview, off by default)
Two new sidebar entries appear as placeholders for work that is coming. They do nothing yet and are hidden unless you turn them on in Settings → Experiments.
Also in this release
iOS: the app builds and installs as Volta, not Buzz — launch screen, product name, and the permission prompts you see on first run.
iOS: pods pinned to the app's deployment target, and the signing team and pod lock committed, so archives are reproducible.
Release tooling: screenshot posting and publish scripts now target this repository instead of upstream.
iOS
Shipped to TestFlight internal as 0.1.1 (2) — the first Volta mobile build with a real version and build number. Earlier archives were all 0.0.0 (1), which App Store Connect would have rejected as a duplicate on the next upload.
Known gap: sharing with specific people
The anyone and owner-only sharing modes work — "anyone" is verified with a second person on a second machine.
The allowlist mode ("specific people") is effectively unusable, because the user search inside its picker does not return anyone, so there is no way to add a person to the list. The mode is implemented and enforced correctly underneath; it is the people-picker's search that is broken. Use anyone for a shared agent, or leave it owner-only.
This is tracked as a watch item rather than a fix — see [UPSTREAM_WATCH.md](../UPSTREAM_WATCH.md).
The first Volta release — the Buzz-based desktop app, rebranded and wired into Verena's own hosted infrastructure.
Highlights
Verena-hosted communities. "Create a community" signs you in with a Verena account (in your browser) and provisions <name>.communities.verenalabs.com on Verena's production relay — no self-hosting or dev setup required. Your device's keys own the community; sessions survive restarts. Manage everything (create, archive, unarchive) from onboarding, the sidebar's add-community dialog, or Settings → Hosted communities.
Web account portal. hub.verenalabs.com — see your account, plan, and communities from any browser.
Volta brand throughout. The Volta wash and wordmark across onboarding, the app, and the installer; the mono V mark everywhere.
Projects work with GitHub and GitLab. Repos, pull requests, issues, reviews, and merges against real forges with OAuth sign-in; git-derived views (files, commits, contributors, diffs, terminal) work against any remote.
Under the hood
Signed and notarized macOS build (Developer ID: Verena Labs LLC).
Community provisioning and forge actions taken through Volta are recorded in the relay's tamper-evident audit chain, attributed to the acting agent or human.
The Builderlab (Block-hosted) integration is fully removed; its IPC surface is closed.
Known limitations
macOS (Apple silicon) only; iOS arrives via TestFlight separately.
No auto-update yet — new versions are installed manually.