Changelog
What has shipped.
By date, newest first. Everything here is live; nothing is listed ahead of being built. The reasoning behind each change is kept in the product’s own decisions log, which we walk design partners through on request.
- Product
Settings, a firm roster, and mail for what a person does
A settings page: your name, your notification preference, who is at your firm and where they hold binding authority, and sign-out from every device. The counterparty is now emailed when a person counters a term, gives a quote, places a bind order, imposes a condition, files a document or asks for an endorsement — not only when an assistant acts. A message says what kind of thing happened and never what was said. Colleagues at one firm can now see each other by name, which is the first read in the product that reaches past a room and reaches only sideways.
- Governance
Every function in the schema is unreachable without a session
Postgres grants execute on every new function to everyone, and revoking from a named role does not remove what that role inherits. Twenty-three governed functions were reachable by the anonymous key — every one refused a caller with no session, so nothing was exposed, but the guarantee rested on each function remembering to check. It now rests on a grant as well, asserted by two verification checks that were confirmed to fail before they were trusted.
- Product
Signing down
A shared layer is routinely offered at 160% and everybody is cut back. A quote now records the written line and a bind order the signed line; a broker may sign a market down and never up, a signed-down premium is pro-rated, and a layer completes at 100% of signed lines.
- Product
Endorsements
The record used to stop at the binder. A bound policy can now be endorsed mid-term: the broking side asks, the market issues, both need binding authority, and nothing about an endorsement is editable afterwards — a correction is a further endorsement and a dropped request is withdrawn, not deleted. Premium adjustments are signed, so a return premium cannot read as a charge.
- Product
Activity, read as a feed
One page across every placement you are in, built from the same trail the compliance record is built from — no new table, no new write. Your own firm’s actions never appear; an assistant’s always do.
- Product
Layered programmes
A programme is a tower. Layers carry attachment and limit, a market is approached on a rung, a quote states its line as a share of that rung, and a rung cannot be bound past 100% counting outstanding orders as well as bound lines. Binding one rung releases only that rung’s other markets, and the placement is bound only when every rung is.
- Product
The book
Portfolio reporting over what you can already see: hit rate, time to bind, premium on risk by currency, which counterparties actually answer, and a queue of what has stopped moving. A rate with no denominator is shown as none rather than zero, money is never summed across currencies, and the pipeline counts one premium per rung rather than one per market.
- Product
The assistants know which rung they are on
Alex and Sam now read the whole negotiation — what is agreed, quoted, conditional and already flagged — and which layer of the programme they are drafting for. Sam no longer raises a concern that is already open.
- Governance
The whole trail, in the room
The activity tab loads the full record on request rather than the latest forty rows, and says when it is capped. A document row can no longer name another placement’s file, closed before it was ever exercised.
- Governance
Binding authority, and what a firm is
Who may commit a firm is a mark on the seat, delegated per placement, and cannot be self-granted or granted into another firm. Colleagues join an existing firm by invitation rather than each account becoming its own firm, and a colleague invitation is spent on joining.
- Product
One workspace per room; the placement file leaves the building
The room became a tabbed workspace — slip, negotiation, market, documents, activity — with a summary strip that never scrolls away. Either firm can export the whole placement as one self-contained file with every document’s hash computed at export and the chain checked at that moment. The renewal comparison lands against expiring terms that cannot move once stated. Approaching a second market carries the submission and never the first market’s negotiation.
- Product
Placements, quotes, bind orders and the placement file
One risk, several markets, each in its own room. Markets quote — indication or firm, superseding rather than editing — and decline; the broking side places a bind order and the market issues the binder. Loss runs, statements of values, financials and surveys file alongside the submission, and who may file what is enforced by the database.
- Product
Terms are negotiated, not decided
A term becomes a bilateral thread — proposed, countered, accepted, rejected, discussed, withdrawn — and a firm cannot accept its own number. Conditions precedent to binding are tracked items released only by the firm that imposed them.
- Governance
The assistants moved to Anthropic
Document reading and both assistants run on a paid Anthropic workspace whose terms do not train on prompts. The restriction that refused any upload not attested as synthetic — which existed only because the earlier free tier trained on submitted data — is gone with the reason for it. Which model read a submission is written to that submission’s audit row.
- Product
Email the counterparty; close a placement
The other firm is mailed when an assistant drafts terms or raises concerns. A placement can be closed and reopened, and a closed one stops asking for attention. The export and deletion position is written down.
- Governance
Amend before approving
A reviewer can adjust a drafted term before approving it. The adjustment is recorded as an amendment against their name, distinct from an approval, with the original proposal kept beside it.
- Product
The placement room
A broker uploads a submission, the slip fills from it without overwriting anything a person already settled, the counterparty joins by a single-use link, Alex drafts terms and Sam flags concerns, a person on each side decides, and every action lands on an append-only trail. Approval is a database gate, not a button.
Looking for what is not here yet? SSO and SCIM, SOC 2 and EU residency are listed, with their status, on the security page.