> For the complete documentation index, see [llms.txt](https://docs.maiagent.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.maiagent.ai/release-note/untitled/readme.md).

# Changelog

## v2026.08.21 <a href="#v2026-08-21" id="v2026-08-21"></a>

***

### ✨ New Features

* **Fixed abnormal MCP interactive app card height after exiting fullscreen**: After an MCP interactive app card returned from fullscreen to the conversation, the card height was compressed and the content became hard to read. After the fix, the height reported by the application is preserved, and you can continue working right after returning to the conversation.
* **Web Chat waiting screen brand customization**: The Web Chat AI reply waiting screen can now be customized to your brand: administrators can choose between narrative copy and brand animation modes, configure multilingual copy for each stage plus a long-wait message, and set tool card icons and tool category display text (with one-click AI translation), all with a live preview on the settings page that matches the actual result. A "show copy during typing stage" toggle is also available for a clean animation-only style; the earlier issue where tool card status icons could not be saved has been fixed as well.
* **MaiGPT quick entry and meeting records integration**: The MaiGPT entry page now officially offers quick entries: meeting records, presentations, documents, and spreadsheets are all one click away. The meeting records panel lets you start real-time transcription recording with one click (including a timer and live transcript) and view your three most recent meeting records directly. The workflow has also been streamlined: clicking a record now previews the summary in place, you can return to the entry page with one click to start the next meeting, and the summary view's title bar has been simplified to keep only the back button, giving the content more display space.

  <figure><img src="/files/pZDc6eKRGa08SHNZKTWO" alt="MaiGPT quick entry and meeting records panel"><figcaption><p>MaiGPT quick entry and meeting records panel</p></figcaption></figure>
* **Web Chat login-free identity integration**: Web Chat adds "login-free conversations via Source ID": enterprises can use signature verification to bring member identities already signed in to their own systems directly into Web Chat conversations, so end users no longer need to log in again. The admin settings offer both signature-verified and non-verified modes, platform secret generation and reset, and signature validity period configuration, along with PHP, Node, and Python integration examples and a verification-failure diagnostic checklist. Also fixed an issue where the same user was created as multiple duplicate contacts; voice assistant calls and first-time Web Chat connections now map correctly to the same contact.
* **Official Agent Marketplace revamp**: The official Agent Marketplace has been fully revamped: it adds three-level filtering with category tabs, dimension switching, and multi-select labels, cards get a new design with 14 category theme colors, and a "Recently Used" section and seat summary let you return to your frequently used official AI agents with one click. Category names have also been adjusted to more intuitive ones such as "Job Function", "HR", and "Project Manager". The marketplace now clearly distinguishes "not enabled for the organization" from "you don't have usage permission": members outside the access scope see a "No usage permission" label with the start-conversation button disabled, and clicking it prompts them to contact their organization administrator.
* **Connector management and activation request revamp**: "Manage My Connectors" has been fully revamped into a master-detail window that clearly presents the four states of organization enablement and personal authorization. Members can view authorization scopes and authorized accounts, complete authorization themselves, or request activation of connectors not yet enabled, with a confirmation step added to disconnection to prevent accidental clicks; administrators can see members' pending requests on the same screen and go straight to activation. The "Connectors" tab in AI agent settings no longer requires individual enablement — agent-mode AI agents in all organizations can use connector bindings directly.
* **Connector custom data injection**: Embedded Web Chat adds custom data injection: integrators can pass user identity or context information (such as a patient ID) when opening the chat, and the AI agent can reference this data in every conversation turn to provide personalized replies. Connectors also support an embedded-data allowlist: administrators can configure in the admin panel which embedded data can be safely carried into a connector's outbound authentication headers (for example, writing patient identification back to a hospital system). Adding new data items only requires admin configuration, with no code changes, and organizations that don't configure this are completely unaffected.
* **Embedding domain allowlist management**: Web Chat adds an embedding domain allowlist: administrators can specify which website domains are allowed to embed on the conversation platform settings page (with subdomain wildcard support). At embed time, the embedding site's real domain is reported for comparison, so sites not on the list cannot hijack the embed. Allowlist changes apply to all nodes in real time — after tightening, removed domains can no longer embed within about a minute; customers who haven't configured a list see no change in behavior.
* **Automatic cross-backend model failover**: Added automatic same-model cross-backend failover: when a model provider is congested or fails (such as rate limits or timeouts), the system automatically switches to the same model on another backend to complete the reply, with a seamless switch for users and no change in answer quality or behavior. Failover takes effect fully automatically with no per-item configuration — as long as a capability-equivalent same-model failover backend exists, AI agents across the platform keep replying without interruption during provider outages.
* **Custom logout redirect URL**: Added a configurable logout redirect URL: users in on-premises and SSO environments can be sent directly to an enterprise-designated page (such as the corporate portal) after logging out, instead of being left on a meaningless admin login page. Behavior is unchanged when not configured, and dangerous URL formats are blocked. All unauthenticated visits (back button, refresh, opening a protected link directly, timeout) consistently redirect to the designated page instead of being sent back to the admin login page.
* **Data collection forms linked to logged-in identity**: Web Chat's pre-chat data collection now officially supports logged-in users: when both "login settings" and "data collection" are enabled, logged-in users also fill out the form as configured, and the submitted data is correctly associated with their own account — no more orphaned anonymous contacts, and the logged-in identity is no longer overwritten by leftover data from a previous anonymous visitor. Users who have filled out the form before can choose to keep their previous identity or fill it out again; the anonymous visitor flow is completely unchanged.
* **Agent Teams feature status disclosure**: Organization detail information adds the availability status of the "Teams (Agent Teams)" feature, so the organization overview page can correctly display this advanced feature tag. The overview's advanced feature tags have also been fully aligned with the product spec: feature names corrected, disabled features labeled with their plan and how to enable them, and Beta features clearly marked — making plan differences easy to explain to customers at a glance.
* **Viber messaging platform integration**: Added Viber messaging platform integration: administrators can create a Viber conversation platform in the admin panel — just enter a token to let AI agents serve customers on Viber, with support for a Viber-specific welcome message.
* **File library management interface**: Added a file library feature: it provides two spaces, "My Files" and "Organization Shared Files", with folder browsing, multi-file import, renaming, batch moving and deletion, and one-click restore of mistaken operations via version history — file management finally has a unified entry point.
* **Knowledge base cross-base file moving**: Added cross-base file moving for knowledge bases: move files between knowledge bases with the same embedding model via a transfer box, with no re-parsing or re-vectorization needed. Moves run in the background and continue even if the window is closed; on completion, a success/skipped/failed result list is provided with one-click retry.
* **MS365 OneDrive file authorization**: Microsoft 365 member authorization adds a OneDrive files option: once checked, AI agents can upload and read OneDrive files on the member's behalf; existing authorized connections need to re-authorize once to use the file features.
* **AI Gateway traffic fee display**: Traffic-fee pricing for AI Gateway self-hosted models is now fully displayed: the billing method page clearly presents the "total tokens × rate" calculation and the organization's actual rate, and consumption records and usage statistics can show the platform fee category.
* **MaiGPT cross-conversation history retrieval**: MaiGPT adds a cross-conversation retrieval setting: when enabled, the AI can still search and reference the user's own previous conversations when they start a new one (with a configurable lookback window, 90 days by default), so there's no need to re-explain background; the scope is strictly limited to the user's own conversations.
* **Answer images aligned to operation steps**: Answer image attachment adds an "align to operation steps" setting: in multi-step how-to answers, each step only gets the screenshots belonging to that step's heading, ending mismatched images; off by default, and must be enabled together with the existing cited-page image restriction.
* **MaiGPT multi-format file preview**: MaiGPT output files and knowledge base upload previews add DOCX, SVG, XLSX, and PPTX support; document layouts, spreadsheet styles, and merged cells can be viewed directly, and presentations can generate previews on demand — no more downloading first and opening another application.
* **Knowledge base EPUB e-book support**: Knowledge bases add EPUB e-book format support — upload directly and build searchable content without first converting manually to PDF or plain text.
* **Dedicated loading screen logo**: Brand customization settings add a dedicated loading screen logo that can be configured separately from the login page logo, keeping brand presentation consistent and appropriate during loading.

### 🚀 Core Performance Optimization

* **Faster conversation record rating filters**: Fixed query timeouts when filtering conversation records by dislikes or ratings over 30/90-day ranges; queries now work correctly and the time-range condition takes proper effect. Also fixed Excel export ignoring like/dislike and other filter conditions — export results now exactly match what the list view shows.
* **Faster conversation platform tab counts**: Greatly accelerated loading of conversation counts on conversation platform tabs: for regular members, count query time dropped from up to 3.3 seconds to 5–120 milliseconds, while significantly reducing overall database load.

### 😊 User Experience & Interface Optimization

* **MaiGPT presentation preview panel improvements**: MaiGPT's AI presentation preview panel adds a close button and remembers the user's open/closed preference; once closed, it no longer pops back open during subsequent operations.
* **Better guidance for oversized attachments**: Previously, conversation attachments over the size limit only produced a single "file size exceeds the maximum limit" message, files far over the limit got no response at all, and large files could be only partially processed, yielding incomplete answers → the conversation attachment limit is now explicitly set at 10 MB and enforced immediately at upload, and both Web Chat and admin conversations now show a guidance dialog explaining the limit and offering actionable next steps (upload to a knowledge base instead, paste the passage, or split into smaller files). Other upload channels such as knowledge bases keep their 100 MB limit unaffected.
* **Friendly tool name display**: Previously, when the AI executed tools, Web Chat cards often showed raw English technical names, leaving users unsure what the AI was doing → tool execution cards now prefer easy-to-understand localized descriptions, with card titles and per-step labels all shown as friendly copy, falling back to name inference only when no copy is available.

### 🔐 Security & Governance Enhancements

* **Secure assistant cleanup on logout**: Comprehensively strengthened AI assistant security on logout: the assistant window closes automatically at logout, fully clearing connections, conversations, and identity credentials, while the backend revokes credentials in sync and re-verifies login state before every operation. On shared computers, the previous user's conversations and identity no longer linger, public Web Chat also clears leftover login identities that shouldn't exist, and features recover automatically after logging back in (including the on-premises 2026.Q2 release line).

### 🛠️ Bug Fixes

* **Fixed repeated questions in step-by-step agent questioning flows**: In step-by-step questioning agent flows (such as form-style data collection), the AI would forget questions it had already asked, ask them again repeatedly, and even get stuck in loops. After the fix, all of the AI's questioning turns (including pure questions, client-side tools, quick-reply menus, and explanatory text combined with question forms) are fully preserved in conversation memory, so multi-turn data collection flows complete smoothly without repeated questions.
* **Fixed layout and interaction issues on the AI agent monitoring pages**: When viewing monitoring record details, the statistics section lacked card borders, timeline ticks were misaligned, rows with zero character counts disappeared entirely, and returning to the list lost filter conditions and page numbers. After the fix, the detail page layout is tidy again, zero values display truthfully, entire list rows are clickable to open details, and returning preserves filters, page number, and page size — no more re-configuring while auditing records page by page.
* **Fixed multiple stability issues in meeting and audio transcription flows**: Offline audio transcription previously got stuck after system interruptions, couldn't handle some formats, and billed imprecisely, and the Taiwan AI RAP transcription language menu was once unselectable, blocking audio uploads. After the fix, transcription tasks resume automatically after interruptions, more audio formats are supported, billing is attributed correctly, and language selection (including Taiwanese) truly takes effect; meeting recording connection drops now trigger immediate warnings, transcript loading failures show a clear message with a retry button, and the issues blocking access to real-time transcription and meeting record detail pages have also been fixed.
* **Fixed knowledge base Markdown images not displaying after chunking**: When knowledge bases processed Markdown documents containing images, the image syntax could be split across chunks, producing broken images in cited content. After the fix, image markup stays intact within a single chunk, and images display normally after re-parsing.
* **Fixed blank canvas charts and shared canvases failing to render**: Charts in the canvas often showed up blank, disappeared after switching between source and preview, flowchart generation could show a syntax-error screen during streaming and get permanently stuck, and shared conversation canvases displayed as a pile of source code. After the fix, every render uses a clean environment so charts display reliably, flowcharts render only after content is complete with a progress hint during generation, and the share view page (including existing old share links) correctly renders AI-generated web pages and charts.
* **Fixed built-in Agents unusable by regular members and wrong model bindings**: After enabling an official built-in Agent from the Agent Marketplace, previously only the owner could start conversations — other authorized members couldn't use it — and rented Agents actually used the platform default model instead of the model specified in their design. After the fix, setting the access scope also grants members conversation entry permission (existing rentals are backfilled once), all 98 official built-in Agents are correctly bound to their designated models, and the AI agent list no longer mixes built-in Agents into the "organization-built" category.
* **Fixed unclear PDF translation failure messages and download timeouts**: When uploading PDFs the system cannot translate, such as scanned files, users previously waited through about 7 minutes of retries only to get a cryptic English error; downloading translation results also frequently timed out. After the fix, untranslatable files immediately report a clear reason with actionable advice (such as "please upload a text-based digital PDF instead"), and downloads now connect directly to the file storage service, so bilingual, translated, and original PDFs all download reliably and quickly.
* **Fixed wrong citation page numbers and broken citation images**: Citation sources in AI answers previously always showed page 1, making it impossible to verify sources in the original document by page number, and citation images from PowerPoint presentations were broken. After the fix, documents such as PDFs and presentations show real page numbers (including cross-page ranges), while sources without pagination (such as web pages and plain text) are honestly labeled "source not paginated"; citation images for newly uploaded or re-parsed presentations display normally with filtering rules fully in effect.
* **Fixed member pickers not finding all members in large organizations**: In organizations with more than 100 members (16 in production, the largest over twenty thousand), member pickers — meeting participants, conversation labels, customer-service CC lists, MaiGPT sharing, and every other member-selection menu — previously couldn't find members beyond the 100th. After the fix, all member pickers search the entire organization server-side and load in batches while scrolling, so organizations of any size can find every member, failed loads can be retried in place, and deactivated members are clearly labeled; organizations under 100 members see no change in workflow or speed.
* **Fixed the code interpreter image preview sidebar failing to open**: After clicking a code-interpreter-generated image in a conversation to open the preview, repeatedly opening/closing it or switching conversations could easily leave the sidebar permanently unopenable, with clicks doing nothing (on mobile, closing it once could make it impossible to ever reopen). After the fix, every image click reliably opens the preview, and the preview state resets correctly when switching conversation platforms or leaving the page, fixed on both mobile and desktop.
* **Fixed wrong source types in usage statistics**: The type column in "Usage Statistics → Conversation Platforms" previously showed mostly "-" or blank, and exported Excel always showed "web", making channel sources indistinguishable. After the fix, both the list and Excel export correctly break down internal, API, web, Desktop, and other source types, with labels shown in the exporter's language, helping administrators track actual usage per channel.
* **Fixed tables in AI replies failing to display**: When receiving AI replies in table form, tables were previously downgraded to plain text by a security mechanism, squashing the whole table into an unreadable blob. After the fix, model-emitted tables render normally as tables again, with the original security protection standards unchanged.
* **Fixed the previous conversation platform's name flashing when entering a new conversation**: When switching conversation platforms or clicking "Start conversation" in the official marketplace to enter a new conversation, the header previously flashed the previous platform's name briefly before showing the correct one after loading. After the fix, no name is shown while loading and the correct new name appears directly when loading completes — no more flashing the old name.
* **Fixed code interpreter output files disappearing without reason**: When the code interpreter produced files, if the execution environment ended early, the system still assumed it was running and kept querying and failing, and in some cases the file list and contents came back empty. After the fix, when the system detects the execution environment has ended, it immediately updates the status and reads the last saved file backup instead, so file results no longer vanish.
* **Fixed qwen3.6-series pricing unit misplacement causing severe undercharging**: The pricing units for the qwen3.6-max-preview and qwen3.6-plus models were misconfigured, so actual charges were only about one-thousandth of the correct price, leaving billing severely out of line with actual costs. The pricing rules have been corrected to the official list prices; subsequent usage is billed correctly, and past differences will not be retroactively collected.
* **Fixed conversation memory quotas being wrongly compressed for some models**: Some models' available context was previously derived from a hardcoded legacy lookup table, so new or aliased models not in the table had their conversation memory silently squeezed to a tiny size — or every reply simply failed. After the fix, a model's available context is based on the platform-managed model configuration, large-window models get their full conversation memory quota, and newly onboarded models no longer risk being missed.
* **Fixed misleading provider and model on aggregated transaction rows**: When viewing usage transaction details in the admin panel, aggregated rows could show the wrong provider and model (for example, showing a small-amount model when traffic fees made up the bulk), causing billing misreads. After the fix, for transactions mixing multiple sources, the parent row's provider/model columns show "-", while the expanded child line items still fully show each entry's actual provider and model.
* **Fixed the Cohere model reply length limit having no effect**: The reply length limit configured for Cohere models previously had no effect at all, so models could produce replies far beyond the setting and consume extra usage. After the fix, the configured limit is actually sent to Cohere and model output is correctly truncated at the configured limit, avoiding unnecessary usage consumption.
* **Fixed Web Chat replies permanently stuck on "typing" after backgrounding**: After putting Web Chat in the background in a mobile browser for a while and coming back, the AI reply would be permanently stuck on "typing" with the input box locked, even though the backend had long since finished replying (from a customer report). After the fix, returning to the foreground or reconnecting automatically reconciles with the server, backfilling messages missed during the disconnect, clearing the stuck state, and unlocking the input box; expired connections also recover automatically.
* **Fixed web content extraction drifting from the source text**: When AI agents use the web fetch tool to organize content, results are now grounded in the actual page text retrieved, no longer adding information that doesn't exist on the page.
* **Fixed AgentOps unable to add FAQs**: The "Add to FAQ" entry in AgentOps monitoring records has been restored — you can create new items or add to existing items from record content.

## v2026.08.18 <a href="#v2026-08-18" id="v2026-08-18"></a>

***

### ✨ New Features

* **Comprehensive API Key Management Upgrade: Personal Key Self-Service Issuance and Organization Key Management**: Every member can now issue and revoke personal API keys in organization settings without needing an administrator to issue them on their behalf. The limit of one active key per person has been removed, so when rotating keys, revoking an old key no longer interrupts connections that still hold other valid keys. The organization key list adds a "Source" indicator (system-issued / self-created / administrator-issued) with source-based filtering, and deactivated members no longer appear in the menu when issuing keys on behalf of others. In addition, reading the conversation platform list with an API key now returns platforms of all types, consistent with single-item query behavior.
* **LINE WORKS Conversation Platform Integration**: Added a LINE WORKS channel to conversation platforms: it provides a complete creation flow (credential fields, connection testing, permission setup) and the same full set of settings tabs as other channels (Webhooks, human agent handoff, conversation labels, conversation analytics, Copilot). Once created, AI assistants can serve users on LINE WORKS.
* **One-Click Add to FAQ from AgentOps Conversation Records**: When you find a conversation with a poor AI answer in AgentOps "AI Assistant Monitoring → Conversation Records", you can now bring that Q\&A into a form directly from the detail view with one click, edit it, and add it to a designated knowledge base's FAQ — condensing "find the problem → fix the knowledge base" into a single screen.
* **AgentOps Monitoring Record Detail Page with Deep Linking**: AgentOps adds a conversation record detail page: complete basic information, identifiers, a processing timeline, previous/next navigation, JSON/Markdown/Excel export, and deep links for sharing a specific record directly with other members.
* **Meeting Record Summary Background Generation and Version Flow**: Meeting record summaries are now generated in the background: long meeting transcripts are automatically processed in segments with progress display, and individual segment failures continue with placeholder markers instead of interrupting the whole job. You can optionally have a designated AI assistant read the transcript and generate the summary with its own logic. You can leave the page during generation and come back when it's done, with support for summary resumption and a version flow.
* **Role (Group) Credit Quota: A Third Quota Management Layer**: Credit quota management adds a third layer, "role quotas": in addition to organization and member quotas, you can set a monthly Credit quota cap for each role (group). When any role's quota is exhausted, usage is suspended for that role's members (each role's quota accumulates independently). Organization settings add a role quota tab and a group settings card, and members can also check the quota status of their roles on their profile page.
* **Usage Statistics Show Prompt Cache Usage and Credits Saved**: "Organization Management → Usage Statistics" adds Prompt Cache usage: you can view cache write and cache read token counts and the cache hit rate, and the Credit summary card shows the credits saved by caching, helping you assess the cost benefits of caching.
* **Contact Bulk Import: Preview Mode and Inbox Merge**: Contact bulk import is now a two-step flow: first, an "import preview" shows how many records will be created and updated (with no data written at all), and the import only runs after you confirm. A new "merge" mode for inbox assignment adds the inboxes in the file to the existing set instead of replacing it entirely (the default remains replace, so existing behavior is unchanged).
* **Micro Subscription Plan**: Added a "Micro" subscription plan: a single RAG assistant, 250,000 monthly credits, and a streamlined feature set, serving as an entry-level option for small customers. The plan, billing, and organization info pages correctly display the "Micro" label in five locales. The plan is activated with the assistance of platform operations staff.
* **Support Center Single Sign-On (MaiDesk SSO)**: The "Support Center" entry in the console header now supports single sign-on: clicking it automatically logs you into the MaiDesk support center with your current login identity — no separate registration or login needed — and tickets are correctly associated with your organization. If automatic login is unavailable, it falls back to the original opening behavior.
* **MaiGPT Quick Entries Officially Available**: The MaiGPT conversation landing page officially opens the "Presentation Generation, Document Generation, Table Generation" quick entries — click one to start a conversation with the corresponding context. The "Meeting Records" entry is displayed based on the organization's feature activation status.
* **Official Build-in Agent Experience Feedback Card**: Official Build-in Agents (98 of them) now send an experience feedback card at the end of a conversation, letting users fill in a questionnaire tailored to each assistant for that session. Feedback automatically carries the organization and user identity, helping the team continuously improve each assistant's quality.
* **Connector Auth Headers Support Embed Page Context Data**: MCP connector auth headers now support template variables: context data passed in from a Web Chat embed page (such as the site's user identifier) can be injected into the auth headers of outbound service calls. The available keys are declared by each connector via its own whitelist, so adding keys requires no new release. Behavior is completely unchanged when no whitelist is configured; keys declared as sensitive also no longer appear in message-related APIs and real-time channels.

### 🚀 Core Performance Optimization

* **Faster Real-Time Connection Establishment**: Real-time communication connection establishment is now much faster across the board: the connection handshake uses a database-query-free authentication method, and a redundant authentication layer was removed. Mass simultaneous reconnections (for example, after a system update) no longer cause waits of 3+ seconds and cascading connection failures.
* **Faster Unread Announcement Queries**: The unread announcement query when opening the platform is now faster: a duplicated query and a full-table scan were eliminated, reducing the worst case from over 1.3 seconds to a response within a few hundred milliseconds.
* **Faster Knowledge Base Picker Panel Loading**: The knowledge base picker panel now loads faster: for organizations with thousands of knowledge base files, opening the picker panel drops from 3–4 seconds to about 1 second or less (the response is slimmed down to only the fields the panel actually needs; functionality and UI are unchanged).

### 😊 User Experience & Interface Optimization

* **MaiGPT Interface Optimization: Card-Style Right Panel and Standalone File Preview**: MaiGPT interface optimization: the right-side "Knowledge Base / Outputs" panel now uses a card-style collapsible design (one card expanded at a time, with thumbnails), the panel and the conversation area merge into a single canvas with a more stable fixed width. File previews opened from cards are now a standalone layer whose width can be dragged to enlarge for reading; the knowledge base scope filter and selected-count display are retained.
* **Stronger Edit Permission Checks on the Assistant Settings Page**: When opening an AI assistant's settings page from the Agent Marketplace and other entry points, editability is now determined by server-side resource-level edit permission: members without edit permission see a read-only settings page, eliminating "looks editable but fails on save". The page is protected as read-only until permission is confirmed, then unlocks automatically.
* **Assistant Rename Syncs Platform Names and Improved Deletion Flow**: When renaming an AI assistant, you can now also opt to sync the names of related conversation platforms. The assistant deletion flow now deletes the selected platforms first and only deletes the assistant after all succeed, clearly reporting the current state on partial failure. System-managed built-in platforms (internal chat / API) no longer appear in the selectable list and are instead marked with explanatory text as automatically managed by the system.
* **Meeting Record Permission Management Improvements**: Meeting record permission management improvements: when creating a live transcript meeting, "Participants" is now a selection of organization members, and selected members automatically receive view access to the meeting after creation. In the role editor, checking "Meeting Records permission" now also checks "Meeting Records management permission" by default (you can uncheck it to restrict members to only meetings they participate in), and the deprecated "meeting privacy mode" label was removed.
* **Database Table Management Grouped by Source File**: Table management in "MaiAgent Database" is now grouped by source file: after uploading a multi-sheet Excel file, each table is collapsed under its source file with its own sheet name displayed; new tables appearing while an upload is processing show up in the corresponding group in real time.
* **Pricing Page Auto-Cleans the Model List**: The model pricing list on "Organization Settings → Credits → Billing Method" is now automatically tidied: disabled or never-launched models no longer appear, and the pricing page updates automatically when models are disabled or renamed. The actual billing price-lookup logic is completely unchanged.
* **Copilot Embed Page Login Guidance**: When a Copilot page is embedded in an external customer service system (such as Genesys Cloud), the logged-out state now shows a "Please log in first" prompt; clicking it completes login inside the embedded window and automatically returns to the original page. The login state is maintained with a 30-day rolling renewal, so each browser environment only needs to log in once.
* **Clearer Error Feedback in the SDK Credential Setup API**: Developer experience improvements for the SDK "set contact credentials" API: passing a non-MCP tool now returns the specific reason and the correct approach (no longer wrongly claiming the tool doesn't exist); the response adds a created field so integrators can programmatically tell whether the contact was created in this call or already existed.

### 🔐 Security & Governance Enhancements

* **MaiAgent Assistant (AskAI) Organization Binding and Logout Protection**: MaiAgent Assistant (AskAI) identity and organization binding is comprehensively hardened: for cross-organization accounts, the assistant always acts under the identity of "the organization at the time the conversation was created", no longer misusing a leftover identity from another organization. Switching organizations switches the AskAI workspace accordingly and shows a badge for the currently bound organization, with conversation history separated by organization. Logging out of the console automatically closes the chat window, clears the embed identity, and revokes server-side credentials — after logout, conversations can no longer continue under a leftover identity.
* **Multi-Tenant Isolation as a Mechanism**: Multi-tenant isolation is upgraded from "convention" to "mechanism": anonymously readable conversation and message endpoints now bound visibility by channel and organization; a vulnerability allowing cross-organization reads of contact data was patched; an organization-scope enforcement mechanism is being rolled out platform-wide across APIs with ongoing convergence, and several system errors caused by malformed identifiers were also fixed. Existing anonymous Web Chat usage flows are unaffected.
* **Tightened Permissions on Assistant Sub-Resource Endpoints**: Permissions on six AI assistant sub-resource endpoints (statistics, usage, and more) are tightened: they now use exactly the same per-assistant authorization criteria as the assistant itself, so members not authorized for an assistant can no longer read its message counts, conversation counts, satisfaction scores, and similar information.
* **Knowledge Base Label Filter Failure Protection (Fail-Closed)**: Knowledge base label filter protection is hardened: when a filter condition cannot be resolved (for example, a referenced label was deleted), retrieval now returns 0 results instead of silently returning all data, eliminating data isolation failures. The UI also marks invalid labels in gray with a warning, blocks submission, and offers one-click removal.
* **Web Chat Embed Communication Security Hardening**: Web Chat embed communication security is hardened: all overly broad cross-window message targets on embed pages (items reported by external vulnerability scans as CWE-942) are eliminated, and the boot control signal now locks onto the embed page origin at load time. Legacy embed scripts and directly opened pages are unaffected.
* **AI Gateway Role Permission Control**: AI Gateway adds a role permission node: organizations can use the existing role permission mechanism to decide which roles can see and use the AI Gateway menu and pages; the menu is automatically hidden for unauthorized roles.
* **Separation of Conversation Platform Usage and Conversation Viewing Permissions**: A conversation platform's "usage permission" and "view all conversations" permission are now separate: assigning a platform to a role no longer implicitly grants permission to browse all conversation records on that platform. The role platform settings add a "view all conversations" field for independent control; members can always see conversations assigned to them and conversations they participate in, and human handoff notification links are unaffected.

### 🛠️ Bug Fixes

* **Fixed Occasional System Errors During AI Replies**: Fixed occasional system errors during AI replies: when a user leaves or disconnects before a reply completes, subsequent processing no longer fails and later replies no longer show "The system is temporarily unable to process your request"; replies from models that only return a final result without streaming fragments are no longer misjudged as empty; and when a model service's stream stalls midway, the system automatically retries once in non-streaming mode.
* **Fixed Tool-Intensive Agent Replies Being Forcibly Cut Off**: Fixed replies from assistants requiring many tool calls being forcibly cut off: as the tool call count approaches the limit, the system now guides the model to wrap up gracefully and produce a complete final reply — users no longer wait several minutes only to receive truncated content.
* **Fixed Three Agent Team Collaboration Issues**: Fixed three Agent team collaboration issues: 1. Member assistants' Canvas mode now outputs correctly under team delegation — structured content no longer degrades to plain text 2. Internal events from delegated sub-agents no longer leak into the conversation view 3. After a handoff between assistants, the receiving assistant no longer occasionally replies blank with "No response received from the LLM".
* **Fixed Assistants with Fallback Model Groups Unable to Reply**: Fixed AI assistants with fallback model groups enabled being unable to reply: this now works normally again — when the primary model call fails, the system automatically switches to the fallback model to continue the reply.
* **Fixed MaiGPT Messages Requiring a Refresh to Appear**: Fixed MaiGPT replies requiring a page refresh to appear: real-time streaming is restored and messages now appear in the conversation immediately.
* **Fixed Conversation and Knowledge Base Images Expiring After a While**: Fixed images in conversations and knowledge bases — including generated images and videos — becoming inaccessible after a while: media links in stored content now use stable URLs with a valid signature freshly issued on every read, and existing data has been repaired as well. Also fixed browsers blocking image loading in cross-site embed scenarios (admin console, Web Chat, IM platforms), and misparsing of links followed by CJK punctuation.
* **Fixed Message Loss When Replies Contain Special Characters**: Fixed message loss when AI replies contain special control characters: previously the reply was visible on Web Chat but disappeared after a refresh, while platforms like LINE and Teams never received it at all. This is now handled uniformly at the storage layer, and messages are no longer lost.
* **Fixed Maps and Tables Not Rendering in Conversations**: Fixed maps and tables not rendering correctly in conversations: 1. Google Maps embeds in model replies now render as interactive maps instead of showing raw source code 2. HTML tables output by models (including merged cells) render correctly as tables. Both rebuild content with a safe whitelist and trust no original attributes, so security is unaffected.
* **Fixed Three Web Chat Embed Script Configuration Issues**: Fixed three Web Chat embed script configuration issues: 1. When a MaiGPT target container cannot be found, the script now waits up to 5 seconds then safely gives up with a notice, instead of covering the entire page 2. Position and size settings correctly support rem units, and updated embed settings from the site take effect again instead of being permanently overridden by a user's earlier drag adjustments 3. Using the auth setting no longer produces a false "unknown setting" warning.
* **Fixed PDF Translation Download Timeouts**: Fixed PDF translation result download timeouts: downloads are now served directly from cloud storage instead of being relayed through the platform — small files no longer time out, and the download file name remains correct.
* **Fixed Broken Live Preview After Image Upload**: Fixed the live preview appearing broken between uploading an image and saving: the preview now displays correctly in real time, and file names in the upload list and preview window no longer show as a long signature string.
* **Fixed Two Login Issues**: Fixed two login issues: 1. Users being unable to log in after an administrator changed their email (the email verification record was not synced) is fixed 2. Login failure messages no longer always show a generic "Login failed" but display the actual reason (such as account deactivated or email unverified), so users can self-recover or seek help accordingly.
* **Fixed Member Search Failing When Creating API Keys in Large Organizations**: Fixed member search failing when creating API keys in large organizations: the member menu now uses real-time backend search, so organizations with more than 100 members can find all members; deactivated members no longer appear in the menu.
* **Fixed Tables Disappearing When There Are More Than 20**: Fixed some tables disappearing in database table management when there are more than 20: the list now loads with correct pagination — up to a hundred records still feel like a single scrolling page, pagination appears beyond that, and all tables are visible.
* **Fixed Conversation List Contact Search by Email**: Fixed the conversation list "filter by contact" returning no results when entering an email: entering a contact's email now correctly finds the corresponding contact.
* **Fixed AgentOps Rating Filter Timeouts**: Fixed AgentOps conversation record rating filters (thumbs up/down) timing out on 30/90-day ranges: the query now uses a faster two-stage approach, and the time range condition was also fixed to actually take effect.
* **Fixed False "No Permission" Prompt on the Credit Page**: Fixed members with only Credit permission seeing a false "no permission" prompt when opening the Credit page: the billing provider information the page needs is now included in the wallet balance query, no longer triggering a permission error.
* **Fixed Incorrect Cloud/On-Premises Model Classification**: Fixed incorrect cloud/on-premises classification in the model list: cloud service models connected via the OpenAI-compatible protocol are no longer mislabeled as on-premises; classification now correctly reflects each model's actual deployment location.
* **Fixed Video Generation "Draft" Tier Failures**: Fixed the video generation "draft" tier mostly failing: that tier has been retired, and the tool now asks which quality tier you want (fast / best quality) before starting generation, no longer letting the model decide your credit spend for you.
* **Fixed Three Knowledge Base File Parsing Issues**: Fixed three knowledge base file parsing issues: 1. When special vector images (WMF/EMF) embedded in Word files cannot be decoded, the image is now skipped and the text content is indexed as usual, no longer failing the entire file 2. The automatic repair conversion for corrupted files, which previously never actually ran, is now in effect 3. The parse time limit for first uploads is aligned with re-parsing (1 hour → 4 hours), so files queued during peak hours are no longer wrongly marked as failed.
* **Fixed System Prompt Not Applied with Structured Output**: Fixed assistants configured with a structured output format not applying the system prompt: the assistant's instructions and system prompt now correctly reach the model, restoring answer quality to expected levels.
* **Fixed Dataset Evaluation Failing Entirely on Reasoning Models**: Fixed dataset evaluation failing on every test with OpenAI reasoning models (o-series): the system no longer sends parameters these models don't support, and evaluation runs normally.
* **Fixed Meeting Recordings Ending Early Due to Network Reconnection**: Fixed meeting recordings ending early due to brief network interruptions: recording rooms now use their own, more generous reconnection grace period and are no longer destroyed prematurely by the system during reconnection, so long meeting recordings no longer lose their second half.
* **Fixed Cached Token Double Billing**: Fixed cached tokens being billed twice: cache-hit tokens are no longer counted in both the regular input and cache read dimensions — they are billed once at the cache rate only, making billing more accurate.
* **AgentOps Evaluation Usage Now Billed**: AgentOps evaluation model usage is corrected to bill normally: model tokens consumed by evaluation (LLM judge) calls were previously not deducted; they are now billed normally across the four dimensions of input, output, cache write, and cache read, keeping usage statistics and billing consistent.
* **Fixed Three Tool Execution Issues**: Fixed three tool execution issues: 1. When a GET-type API tool is called without parameters, the query string built into the URL is no longer wiped (previously causing upstream errors or empty results) 2. Tools with UUID/URL-typed parameters no longer fail to execute 3. Assistants triggered automatically by schedules no longer occasionally fail when calling MCP tools.
* **Fixed Database Column Description Loss**: Fixed database column descriptions being lost: when a table's column structure is reloaded, the column descriptions you wrote are preserved; description lookup failures are also no longer silently skipped, so operations can notice them immediately.
* **Fixed Occasional Concurrent Sync Errors**: Fixed three classes of occasional concurrency errors: 1. Database deadlocks when calendar events sync simultaneously 2. Database deadlocks when SCIM directory group members sync simultaneously 3. Execution failures caused by the system cleanup schedule occasionally reclaiming code sandboxes right after startup.
* **Fixed Wrong Navigation from the Team Edit Page Platform Gear Icon**: Fixed the gear icon in the team edit page's "Linked Conversation Platforms" navigating to the wrong page: clicking the gear now correctly goes to that platform's settings page.
* **Fixed Greeting Not Shown on First Entry to Internal Chat**: Fixed the greeting not being displayed on first entry to internal chat in the admin console: assistants with a configured greeting — including official Build-in Agents — now correctly display it on first entry to a conversation.
* **Fixed Completions API Rejecting Attachment-Only Messages**: Fixed the Completions API rejecting messages containing only attachments: consistent with web behavior, the text content may now be empty when a message carries attachments; messages with both empty text and no attachments are still correctly rejected.
* **Fixed Blank Full Conversation Log in AgentOps**: Fixed the "Full Conversation Log" section being blank in AgentOps conversation record details: complete model request content is once again recorded across all reply modes (including Agent teams) for tracing and evaluation.

## v2026.08.11 <a href="#v2026-08-11" id="v2026-08-11"></a>

***

### ✨ New Features

* **Organization Model Access Control**: Added organization-level model access management. Organization owners can view all platform models on the "Organization Settings → Model Access Permissions" page (with vendor icons and brand labels, grouped by cloud/on-premises), and enable or disable each model within the authorized scope; the page also shows how many AI assistants are currently using each model, so the impact can be assessed before disabling. Permission settings are fully enforced: unauthorized models cannot be selected when creating or editing an AI assistant, and assistants bound to disabled models are rejected before replying, preventing bypass of the controls. If an assistant's bound model is disabled, the edit page shows "model name (disabled)" with a warning prompting reselection. (Previously: organizations could not control which models members could use, newly launched models were automatically available to the entire organization, and administrators could not restrict models based on cost or compliance; disabled models showed only a blank on the assistant edit page, making the problem hard to notice.)
* **Official AI Assistant Marketplace**: Introducing the brand-new official AI assistant marketplace. The marketplace offers nearly one hundred official pre-built AI assistants covering industry scenarios such as general office work, healthcare, manufacturing, banking, retail, public sector, and securities, with two-level scenario category browsing and keyword search; each assistant has a preview window where you can watch demo conversation replays, insert sample questions with one click, and view sample outputs. Organization administrators can enable official assistants with one click within their plan's seat quota; the system automatically creates a dedicated knowledge base and conversation entry point, with configurable access; when no longer needed, assistants can be disabled to release seats (with an adjustable cooldown period in days; conversation history is still retained). Official assistant instances and organization-built assistants are clearly separated in the AI assistant list and the marketplace's "Organization-built" tab to avoid confusion. (Previously: to build industry-scenario assistants, customers had to design prompts and knowledge bases from scratch, creating a high adoption barrier, and the platform had no ready-to-use official templates.)
* **OAuth Application Self-Service Management**: Added an "OAuth Applications" management page to organization settings. Organizations can now register the OAuth applications needed for external tools (such as Claude and other MCP clients) to connect to the platform, with full support for creating, editing, deleting, and regenerating secrets; credentials are shown only once and require double confirmation to ensure security. The page also provides a connection endpoint info card (with one-click copy) and redirect URL format pre-validation, making setup less error-prone. (Previously: to let external tools connect via OAuth, organizations could only ask MaiAgent back-office staff to manually create the configuration, which took time and could not be self-maintained.)
* **Plan History Timeline at a Glance**: Added a "Plan History" timeline below the current plan card on the organization overview page, presenting the full context of the organization's plans in a clear chain diagram: previously used plans, the currently active plan (with a "Today" marker), and the next pre-scheduled plan, each labeled with start and end dates; on mobile it automatically switches to a vertical layout, and when there are many plans it auto-collapses and provides a "Back to Today" quick-locate button. Customers can self-serve checking plan start/end dates and change arrangements at any time. (Previously: organization members could only see the current plan name and expiry date; past and future plan arrangements were completely invisible, and members had to repeatedly ask customer support to confirm.)
* **Web Crawl Auto-Creates Knowledge Bases**: Added an "auto-create knowledge base" mode to the web crawl feature. When setting up a crawl task, you can choose not to import into an existing knowledge base and instead have the system automatically create a brand-new knowledge base and import the content each time a crawl completes; when used with recurring crawl schedules, each run produces an independent knowledge base (with a date stamp), making per-batch management and source tracking easier. (Previously: crawled content could only be imported into a manually pre-created and selected knowledge base, making the workflow cumbersome when recurring crawls needed to be stored separately per run.)
* **Custom Scoring Criteria & Multi-Turn Conversation Evaluation**: Major upgrade to the AI assistant evaluation feature. When launching an evaluation, you can add custom scoring metrics, define task-specific scoring criteria or step-by-step scoring steps, and set passing thresholds — no longer limited to built-in metrics; also added multi-turn conversation evaluation: manually create multi-turn test conversations, or auto-synthesize test data from knowledge base files with one click, then view each conversation's full transcript and per-metric scores on the results page after execution. Single-turn and multi-turn evaluations are consolidated into the same launch dialog, with one-click mode switching and consistent field rules. (Previously: only single-turn Q\&A evaluation with built-in metrics was available; scoring standards could not be customized for specific tasks, and assistant performance in multi-turn conversations could not be tested.)
* **Meeting Records Complete Overhaul**: Complete overhaul of the meeting records feature. The MaiGPT blank conversation page now has a "Meeting Records" quick entry panel: start real-time transcription with one click (including a recording timer, live transcript, and mute control); when recording ends, an AI summary is generated automatically and can be inserted directly into the conversation or opened as a full page, and the panel also shows recent meeting records. It also supports connecting Google Workspace or Microsoft 365 calendars: once linked, the panel shows a list of upcoming meetings, and ongoing meetings can be recorded with one click with the meeting title and attendees filled in automatically. Meeting record visibility has also been adjusted: for all organizations, regular members can now only view meetings they created or participated in, and only users with management permissions can view all of them (existing roles automatically retain their original viewing scope, so visible content remains unchanged before and after the upgrade); the broken legacy real-time meeting page has also been officially retired. (Previously: starting a recording required leaving the conversation to find another entry point; meetings were disconnected from calendars with no way to start recording directly from a scheduled event; meeting records were visible to the entire organization by default, lacking privacy protection; and the legacy page's buttons were broken yet the page was still directly accessible.)
* **SeedDance Video Generation Tool**: In-conversation video generation now supports the SeedDance 2.0 tool. When users select video generation in a conversation, the system estimates the required credits in real time based on video length, resolution, frame rate, and standard/fast mode, so costs are clear before submitting; the pricing page also merges the multiple rates of the same tool series into a single expandable row, making it easy to compare billing across specifications. (Previously: the cost of the new-generation video generation tool varied by specification, users could not estimate credit costs before submitting, and the pricing page struggled to clearly present multi-specification rates.)
* **MaiGPT Presentation File Online Preview**: Backend integration for MaiGPT presentation file preview is complete. Fixed the issue where files listed in the output panel could not be opened, and enabled online preview for both presentations generated by MaiGPT and presentations uploaded to the knowledge base: a preview version is automatically generated on upload, and presentations without an existing preview version also support on-the-fly conversion (with caching, so subsequent opens are faster), eliminating the need to download files and open them in separate software. (Previously: presentations in the output panel occasionally failed to open, and knowledge base presentations could not be previewed online — both had to be downloaded and opened with other software.)
* **Tool Support for URL Query Parameter Configuration**: The tool edit page adds a "Query Parameters" field: when integrating external APIs that only accept keys via URL query parameters, such as Google PageSpeed, you can now configure fixed parameters in this field. The system automatically includes them with every request, configured values take precedence over same-named parameters generated by the AI model, and execution logs do not retain key contents. The field supports context variables and shares the same configuration experience as HTTP headers. (Previously: keys could only be written in plaintext into the tool's API URL, which was both insecure and hard to rotate and manage.)
* **TeamPlus Per-Channel Connection Address Configuration**: The Team+ conversation platform supports per-channel custom connection settings: the channel form adds an optional API address field, allowing customers whose production and test environments run on different servers to validate credentials and create conversation platforms directly against their own environment. For enterprise internal servers with incomplete certificate chains, a "Trust insecure certificates" toggle is also provided (it appears only after an address is entered, and when enabled the interface switches to warning colors as a reminder that connection security is reduced). The address field includes format validation, showing errors immediately as you type instead of only after submission. (Previously: all Team+ channels could only connect to a shared address, production-environment customers could not validate credentials, and servers with incomplete certificate chains could not be integrated at all.)
* **File Query Supports Upload Time Filtering**: The AI assistant's file query tool now supports filtering by "file upload time": users can directly ask "summarize the audio files uploaded on July 27, 2026", and the assistant will first find files by time range, then read their contents to answer. The filename condition is now optional, so there is no need to force keywords when querying by date alone. Query results also include each file's processing status and the server's current time, allowing the assistant to correctly interpret relative dates like "yesterday" and "last week". (Previously: file queries relied solely on filename matching, so when asked "which files were uploaded on a given day", the assistant could only guess keywords, and wrong guesses filtered out the correct answers.)
* **More Model Providers Support Thinking Configuration**: Thinking configuration support is expanded: models self-hosted via vLLM and models on Azure can now be configured with thinking effort (off/low/medium/high); Ollama models get a thinking on/off toggle. The settings are actually passed through to the model side to take effect, and the assistant settings interface automatically shows the corresponding options by provider. For enterprises self-hosting open-source reasoning models or deploying on Azure, complex analysis tasks gain the same deep reasoning experience as official cloud models. (Previously: thinking configuration was only supported by some providers, and reasoning models on vLLM, Azure, and Ollama did not take effect even when the setting was enabled.)
* **Connector Binding Fully Available**: Connector binding is now officially available to everyone: the "Connectors" tab on the AI assistant edit page is no longer gated by a feature flag, and all organizations can bind connectors to assistants directly in Agent mode. Once bound, the assistant's conversations automatically enable these connectors, letting the assistant use external service capabilities directly without per-organization activation requests. The corresponding activation option on the organization advanced features page has been removed accordingly. (Previously: the feature was gated by two layers of flags, only a few activated organizations could see the connector binding entry, and other organizations could not use it.)

### 🚀 Core Performance Optimization

* **Database Query Result Row Limit Protection**: The AI assistant's database query (Text2SQL) adds row limit protection for results: when query results exceed the limit (default 1,000 rows), the system truncates them and explicitly tells the assistant "the data is incomplete", guiding it to answer with aggregate queries such as counts, sums, and grouping instead, preventing massive results from dragging down the service. The limit can be adjusted by system administrators as needed. For enterprises running report analysis on large tables, query stability is greatly improved. (Previously: query results were loaded in full with no row limit, and hitting hundreds of thousands of rows would exhaust memory and cause a service outage.)
* **Comprehensive AI Reply Engine Upgrade & Stability Enhancements**: The AI reply engine has completed a next-generation architecture upgrade, unifying the Web Chat and API reply flows into a single engine. After the upgrade, model providers such as Groq and OpenRouter gain native support, and image messages, thinking-process display, AI slides (Canvas), team collaboration, and tool searching all operate consistently on the new engine, making reply behavior more stable and eliminating gaps in the cross-channel experience. Issues discovered during the migration have also been fixed: the thinking process of some models (Bedrock, OpenRouter, Ollama) could fail to display, tool searching could fall into a retry loop causing reply timeouts, scheduled conversations occasionally errored, and the memory feature and classification billing behaved abnormally — all now restored to normal. (Previously: the thinking process of some models did not display, tool searching mode spun repeatedly on the new engine until timing out, image messages and new model providers required processing through a compatibility layer with inconsistent behavior, and the two reply pipelines had drifted apart in error handling and feature coverage.)
* **Model Prompt Caching Optimization: Faster Responses and Lower Credit Consumption in Long Conversations**: Two rounds of optimization were applied to the prompt caching mechanism for model providers such as GMI and OpenRouter: the cache no longer covers only the fixed system prompt — conversation history and tool results can now hit the cache across turns — and real-time information that changes every turn (time, location) was moved out of the cached scope to maintain the hit rate. For long conversations and scenarios with multiple tool calls, both response wait time and model usage costs improve noticeably, and bills for customers using their own keys (BYOK) are no longer inflated by repeated content. (Previously: conversation history was resent and billed at full price every turn — measurements showed over 76 million tokens redundantly resent within 4 days, the cache hit rate dropped from 73% to 42.7%, and p95 time-to-first-token worsened from 60 seconds to 104 seconds.)
* **Real-Time Messaging Architecture Adjustment: More Reliable Message Delivery, No Disconnections During System Updates**: The real-time messaging architecture was adjusted: operations such as sending messages, stopping replies, marking as read, and rating messages now go through the standard API channel, while the real-time connection is dedicated to receiving AI replies and notification pushes. This architecture lets the real-time connection layer be deployed independently of the business code, so users' connections are no longer forcibly interrupted during routine system updates, connection errors caused by mass reconnections are greatly reduced, and message delivery is more stable and reliable; error prompts on failed operations (insufficient quota, rate limiting, etc.) remain fully consistent with the original experience. (Previously: every system deployment triggered a real-time connection reconnection storm, with over 1,200 connection errors in a single day at peak in production, and message delivery could fail as a result.)
* **Conversation Message Rendering Performance: Huge Tool Results No Longer Freeze the Browser**: Conversation message rendering performance has been comprehensively strengthened. When viewing tool execution results containing large amounts of data (for example, Code Interpreter producing reports with hundreds of thousands of rows), the screen no longer freezes: unchanged content is not recomputed, syntax highlighting during streaming is consolidated, and oversized results automatically fall back to full plain-text display. Safeguards were also added for extremely long messages with unusual formatting (such as extremely long single-line posts), which are now rendered as collapsed plain text, ensuring a single message cannot drag down the entire conversation window. (Previously: viewing a tool result with 670,000 rows made Chrome repeatedly show "Page Unresponsive", and a single 95,000-character message could freeze the page for over 120 seconds and lock up multiple windows at once.)
* **Faster Citation Source Loading**: Optimized how knowledge base citation sources in conversation histories are queried: previously each cited document triggered its own database query; now all required data is loaded in a single batch. Conversations citing many documents load noticeably faster when opening the message list, and the position and content of citation annotations remain exactly the same as before. (Previously: each distinct cited document triggered a full-table query, so the more cited documents there were, the slower the message list loaded, and performance alerts had already appeared in production.)
* **Tool Output Length Control & Repeated-Call Protection**: Improved large-data handling when the AI assistant calls tools: the tool output length budget is now calculated in the correct units, and when the budget is exceeded, both the head and tail of the data are kept with a clear truncation notice prepended, so the AI clearly knows it received partial data; repeated-call protection was also added, so when the AI repeatedly calls the same tool with the same conditions in the same turn and gets the same result, it receives a clear notice instead of spinning idly. Affected use cases (querying large datasets, report aggregation) now complete replies faster and no longer get stuck. (Previously: mixed length-budget units shrank the usable budget to a quarter, the tail of the data was permanently unreachable, and the AI, unaware the data was truncated, repeatedly re-called the same tool up to the 20-call limit, leaving a single reply turn stuck for as long as 6 minutes.)

### 😊 User Experience & Interface Optimization

* **Avatar Editing Keeps the Original Image for Re-Cropping**: Improved avatar editing experience: when uploading an avatar, the system now keeps the original photo and the crop box position, so every subsequent avatar edit loads the original image in the crop window and returns to the last crop position, making "fine-tuning" truly fine-tuning — you can shift or zoom the avatar frame slightly with zero loss in image quality. If the original image is temporarily unavailable, the interface shows a clear notice and lets you continue editing with the current avatar without getting stuck. (Previously: every edit re-cropped the result of the previous crop, so the more you edited, the smaller and blurrier the avatar became, and the original image had already been discarded and could not be recovered.)
* **Comprehensive Web Chat Desktop Interface Overhaul**: Comprehensive overhaul of the Web Chat desktop interface: full-page mode now uses a dedicated desktop layout on computers, with the message area and input box fluidly widening with the window (up to 1200px), no longer looking like a stretched mobile layout with large blank margins on both sides. Four frequently used settings — font size, theme mode, voice playback, and interface language — have been moved from the second level of the top-right menu to the header, adjustable in a single step. The top-right menu's readability has also been improved: each row now uses a "Name: Value" format (e.g. "Font Size: Medium"), the language list shows each entry as "native name (translated name in the current interface language)" (e.g. English (英文)), and language search matches against native names, translated names, and language codes. The mobile version and the embedded floating bubble are completely unaffected. (Previously: the desktop version was just a stretched mobile layout with excessive blank space, the font size adjustment entry was buried deep in the menu where users couldn't find it, and the menu showed only values without names while the language list was hard to identify.)
* **Web Chat Connection & Loading Enhancements**: Enhanced the connection and loading stability of Web Chat. Previously, any brief network instability when opening Web Chat would immediately show "Unable to connect to server"; the system now automatically retries up to 3 times, so users are completely unaware of momentary network drops. If it still ultimately fails, the error screen displays the failure stage, error category, and occurrence time, so users only need a screenshot when reporting issues for support to quickly pinpoint the cause. In addition, in some embedded browser and private browsing environments, offline status detection would prevent Web Chat from opening at all — this has also been fixed. (Previously: a single momentary network drop showed a connection failure with no diagnostic information; in certain browser environments Web Chat simply failed to launch.)
* **Deep Research Progress Display Revamp**: Revamped the progress display for deep research. Previously, the progress panel relied on presentation content assembled by the backend, and after the security hardening release it was displayed as raw markup text, making it hard for users to track research progress. The panel is now rendered by the frontend from structured step data, clearly presenting each research step's running, completed, and failed states, restoring readable and more stable progress information. (Previously: the deep research progress panel displayed a long string of unrendered raw markup text.)
* **Confirmation Popup Visual Fixes**: Fixed multiple visual issues with confirmation popups. Previously, delete confirmation bubbles in tables would first appear oversized and then gradually shrink over a second or two, titles were squeezed into two lines, and the warning icon was misaligned with the text. More importantly, confirmation buttons for irreversible operations like deletion used the brand blue that signals a "safe option" — semantically opposite to the red delete icon — making accidental clicks likely. After the fix, bubbles open at the correct size immediately, the icon aligns precisely with the title's first line, and confirmation buttons for all 33 destructive operations across the site are now uniformly red with verb-based copy (e.g. "Revoke" for API Keys), while non-destructive confirmations remain blue. (Previously: delete confirmation bubbles shrank frame by frame on open, icons were misaligned, and confirmation buttons for destructive operations appeared in safe blue.)
* **MaiGPT Interface Detail Refinements**: Refined multiple interface details in MaiGPT and the admin console. The sidebar's right edge previously had two controls — a persistent gray bar and a semi-transparent collapse button — creating visual noise; these are now merged into a single interaction rail that is invisible at rest, reveals a gray bar on hover, can be dragged to resize, and clicked to collapse. All collapsible sidebars now share this same interaction, with a persistent divider line consistent with the rest of the site. The hover menu on the conversation list no longer pushes titles aside, and the full-text tooltip that popped up for truncated titles has been removed. The entry loading stroke animation, previously almost invisible, now uses a clear ink-line stroke; the opening brand icon has been enlarged with its jagged bevel edges and draw-animation flaws fixed, making the opening experience more polished. (Previously: the sidebar's dual controls were noisy and lacked a divider, conversation list hover caused pushing and tooltip interference, the stroke animation was invisible, and the opening icon had visible jagged edges.)

### 🔐 Security & Governance Enhancements

* **PII Detection & Content Safety Classification Protection**: Added content safety protection capabilities: the AI assistant's Hook automation flows can now call "PII Detection" and "Content Safety Classification" for scanning. PII detection uses Google Cloud DLP, with selectable PII types to detect, covering financial information, account credentials, device and network information, and ID numbers for regions including Taiwan, the US, Japan, Korea, Hong Kong, and Singapore. Content safety classification provides 7 major categories including hate, harassment, self-harm, violence, and jailbreak attacks, with policy-based selection of which items to report in detail. The admin configuration interface has launched alongside (supporting 5 languages), and the credits page adds a "Content Safety & Compliance" category that clearly lists the pricing for both scans. Ideal for enterprises in finance, healthcare, and other compliance-sensitive industries to automatically intercept sensitive PII and inappropriate content as messages flow in and out. (Previously: the platform lacked a configurable PII and content safety scanning defense line — sensitive data and inappropriate content could only be gated manually or by external systems, and scanning fees had no corresponding pricing category to reference.)
* **Comprehensive Data Access Permission Hardening**: This release systematically hardens the platform's data access permissions. All organization-bounded data — member lists and permissions, AI assistant settings (including database connections and system prompts), knowledge base document content, conversation details, and usage statistics — is now strictly restricted to the caller's own organization; cross-organization access is uniformly denied without revealing whether the resource exists. Sensitive information such as credit balances, transaction details, usage statistics, billing invoices, and API request logs now requires the corresponding read permission to access (previously only the frontend menu blocked this — direct API calls could bypass it). In addition, members deactivated via identity sync immediately lose call center access and no longer receive handoff notifications containing customer conversation content. (Previously: obtaining another organization's identifier allowed cross-organization reading of member PII, database connection strings, full system prompts, and knowledge base documents; any member could read organization-wide billing and credit data without authorization; deactivated members retained call center access.)
* **Credential & API Key Protection Hardening**: Comprehensively hardened the protection of API keys and integration credentials. API keys are now shown in full only once at creation time; the system no longer stores them in plaintext or returns them via any API (all existing plaintext has been purged), the list shows only masked values, and the now-useless copy button has been removed. When editing LINE, Telegram, Webhook, LDAP, and similar settings, forms no longer backfill credential plaintext, and instead present a "configured / leave blank to keep unchanged" state. Also fixed interference from browser password managers: machine credential fields across the site now use a dedicated masked input, so users' login passwords are no longer auto-filled into channel credential fields and no credential dropdowns pop up while typing. (Previously: API keys were stored in plaintext and retrievable via API, edit pages displayed credential plaintext, and browsers auto-filled users' login passwords into credential fields, causing credential errors and password leakage risk.)
* **Signed Media File URLs: Safer, Time-Limited File Links**: Media file access security has been fully upgraded. Knowledge base documents, file links cited in AI replies, AI-generated images, avatars, AI presentation template thumbnails, meeting record audio files, and more are now served via time-limited signed URLs: links automatically expire after 1 hour by default, any access without a valid signature is rejected, and storage can be set to private. Historical data is fully compatible — legacy files are also automatically reissued signed URLs on read, and contact avatars, presentation thumbnails, and meeting record playback have each been verified to work. Deployment to the cloud production environment is complete, and on-premises deployments support the same mechanism. (Previously: all media file URLs were permanently valid public download links; anyone with the link could download files indefinitely with no way to revoke access.)
* **Web Chat Embed Origin Verification Hardening**: Hardened the communication security of the Web Chat embed widget (in response to customer vulnerability scan AppScan 11347). Cross-window messages between the embed widget and its host page are now locked to a browser-verified counterpart origin via a handshake mechanism: sensitive messages are sent only to the confirmed embedding page, and incoming control messages are verified to originate from the parent window, preventing other scripts on the same page from intercepting or forging them. Existing customers' embedding setups are completely unaffected. (Previously: cross-window messages used a wildcard target origin and did not verify message sources; the vulnerability scan flagged this as an overly permissive messaging policy.)
* **Vulnerability Scan Fixes (ZAP DAST)**: Completed fixes for all 3 medium-risk findings reported by the third-party dynamic vulnerability scan (ZAP DAST): hardened the API's Content Security Policy (adding form submission and base URL restrictions) and eliminated the sources of API documentation strings being misidentified by scanners as error messages and SQL source code leaks. When customers rescan the platform for security, these 3 findings will no longer appear. (Previously: the vulnerability scan report contained 3 medium-risk findings, 1 of which was a real gap in the Content Security Policy.)
* **Anonymous Conversation Attachment Upload Limits**: Added anti-abuse protection for attachment uploads by anonymous Web Chat visitors: at most 30 uploads per minute per source IP, at most 50 unsent draft attachments per conversation, and a total size cap of 500 MB. The quota counts only attachments that are "uploaded but not yet sent with a message," so a regular visitor's quota is released once they send the message and normal customer-service scenarios will not get locked out; uploads by logged-in users are completely unaffected. (Previously: anyone with a conversation identifier could upload attachments anonymously without limit, with each upload consuming virus scanning, storage, and knowledge base processing resources.)

### 🛠️ Bug Fixes

* **Code Interpreter File Persistence Across Steps**: Fixed a Code Interpreter file retention issue: when the AI assistant performs multi-step data processing (for example, cleaning data first, then producing an Excel report), intermediate files are now reliably preserved between steps and no longer lost due to execution environment restarts, so large-data report tasks can complete successfully. The assistant's tool usage guidance was also strengthened: when a file is temporarily missing from the workspace, the assistant first confirms the file location and loads it from the knowledge base instead of incorrectly telling the user to "please re-upload the file." (Previously: intermediate files from multi-step tasks were unreadable in the next step, Excel reports could never be produced, and the assistant misjudged the environment as reset and asked users to re-upload files.)
* **MaiGPT Clearly Announces Disabled Capabilities**: Fixed MaiGPT's awareness gap regarding disabled capabilities: when an administrator disables certain tools, skills, or connectors (for example, image generation) via a MaiAgent role, MaiGPT now clearly knows which capabilities are disabled and, the first time a user asks, explicitly states in the user's language that it cannot perform them — it no longer claims it can, pretends to be processing, or fabricates execution results. The announcements use the same capability names as the permission settings page, aligning administrators' and users' understanding. (Previously: when tools, skills, or connectors were disabled, MaiGPT was completely unaware, would answer "I can generate that image for you" and pretend to execute, never admitting it could not.)
* **Post-Deletion Lifecycle Fix: Schedules Properly Stop, No More Ongoing Charges**: Fixed lifecycle cascading for delete operations: after deleting an AI assistant or organization, its scheduled tasks now properly stop — no longer continuing to run AI replies in the background, deduct credits, or query customers' production databases. The same mechanism's other gaps were also systematically patched: API access for deleted organizations is revoked immediately, a member's calendar subscriptions and related caches are cleaned up upon member deletion, and audit and billing records are correctly written in all deletion states; the cleanup scope for temporary deactivation versus permanent deletion is now clearly distinguished, so reinstated members' functionality is not affected by mistake. (Previously: schedules of soft-deleted AI assistants and organizations kept running and charging, API keys of deleted organizations could still be called, and external subscriptions were not revoked after member deletion.)
* **Cascade-Delete Conversation Platforms When Deleting an AI Assistant**: Fixed platform cascading when deleting an AI assistant: bound conversation platforms (Web Chat, LINE, Slack, etc.) are now deleted along with the AI assistant, no longer lingering as orphans in the Agent store. Reasonable history visibility is preserved — for platforms removed via AI assistant deletion, their conversation history remains viewable; the history-hiding behavior when a user actively deletes a single platform is unchanged. (Previously: deleting an AI assistant only unlinked platforms without deleting the underlying channels, and the Agent store kept showing ownerless orphan platforms.)
* **Customer Service Settings Fix: Deactivated Members Auto-Removed, Restricted Roles No Longer Hit Permission Errors**: Fixed two long-standing pain points in customer service human-handoff settings. First, when deactivated or deleted members linger in the list, saving no longer fails wholesale: the system now automatically removes these members on save and updates the UI accordingly, so administrators no longer have to manually track down which member caused the error. Second, roles with only customer-service conversation permission no longer trigger a global error caused by insufficient member-query permission when opening pages such as assignment and notification settings, conversation labels, transcript speakers, and MaiGPT sharing targets — member roster queries now uniformly go through a minimal-permission roster interface that exposes only the necessary fields. (Previously: deactivated members lingering in the list caused the whole settings save to be rejected with no clear reason, and restricted roles triggered permission error popups when opening customer service settings.)
* **Fixed Suggested Questions Not Showing in Web Chat Embed Mode**: Fixed suggested questions never showing in Web Chat embed mode. Previously, when Web Chat was embedded in a website, the chat window started collapsed, so the system wrongly concluded the content had not loaded and never retried, leaving suggested questions permanently hidden and visitors unable to use quick questions; after the fix, expanding the chat window correctly shows the suggested questions, with no regressions in standalone-page, no-welcome-message, and after-asking scenarios. (Previously: suggested questions in embed-mode Web Chat never showed, so visitors could not click quick questions.)
* **Fixed Embed Window Opening Position Setting Not Taking Effect**: Fixed the embedded Web Chat window's opening position setting not taking effect. Previously, the floating window did not follow the administrator-configured position on first open; if the site hid the launcher button via styles, the window could even be pushed to the top-left corner of the screen, and the wrong coordinates were immediately remembered so every subsequent open was wrong; resizing the browser window also permanently overwrote the position setting. After the fix, the window opening position is properly anchored to the setting, the position is remembered only when the user actively drags or adjusts it, and incorrect legacy position records are automatically reset. (Previously: the embedded chat window could open in the wrong position (such as the top-left corner) and the wrong position was permanently remembered, rendering the position setting useless.)
* **MCP Apps Interactive Card Fix and Wider Card Width**: Fixed MCP Apps interactive cards in conversations failing to load and respond to interaction, and relaxed the card display width. Previously, interactive cards (such as train timetable cards and bus arrival boards) never loaded data due to a communication protocol version gap, leaving the screen stuck at "Waiting for data..." with interactive buttons unresponsive to clicks; after the fix, cards in both new and legacy formats can properly connect, load data, and interact, legacy cards in message history are also recovered, and both Web Chat and the conversation platform chat preview are fixed in sync. In addition, cards were previously constrained to a 448px width, squeezing multi-column content on tablets and desktops; cards now decide their own width, with mobile display unaffected. (Previously: interactive cards were forever stuck at "Waiting for data..." with no response to interaction, and cards were locked into a narrow column on tablets/desktops.)
* **Fixed No Alerts on Connector Authorization Service Failures**: Fixed third-party connector authorization failures being silently swallowed. Previously, when a connector's (such as Google Analytics or Asana) authorization provider had an outage, the error was shown only to the user performing the operation, and the platform operations side received no notification at all — the previous two connector outages were only discovered after users reported them; after the fix, authorization flow failures are reported to the monitoring system in real time, and a new daily automatic health check proactively probes each provider's authorization endpoints, so provider-side anomalies can be proactively detected and handled before the impact spreads. (Previously: connector authorization provider outages could only be discovered when users hit them and reported back, with no alerts on the operations side.)
* **Fixed Canvas Charts Disappearing**: Fixed Canvas charts disappearing for no reason. Previously, AI-generated Canvas HTML charts could render as a blank area while the surrounding titles, tables, and stat cards were all fine; this could be triggered by viewing the source code and switching back to preview, or during streaming generation. After the fix, a clean preview environment is rebuilt before every render, so charts display reliably through repeated view switching and previews during streaming generation. (Previously: Canvas charts could turn into a fixed-height blank area, especially after switching to the source code view.)
* **Shared Conversations Correctly Display Canvas Content**: Fixed an issue where canvas content in MaiGPT shared conversations was displayed as raw source code. Previously, when a canvas web page produced by the AI in a conversation was shared with other members, the shared view page only showed a long string of HTML source code that could not be read normally. After the fix, shared content preserves its full structure, text and canvas sections are precisely restored, and the canvas renders correctly in a secure sandbox; existing legacy share links are also fixed through data backfill, and the canvas likewise displays normally after copying a shared conversation. This change also excludes creator-private data such as AI thinking processes and tool execution records from shared content, strengthening privacy protection for cross-member sharing. (Previously: Canvas content in shared conversations was displayed as HTML source code, and members receiving the share could not view the rendered canvas.)
* **LINE Message Handling Fixes**: Fixed two LINE channel issues. First, the official format attributes of LINE Flex message templates were mistakenly rewritten by the system when saved, so the entire style set was discarded when sent to LINE, cards displayed as blank bubbles, and the admin preview showed no abnormality — 102 templates in production were affected; after the fix, format data is preserved as-is and all existing damaged templates are automatically repaired. Second, messages from LINE multi-person chat rooms failed during processing due to a gap in source-type detection, and the error was swallowed, causing messages to disappear silently; after the fix, unsupported sources leave a clear alert so operations can track the number of missed messages. (Previously: Flex message cards displayed as blank bubbles in LINE; chat room messages disappeared silently with no record at all.)
* **Teams Channel Fixes**: Fixed two Teams-related issues. First, OneDrive images uploaded via Teams were misclassified as general attachments due to a hard-coded file type label, so the AI assistant could not perform visual understanding on them; after the fix, images are correctly identified by their actual file type and the vision feature works normally again. Second, tool calls from member nodes in team mode were previously missing the credit gating mechanism, so tool executions performed no balance pre-check and were not billed; after the fix, they use the same gating flow as single-assistant mode, restoring consistent credit management. (Previously: Images uploaded via Teams could not be visually understood by the AI; tool usage in team mode bypassed credit checks and billing.)
* **Knowledge Base Stability & Correctness Fixes**: Fixed four knowledge base issues. First, structured files such as spreadsheets, CSV, and JSON were incorrectly merged into giant chunks before chunking, and sending whole chunks to the model during retrieval caused conversation credit costs to spike (in an actual case, a single conversation rose from 234 to 1,899 credits); after the fix, the correct one-row-per-chunk granularity is restored (existing affected files must be reprocessed for the fix to take effect). Second, oversized custom file fields could crowd out chunking space, degrading retrieval quality and inflating costs at best, or causing file processing to fail outright at worst; after the fix, custom fields no longer consume the chunking budget. Third, files stuck during processing previously had to wait up to 24 hours before being marked as failed; they are now automatically detected within as little as 1 hour, and once past the threshold they can be manually reprocessed. Fourth, when a file had more than 20 custom fields in the file details window, some fields were mislabeled as "deleted from definitions"; after the fix, all field definitions are fully loaded and displayed correctly. (Previously: Broken chunking granularity for structured files caused credit spikes, large numbers of custom fields caused processing failures, stuck files had to wait a day, and custom fields were mislabeled as deleted.)
* **Fixed Multiple Defects Caused by Duplicating AI Assistants**: Fixed multiple defects in the AI assistant duplication feature. Previously, a duplicated assistant lacked group inbox permissions, so non-owner members could not see it at all in the assistant marketplace; connectors configured on the original assistant were also not carried over to the new one; and duplicating a team entry assistant returned a server error outright due to an internal system conflict. After the fix, the duplication flow fully syncs group access permissions, copies connector settings, and duplicating a team entry assistant completes normally. (Previously: Duplicated assistants were invisible to other members, connectors were lost, and duplicating a team entry assistant caused a server error outright.)
* **MaiGPT Model List Display Rule Fix**: Fixed the display rules for the MaiGPT model list. Previously, the model selector's filter conditions were stricter than the backend definition, so some authorized models (such as several Gemini-series models) did not appear in the menu — a customer actually reported selecting 5 models but seeing only 3; meanwhile, the permission settings page listed all models, so administrators could authorize models that were unselectable on the conversation side, creating a gap between "authorized but unselectable". After the fix, the selector fully displays all eligible authorized models, and permission settings and the conversation side share the same evaluation rules, making the display criteria fully consistent. (Previously: Some authorized models did not appear in the MaiGPT model menu, and permission settings did not match the actual selectable list.)
* **Fixed Missing Redirect to Original URL After Login**: Fixed an issue where users were not redirected back to the original URL after login. Previously, when opening a bookmark, shared link, or link from a notification while logged out, users were always taken to the home page after logging in and had to find the target page again on their own. After the fix, both regular login and SSO login correctly return to the page originally requested (including query parameters), and external URL protection has been strengthened so malicious off-site redirect links are explicitly rejected. (Previously: Users always landed on the home page after login, and redirects for deep links, bookmarks, and notification links all failed.)
* **Fixed Service URL Not Prefilled When Editing Self-Hosted Model Credentials**: Fixed an issue where the service URL was not prefilled when editing self-hosted model credentials. Previously, when editing credentials for vLLM or OpenAI-compatible providers in AI Gateway, the service URL field appeared blank; if a user only updated the key and saved, the blank value overwrote the existing service URL setting on the backend, disconnecting the self-hosted model. After the fix, the edit dialog automatically prefills the existing service URL, and required fields that have been cleared are blocked at save time, preventing accidental damage to connection settings. (Previously: The service URL appeared blank when editing credentials, and saving after only changing the key cleared the service URL and broke the connection.)
* **Fixed Credentials Being Wiped When Editing Tools**: Fixed an issue where credentials were silently wiped when editing a tool. Previously, tool credentials such as API keys were masked on read, but the edit form still loaded them the old way and received empty values. As a result, simply opening the edit form and saving (even if only the description text was changed) would wipe the configured keys without any error message, and the problem would only surface when the tool failed on its next execution. After the fix, the edit form correctly displays masked credentials, unchanged credential fields are never submitted in updates, and the backend keeps the original values. (Previously: editing any tool and saving could silently wipe its keys, causing subsequent tool executions to fail.)
* **Fixed Blank Names in the Connector Selection Modal**: Fixed an issue where names appeared blank in the "Select Connector" modal. Previously, when creating an AI assistant, connectors without a display name (such as Microsoft 365) showed an entirely blank name row in the selection list; users could only see the icon and enabled status, making it hard to identify which item to check. When the list failed to load, it was also incorrectly shown as "No data". After the fix, unnamed connectors automatically display their type name (search included), with added placeholder display for failed icon loads, a load-error message, and a retry button. (Previously: unnamed connectors showed blank rows that were hard to identify, and load failures were mislabeled as no data.)
* **Fixed Flickering Channel-Count Badge on AI Assistants**: Fixed an issue where the channel-count badge flickered on the AI assistant settings page. Previously, when switching tabs on the settings page, the channel-count badge next to "Conversation Platforms" would disappear first and reappear only after the data reloaded, flickering on every switch. After the fix, the badge immediately shows the last known value when switching tabs and updates silently once the data returns, keeping the visuals stable. (Previously: every settings tab switch made the channel-count badge disappear and flash back.)
* **Frontend Intermittent Error Fixes (Three Long-Standing Production Issues)**: Fixed three long-standing intermittent frontend errors. First, the AI assistant settings page threw a program error outright when the selected model had been retired, organization permissions had changed, or data was still loading; after the fix, it degrades gracefully. Second, for members without AI assistant view permission, associated-assistant tags on screen generated invalid links and triggered errors; after the fix, they render as plain-text tags showing the name but not clickable. Third, network timeout and disconnection errors were previously all lumped into a single unanalyzable report; after the fix, they can be properly classified by message. (Previously: the three errors had occurred steadily every day since June, affecting more than 150 users in total.)
* **Login Method Settings Protection**: Strengthened protection for organization login method settings. Previously, when the settings page failed to load the existing configuration, the screen silently fell back to the default state of "platform account and password login"; administrators could not tell anything was wrong, and pressing Save at that point would unknowingly overwrite and clear the existing SSO configuration. After the fix, a load failure clearly displays an error message and a refresh entry point, and the save function is suspended, ensuring administrators only make changes when they can see the true current state. (Previously: when settings failed to load, the screen showed an incorrect default state, and saving would mistakenly delete the existing SSO configuration.)
* **Fixed Server Error Caused by the FAQ Knowledge Base Field**: Fixed a server error in the FAQ management API. Previously, when creating or updating an FAQ via the API, any request that included the knowledge base field triggered a server error (500) outright, affecting 8 users in production. Since an FAQ's ownership is determined by the URL path anyway, after the fix the field is read-only and safely ignored; including it no longer affects the operation, and requests complete normally. (Previously: FAQ create/update requests carrying the knowledge base field always returned a server error.)
* **Fixed Multi-Line Input Text Flush Against the Left Edge**: Fixed an issue where text in multi-line input fields in the admin panel sat flush against the left edge. Previously, multi-line input fields in forms (including Team+ channel keys, AI assistant instructions, tool prompts, knowledge base file content, and 10 locations site-wide) had placeholder text and input content pressed against the left edge, inconsistent with the indentation of regular single-line inputs and visually jarring. This update removes an invalid style override left over from a 2021 template, restoring correct padding to multi-line inputs so they visually align with other input fields. (Previously: placeholder text and content in multi-line inputs sat flush against the left edge, inconsistent with regular input indentation.)
* **Conversation Attachment Handling Fixes**: Fixed three handling issues with conversation attachments. First, when an anonymous Web Chat visitor removed an attachment not yet sent, the attachment disappeared on screen but the server actually rejected the deletion; the file remained within the conversation's knowledge retrieval scope, and the AI's subsequent replies kept citing content the user believed was deleted. After the fix, visitors can properly delete their own uploaded draft attachments, with the existing cross-organization protection fully preserved. Second, deleting an attachment already referenced by a knowledge base triggered a server error outright; after the fix, the association is handled correctly—only the conversation-side record is removed, and files the user saved to the knowledge base are unaffected. Third, after an associated Hook was deleted, the attachment list still showed stale items and saving was rejected; after the fix, stale items are automatically hidden and cleared on the next save. (Previously: visitor attachment deletion had no effect and the AI kept citing the content, deleting knowledge-base-associated attachments returned a server error, and stale items lingering in the Hook attachment list caused save failures.)
* **Fixed Conversation List Preview Not Updating After Message Edit**: Fixed an issue where the conversation list preview was not updated in sync after editing a message. Previously, after editing a message on the conversation platform, only the operator's own screen would update, while other tabs or other support agents' conversation lists still showed the old pre-edit preview and required a manual refresh to sync; after the fix, the latest preview is broadcast in real time as soon as the edit completes, so all screens update in sync without affecting the list order. (Previously: after editing a message, other agents' conversation list previews kept the old content and required a manual refresh.)
* **API Conversation (Completions) Stability Fixes**: Fixed five issues in the API conversation (Completions) interface. First, streamed reply text in agent and team modes was not written to the standard content field, so every reply received by external integrations that relied on that field was empty, which once caused a major customer's public-facing service to continuously display "the system is temporarily unavailable"; after the fix, the content field works correctly again. Second, replies with citation sources triggered a server error when assembling the final frame; this has been fixed. Third, assistants configured with JSON output format previously returned a server error outright when formatting failed; they now return a normal response containing the original answer plus an error explanation. Fourth, the system errored when some model providers returned nested structured-output content as strings; this is now parsed with automatic fault tolerance. Fifth, switching a conversation to an organization custom model via the API was mistakenly rejected as an invalid model; this has been fixed. (Previously: agent/team mode API reply content was empty, cited replies threw server errors, JSON formatting failures failed entirely, provider stringified output errored, and switching to custom models was rejected.)
* **Fixed File Presentation Tool Falsely Reporting File Not Found**: Fixed an issue where the AI assistant file presentation tool falsely reported files as not found. Previously, after the assistant produced files such as presentations or reports, contradictory internal descriptions of the file path format caused genuinely existing files to be falsely reported as "not found"; the assistant kept retrying until it exhausted its execution attempts, the entire reply round was aborted, and the user never received a download link. After the fix, files are correctly located and made available for download regardless of which path format is used. (Previously: files that clearly existed were falsely reported as not found, the assistant retried up to the limit and the reply failed, and the user never got the files.)
* **Fixed Query Failures After Idle Database Connection Drops**: Fixed an issue where the database query feature failed after idle connections were dropped. Previously, when a Text2SQL assistant's database connection was proactively closed by the infrastructure after being idle for over 30 minutes, the system could not detect it, and the next query would fail outright with a connection-dropped error, with the raw error message even appearing in the conversation. After the fix, the system automatically validates each connection before use, transparently replaces invalid ones, and periodically recycles them, so queries after idle periods are stable again. (Previously: the first database query after a period of idleness failed with a connection-dropped error.)
* **Explicit Error Reporting for Malformed Knowledge Base Citation Filter Conditions**: Strengthened error reporting for knowledge base citation source filter conditions. Previously, when setting contact label filter conditions via the API, if a field name was mistyped, the system would accept and store it as usual, but the condition was silently skipped during actual queries — the caller believed knowledge base access had been restricted when in fact no filtering occurred at all, creating a security risk. After the fix, malformed conditions are rejected immediately upon submission with a clear error report, making the validity of the configuration obvious at a glance, and custom fields already in use by existing customers are unaffected. (Previously: mistyped field names in filter conditions were silently ignored, leaving permissions broader than expected with no warning at all.)
* **Voice Assistant Waiting Animation Stays Visible**: Fixed an issue where the waiting animation on the voice assistant site disappeared prematurely. Previously, the animated icon (OhBear) shown while waiting for the AI reply was dismissed as soon as the first fragment of the reply arrived, but on that site replies typically begin with hidden tool executions or thinking processes, so no visible content was on screen yet, resulting in a blank box or a gap where the animation vanished leaving only the avatar. After the fix, the animation stays visible until the first genuinely visible content appears, and the tool-execution and general thinking animations now toggle correctly in a mutually exclusive manner. (Previously: the animation disappeared prematurely while waiting for a reply, leaving a blank box or gap on screen.)

## v2026.08.03 <a href="#v2026-08-03" id="v2026-08-03"></a>

***

### ✨ New Features

* **Custom Evaluation Metrics and Multi-Turn Conversation Evaluation**: Evaluations can now include up to 10 custom metrics (with custom names and scoring criteria); adds multi-turn conversation evaluation, where a simulated user converses back and forth with the real AI assistant and is scored on three metrics: faithfulness, relevancy, and conversation completeness. (Previously: evaluations could only use fixed built-in metrics and supported single-turn Q\&A only, unable to simulate the real scenario of multi-turn back-and-forth between a user and the AI assistant.)
* **BYOK Support for Compatible Model Services**: The add-credential form now offers an OpenAI-compatible provider option (service URL required, key optional); Anthropic credentials can also specify a custom service URL to route through a compatible forwarding endpoint. (Previously: the backend had long supported OpenAI-compatible third-party model services (such as forwarding services and self-hosted services), but the frontend credential form had no such option, so admins had no way to configure them.)
* **Attachment-Aware Reply Review**: The review process can now access non-sensitive information such as attachment counts by default, with an optional image re-review that lets a multimodal model actually inspect the current message's images within a controlled scope before making a judgment; behavior is completely unchanged for those who do not enable it. (Previously: reply review could only see text and could not distinguish "the AI assistant ignored the customer's uploaded screenshot" from "answered correctly based on the screenshot", so text-only rules could mistakenly rewrite replies that were already correct.)
* **Conversation Attachment Storage Billing and Deletion Countdown**: Attachment cards in the conversation panel show a "deleted in N days" countdown with a tooltip explaining costs and activity-based resets; the billing page adds names and descriptions for attachment-storage credit items (the retention period follows the system settings), so users have clear awareness before attachments are cleaned up. (Previously: the backend began charging storage credits for conversation attachments and automatically cleaning them up after a period of inactivity, but the frontend gave no indication — users did not know attachments would be deleted and could not see descriptions of the new billing items.)
* **Individual Toggles for AI Assistant Built-in Tools**: The assistant settings page adds a "Built-in Tools" section where each of the 7 built-in tools has its own toggle with a plain-language description, so they can be enabled or disabled individually; users without edit permission can only view, with toggles shown as disabled. (Previously: the AI assistant's 7 built-in tools could not be controlled individually, so admins could not turn off specific tools as needed.)
* **Dynamic Variables in Connector Auth Credentials**: Connector authentication settings can use variable placeholders that automatically substitute the current conversation's source, conversation, contact, channel, and organization information when calling external services; connectors without variables behave exactly as before. (Previously: connector auth headers could only contain fixed strings, with no way to dynamically pass contact, conversation, or organization identifiers to external systems based on the current conversation.)
* **Deep Research Credit Estimation and Quota Pre-Check**: Before execution, the AI shows an estimated credit cost in the research plan confirmation message (inferred from the median of the organization's recent runs, with a disclaimer); at execution time, a triple precise pre-check runs against organization credits, personal quota, and channel quota — if the quota is insufficient, the AI assistant explains in natural language, the conversation continues uninterrupted, and the research plan is kept for further adjustment. On-premises deployments with credits disabled show none of this text. (Previously: the credit mechanism only checked whether the balance was above zero, while a single deep research run can consume tens of thousands to over a million credits, so members allocated only a small number of credits could still run research far beyond their quota, causing major overruns.)
* **Numbered Conversation Starter Options**: With this setting enabled, starter options are displayed numbered "1., 2., 3." in order, exactly matching the order the AI assistant understands; users can reply with just the number to select the correct option, while clicking an option still sends the original option text without the number. (Previously: starter options had no numbers, so once the greeting and option list were provided to the AI assistant, a user replying "2" had no corresponding number on screen to match against, easily leading to mismatched answers.)
* **Separate Billing for Image Embedding Usage**: Image embedding usage is now a dedicated credit item billed at the image rate, so bills and usage statistics show text and image items separately. (Previously: image embedding actually costs about 4x as much as text, but its usage was merged with text and billed at the text rate, so bills could not reflect true costs and image usage was invisible.)
* **Inbox Channel Credit Quota Management**: The organization credit usage page adds a "Channel Quota" sub-tab for distributing credit quotas to individual channels and viewing their usage; the inbox settings page provides a quota summary card and lets you configure multilingual over-quota messages so a channel shows a custom notice when its quota runs out. (Previously: credit quotas could only be allocated per member, with no way to set usage caps for individual inbox channels, and no customizable message when a channel exceeded its quota.)
* **MCP App Cards Support Tool Sources**: Cards now correctly report their own source during interaction, so tool-generated cards can execute actions and pass authorization confirmation; multiple cards display independently without overwriting each other, and cards from existing connector sources behave unchanged. (Previously: after the backend consolidated connector bindings into a single tool track, pressing a button on a tool-generated interactive card left the system unable to identify the card's source and it refused to execute; cards from different sources could also overwrite each other due to duplicate identifiers.)
* **Standalone Real-Time Voice Prompt Setting**: The real-time voice prompt is split out of the role instructions into its own field, so voice-specific instructions can be written separately; save validation now uses interface-language-independent logic, automatically expanding the misconfigured settings section and showing a clear error message when input is invalid, and summary labels no longer overflow the layout on small screens. (Previously: real-time voice behavior instructions were mixed into the same settings as the role instructions and could not be tuned separately for voice scenarios; additionally, in the English and Korean interfaces, clicking save with invalid input could do nothing at all, with no error message shown.)
* **SeedDance Video Generation Tool**: Adds the SeedDance 2.0 video generation tool in standard, fast, and lite versions; when the primary service fails, it automatically switches to the fallback service with no user impact; billing now uses credits based on generation usage and is displayed merged with the existing video generation item on the pricing page. (Previously: the platform offered only a single video generation tool, with no way to choose video generation options at different speed and quality levels.)
* **Hang Up Active Calls in the Call Center**: The call history page adds a "Hang Up" action: shown only for calls that can be hung up, with a red confirmation dialog to prevent accidental clicks, and the list updates immediately after a successful hang-up; the status column is now display-only and statuses can no longer be changed manually. (Previously: there was no way to hang up an in-progress voice call — when something went wrong, engineers had to operate the underlying service directly; the call status column could also be changed arbitrarily, easily producing dirty data.)
* **SynxDB Credential Settings in Knowledge Bases**: The knowledge base form provides username and password fields, required-field validation, and a connection test for SynxDB, and edit mode shows a summary of existing credentials, so SynxDB knowledge bases can be created and saved normally. (Previously: the backend already supported the SynxDB vector database, but the knowledge base form did not recognize its credential type: after selecting SynxDB there were no username and password fields to fill in, and every save was rejected by the backend with "username and password required".)
* **Team+ Channel Integration**: Adds a Team+ channel type following the same creation flow as existing channels like LINE and Telegram: select the channel, fill in the Team+ credential settings, and complete creation, with a channel icon and interfaces in five languages. (Previously: the inbox channel integration options lacked Team+, so customers could not connect Team+ accounts to MaiAgent.)
* **URL Query Parameter Settings for API Tools**: Tool settings add a dedicated query parameter field supporting the same template variables and validation as headers; configured sensitive parameters are excluded from execution logs, automatically masked before saving, and matching values in error messages are scrubbed as well. (Previously: some external services accept keys only via URL query parameters, so in the past keys had to be written in plain text into the tool's URL field — neither secure nor easy to maintain.)
* **Trial Invitation Code Auto-Activation Flow**: Operations can issue single-use invitation vouchers valid for 14 days; customers who register with a voucher are automatically approved and granted the trial, with the binding automatically reported back to the CRM; registrations without a voucher still go through manual review. (Previously: all newly registered organizations went into the manual review queue, so even target customers invited by sales had to wait for review before starting their trial.)

### 🚀 Core Performance Optimization

* **Major Speedup in Conversation History Reads**: After adding the correct index, measured reply throughput increased 2.1x, median time to first token dropped from 1.8 seconds to 0.37 seconds, and median generation time dropped from 8.1 seconds to 1.4 seconds. (Previously: the conversation memory storage table lacked a query index, so every reply required a full table scan to read conversation history — slower as data grew — and under high concurrency the entire reply pipeline was stalled by the database, with adding servers having no effect.)
* **Claude Prompt Caching on the Compatible Interface**: Request assembly now attaches cache markers in the correct positions; in real agent conversations, measurements show over 70% of input now bills at the cached rate. No provider settings need changing and no credentials or model lists need rebuilding, and the gains stack directly on top of the existing native-path fix. (Previously: using Claude through the OpenAI-compatible interface got no prompt caching at all — not a configuration issue, but because the request format simply carried no cache markers, so every conversation turn paid the full input cost.)
* **Video Generation Fallback Provider Switching**: When the primary provider fails or times out, the fallback provider automatically takes over (waiting up to 300 seconds); on success, the same file storage and notification flow is used, and credits are still settled only once. (Previously: video generation relied on a single provider, so a temporary outage, quota limit, or task timeout (over 120 seconds) meant outright failure.)
* **Long-Term Memory Writes No Longer Slow Down Replies**: Long-term memory writes now run in the background, so users no longer wait for them; measured tail latency for time to first token dropped 38% (from 5.3 seconds to 3.3 seconds), with zero write loss. (Previously: once a conversation reached a certain length, long-term memory consolidation and writing ran synchronously while the user waited for a reply, so the affected message took several extra seconds (tail latency could exceed 8 seconds).)
* **Faster Batch Conversation Updates and Organization Deactivation**: Switched to a single query and a single lock for the whole batch, greatly reducing database round trips, making batch operations and background cleanup jobs faster and more stable; API format and permission logic are completely unchanged. (Previously: several flows queried the database record by record even though they already held the whole batch, getting slower as batches grew; batch conversation updates locked each record separately — up to one hundred independent locked round trips.)
* **More Reliable Messaging Platform Attachment Downloads**: Attachment downloads gain timeout and automatic retry mechanisms, and failure states are recorded and observable; on certain paths, the risk of "messages silently lost" is converted into "duplicate delivery in rare cases", ensuring messages never vanish without a trace. (Previously: downloading user attachments from the various messaging platforms had no timeout protection, no retry on failure, and no record after failure, so attachments could quietly go missing with no way to trace them.)
* **Faster Delivery of Finalized Web Chat Replies**: The finalized message is now sent directly at the moment the reply is produced, no longer detouring through the background queue; measured latency for this stage dropped from about 9.2 seconds to about 1 second. (Previously: after a streamed reply finished, the final finalized message had to pass through the background task queue before reaching the frontend, and under high concurrency the queue backed up — this stage alone took about 9 seconds.)

### 😊 User Experience & Interface Optimization

* **AI Assistant Monitoring Dashboard**: The monitoring page adds a dashboard: key metric overview cards, multi-dimensional trend charts for response time / error rate / processing speed / quality score, a model distribution chart, and an AI assistant ranking table, with drill-down from charts to the conversation records of the corresponding time period. (Previously: the monitoring page lacked an overall overview, so trends across service metrics could not be seen at a glance and AI assistants could not be compared.)
* **Revamped AI Assistant Edit Page Navigation**: The assistant edit page has been fully revamped: it now uses grouped vertical settings navigation, with main tabs at the top of the page for "Settings, Usage Analytics, Inbox, API Integration, Webhook"; settings are grouped by topic for easier discovery, and breadcrumb navigation is consistent with the rest of the site. (Previously: the old assistant edit page used a left-hand list with horizontal tabs, so settings were scattered with unclear hierarchy and finding a setting meant switching back and forth.)
* **Audio Source Hint in Credit Consumption Details**: The always-present audio source column is removed; the source (microphone or system audio) is now shown as a hover hint next to speech-to-text items, consistent with the detail table's existing hint style. (Previously: the consumption record detail table added an "Audio Source" column for every item, but only meeting record speech-to-text had a value — all other items always showed "-", wasting space and misleading people into thinking data was missing.)
* **Editable Evaluation Task Names and Descriptions**: Each row in the evaluation list adds an edit action for modifying the evaluation's name and description in a dialog; editing is available in any state (running / completed / failed). (Previously: once an evaluation task was created, its name and description could not be changed, so a misnamed task or one needing extra notes could only be recreated.)
* **Role Usage Statistics Methodology Note**: The roles tab adds an explanatory notice at the top clarifying how statistics are counted: when a member belongs to multiple roles, their usage is counted in each of those roles. (Previously: role usage is the sum of the personal usage of all members in that role, so members in multiple roles are double-counted — but the page had no explanation, and a customer once reported it as a statistics bug.)
* **Hide Knowledge Base Entry Points by Role Permission**: The knowledge base selection panel and related entry points are hidden according to the member's effective permissions, so users with the capability disabled no longer see ineffective controls; the entry point for browsing organization shares is unaffected. (Previously: after a role disabled knowledge base retrieval, the knowledge base entry points on the chat page were still visible and operable, but the operations had no effect at all, and the AI assistant would even reply with misleading messages.)
* **Upgraded Chat Page Loading Animation**: The entry page now uses a "pen stroke" animation that first traces the input box outline, then fades in the content once loading completes, with positions staying continuous and jump-free; when entering via a conversation link, staggered message skeleton placeholders are shown instead, making loading feel smoother. (Previously: entering the chat page showed only a centered spinner on the right, and the greeting and input box popped in as one block only after all initialization finished, which felt jarring.)
* **MaiGPT Permission Page Features Section Now Uses Toggles**: Feature items are extracted into a standalone toggle section, clearly separated from the availability list, each with its own rule description; when the list has nothing checked, the badge shows "All" to avoid misreading it as nothing being available. (Previously: the availability list and feature items shared the same checklist layout but followed opposite rules (list unchecked = all available, feature unchecked = disabled), so admins following the page-top hint to clear the features section would accidentally turn off that role's code interpreter and knowledge base retrieval.)
* **MaiGPT Sidebar No Longer Auto-Collapses**: The auto-collapse mechanism is removed, so collapsing the sidebar is entirely up to the user, with a collapse style consistent with other feature pages; also fixes an issue where switching conversations left the previous conversation's content lingering on the canvas. (Previously: whenever any right-side panel was expanded, the left sidebar was automatically collapsed into a hidden state that only floated out on hover, did not restore after the panel closed, and behaved inconsistently with other pages.)
* **Unsupported Read-Aloud Language Notice for Meeting Summaries**: When the meeting language is outside the read-aloud support range, the summary section shows a persistent warning clearly stating that the default language will be used for reading aloud, so users do not mistake it for an error. (Previously: the read-aloud feature supports only 7 languages, and when the meeting language was not among them, clicking read-aloud silently fell back to the default voice with no notice, leading users to think the system was broken.)
* **Trial Plan Expiry Now Calculated in Whole Days**: Newly granted trials always start at midnight on the grant day and cover 14 full calendar days including that day, so expiry falls on a clean day boundary for seamless transition to a paid plan; existing trials are not retroactively adjusted. (Previously: the trial period started at the exact moment of granting, so expiry fell at an odd time of day, and transitioning to a paid plan required manual alignment, easily producing gaps or plan overlaps.)
* **No More Storage Fees for Self-Hosted Vector Databases**: The billing base now counts only platform-hosted vector storage, completely excluding the capacity of self-hosted vector databases; organizations using self-hosted vector databases exclusively no longer incur any vector storage fees. (Previously: the daily vector storage fee included the capacity of all of an organization's knowledge bases, including self-hosted vector databases whose data is not on the platform at all, resulting in credit overcharges.)
* **Improved Voice Call Connection Waiting Experience**: The initial connection wait is extended to 20 seconds, with connection progress notices shown every 5 seconds during the wait (in five interface languages); the existing failure message appears only after 20 seconds, and the waiting state ends correctly whether the call succeeds, fails, or the user leaves. (Previously: when the voice assistant was slow to start, the call was prematurely judged failed at 10 seconds; the screen gave no progress feedback during the wait, so users easily assumed the system had frozen.)
* **Voice Feature Toggle Unified at the AI Assistant Level**: Voice features are now governed by a single AI-assistant-level switch covering all three entry points, and Web Chat channels that already had voice enabled automatically inherit the setting; authorization and validation-order vulnerabilities are also patched, so public Web Chat without voice enabled no longer issues voice connection credentials to anonymous visitors. (Previously: the voice switch existed only in Web Chat channel settings, so SIP phone and admin-console voice testing could not be governed by the same switch, and several authorization and validation-order vulnerabilities existed.)
* **More Precise Credit Quota Error Messages**: Error notices now display detailed messages assembled by the backend for the actual situation and interface language (for example, including used and limit numbers); if the backend has not been updated, the original copy is still shown and existing behavior is unaffected. (Previously: quota-related errors could only show fixed frontend copy, unable to distinguish "no quota configured yet" from "quota exhausted", with no actual usage numbers shown, easily misleading users.)

### 🔐 Security & Governance Enhancements

* **Comprehensive Masking of API Credential Fields**: Credential fields are now write-only or output as masked values across the board, and frontend edit pages display masked values; contact credentials are now visible only to active members of the organization; connection-test error messages also scrub sensitive content, with comprehensive consistency tests to prevent future regressions. (Previously: read responses in many settings returned credentials verbatim in plain text, and a cross-organization logged-in user who obtained a conversation contact identifier could even read auth headers in plain text — far too large an exposure surface for sensitive information.)
* **Chat Messages Block Malicious Web Code Injection**: Web markup in messages is now governed by a strict whitelist: only safe, purely presentational effects are kept (bold, italics, line breaks, superscript/subscript, highlighting, expandable deep research progress, citation links, etc.), and everything else is downgraded to plain text display; existing features such as code blocks, math expressions, ordinary links, and tables are unaffected. (Previously: raw web markup in chat messages was executed directly as a web page, so malicious content — whether from user input, AI replies, or knowledge base documents — could run code in the browsers of other users or admin-console administrators, constituting an exploitable security vulnerability.)
* **Conversation Attachment Deletion Permission Fix**: Deleting an attachment now requires being logged in, being a member of the organization, and having access to the conversation; cross-organization deletion requests are always blocked. The existing flow for anonymous visitors uploading attachments is unaffected. (Previously: the endpoint for deleting conversation attachments performed no identity or ownership verification at all, so anyone who knew or guessed an identifier could delete other people's — even other organizations' — conversation attachments.)
* **Tightened External Conversation Access Permissions**: Access is now verified per individual AI assistant — members must actually be linked to that AI assistant (or be the organization owner) to join the conversation room; a room-naming collision issue is also fixed, ensuring different conversations never end up in the same room. (Previously: members of the same organization with organization-level chat permission could obtain conversation identifiers of AI assistants they were not responsible for by guessing external conversation numbers; certain naming combinations could also cause different conversations to share the same real-time messaging room.)
* **AI Assistant Instruction Content Access Fix**: Instruction content is now readable only by members of the organization with builder permission, with dual isolation across assistants and organizations, so members of other organizations or without builder permission can never access it. (Previously: an AI assistant's instruction messages (i.e., system prompt content) were readable by anyone logged in — any logged-in user who guessed an identifier could see another organization's AI assistant system prompts.)
* **Shared Tool Authorization Identity Fix**: Shared tools now use only the organization-level authorization identity, and personally bound tools use only the personal authorization identity — the two are no longer mixed; shared tools that have not completed organization authorization are simply hidden, avoiding unusable tools or misleading linked-account prompts. (Previously: after an admin completed organization-level account authorization for a shared tool, its actual execution could be quietly overridden by some member's personal account authorization, causing all operations to be sent under the wrong personal identity.)
* **Strengthened Code Sandbox Network Isolation**: Network isolation is enforced at sandbox creation and actively verified after startup — if any reachable dangerous target is detected, the sandbox is immediately destroyed and execution refused, turning isolation from "assumed effective" into "provably effective". (Previously: sandbox containers could potentially reach the host's container management service and cloud metadata endpoints, which malicious code could in theory exploit to break isolation and access host resources.)
* **Tool Query Parameter Masking and Voice Conversation Fixes**: Query parameters are now write-only, with reads always returning masked values; auto-reply is disabled at SIP conversation creation; and billing tracking state is properly cleaned up after conversation simulations end, so usage is attributed correctly. (Previously: three issues: reading tool settings returned query parameters in plain text (the header field had long been masked — only this field was missed); SIP voice conversation creation omitted disabling auto-reply, potentially triggering auto-replies that should not occur on calls; and billing tracking state was not cleaned up after conversation simulations ended, so usage from subsequent unrelated jobs could be attributed to the wrong party.)

### 🛠️ Bug Fixes

* **Fixed the billing gap when AI Gateway streams were interrupted**: When the upstream failed mid-stream or the client disconnected, nothing was billed at all (even though upstream costs had been incurred), and when billing itself failed there was no way to identify it and the charge was never recovered. After the fix, interrupted streams are billed according to the usage actually incurred, and requests whose billing failed are now explicitly flagged so operations staff can identify them and recover the charge manually.
* **Fixed missing translations for the API key permission option**: The name and description of the "API Key Management Permission" option on the role edit page still displayed Chinese in non-Traditional-Chinese locales. After the fix, the option name and description display correctly in the corresponding language across all five locales, with the Traditional Chinese display unchanged.
* **Fixed a server error when deleting BYOK credentials**: Deleting a BYOK credential still in use by a model returned a raw server error instead of clearly stating "the credential is in use and cannot be deleted". After the fix, deleting an unused credential completes normally and deleting an in-use credential returns a clear conflict notice; Anthropic credentials also support a custom endpoint setting, enabling connections through compatible relay services.
* **Fixed missed updates from transient calendar sync conflicts**: When two sync jobs ran simultaneously, the later-arriving calendar change notification was misjudged as a failure and left unprocessed, so calendar changes might not be reflected in meeting records. After the fix, transient sync conflicts automatically retry after a few seconds' delay (up to three times), while genuine authorization expiry or errors are still reported as failures as usual.
* **Fixed inaccurate billing for knowledge base search**: The AI assistant's knowledge base searches actually consumed model resources but were not billed at all; and when searching across multiple knowledge bases, usage from different models was merged and priced at a single rate, resulting in inaccurate billing. After the fix, knowledge base search is formally included in credit billing and priced separately by the model each knowledge base actually uses, so bill details match actual usage; searches are blocked upfront when credits are insufficient.
* **Fixed conversation failures when using Claude models through relay services**: Claude models under relay-service naming could send requests normally, but when the system read the model specs, it did not recognize the naming and the entire turn failed — users saw only "An error occurred during Agent mode processing, please try again later". After the fix, model spec lookup tries an exact match first, then a normalized-name match; if still not found but confirmed to be in the Claude family, a conservative lower bound for context length is used and the conversation completes normally; incorrect naming of non-Claude models still raises a clear error.
* **Fixed thousandfold inflation of amounts in credit usage statistics**: The unit basis of some billing items (per 1 unit or per 1,000 units) was inferred from names, causing the cost amounts of certain items in statistics reports to be inflated a thousandfold; actual credit deductions and charged amounts were unaffected. After the fix, every billing rule now explicitly records its pricing basis and freezes it at transaction time, and statistics amounts are calculated with a unified formula, completely eliminating the thousandfold error; actual credit deductions and charges for all customers remain entirely unchanged.
* **Fixed member list truncation in personal credit quota allocation**: The member list on the "Allocate Personal Quota" page was truncated at one hundred people, so members beyond that could not be allocated quota. After the fix, a dedicated member list query is added: it supports pagination, searching by name / email / member ID, filtering and sorting by quota status, and organization-wide quota statistics; sorting adds a stable secondary key to prevent batch-imported members from being duplicated or omitted across pages.
* **Fixed template application failures in the Doc Quick Entry**: Sending a message with a template selected via the document / spreadsheet quick entry was rejected by the server, showing "Network connection lost" — the feature was effectively unusable. After the fix, the way template information is sent is adjusted so the server validates it and creates an official template snapshot; sending messages with a selected template works normally again, and template card display in historical messages is unaffected.
* **Fixed duplicate credit deduction at the instant an AI Gateway stream ends**: When the client disconnected immediately as a streamed response finished, credits were deducted twice, and the amount on the usage dashboard was overwritten rather than accumulated, so the extra deduction was completely invisible — customers only discovered it by reconciling on their own. After the fix, a uniqueness constraint at the database layer eradicates duplicate transactions, the billing flow marks completion before deduction, and the cancellation timing is corrected, guaranteeing a single request is billed only once.
* **Fixed knowledge base label filters not covering file queries**: Label filtering took effect only on the vector retrieval path; when users asked by file name or similar, the AI assistant switched to the file query path where the label restriction was ignored entirely, returning files outside the specified label scope. After the fix, label filter conditions now also apply to all three retrieval methods — file query, content search, and file reading — so filtering semantics are consistent across both paths; behavior without label conditions is completely unchanged.
* **Fixed silent failures of personal authorization for external tools**: Layers of accumulated legacy design caused "tools configured successfully yet silently failing": after an admin attached an external tool requiring personal authorization, the tool never appeared in actual conversations, with no error message of any kind. After the fix, external tools converge on a single configuration path — attaching a tool expresses the intent to authorize, and it is no longer silently blocked by hidden associations and switches; existing configurations are converted automatically and personal authorization data is fully preserved.
* **Fixed indistinguishable same-name members in the meeting participant menu**: Members with the same name looked completely identical in the participant dropdown and could not be distinguished, and while the member list was loading it displayed "No data", leading users to think the organization had no members. After the fix, same-name members show their email in the option for differentiation (full details visible on hover), and a loading state is added so loading no longer misdisplays as no members found.
* **Fixed meeting recording loss caused by browser disconnections**: When the browser briefly disconnected, the meeting room was destroyed immediately, and the recording and transcript were silently cut off and lost, with no notice to the user at all (this had caused customer complaints). After the fix, a 60-second buffer period is kept after disconnection so the browser can automatically reconnect to the same meeting and continue recording; when the user stops deliberately, a new stop action finalizes and produces the file immediately, without waiting for the buffer period.
* **Fixed recent conversations being evicted from short-term memory too early**: Short-term memory capacity was fixed at a cap far below the model's actual capability, so recent conversations could be cleared out too early; when a user replied "3" to the previous turn's numbered list, the AI instead matched it against an old, outdated list (a production customer complaint incident). After the fix, memory capacity is derived from the model's actual context capability (with a higher cap while keeping the old lower bound), cleanup removes old tool results first while preserving conversation structure, and the most recent turns are kept unconditionally, so the AI correctly understands brief replies referring to the previous turn.
* **Fixed server errors on batch re-parsing of knowledge base files**: Batch requests sent in list format (such as batch re-parsing files) failed entirely due to an error in the request-recording step, returning a server error. After the fix, the request-recording step now supports both list and object formats, and batch re-parse requests execute normally.
* **Fixed database deletion jobs getting stuck**: When system connection settings were missing, the deletion job re-picked the same table every two seconds in an infinite loop, leaving the database stuck in "Deleting" status forever while continuously occupying background resources. After the fix, tables that fail deletion are explicitly flagged and skipped rather than re-picked, and round limits plus timeout protection are added, guaranteeing deletion jobs finish within a bounded time, with failure details available for investigation.
* **Fixed SSO single sign-on compatibility issues**: Three combined issues prevented some customers from completing SSO setup and login: identity service metadata fetches were blocked by protection mechanisms, standard email fields sent by non-Azure/ADFS systems were unrecognized and caused server errors, and login failures showed only a blank error page. After the fix, metadata fetches use a proper identifying header and are no longer blocked; email resolution supports the standard field formats of each identity service; and login failures now redirect back to the frontend with a clear error reason. Existing Azure AD customer behavior is entirely unchanged and fully verified in production.
* **Fixed missing human verification on registration and forgot-password**: Only the login form was wired to human verification — registration and forgot-password were missed, so in environments with human verification enabled, submissions in these two flows were always rejected and could not be completed at all. After the fix, the registration and forgot-password forms are both wired to human verification and send the verification result with the request, restoring both flows; behavior in environments without human verification enabled is completely unchanged.
* **Fixed broken table layout in Web Chat messages**: Table text in AI replies overflowed cells and crowded adjacent columns, columns were truncated and required extensive horizontal scrolling (on mobile, width could reach nearly six times the screen), and cells in the same row did not align vertically. After the fix, table text wraps normally, cells in the same row are top-aligned, and table width no longer exceeds the chat bubble; horizontal scrolling on mobile is greatly reduced, and genuinely oversized tables now scroll within the table itself with a scroll-hint shadow retained.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.maiagent.ai/release-note/untitled/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
