18 — 25 SEPTEMBER 2026

What didDavid do?

A Microsoft Teams bot, merged in one Thursday · org admins can see their whole app’s memories again · a company’s name back on its workspace · seventeen merged

0MERGED
0OPENED
0CLOSED
0STILL OPEN

SCROLL ↓

ACT I — ONE THURSDAY

Thirteen mergedon Thursday. Eightwere a Teams bot.

A stack, merged in order through the queue · 3:23pm to 6:35pm Central

MERGEDOPENED

SLACK NOW A CALLER TEAMS NEW THIS WEEK LIB/AGENT_TURN ONE LOOP · ONE BUDGET ONE WAY TO CITE
First, the Slack bot’s agent loop moved out of Slack into a shared library. Slack’s prompt came out byte-identical, checked by comparing the two, not by eye#4009
A Teams endpoint that verifies Microsoft’s signed token, and pins it to where the reply is going, so a valid token can’t be replayed to send answers elsewhere#4010
Who is asking: a Teams user resolved to the Hyperspell person who owns their connections, reusing the email bridges pulled out of Slack’s identity ladder that morning#4020
Answers rendered as Teams cards, with the same turn budget and citation links as Slack, now held in one place#4022
Then the turn itself: mention the bot in a channel, or message it directly, and get a cited answer from the same agent Slack uses#4024
And the runbook for the Microsoft side that no code can do: the app registration, the bot resource, the app package, the tenant binding#4032
Off wherever its Microsoft app ID is unset. Staging is first, and waits on that registrationNOT LIVE

The first pull request was the one that made the rest small. Once the agent stopped being a Slack thing, Teams was intake, identity and rendering — not a second bot.

ACT II — WHO GETS TO SEE WHAT

Every adminin every org, pinnedto their own memories.

A permission read from a list Clerk never puts it in · since May

233 → 0

Org apps where no admin could see the whole app · before and after #3919

“Can view all memories” was checked against a membership payload that only ever carries Clerk’s system permissions. It said no to every member of every org, admins included. The test had mocked a payload Clerk does not produce#3919
Its two sibling checks promised to fail closed and didn’t: six of seven callers turned a Clerk hiccup into a broken page instead of a clean “no”. Never a privilege risk — an error can’t return yes#3936
Sixty-two workspaces from before May had their company’s name replaced by “Personal” in the redesign. A customer asked how to get it re-connected. Nothing was disconnected; it now says their name#3920
The same customer then saw “No memories yet” on every source page, over 128,790 documents the API returned fine. The page asked as the viewer, who owns almost none of them. This one reversed a written decision, and the pull request said so#3973

None of these widened anyone’s access. Each one either restored what a permission already promised, or made a failure read as “no” instead of as a crash.

ACT III — SMALLER, SHARPER

Two bots onthe standup roster.

Found by the first live cards, fixed the next morning · and four more like it

The first live standup cards listed two of our own bots as teammates. Other apps’ posts and Slackbot are no longer counted as people#4021
Several messages sent together shared one timestamp, so they could be replayed in any order — scrambled bodies, a title from the wrong turn. Each now carries its place in line#4082
A GitHub resync now actually walks for missing documents, instead of asking for a replay that stopped after one delivery#3921
App-owner settings reached through the bot had been refused since 4 September. Latent — those tools are switched off — and caught in review of the Teams work#4047
A conversation between a person and an agent is no longer titled after whoever spoke first#3870
#3913+747

Re-indexing unchanged content is meant to cost nothing. On one resync of our own repo, 2,838 of 2,838 unchanged chunks were summarised and embedded again. This skips them.

IN REVIEW
#4106+234

Why nobody has seen the bot jump in on its own: it spent its daily budget deciding whether to speak, so three silent looks muted a channel for the day.

IN REVIEW
#4045+1,554

One live smoke test for the Slack bot: threads, date windows, the standup card and its roster, run against the real thing.

APPROVED
#4025+1,126

Telling a real GitHub push from metadata churn, so a changed repo re-indexes only the modules that changed.

IN REVIEW
#3976+458

Live GitHub access can search code and read a single file, with secrets files refused before any request is made.

IN REVIEW

The first two in that queue are the next week’s story. One makes a routine refresh cheap enough to turn on; the other is why the bot has been so quiet.