Changelog

What shipped.

New capabilities, in plain language, with the technical detail underneath. Updated when there’s something to say — which, so far, is most weeks.

September 2026

Available

Your model keeps working when the platform moves on

Every definition file states the format it was written for, and the platform reads older files as they were meant, indefinitely. When the format does change, you get your whole repository back rewritten, with a report of what changed, so upgrading is a review rather than a project. A model with an error is refused with every problem listed at once — file and location included — and your previous model keeps serving the application, so a bad commit means nothing changed rather than something broke. Removed features get at least twelve months of warnings first.

Technical: definition format v1 with a versioned upgrade chain applied before binding; apiVersion per script against a frozen ScriptApi facade; strict validation with all ModelIssues reported and swap-on-success reloads; GET /admin/{tenant}/modelUpgrade returns the rewritten repository plus report; gateways declare stable/beta; published JSON Schema per version.

Available

Documents stay behind their own record

A file’s download link is tied to the record that owns it and checks read access, instead of standing on its own.

August 2026

Available

Permissions that follow your data, not a spreadsheet of checkboxes

Access rules are declared in your model over the relationships that already exist (“this role works with these dossiers and everything beneath them”). Access spreads along those relations however far they run; rules can depend on a record’s own state, checked against the state a change would produce. Lists, searches and detail pages show only what a user may see; changes the model doesn’t permit are refused; deleting a record takes down the access it handed to everything beneath it; and the interface asks the server what a user may do, so no button is offered that will be rejected. We can answer not only who may see a record, but along which path they were granted it. In production and enforcing.

Technical: ReBAC phases 1–3 — grantToObjects roots and multi-hop traversal on a dedicated cascade queue with set-based rebuild; grantToUsers with anchored per-instance AC-ids materialised into user_access; local-field conditions enforced at model load, gating materialisation and evaluated live on CREATE and against a WRITE’s resulting state; read/Elasticsearch filtering; create, re-parent and delete authorisation; capabilities published on the operations’ own routes; provenance reporting; audit namespace. What a response volunteers about an object’s neighbours stays outside the filter by design — documented as a modelling rule.

In development

Models that check themselves

A design for verifying a model against a disposable environment: unresolved references, and every label that is only a field name in disguise, reported per language before anyone opens the app.

Technical: session tenants, derived model checks, declarative scenarios.

Available

Search that finds more of what you meant

Related record names, numeric values and per-field index control, so a search reaches the things people actually look for.

Technical: per-field/per-relation index override; numeric values indexed; 1-n related names indexed from the n-side.

July 2026

Available

Archetypes: the platform now understands what a record means

A class can declare that it is a document, an event, an invoice or an email, and the application renders it as such instead of as a generic table. Document folders, invoice line-item roll-ups and email views followed within weeks.

Available

Merging duplicate records

A generic merge endpoint plus a merge action in the interface; references to the merged-away record resolve automatically.

Available

Documents you can browse, not just list

Files open in place instead of downloading, and large collections group into folder trees with counts.

Technical: inline rendering for previewable types; distinct-values endpoint with counts, including a null bucket.

June 2026

Available

Live dashboards on your own analytics database

A derived subset of your data replicated continuously to BigQuery, so dashboards read near-live figures without touching the operational system.

Technical: DatastoreReplicator consumer gateway, batched micro-flushes, initial sync endpoint.

Available

International company lookup

Official company data from 17 further jurisdictions via OpenCorporates, alongside the Dutch and UK registers, plus organisation trees and corporate relations for the Netherlands.

Available

Field history

A field can keep its own change history, visible in the application and in Excel exports.

May 2026

Available

AI document processing

Incoming documents are classified, converted and read automatically: a declarative multi-phase pipeline runs extraction tasks in parallel and writes the results onto the record.

Technical: pipeline block on a class, Gemini via Vertex AI, prompt and response-schema files, aggregation script.

Available

AI with a visible bill

Every AI call records its token usage and estimated cost on the record itself, with a fast or precise model tier per task; external services are rate-limited and tracked, normalised to euros.

Available

Users, invitations and API keys

User profiles with an invitation flow, per-tenant API keys, and a field type for credentials that is never shown in the clear.

April 2026 First month in production use

Available

Official company data, automatically

Look up a company by name or number and have its official details filled in from the Dutch business register (KvK) or UK Companies House, instead of typing them.

Available

Generated documents

Letters, statements and reports produced from templates, correctly formatted for the reader’s language and time zone, and shareable by link.

Technical: server-side Handlebars reports, tokenised report URLs, locale-aware formatting.