What's new in MaiaChat
Human-reviewed notes covering the capabilities, improvements, fixes, and safety work that matter when you use MaiaChat.
- LatestImprovedFixedSafety
Device Access follows your account, not the provider
Turning local access on once now gives every agent, chat, and provider the same access to your paired computer, and changing model or provider never changes what can reach your files.
- When local access is enabled for your account, agents, chats, OpenRouter, LM Studio Link, subscription runtimes, and local runtimes all reach the same paired computer. You decide whether computer access is on; the provider only decides which model answers.
- Team turns aimed at a paired project folder now reach your computer for every provider, instead of quietly answering from the MaiaChat server workspace.
- Turning Device Access off fails closed: the turn loses computer access rather than silently falling back to server-hosted files.
- Paired folder creation and finished device results are verified before they are reported, so a device turn no longer claims success without confirmation.
- An explicit denial of paired-device tools is respected instead of being overridden later in the turn.
- Paired runtime models stay visible in the model picker, with bounded diagnostics when device transport has a problem.
Commit references2cdb24e1e0d34cd3ad557cb8b4c8e8eb4104c1620cf06da9a534d9ff - NewImprovedSafety
Evidence you can check, and safer recovery
Answers carry evidence you can inspect, citations state how well a source supports a claim, and recovery refuses a backup generation that is known to be corrupt.
- Citations show freshness evidence and a deliberately conservative reading of how strongly each source supports the claim, including when support is weak.
- Messages expose trustworthy run evidence for the turn that produced them.
- Completed artifacts can be downloaded together with their active lineage.
- Reliability advisories arrive in an accessible review inbox where you approve or reject them.
- Artifact references can be deleted without disturbing the artifacts themselves.
- Restore and recovery refuse a backup generation that an external quarantine marks as corrupt, and that quarantine state stays readable even when the main database is unavailable.
Citation freshness evidence and the reliability review inbox are enabled per owner while wider rollout continues.Commit referencesfde9b9c924dad8bb1a610b1d5308a5b4737789a75a823e7272b9b031c9d0b59be101b46c - NewImprovedSafety
Memory provenance and forgetting
Memory records where each source came from, shows you what forgetting it would affect, and then excludes it from recall once you confirm.
- Memory keeps a durable receipt for each source, so recall can say which source answered instead of presenting memory as unattributed.
- You can inspect the sources behind a memory and preview exactly what forgetting them would affect before you confirm anything.
- Forgotten sources are excluded from recall, including holographic and Gemini-backed recall, and the exclusion is persisted rather than applied for one turn.
- Confirmed erasure is reconciled across working files, archives, and Gemini documents, and an interrupted erasure can be resumed and reviewed.
- Managed imports and archive uploads keep receipts so an interrupted write recovers without capturing the same content twice.
- Clear disclosures and owner controls appear when a memory source limit is reached, including in orchestrated and connected-channel turns.
- Turns whose memory came from an untrusted source are no longer promoted into managed memory.
Source inspection and forgetting are owner-scoped and were enabled for the account owner first.Commit references275cf09878df216b37daab4a804fed7bec0b8ef9d93bafceb8e952dd40daa857dd7b82d76f1502cd9e7d6085d9de908e277c7c299bffe18e6c4180b35e0e3a83fe106088bac00a05a257f3e208579952f6c65a1517eb1c0cac8d3f2bbb6d6f64 - NewImprovedFixed
Longer conversations that stay workable
Very long threads stay responsive, work in progress survives interruption, and you can explore a different direction without losing the original conversation.
- Long transcripts are virtualized, so scrolling a very large history no longer stalls the page.
- Work in progress is durable: reopening a conversation resumes where it stopped instead of starting over.
- Conversations can branch, letting you take a different direction while the original thread stays intact.
- Branch context is retained encrypted. Restoring it requires the original source encryption key, and context made unusable by source changes is reported rather than silently dropped.
- Long turns checkpoint before irreversible compression and restore on failure, so recent instructions are not lost.
- Pending prompts are revisioned and editable, and queued prompts can be reordered before they are sent, with the saved order preserved.
- Conversation search reopens the exact point you were at, and paired runtimes keep their results visible while a turn completes.
Conversation branches and context compaction remain behind owner-only flags while acceptance completes; transcript virtualization and progress continuity are live.Commit references5b5cafc133067807edd376ed04668e04b6723595ce084e8bc5c273b22126d9a6 - NewImprovedFixed
More dependable local models and providers
Local and cloud providers became harder to trip up: responses stream instead of timing out, catalogs show only usable models, and failures explain themselves.
- Ollama Cloud can be connected as an authenticated provider alongside your local runtimes.
- Local completions stream instead of timing out mid-generation, fit the context that is actually loaded, and use compacted tool schemas to leave more room for your prompt.
- Local models without native tool calling keep their tool round trips instead of losing them.
- Readiness problems are explained before you run a turn, and unloaded or helper models are hidden or called out rather than failing with a generic error.
- A local-model browser guide and context guidance were published to help choose a model that fits the work.
- A truncated tool call from a local model is repaired rather than surfacing as a broken turn.
Commit referencesbb4580dcb28a1186748d0ce065e51c6e4da42ef3a580ad871edb28e6848c4c2120d3a7fb4b71f0d1fb8a5b10a060d103e92a2da406175c32f813b3e9663a8595bc172bf5ea472a7d - NewImprovedSafety
Routines you review before they can run
Recurring work gained a reviewable foundation: versioned routines, previewed schedules, exact-operation grants, bounded budgets, and an incident ledger.
- Routine Studio lets you assemble and review a routine without giving the review itself any power to run it.
- Routines are versioned immutably: an edit or rollback appends a new version, and editing an enabled routine disables it until it is freshly simulated again.
- Schedules are authored by you and previewed as their next occurrences. Nothing is registered or executed by the schedule preview itself.
- Standing grants authorise one exact operation rather than a broad capability, and protected credentials are handed off through an encrypted path whose handles carry no authority.
- Routine runs are bounded by execution budgets, and operational incidents are recorded in a ledger rather than disappearing.
- Owner questions, sanitized trace intake, and configuration, version, schedule, and event governance are in place, with drift classified as application-driven or manual.
Routine execution, scheduler dispatch, real destinations, and credential egress remain disabled. These changes add the reviewable foundations, enabled per owner.Commit referenceseb9abf9d1e3a9fb854b9735bf386f15059faa668f28565e5dd35c302dd987792ddd3940af52466e0eb8713dc8b506041cabbea4c41e9e98ef33a62a5e4c99072dcd2b81151101248df2c4d329bb52aa0 - NewImprovedSafety
A browser companion bound to your own tab
A companion can work with the tab you are actually using, under per-origin grants, with read-only actions and a handover when something sensitive appears.
- The companion binds to the current tab and profile, with per-origin grants instead of all-sites or history-wide access.
- Page actions start read-only, and the one admitted action requires your approval and a fresh gesture.
- When a secret, 2FA, CAPTCHA, or payment step appears, control is handed to you and resumes only once, from a new gesture, instead of an automatic retry.
- The extension keeps a stable identity across updates, and page inspection is isolated so an ordinary page cannot widen what the agent may do.
- A macOS menu-bar control provides local status, explicit enable and disable, managed rollback, and an emergency disable when a refresh fails.
- An opt-in Launch at Login control and a deliberately fail-closed updater foundation were added without granting any browser authority.
The companion remains unsigned and unpublished, browser feature flags stay globally off, and only the reviewed read-only fixture is admitted. The menu-bar app is ad-hoc signed, not yet Developer ID signed or notarized.Commit referencesf213eb3bdd1fbec99c4612f932aca558a416978317d37b45f0cf460b325661ec4e87a4047d3fe8789e8306cc513d87c61d1a4794 - NewImprovedSafety
Maia Teammates and small team rooms
Specialists gained durable handoffs and a shared room, so a few teammates can work one task while you keep one canonical result to read.
- A teammate is backed by a profile, so it keeps its declared model, effort, tools, and budget instead of duplicating an identity.
- Handoffs between teammates are attributed and durable, and survive a reload or reconnect so they resume exactly once.
- Groups of two to six teammates share one room with a single canonical result, bounded by turn locks, leases, and caps that prevent runaway loops.
- Cloning a teammate does not copy credentials, memory, or history.
- Room turns are fenced so a result is delivered to the room it belongs to and never across rooms.
Teammates are enabled per owner while acceptance continues; group runs stay bounded and are not yet generally available.Commit referencesa3507bcb41f38af06748947dc2614936621cfdc5 - NewImprovedSafety
Foundations for reliable autonomous work
Unattended work gained the machinery that makes it trustworthy: recorded obligations, resumable approvals, typed failures, verified completion, and durable companion memory.
- An obligation is written before work is dispatched, so an interrupted or uncertain effect is never replayed as though it had not happened.
- An approval shows exactly what will happen, who approved it, and when it expires, and it survives a reload or reconnect so it resumes or cancels exactly once.
- Failures are typed, from transient and rate-limited through policy-denied, uncertain-effect, stale-source, and permanent, with bounded retry and no replay of uncertain effects.
- Completion is verified against the intended effect, so a no-op or a write to the wrong target is caught instead of reported as success.
- Budgets reserve and reconcile cost once, including for models whose cost is unknown.
- A companion keeps a durable identity and relationship memory, with agent-proposed changes staged for your approval and append-only revisions you can roll back.
- Context is checkpointed before irreversible compression and restored on failure, and a session export carries redacted lineage.
These are the foundations unattended effects depend on; broader side-effect paths remain disabled by default.Commit references5fe233e0984191217d9a45fd790956ca4d35ae47d63243e0dd0c908757bdf5cea86717f080fcd16ac9373c43e71b4b836428d6b4 - NewImprovedSafety
Model Showcase: comparable evidence, kept private
Comparison Lab grew into a versioned, blinded showcase that reports how each model actually performed and exports evidence you control.
- Showcase suites are versioned, non-personal, editable by you alone, and carry fixed fixtures with a holdout.
- Runs are blinded and randomized, with sequential A/B and AB/BA ordering so one model is not systematically given the easier position.
- Results report repetitions and variance alongside time to first token, end-to-end time, tokens per second, tokens, cost basis, errors, and retries, with the actual route and parameters recorded rather than assumed.
- Grading starts with deterministic structural checks, and any external judge records its provider, model, version, prompt template, privacy, and cost.
- Evidence exports as JSON, CSV, or a 16:9 methodology card, including terms, licence, disclosure, and approval state.
- Private content can be retained, exported, or erased on your instruction, and a public-ready state never publishes anything by itself.
Commit referencesf2f3c9d7467ac75bf9745e96f2002fa50dd88232475c563b57a67881266408fa98cfc8caa3b70cf0cf3e1fef - ImprovedFixedSafety
Device Access across paired computers
Device Access now follows the account and selected paired computer instead of disappearing when you switch models or providers.
- Device policy now persists across model changes and is shared with explicitly configured agents, including agents using different providers.
- The selected paired computer, Files scope, filesystem mode, destructive policy, and Full Computer File Access authorisation remain available when you change models.
- The latest policy migration preserves each account's most recently updated Device Access settings while retaining legacy model rows for audit attribution.
- Explicitly selected agent models can use shared Device Access; unrequested automatic provider failover remains blocked rather than inheriting computer access.
- The Device Access UI now uses Paired computer and Full Computer File Access so Windows and Linux users are not presented with Mac-only wording.
Commit references2ce87cb - NewImprovedFixedSafety
Safer paired-computer workspaces
Agent file work now makes the server-versus-computer boundary explicit and keeps project confinement enforced through the entire device path.
- Choose whether an Agent turn uses the MaiaChat server workspace or a selected paired computer.
- Selected project folders are confined at both server and bridge layers; missing or outdated bridge support fails closed.
- Explicit None, Selected Project, and Full Computer File Access modes prevent project selection from silently escalating privileges.
- Device results render as authoritative operation statuses instead of relying on model-generated success text.
- Runtime-backed models are routed to the paired computer when their execution contract requires local work, without silently reusing server tools.
Commit referencesca509ca6a1f6be94cb174 - NewImprovedSafety
Connected provider runtimes
MaiaChat can now use more provider subscriptions and local runtimes through explicit, bounded, and inspectable connections.
- Connect supported provider accounts and use subscription-backed chat and coding models without copying provider secrets into ordinary chat settings.
- Codex subscription chat and workspace-write tasks run through explicit paired-device workflows with bounded permissions.
- Added supported runtime paths for Grok, Kimi, Qwen, MiniMax, Copilot, and OpenCode with readiness checks and permission ceilings.
- Hosted LM Studio and LM Studio Link support local model access while keeping local credentials on the paired computer.
- Provider status, runtime discovery, stale-login handling, executable lookup, and embedded LM Studio reasoning output now fail or render safely.
Commit referencesc9e58b42af38d2940437f4e2fa4c555513d35cfa46e2a0da74acc6aed85431ac971bd2 - NewImprovedSafety
Reviewable coding workbench
Long-running coding work is now easier to inspect, control, review, restore, and integrate without losing the surrounding Agent session.
- Coding sessions record runs, events, changed files, checkpoints, and completion evidence.
- Review changes with diffs, restore reversible change sets, integrate managed worktrees, or create pull requests without losing session context.
- Governed specialist delegation and durable run controls make parallel work inspectable, stoppable, and bounded.
- Verification reports distinguish completed work from unverified, incomplete, or failed outcomes.
- Coding interoperability supports importing and exporting project work while preserving review and integration evidence.
Commit referencesec3307eeb7c842a847c7fa941c987fb3006ae00db6aca4f7450d422a - ImprovedFixedSafety
More predictable autonomous work
Autonomous runs now respect their execution limits and recover more cleanly when optional verification or hosted shell capabilities are unavailable.
- Loop presets now respect autonomous API timeouts instead of overrunning their execution budget.
- Hosted loops complete cleanly when optional shell verification is unavailable, rather than remaining stuck.
- Simplified chat entry and Agent harness controls make Agent tools and coding work easier to discover.
- Memory hook and deployment checks stay aligned across chat and autonomous execution paths.
Commit references282a628d71c16042d7879 - NewImprovedSafety
Safer recovery and interoperability
MaiaChat gained stronger recovery controls, secure external interoperability, and safer shared-installation administration.
- Added encrypted portable-backup integrity checks and isolated restore workflows.
- Durable maintenance and backup-attempt fencing improve recovery after restarts or replica handoffs.
- Secure MCP interoperability supports scoped keys, idempotent operations, rate limits, and audit controls for external clients.
- Private GitHub mirroring exports redacted, encrypted state without exposing credentials or sensitive content.
- Tenant-safe skill curation, review, pinning, rollback, and fail-closed feature rollouts keep shared installations separated.
Commit referencesa815c54a4012685e0eafcee23ba331edaeff3b7099c09f961 - ImprovedFixedSafety
Device Access follows permission changes
When you update Device Access during a conversation, MaiaChat now continues the original computer task with the newly available capability.
- File-creation requests with quoted macOS paths now route to the paired computer instead of becoming an ambiguous server task.
- Natural follow-ups such as “I gave access to files” retain the original computer context and immediately retry through Device Access.
- The Agent no longer redirects these requests to Terminal or Google Drive when the paired-device tool is available.
- Block, Ask, and Allow remain authoritative: the current policy still decides whether a requested change is refused, approved, or performed.
Commit referencese6b0a90 - NewImprovedFixedSafety
Live Agent activity in chat
Agent mode now shows what MaiaChat is doing as work progresses, while keeping private prompts, tool inputs, and raw results out of the activity feed.
- An inline activity timeline shows the current stage, elapsed time, tool count, and completed steps during longer Agent requests.
- File, browser, search, calculation, and connected-tool activity uses clear fixed labels instead of exposing provider logs or raw tool payloads.
- Read-only and approval blocks are shown immediately with an explicit confirmation that the protected action was not performed.
- Useful answer text now streams into chat as it arrives, avoiding a large single update at the end of a long request.
- Completed activity collapses into a compact summary that can be reopened on desktop or mobile.
Commit references7300b0a - NewImprovedFixedSafety
Device Access preview and current AI models
MaiaChat can now work with a computer you explicitly pair, while fresh chats start with a current multi-provider model catalogue.
- Pair a macOS, Windows, or Linux computer and choose Browser, Files, Applications, Screen, Terminal, or OS Administrator access.
- Device policy is shared by one MaiaChat account and its selected paired computer; normal application routes isolate other site users.
- Hosted users can download the one-file Node.js bridge directly; a full MaiaChat source checkout is no longer required for pairing.
- Computer requests now route to the paired computer instead of probing the hosted server workspace, including short follow-ups such as “try again.”
- Completed pairings now appear automatically and are matched to their exact pairing code, with clearer restart and activation instructions inside Device Access.
- Google and other social-only accounts are no longer asked for a nonexistent MaiaChat password; Google verification can be renewed without manually signing out.
- Small models now recover safely when they announce a folder-listing tool call without sending its payload, and the verified device result is always shown in chat.
- Computer-changing actions start blocked, with separate Ask and Allow modes protected by short-lived account reauthentication.
- Fresh chats use GPT-5.6 Terra, with current OpenAI, Anthropic, Google, xAI, OpenRouter, Ollama, and LM Studio catalogues.
Device Access is an experimental preview. The companion now includes a source-built macOS menu-bar control preview over the managed Bridge lifecycle, a separate M8.6a credential-free read-only artifact verifier, an M8.6b opt-in Launch at Login source path backed by macOS SMAppService.mainApp, an M8.6c fail-closed source-only MaiaChat app-updater foundation, and an M8.7a dark, named-user-only sensitive-step takeover ledger/API foundation with no extension/Bridge caller or browser execution. M8.7a stores only bounded redacted lifecycle facts, never secrets or browser payloads; physical takeover, M5.7 task integration, production migration, rollout, and secret handling remain open. Sparkle 2.9.6 is reviewed planning input only and is not bundled, with no feed, key, dependency, network, download, install, or relaunch path. The verifier separates artifactReady from distributionReady, and the locally staged app bundle remains arm64, ad-hoc signed, and strictly codesign-valid, but no authorized Maia TeamIdentifier is configured and it is not Developer ID signed, notarized, stapled, Gatekeeper-accepted, published, or physically accepted for login-item approval/login-cycle/updater behavior, and Linux/Windows tray surfaces remain unavailable.Commit references693894ad605aa00724473 - Improved
A clearer MaiaChat front door
The public introduction and signed-in workbench now explain MaiaChat through real outcomes instead of a generic chat screen.
- Reworked guest and signed-in starting experiences with clearer next actions.
- Added outcome-led starters for learning, comparing, creating, and automating with AI.
- Made the Learning Lab and Comparison Lab easier to discover from primary navigation.
Commit references2a17cb1 - NewImproved
Learning Lab and Comparison Lab
A guided path now helps people move from basic chat toward documents, agents, coding, loops, and automation using real MaiaChat controls.
- Added practical lessons, private progress tracking, achievements, and guided capability paths.
- Added side-by-side model and prompt comparisons with latency, token, and cost context.
- Introduced organization-managed lessons and clearer onboarding for different experience levels.
Commit references1d69d2781c70cc - ImprovedSafety
Stronger Agent mode controls
Longer-running agent work is more bounded, easier to inspect, and clearer about when it has verified an outcome or stopped.
- Added clearer loop controls, project context, verification gates, and stop behaviour.
- Improved parallel subtask coordination for work that benefits from independent specialists.
- Tightened tool discovery and hosted safety boundaries so disabled capabilities stay unavailable.
Commit references75ea906 - ImprovedFixed
More reliable local-model agent runs
Ollama and LM Studio users can run agent loops without cloud keys, with better control over context growth and completion.
- Made local providers first-class in autonomous model access decisions.
- Compacted older loop history and bounded large tool results before replaying them to a model.
- Improved completion checks, recovery, and reporting when verification cannot finish.
Commit references78f38ba - ImprovedFixedSafety
Clearer and safer file work
Agent file tasks now show what changed, stop more predictably, and preserve better recovery points when work fails or is cancelled.
- Added visible file-change summaries and better progress for local file tasks.
- Added reliable stop and cancellation handling for active chat and model runs.
- Improved model failover, message deduplication, scoped file browsing, and mutation checkpoints.
Commit referencesc070f09add34ed - NewImproved
Mixture of Agents and in-product help
Multiple specialist agents can collaborate on one task, with visible roles and practical guidance for choosing the right workflow.
- Added specialist-agent orchestration for chat, schedules, profiles, and connected channels.
- Made agent roles visible when configuring and selecting a team.
- Added practical MaiaChat and Mixture of Agents manuals inside the application.
Commit references97f66f363eba83 - NewSafety
Plain-language automation with safer hosted defaults
Common recurring tasks can be created from reusable blueprints and natural-language shortcuts, while hosted installations enforce stricter isolation.
- Added automation blueprints, suggestions, slash commands, and channel-friendly shortcuts.
- Improved approval defaults and workspace isolation for hosted deployments.
- Made the application code read-only in hosted containers while preserving explicit runtime directories.
Commit references952be7d02af46710c4f2a0ffef2cd5daf63 - NewImproved
Goals, loops, schedules, and memory controls
MaiaChat gained bounded autonomous work that can pursue a goal, run on a schedule, and remain visible from the normal chat experience.
- Added standing goals, bounded agent loops, and scheduled autonomous runs.
- Integrated loop controls into chat instead of hiding them on a separate management page.
- Improved session recall, self-review controls, and navigation on shorter screens.
Commit references5355922ce84b208fea594 - NewSafety
Agent workbench foundation
The Worker Board and safety layers established a more inspectable foundation for longer-running agent work.
- Added Worker Board triage, artifacts, checkpoints, handoffs, dependencies, and cost caps.
- Hardened autonomous task concurrency and workspace boundaries around file mutations.
- Improved reviewed skill discovery, connected-channel actions, and approval-aware workflows.
Commit references604862b525233ad3868fabc901c70c06204