.35
v0.35.0 β π« No more scrollbars. The grey bars down the side and along the bottom of a panel are gone everywhere in the city. Everything that scrolled still scrolls exactly as it did β swipe on a phone, wheel on a desktop β the bar itself just stopped taking up room and stopped nudging things out of line. It is one rule in one shared place rather than a patch per panel, a test now fails the moment anything brings a bar back, and it is a rule the whole suite owes from today.
.34
v0.34.0 β π€ A real person, at their own company's address. Some invitations should look like they came from a named person at the customer's own company, not from Appolis. Now the owner can pre-authorise one specific address for one specific app β and only after the mail service has actually proved that company owns the domain. An app can then ask to send as that person, but it can never pick an address of its own and it can never borrow a name. Adding a sending domain hands the owner the exact records to set up, and they sit on a sub-name, so a company already receiving its mail through Microsoft or Google keeps receiving it untouched.
.33
v0.33.0 β π See it before you say yes. When something about how the city looks or works is up for decision, the owner no longer reads a description of it. He opens one page that shows the real thing as it is now beside how it would be, and says yes or no right there. The same question also lands in his inbox as a one-tap form, so an answer is never trapped behind a single screen. v0.33.1 β the first thing decided this way: the Rules page now says plainly that the rules are the owner's and the platform's, that nobody else can set them, and that the way the city itself looks and works is not up for customisation.
.32
v0.32.0 β β One tap decides it. Every question the city has for the owner now arrives in his inbox as a form he answers with a tap, and the tap itself is the decision: an app's claim that it has complied is accepted or sent back in his own words, an idea from an app is approved or declined, and the form clears itself. Each rule also names which app built the example everyone else copies, so nobody has to invent the same thing five times.
.31
v0.31.0 β π The cheap hands go first, and the owner answers with a tap. Two new rules for the whole city: every AI job goes to a Hephaestus specialist when one fits, through whichever door is open, and the most expensive model only directs; and anything that needs the owner's decision reaches him as a form, never a list to decode. The hub lives by both from this version: every session is told at connect which Hephaestus doors are open right now, and a suggestion filed by any app lands in the owner's inbox as a one-tap form.
.30
v0.30.0 β π§© Surfaces: the door is open. Something built inside an app β a theme, a member portal, a page β can now be put on the compliance wall by itself, from the wall, without a code change. It answers only to the rules that name it, in its own look, and the app it lives inside is told what it owes every time a session connects. FLIP HQ is the first one on the wall.
.29
v0.29.0 β π¦ The member portal answers to the progress rule too. FLIP HQ, the portal members use every day on flipmylifenow.com, is now on the compliance wall for one rule: nobody waits without knowing they are waiting. And the wall learned a fairer habit for surfaces like it that were never full apps: they owe only the rules that name them, not every suite-wide rule at once.
.28
v0.28.0 β π Hephaestus joins the connector. The agent factory now has its own door on the one Appolis connector: a master-admin session can see its roster of specialists, look one up, ask for a dispatch plan and read its ledger, through the same identity handshake every other app uses. The key that opens that door was minted and set on both sides without anyone ever seeing it.
.27
v0.27.0 β βΆ Appolis fills the whole phone screen. Installed on a phone, Appolis now runs edge to edge like Hermes and Kosmos, without the phone's own back, home and recents bar eating the bottom of the screen. In a browser tab, the Hub has a βΆ Full screen button that does the same, remembers your choice, and picks it back up on your next tap.
.26
v0.26.2 β π§ The Hub button now says so. The Appolis mark reads "Hub" on every screen, so nobody has to guess what the logo does. And when an AI session asks the compliance wall the wrong way, it is now told which word it got wrong instead of being handed the whole wall.
.26
v0.26.1 β π©Ή Three small things the check-up caught. Closing the Hub now puts you back exactly where you were on the page instead of at the top; the phone bar only appears once you are signed in; and if a start screen you chose is no longer yours to open, Appolis forgets it rather than apologising every time you arrive.
.26
v0.26.0 β π§ Appolis is no longer one long scroll. The admin's page used to be the city and then five whole panels stacked underneath it. Now there are departments β City, Identity, Compliance, Mail, Rules β one on screen at a time, in a single sticky row on a computer and a bottom bar on a phone. Tap the Appolis mark and the Hub opens as a control room: the live health of Appolis at a glance (version, open rules and who owes them, mail, accounts, teams, connectors), then every department a tap away, and a setting for where Appolis should open for you β remembered on your Appolis ID. Pop-ups now freeze the page behind them, and on a phone nothing scrolls sideways any more.
.25
v0.25.1 β π the rulebook can now name an app that isn't plugged into the AI door yet. The new agent factory, Hephaestus, was handed its first rule β and the rulebook had no row for it, no way to read it and no way to sign it off, because it only knew the apps wired into the connector. It now keeps a short extra list of apps without a door; they get their row and can be read and signed for, and the factory learns of its rules from its own task board until its door is built.
.25
v0.25.0 β π the rulebook's filing cabinet now has one clerk. Every app files its "we did it" claims into one shared record. Until now two claims arriving at the same moment could overwrite each other β and one such collision silently undid a rule change last week. The record now lives behind a single door that takes one request at a time, with a running copy kept where it used to live in case it ever has to move back.
.24
v0.24.1 β π the shared machine key no longer sits in a file that gets printed and committed. Every time Appolis was published, the publishing tool printed the first characters of that key to the screen, and the key itself lived in a settings file kept in version history. It now lives only inside the worker's sealed secret store β moved with no moment of downtime for the five apps that still present it, which keep working exactly as before. The key's value is unchanged; replacing it is a separate, planned job.
.24
v0.24.0 β πβ
the control centre obeys its own two rules. Asking the AI connector "who owes what?" used to answer with the entire rulebook, four times over β about 100,000 characters β on the very app whose newest rule forbids exactly that; now it answers with a short list and hands over the full text only when you ask for one item. And the pop-up that tells you what Appolis is doing now also tells you how it ended β "β App saved Β· Done." β instead of just disappearing, because a screen that goes quiet looks the same whether the save worked or not.
.23
v0.23.4 β π§ three safety checks that could never fail now can. The "send a test email" button only knew who to send to on a brand-new install, never on the real one; the shared email design would quietly dress an app it did not recognise in Appolis's colours; and the check that stops mail leaving from outside our own domain was comparing a setting against itself. All three now stop and say what is wrong instead of passing. One finished directive was tidied off the open list, and one secret stays where it is for now β with the exact reason written down.
.23
v0.23.3 β π¨ the "send a test email" button was sending plain text, from the one app that tells everyone else not to. The rule Appolis wrote for the whole suite says an email that would look the same with all its styling stripped out does not pass. Appolis's own test email had no styling at all β and it is the button other apps are told to use to prove theirs. It now goes out in the proper shell, wearing the colours of whichever app you are testing, and the message itself tells you which address it should have arrived from so you can check the two match. Found while auditing two other apps' sign-offs, not by anything breaking.
.23
v0.23.2 β π¦ and if a screen already says it is loading, it does not get a popup on top. The third ruling of the same hour. A page that already shows "Loading your orders" where the orders will appear has answered the question; a second popup saying the same thing is noise, and noise is how people stop reading the things that matter.
.23
v0.23.1 β π¦ the loading popup now sits in the middle of the screen and tells you what it is actually doing. The version an hour earlier had put it in the bottom corner with a line that just said it was still working β and the verdict was immediate: never in a corner, always a centre popup, and "waiting" is not information. So the popup is centred over a soft dimming of the page (which never blocks a click), and its second line says what is going on in plain words: "Fetching your apps, Appolis IDs, teams and settings", "Emailing a 6-digit code to your address", "Asking Resend which domains are verified". The show-me page was updated the same way, and the suite-wide rule now says the same to every app. v0.23.2, minutes later: one more ruling folded in β if a screen already shows its own specific loading message where the content will appear, it does not need a popup on top as well.
.23
v0.23.0 β π¦ the thin flashing line at the top of the page is no longer allowed to be the only sign that something is loading β starting with Appolis itself. The ruling: every app must show something a person actually understands β a loading message where the content will appear, a card that names what is happening and counts the seconds, a proper progress bar, or a popup that says which step is running. The little line at the top may keep the card company, but it can never be the whole answer. Appolis was the first to break this: loading the city, or refreshing a panel after a change, showed nothing but that line. Now a small card in the corner says exactly what the app is doing ("Loading the cityβ¦", "Saving email settingsβ¦") with a running clock, and disappears the instant the work is done. The show-me page was rewritten to match, and the suite-wide rule was updated so every other app has to do the same.
.22
v0.22.1 β π a second, independent security review of the new email sender found six small gaps, and they are closed. None of them let anyone send as another app or from another address β that held. But an old shared key could have used up another app's hourly email allowance, a cleverly typed label could have read like another app's name in some mail programs, one bad request from any app could have made the admin screen say the whole mailer was broken, an unlikely name ("constructor") slipped past the list of real apps, and a long list of sending addresses could have pushed one of ours off the end. All fixed the same night, each with a test that fails if it ever comes back, and the admin table now updates itself after a test send instead of waiting for a reload.
.22
v0.22.0 β π§ every email now really does come from the app that sent it β including the address. Since 23 August the suite was meant to send each app's mail under that app's name, but one line of code threw the name away, so every message still arrived signed "Appolis" β the change announced two rows below never actually reached anyone's inbox. That is fixed, and it goes further: each app now sends from its own address β no-reply@kosmos.appolis.app, no-reply@hermes.appolis.app and so on β because those addresses were set up with the email provider today. The admin area shows a table of exactly what each app's mail will say it is from, checks with the provider which addresses are cleared to send, and the test button now reports the sender line that actually went out rather than the one it meant to send. If an app's own address is ever not cleared, its mail still goes out β from the main address, under the app's name β and the panel says so in amber instead of hiding it. Matching fixes are waiting in Kosmos and Hermes for their own teams to release.
.21
v0.21.0 β βοΈ emails are now properly designed, and the rule about them can finally be failed. The first attempt at branded email was rejected outright: it was three plain paragraphs wearing the right name. Worse, the rule written to govern it only asked that mail carry "its look" β so any app could have submitted the same thing and there would have been no grounds to refuse. Appolis proved that by doing exactly it. There is now a proper shared email design that survives Outlook, Gmail and dark mode, with each app supplying its own colour and mark so mail looks like the app rather than the platform. You can see it rendered for three different apps at appolis.app/email.html. And the rule now has six specific things that can each be checked, plus a plain fail condition: if the email would look the same with the styling stripped out, it does not pass.
.20
v0.20.1 β βοΈ the test-email button can now send as any app, so you can check the sender yourself. The previous release changed which name emails arrive from, but the button built for testing email could only ever send as Appolis β meaning the one tool for checking mail could not check the thing that had just changed. Now you pick which app to send as, optionally name the area it came from, and the confirmation tells you the exact From line it used, so you are looking at evidence rather than taking it on trust. Three real test emails were also sent and delivered, showing Kosmos, Hermes and Appolis identities side by side in one inbox. β οΈ Corrected in v0.22.0: those three emails were accepted, but all three arrived signed "Appolis" β the app's name never reached the email provider until v0.22.0.
.20
v0.20.0 β π· emails now arrive from the app that actually sent them, instead of all looking like Appolis. A sign-in code for a Kosmos document hub was landing in the inbox signed "Appolis", which is confusing and makes every message look like it came from the same place. Mail now says Kosmos, Hermes, Agora or Phantasia depending on which app sent it β and an app can name the specific area too, so a code from the Lander Chooser arrives from "Kosmos Β· Lander Chooser". The address behind it is unchanged for now: putting each app on its own email address means proving ownership of a separate domain for each one and building its reputation from scratch, so that is a separate decision. Apps still cannot pick who they appear to be β the name is worked out from which app is calling, never from what the message asks for, so one app can never send mail dressed as another.
.19
v0.19.0 β βοΈ the other apps can finally send email β and one finished feature has been sitting unreleased waiting for exactly this. Appolis holds the only email account in the whole suite, but nothing except Appolis itself could actually use it, so every other app was stuck. Hermes had a complete, fully tested invitation feature built and deliberately NOT released, because releasing it before email worked would have locked out someone already holding a link. That is now unblocked. The new door was built to the shape Hermes had already published rather than one of my own, and four of its rules came straight from asking the other app sessions first: an app can never choose who an email appears to come from, the real tracking number from the email provider is handed back so a bounce can be traced later, urgent things like sign-in codes are never queued behind slower mail, and a send can be safely retried without a client receiving the same invitation twice. If sending fails it says so plainly β it never reports success for an email that did not go.
.18
v0.18.0 β π₯ the apps can now send ideas UP, and signing in got the way you wanted it. Until now, when an app had an idea worth making a suite-wide rule, someone had to copy it between chats by hand. Now any app files it straight into a suggestion box on Appolis. Ideas there bind nobody β they wait for you. Your admin area gained a hub where each one can be turned into a draft rule with one click (you reshape it and decide what "done" means before issuing), or declined β and declining requires a reason, which the suggesting app is shown, so the box never becomes a black hole. The next Appolis work session is told about pending ideas the moment it connects, and a scheduled check builds a full plan for anything new and sends it to your phone for approval β nothing ever becomes a rule without you. π And signing in now leads with the emailed code β type your email, get a code, you are in β with the password kept only as a backup until the authenticator app arrives. Tick "remember this device" (on by default) and that device stays signed in for 90 days.
.17
v0.17.0 β π handing work down to apps is now the normal way to get things done across the suite, so the machinery behind it was made safe enough to rely on. A rule can name one app or all of them, which means it works just as well for a single job on a single app as for a standard everyone has to meet β no more writing something up by hand and carrying it over. Before leaning on it, one real fault was fixed: if two apps filed their proof at the same instant, the second quietly wiped out the first, and nothing complained. Now a clash is detected and the work is redone against the latest state, so nobody's evidence disappears β and if it truly cannot settle, it says so loudly rather than pretending it saved. π Separately, the ordinary password sign-in has never limited how many times someone could guess; it now does, counted per computer rather than per person, so nobody can lock you out of your own account by deliberately failing your password.
.16
v0.16.0 β β»οΈ the loading-indicator rule was rewritten, and it now says the opposite of what you would expect: show LESS. The first version told every app to make sure no wait went unexplained. Building it revealed the flaw β an indicator that appears for something already finished tells you that you are waiting when you are not, and one that appears on nearly every action stops being information and becomes furniture. So the rule now leads with restraint: something appears only when you are genuinely kept waiting, quick actions are answered by the button you pressed, and anything running quietly in the background never interrupts you at all, because you never asked it to run. Appolis had the same fault and fixed it β its indicator now waits far longer before showing itself, and it can be told to stay completely silent for background work. The show-me page was updated to match, including a new example where two identical three-second jobs run and only one of them is allowed to say anything.
.15
v0.15.0 β π every app now has to build its own show-me page, and that page is the proof. Saying "we did it" is words, and a convincing paragraph can be written about work that was only half done β the only way to catch that was to go and read the code, which nobody has time for. So each app has to publish a live page, at the same address on every app, where you click a button and watch each loading indicator actually run, in that app's own look. You can check it in thirty seconds instead of auditing anything. There is a deliberate honesty rule too: if an app genuinely has nothing slow enough to need a particular indicator, it has to say so and say why, rather than faking a slow job to look finished β a page claiming something the app does not really do is worse than a short honest one. Appolis now does exactly that about itself.
.14
v0.14.0 β π
a page where you can actually watch the loading indicators work: appolis.app/progress.html. Nothing in the portal is slow enough to see its own progress bar, which made the rule about them impossible to check β and impossible for the other apps to copy. So every pattern on this page runs a real slow job you can click: the thin bar at the top, a card that names what it is doing and counts the seconds while it does it, a button that locks and spins so you can see your click landed, a step-by-step bar for jobs where the total is genuinely known, and what a failure should look like. There is a deliberate one that finishes in a tenth of a second and shows nothing at all β because a bar that flashes on every quick action just looks broken. The page is in Appolis colours on purpose, with a note at the top saying so: every app has to build this in
its own look.
.13
v0.13.0 β βοΈ you can now edit a rule you have already handed down, and add or remove apps from it. The interesting part is what happens to apps that already said they were finished. If you change what the rule actually requires, their tick is now against a rule that no longer exists β so instead of quietly leaving it green, those apps go back on the list marked "the rules changed, needs re-doing", and their assistants are told exactly what moved and warned not to just re-submit the old work. If you only fix a typo, tick the box that says so and nobody gets pulled back. And adding an app to the list never disturbs the apps that already finished. Removing an app keeps its evidence, so putting it back restores what it had proved rather than starting from scratch. π¨ The progress-bar rule also gained a line: each app has to build it in its own look, not paste in the one from Appolis.
.12
v0.12.0 β π you can now hand down a change that every app has to make, and see who actually made it. Write it once in the admin area β what must change, and what "done" concretely means β and every assistant working any app you name is handed it the moment it connects, and again on its next action if it was already running. It stays marked outstanding against that app until the app comes back and proves it complied: the version it shipped in, what actually changed, and how it was checked. A vague "done" is refused outright, and if an answer looks thin you reject it and that app goes straight back to outstanding with your reason attached. It is deliberately not the same thing as the standing rules above β those shape how assistants behave, this is work with a deadline. π¦ And the first one is progress bars everywhere: nobody should sit waiting without knowing they are waiting. Appolis brought itself into line first rather than exempting itself β the whole portal now shows a bar whenever it is doing something, and every button that starts work spins and locks so you can see your click landed.
.11
v0.11.0 β π’ you can now sign in with a code emailed to you instead of a password. On the sign-in box there is a new option: enter your email, get a 6-digit code, type it in, you are in. Passwords still work exactly as before β this sits beside them, nothing was taken away, and no other app has been switched over yet. The code lasts 10 minutes, works once, dies if you ask for a new one, and dies after three wrong guesses. There are limits on how often codes can be requested, both per email address and per computer asking, so nobody can sit there guessing. One detail that matters more than it looks: the screen never tells you whether an email address has an account or not β it says "if that address has an account, a code is on its way" β because a page that says "no such account" is a free tool for working out who has one. And if the email system itself breaks, the person signing in cannot safely be told, so the admin area shows a loud red warning instead with the exact reason.
.10
v0.10.0 β βοΈ the city can send email now, and there is a place for you to set it up. Nothing in the whole suite could send so much as one email, which is why sign-in codes by email had nowhere to go. There is now a βοΈ Email panel in the admin area where you paste a Resend key and the address mail should come from, plus a button that sends a test. Two things it is deliberately honest about: the key goes in write-only and never comes back out to the screen β you only ever see the last few characters, so you can tell which key is installed without it being readable β and saving proves nothing. Only a test email that actually arrives proves anything, so the button says Resend accepted it and tells you to go and check the inbox, spam folder included. If it cannot send, it says so loudly with the exact reason rather than quietly doing nothing. The assistant rules everyone shares also gained a start-and-end-of-shift routine, and a rule that once you have decided something, an assistant builds it instead of arguing the point.
.9
v0.9.5 β π simply typing someoneβs email address can no longer fetch their personal AI connection link. That link is a spare key to their whole account β it works on its own, acts fully as them in every app, and changing passwords or keys does not disable it. Until now, any app asking on someoneβs behalf only had to name them. Proof is now required: the app has to hand over that personβs own signed sign-in pass. It shipped as two releases with checking in between, on purpose β the release before it first built the place people go to see their own link, because closing the old way before the new one existed would have stranded anyone who signs in with an app password rather than an Appolis one. Those people now use the portal at appolis.app.
.9
v0.9.3 β π the old shared password can no longer set anyone's password. One door let a caller name an email and write that account's password β the only place that old password could still change anything rather than just read it, and it only affected invited people who had not signed in yet, which is exactly who nobody is watching. It now demands each app's own key instead. Every app was moved over first, so nothing broke.
.9
v0.9.2 β π§Ή housekeeping on the keys the apps use to trust each other. One slot belonged to an app that never actually connects here and had no key in it β a lock with no door behind it, now removed before anyone could fill it by mistake. And Kosmos was given permission to enrol people into itself and nothing else, which is the first half of repairing two sign-up pages that have quietly been failing.
.9
v0.9.1 β π the page that shows you your personal AI connection link now asks for proof of who you are. That link is effectively a spare key to your whole account, and until now simply naming someone was enough for one app to ask for theirs. Every app now quietly hands over your own signed sign-in pass when it asks, so the answer is tied to you rather than to a typed-in address. Nothing looks different yet β the old way still works on purpose, so nothing breaks while each app catches up.
.9
v0.9.0 β π the master key that signs everyone's login has been replaced. One shared password used to do two very different jobs: letting the apps talk to each other, and signing every person's sign-in pass. That meant anyone who ever saw it could write themselves a pass as anybody β including you β with nothing to notice. Those jobs are now separate, with a brand-new key for signing that has never been written down anywhere. Getting there meant changing four apps in a precise order, because doing it the obvious way would have locked everyone out of three of them. Everyone signs in once more; that's the whole cost.
.8
v0.8.3 β π three more locks. A sign-in pass with no expiry date printed on it used to be honoured forever; now it's refused, so a faked one can no longer outlive everything. The admin screens now check which site a request actually came from, closing a gap where a page on a neighbouring address could ride your logged-in session. And an app asking to give someone access can no longer quietly hand them the admin level β only you can do that.
.8
v0.8.2 β π three quiet locks on the doors the apps use to talk to each other. Asking after a stranger's account now gives the same answer whether they exist or not, so nobody can go fishing for who's registered. Only a real email address can become an account, and names have a sensible length limit β one request can no longer bloat the list every sign-in depends on. And the "give this person an app" door can no longer be talked into handing over every app at once. Nothing visible changed; nothing you use broke.
β¦
v0.4.0 β v0.8.1 β the big middle: one Appolis ID for the whole suite, teams and the role ladder, installable apps, the single AI connector door, and the trust rewrite that gave every app its own key. Written up in the Blueprint; these showcase pages are still catching up.
.3
v0.3.0 β π named grants: a personal door per person (welcome banner greets them by name), revocable one at a time; grant keys never leave the admin view.
.2
v0.2.0 β the library became a layer: no standalone docs building; every app card carries π Blueprint + π Showcase with a per-app visitor toggle (URLs stripped from public view until flipped).
.1
v0.1.0 β the city opens: apex Worker + KV catalog, master-key gate (fail-closed), public/unlisted/private tiers with rotating share keys, night-city UI, seeded with the whole fleet (all private).