Skip to content

Commit 5360348

Browse files
committed
docs: refresh public roadmap and screenshots
1 parent 15d0e67 commit 5360348

22 files changed

Lines changed: 229 additions & 334 deletions

.planning/GOAL.md

Lines changed: 54 additions & 125 deletions
Large diffs are not rendered by default.

.planning/MILESTONES.md

Lines changed: 64 additions & 136 deletions
Large diffs are not rendered by default.

.planning/PROJECT.md

Lines changed: 39 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,40 @@
11
# Project: Memroos
22

3-
*Last updated: 2026-06-06 — v7.0 Client-Ready Security + Architecture Audit started*
3+
*Last updated: 2026-06-08 — v7.0 complete; public docs and screenshot refresh underway*
44

55
---
66

77
## Current Product Goal
88

9-
`memroos.dev` is the control plane where AI-native teams retain what agents learn, retrieve the right context at runtime, dispatch work to the right agent, and turn repeated work into reusable skills.
9+
`memroos.com` is the public front door for MemroOS: the control plane where AI-native teams retain what agents learn, retrieve the right context at runtime, dispatch work to the right agent, and turn repeated work into reusable skills.
1010

1111
See `.planning/GOAL.md` for the full development goal and workflow loop.
1212

1313
---
1414

15-
## Current Milestone: v7.0 Client-Ready Security + Architecture Audit — IN PROGRESS 2026-06-06
15+
## Current Position: Post-v7.0 Public Evidence Refresh — IN PROGRESS 2026-06-08
1616

17-
**Goal:** Harden memroos for client review with a full security and architecture sweep across all codebase layers — eliminating vulnerabilities, cleaning dead code, fixing bad boundaries, and ensuring tests stay green throughout.
17+
**Goal:** Keep memroos.com, the GitHub README, public metadata, and screenshot assets aligned with the now-complete v6.4/v6.5/v6.6/v7.0 product state.
1818

1919
**Target features:**
20-
- Parallel 4-domain audit: Auth/Secrets, API surface, Data/Memory handling, Architecture/Code quality
21-
- Security remediation: critical → high → medium priority order
22-
- Architecture cleanup: dead code, bad boundaries, redundant patterns, unsafe TypeScript
23-
- Dependency CVE sweep: npm audit + pip-audit, patch critical/high
24-
- Test validation: full suite green after all changes, security regression tests added
20+
- Refresh README and public-site screenshots from current app surfaces.
21+
- Align release labels across package metadata, README, installer output, and LLM-readable docs.
22+
- Regenerate public/OG screenshots from current product surfaces.
23+
- Keep roadmap language focused on current evidence: SkillForge hardening, Agent Context Bus, local-footprint inventory, and client-ready security audit.
24+
25+
---
26+
27+
## Previous Milestone: v7.0 Client-Ready Security + Architecture Audit — SHIPPED 2026-06-08
28+
29+
**Goal:** Harden memroos for client review with a full security and architecture sweep across all codebase layers — eliminating vulnerabilities, cleaning dead code, fixing bad boundaries, and ensuring tests stay green throughout.
30+
31+
**What shipped:** Four-domain audit, critical/high remediation, accepted-risk medium dependency notes, architecture cleanup, production build, typecheck, 1079 app tests, and Python service/SDK/voice validation.
32+
33+
---
34+
35+
## Previous Milestone: v6.6 Cloud Offload + Local Footprint Reduction — SHIPPED 2026-06-08
36+
37+
**What shipped:** Local-footprint inventory, cloud-target mapping, prune-safety classification, cache/log guardrails, and `/api/operations/noc` local-footprint status.
2538

2639
---
2740

@@ -31,6 +44,12 @@ See `.planning/GOAL.md` for the full development goal and workflow loop.
3144

3245
---
3346

47+
## Previous Milestone: v6.4 SkillForge Production SkillOpt Hardening — SHIPPED 2026-06-08
48+
49+
**What shipped:** Deterministic sandbox-backed held-out SkillForge scoring, one authoritative proposal path, schema-level split/baseline/edit traceability, typed bounded edit operations, and audit-ready proposal receipts.
50+
51+
---
52+
3453
## Previous Milestone: v6.3 Agent Lifecycle + Memory Observability — SHIPPED 2026-05-29
3554

3655
**Goal:** Implement compact, event-triggered checkpoint/resume with minimal execution overhead, memory-trace causal execution timelines with failure classifications, and immutable agent version release promotions with rollbacks.
@@ -185,17 +204,21 @@ Any agent framework plugs into Memroos — and every agent, knowledge system, an
185204
- ✓ SQLite audit_log table + AuditLogPanel — v1.5 (SEC-02/03, DASH-03)
186205
- ✓ Usage analytics (6 metrics, 3 windows) on Ledger/Library/Cookbooks — v1.5 (ANA-01/02/03/04)
187206

188-
### Active (v5.2)
207+
### Current Completed Milestones
189208

190-
- [x] Competitive memory target architecture — reproducible marketplace benchmark, target profile, live recall hardening, and documented recommendation (MEMTARGET-01)
209+
- [x] **v7.0 Client-Ready Security + Architecture Audit** — AUDIT/SEC/ARCH/TEST requirements complete.
210+
- [x] **v6.6 Cloud Offload + Local Footprint Reduction** — CLOUDOFFLOAD-01..06 complete.
211+
- [x] **v6.5 Agent Context Bus + Synchronous Agent Communication** — AGENTBUS-01..07 complete.
212+
- [x] **v6.4 SkillForge Production SkillOpt Hardening** — SKILLOPT-HARDEN-01..05 complete.
213+
- [x] **v5.2 Competitive Memory Target Architecture** — reproducible marketplace benchmark, target profile, live recall hardening, and documented recommendation (MEMTARGET-01).
191214

192215
### Recent Milestones
193216

194-
- [x] **v2.5 Eval Engine + Self-Improvement Platform (Phases 57-62)**Composite W, SEAL substrate, memory/agent autogen proposal families, L3 outcome layer, public eval API + SDK; Tier 1 modeled W-lift shipped, behavioral W-lift deferred to v3.
195-
- [x] **v2.1 Security + Trust Layer (Phases 42-45)**Agent Shield + Iris pre-flight foundation, tool permission guard, security operations UI, and progressive capability exposure
196-
- [x] **v2.2 LLM Optimization + Evaluation (Phases 46-49)**Model-routing telemetry, recommendation API, eval rigs, quality scoring, optimization dashboard and reports
197-
- [x] **v2.3 Agent Runtime Enhancements (Phases 50-52)**Agent-side middleware, memory client v2, local observability dashboard
198-
- [x] **v2.4 Performance + Caching (Phases 53-54)**Response caching, query performance, cold-start elimination, regression budgets
217+
- [x] **v6.3 Agent Lifecycle + Memory Observability**checkpoint/resume, memory-trace timelines, and agent CI/CD gates.
218+
- [x] **v6.2 Skill Distribution + Knowledge Gateway**skill packs, private config, Circleback ingestion, troubleshooter skill, and public documentation.
219+
- [x] **v6.1 SkillForge Autonomy**Dream Cycle, marketplace, multi-agent skill orchestration, behavioral W-lift v2, and self-hosted eval cluster.
220+
- [x] **v6.0 SkillForge — Governed Skill Optimization**worker, analyzer, proposal generation, eval gate, governance, and integration.
221+
- [x] **v2.5 Eval Engine + Self-Improvement Platform**Composite W, SEAL substrate, memory/agent autogen proposal families, L3 outcome layer, public eval API + SDK; Tier 1 modeled W-lift shipped.
199222

200223
### Deferred (v5.1+ candidates)
201224

README.md

Lines changed: 33 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323

2424
<p align="center">
2525
<a href="https://github.com/lac5q/memroos/blob/main/LICENSE"><img alt="License: PolyForm Small Business 1.0.0" src="https://img.shields.io/badge/license-PolyForm%20Small%20Business-a8392c.svg"></a>
26-
<img alt="Release: v1.0.0-beta.1" src="https://img.shields.io/badge/release-v1.0.0--beta.1-a8392c.svg">
26+
<img alt="Release: v1.0.0-beta.2" src="https://img.shields.io/badge/release-v1.0.0--beta.2-a8392c.svg">
2727
<img alt="Next.js" src="https://img.shields.io/badge/Next.js-16-black.svg">
2828
<img alt="A2A ready" src="https://img.shields.io/badge/A2A-ready-7a2a1e.svg">
2929
<img alt="Local first" src="https://img.shields.io/badge/local--first-yes-4a4a45.svg">
@@ -56,7 +56,7 @@ npm install
5656

5757
Then open `http://localhost:3000`, search retained memory, inspect Knowledge source health, register or dispatch an agent, and review the runtime context pack that gets assembled before work starts.
5858

59-
If you are evaluating the launch build, start with the v1.0.0-beta.1 release, watch the demo, then open a workflow feedback issue with the first place your agents lose context. Maintainers can process launch feedback with the [workflow feedback intake guide](docs/workflow-feedback-intake.md).
59+
If you are evaluating the launch build, start with the v1.0.0-beta.2 release, watch the demo, then open a workflow feedback issue with the first place your agents lose context. Maintainers can process launch feedback with the [workflow feedback intake guide](docs/workflow-feedback-intake.md).
6060

6161
## What MemroOS Is
6262

@@ -78,7 +78,7 @@ The repository began as `memroos.dev`; some internal package names, paths, and e
7878

7979
MemroOS now has a public-evidence benchmark for enterprise agentic memory and a passing live recall gate for the local beta architecture.
8080

81-
Latest local results from May 24, 2026:
81+
Latest generated benchmark results as of June 8, 2026, using the May 24 public-evidence methodology:
8282

8383
| Rank | Provider | Score | Note |
8484
| ---: | --- | ---: | --- |
@@ -110,11 +110,11 @@ Live recall gate after beta hardening:
110110
## Screenshots
111111

112112
<p align="center">
113-
<img src="docs/screenshots/readme-landing.png" alt="MemroOS landing page showing the runtime context pack for product, sales, and engineering agents" width="900">
113+
<img src="docs/screenshots/readme-landing.png" alt="MemroOS public landing page with shared agent memory, governed dispatch, and source-backed proof" width="900">
114114
</p>
115115

116116
<p align="center">
117-
<em>The public landing page leads with retained agent knowledge, runtime context packs, and the new operator console that turns memory into daily agent operations.</em>
117+
<em>The public landing page now leads with the shorter MemroOS story: shared agent memory, governed dispatch, and proof that shows what context moved the work forward.</em>
118118
</p>
119119

120120
<table>
@@ -190,37 +190,44 @@ After setup, you can:
190190

191191
## Release 1.0 Beta
192192

193-
`v1.0.0-beta.1` is the public beta release for MemroOS's memory-plus-governance positioning.
193+
`v1.0.0-beta.2` is the current public beta release for MemroOS's memory-plus-governance positioning.
194194

195195
The current release includes:
196196

197-
- A new NOC-style operator console with grouped navigation, dense operational metrics, and a consistent public-to-product visual system.
197+
- A NOC-style operator console with grouped navigation, dense operational metrics, and a consistent public-to-product visual system.
198198
- A Next.js workspace with Memory, Knowledge, Skills, Agents, Workflow Map, Engage, Improvements, Usage, and Governance surfaces.
199199
- A Skills workflow for reviewing, editing, approving, and promoting procedures from agent-local playbooks into enterprise-ready workflows.
200200
- A task-first Dispatch room with direct chat, group-room standups, voice prompt controls, and inspectable participant context.
201201
- A canonical SQLite-backed agent registry for REST, UI, and A2A-visible agents.
202202
- A2A card ingestion, task routes, streaming subscription endpoints, and Google ADK compatibility fixtures.
203+
- Agent Context Bus routes and MCP tools for durable inbox/reply flows, acknowledgements, bounded waits, and memory-save receipts.
204+
- Local-footprint inventory for permanent state, rebuildable caches, cloud targets, prune safety, and NOC/API visibility.
205+
- SkillForge production hardening with deterministic sandbox-backed held-out scoring, typed bounded edits, and audit-ready baseline/treatment receipts.
203206
- REST reporting endpoints for heartbeats, memory writes, skill reports, and tool outcomes.
204207
- Memory and knowledge visibility across configured file collections, mem0/Qdrant, graph memory, and local SQLite.
208+
- Client-ready security and architecture audit closeout with full-suite Node/Python validation and documented accepted-risk dependency notes.
205209
- Human-gated Agent Lightning/APO approvals so self-learning proposals queue before mutating agent instructions.
206210

207211
## Completed Roadmap
208212

209-
- **Phase 41: Public Polish** - public README, contribution guide, security policy, issue templates, and GitHub Actions checks for public collaboration.
210-
- **Phases 42-45: v2.1 Security + Trust Layer** - Iris dispatch preflight, prompt-injection checks, tool-permission governance, security reporting, and progressive capability exposure.
211-
- **Phases 46-49: v2.2 LLM Optimization + Evaluation** - model-routing telemetry, recommendation surfaces, evaluation fixtures, optimization dashboards, and quality reports.
212-
- **Phases 50-52: v2.3 Agent Runtime Enhancements** - runtime middleware, memory client v2 paths, richer engagement state, and observability surfaces for live agents.
213-
- **Phases 53-54: v2.4 Performance + Caching** - response caching, query-path tuning, and faster memory/knowledge retrieval for operator workflows.
214-
- **UI migration: Memory OS operator surface** - NOC-style home, 8-group navigation, Workflow Map, full authenticated page reskin, task-first Dispatch, and a first-class Skills workflow.
213+
- **v2.0-v2.4: A2A hub, security, LLM optimization, agent runtime, and performance** - universal REST/A2A registration, LangGraph orchestration, trust layer, model-routing telemetry, and cache/performance work.
214+
- **v2.5-v4.0: Eval engine, compliance, context reliability, and orchestration depth** - composite W, SEAL substrate, RBAC/auth hardening, HIL edit-and-continue, rollback, semantic recall, evidence bundles, and governed skill contracts.
215+
- **v5.0-v5.2: Memory Trust + Operational Intelligence** - raw vault, security labels, classification cascade, retrieval authorization, NOC telemetry, cron health, evidence bundles, auth hardening, memory inventory clarity, and public benchmark architecture.
216+
- **v6.0-v6.3: SkillForge + Agent Lifecycle** - governed skill optimization, Dream Cycle, marketplace, multi-agent skill orchestration, agent memory continuity, skill distribution, private config, Circleback ingestion, checkpoint/resume, memory-trace observability, and agent CI/CD gates.
217+
- **v6.4: SkillForge Production SkillOpt Hardening** - deterministic sandbox-backed held-out eval, one proposal path, traceability fields, typed edit operations, and accepted/rejected evidence.
218+
- **v6.5: Agent Context Bus + Synchronous Agent Communication** - durable agent inbox/reply bus, REST/MCP access, acknowledgements, bounded replies, memory-save receipts, and fail-closed denial of self-declared OAuth/data-access claims.
219+
- **v6.6: Cloud Offload + Local Footprint Reduction** - local store inventory, cloud target mapping, prune-safety classification, cache/log caps, and NOC/API local-footprint status.
220+
- **v7.0: Client-Ready Security + Architecture Audit** - four-domain audit, critical/high remediation, accepted-risk medium CVE notes, architecture cleanup, production build, typecheck, and full-suite validation.
215221

216222
## Current Roadmap Focus
217223

218-
The active GSD milestone is `v5.2: Competitive Memory Target Architecture`. It keeps the product focused on measurable memory advantage instead of generic agent breadth:
224+
The active product focus after v7.0 is to keep the public beta evidence current and make the newly shipped control-plane work visible:
219225

220-
- **Phase 84: Competitive memory beta architecture** - live locally. The marketplace benchmark ranks the beta architecture first, and the live recall suite passes 8/8 after vector write hardening.
221-
- **Next focus: hot-path retrieval** - make the benchmark advantage visible in day-to-day runtime latency, cache prewarm, and context-pack assembly.
222-
- **Next focus: temporal invalidation** - close the remaining Zep-style temporal memory gap without weakening MemRoOS governance, audit, or source proof.
223-
- **Next focus: public benchmark proof** - keep the methodology, fixtures, and results reproducible so public claims stay defensible.
226+
- **Public proof refresh** - keep memroos.com, README screenshots, launch assets, and LLM-readable docs aligned with the current product surfaces.
227+
- **Agent Context Bus operator visibility** - expose inbox depth, stale messages, pending replies, and memory-save receipts in the operator UI.
228+
- **Local-footprint visibility** - keep `npm run check:local-footprint`, `/api/operations/noc`, and NOC surfaces honest about permanent state, rebuildable caches, cloud targets, and prune safety.
229+
- **Client-ready security follow-through** - add DAST scanning, prepare external penetration-test handoff, and map SOC 2 controls after the internal v7.0 audit baseline.
230+
- **Memory-save quality spike** - evaluate the deferred Memento-style typed/audited save contract without adopting a backend, hosted trace upload, or dependency swap without Luis approval.
224231

225232
## What MemroOS Does
226233

@@ -237,6 +244,8 @@ The active GSD milestone is `v5.2: Competitive Memory Target Architecture`. It k
237244
- **Task-first dispatch:** Run direct chat, group-room standups, live delegations, and spoken prompts with inspectable context.
238245
- **Workflow map:** Visualize agents, memory, skills, dispatch paths, and infrastructure.
239246
- **Governance:** Gate registry writes, memory reads, destructive actions, and self-learning approvals.
247+
- **Agent Context Bus:** Give registered agents a durable inbox/reply surface with acknowledgements, bounded waits, context-sync receipts, and fail-closed delegated-access policy.
248+
- **Local footprint control:** Classify local stores by permanence, cloud target, size, retention, privacy label, and prune safety.
240249

241250
## What MemroOS Is Not
242251

@@ -637,14 +646,13 @@ memroos/
637646

638647
## Roadmap
639648

640-
Near-term focus:
649+
Near-term focus after v7.0:
641650

642-
- Finish Phase 70: multi-hop retry/rollback and auth-guarded HIL edit-and-continue UI.
643-
- Add semantic/hybrid recall and HIL SLA countdown/escalation without replacing qmd BM25 or mem0/Qdrant memory.
644-
- Treat voice as a memory-ingestion surface with consent and token-safety controls.
645-
- Add cross-project recall with explicit allowed project IDs.
646-
- Make evidence bundles visible: memories consumed, tools/commands run, checks passed, unverified assumptions, residual risks, and replay/rollback artifacts.
647-
- Normalize cross-harness skills into governed contracts with preconditions, allowed tools, risk tier, verification checks, owner, rollback behavior, and dispatch status.
651+
- Keep public docs, screenshots, metadata, and launch assets synchronized with the current beta.
652+
- Add an operator UI for Agent Context Bus inbox depth, pending replies, stale messages, and memory-save receipts.
653+
- Continue local-footprint reduction through managed persistence targets, qmd/search worker offload, cache caps, and encrypted raw-vault object-storage proof.
654+
- Add DAST scanning, external penetration-test preparation, and SOC 2 control mapping on top of the internal v7.0 audit baseline.
655+
- Run the deferred Memento-style memory-save quality spike as a bounded comparison only; no dependency adoption, backend swap, hosted/private trace upload, or replacement of mem0/Qdrant/Neo4j/SQLite without Luis approval.
648656

649657
## Contributing
650658

-371 KB
Loading
125 KB
Loading
-55.2 KB
Loading
-49.6 KB
Loading
-18.6 KB
Loading

apps/memroos/src/__tests__/proxy.test.ts

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -132,15 +132,24 @@ describe("proxy", () => {
132132
expect(response.headers.get("location")).toBeNull();
133133
});
134134

135-
it("serves the public landing on the Epilogue Capital MemRoOS alias", async () => {
136-
const response = await proxy(
137-
new NextRequest("https://memroos.epiloguecapital.com/", {
135+
it("treats the Epilogue Capital MemRoOS alias as an app host", async () => {
136+
const loginResponse = await proxy(
137+
new NextRequest("https://memroos.epiloguecapital.com/login", {
138138
headers: { host: "memroos.epiloguecapital.com" },
139139
})
140140
);
141141

142-
expect(response.status).toBe(200);
143-
expect(response.headers.get("location")).toBeNull();
142+
expect(loginResponse.status).toBe(200);
143+
expect(loginResponse.headers.get("location")).toBeNull();
144+
145+
const appResponse = await proxy(
146+
new NextRequest("https://memroos.epiloguecapital.com/dispatch", {
147+
headers: { host: "memroos.epiloguecapital.com" },
148+
})
149+
);
150+
151+
expect(appResponse.status).toBe(307);
152+
expect(appResponse.headers.get("location")).toBe("https://memroos.epiloguecapital.com/login");
144153
});
145154

146155
it("serves the public landing on memroos.localhost for local preview", async () => {

0 commit comments

Comments
 (0)