@xerg/cli), the @xerg/schemas wire contract, and the bundled Xerg skill ship together on one version. Hosted workspace features deploy continuously and are noted here when they land.
Profile-scoped analysis with source continuity
- Select a named Hermes profile or inspect a local-only all-profile rollup. Supported upload paths reject combined/unresolved scope; established single-source retries preserve their metadata.
- Preserve existing source identity during registration and provide explicit source binding and registry recovery for ambiguous histories. These recovery commands do not upload audits or create hosted sources.
- Reject redirected source-verification responses before registration. The selected workspace credential is sent only to its configured HTTPS origin, with HTTP reserved for localhost development.
- Recheck saved source bindings before fresh uploads and reject conflicting destination metadata. Keep a current registry backup after successful registration so recovery includes newly registered profiles.
- Preserve explicitly supported known-zero usage instead of replacing it with catalog spend, while retaining positive recorded amounts. Correct main-session residuals that auxiliary usage could previously hide.
- Keep corrected accounting separate from incompatible comparison baselines without creating another hosted source or resetting metering highwater. Methodology deltas are not qualified savings.
- Isolate observer writers and correlations across profiles, support unload/reload, and retain v1 ledger/health compatibility. Request-hook tool-result sizes remain separate from raw returned bytes; blocked/cancelled attempts do not become executions. Spill references and content remain private.
- Prevent Xerg-induced policy blocks during concurrent tool observation. Unsupported requested-versus-executed comparisons and dependent mechanical measurements remain unavailable, not zero; observer liveness does not imply complete lifecycle coverage.
- Restore request attribution for already-recorded tool executions when delivered completion evidence uniquely identifies the request. Ambiguous or conflicting evidence remains unassociated; execution counts and authoritative spend stay unchanged.
- Preserve one detailed logical request where equivalent captured starts previously forced aggregate fallback, while requiring one matching completion and exact state request/token totals. Observed-start counts are not complete provider-attempt counts; latency includes retries and per-attempt detail remains unavailable. Ambiguous or missing metadata still falls back to aggregates, and old captures are not repaired. Cost remains state-authoritative; missing charges are neither reconstructed nor proof of zero billing.
- Keep retained historical sessions from incorrectly blocking otherwise complete current-session comparisons. Missing or conflicting evidence for current sessions still blocks unsupported comparisons.
Install a reviewed skill revision explicitly
- Pin the Agent Skills installer and require an operator-reviewed full repository commit SHA. Earlier setup guidance selected a mutable installer and repository head.
- Preserve interactive agent and installation-scope choices, with separate permission for installation, local analysis, remote access, and hosted writes. Without a reviewed revision, stop only the installer step or import an already-reviewed local folder after permission.
- Keep the independently reviewed CLI version unchanged. Installer and source pins do not establish transitive-dependency or cryptographic integrity, and no runtime upgrade is automatic.
- Audit accounting, supported runtimes, observer behavior, Push v7, and Event Payload v4 are unchanged.
Keep agent execution on the reviewed CLI version
- Pin the canonical agent skill’s CLI installation and execution instructions to an exact reviewed version.
- Preserve the running CLI version in package-runner follow-up commands. Earlier recommendations could select another version through a mutable package tag.
- Keep upgrades explicit and preserve separate permission for installation, local analysis, remote access, and hosted writes. Offline QM still requires an operator-provisioned CLI.
- Audit accounting, supported runtimes, observer behavior, Push v7, and Event Payload v4 are unchanged.
Update dependencies while preserving audit behavior
- Update runtime dependencies for security and compatibility across the CLI and hosted workspace.
- Correct terminal-cell widths and wrapping for decomposed Hangul and Devanagari spacing marks while preserving grapheme boundaries and copyable commands.
- Report structure, CLI commands, audit calculations, pricing, Push v7, and Event Payload v4 are unchanged.
Make long terminal reports easier to scan and copy
- Findings, signals, and repeated tool chains now render as separated records with a title, metadata, an optional summary, and the exact explain command beneath an Explain: label.
- Complete
key: valuefields pack together when they fit and stack below 64 columns. Copyable commands remain one unchanged logical line; narrow terminals may soft-wrap them visually. - Compact omission summaries and Next command: actions are separated from the content above, while short ranked lists remain compact.
- Multi-line errors and recovery guidance now render as individually labeled lines. Earlier output could expose a literal
\nsequence instead of the intended line break. - JSON, Markdown, push payloads, SQL, configuration snippets, exit codes, flags, and report ordering are unchanged.
Align current economics, change, and observed agent lineage
- Sources cards and Source Detail use the newest eligible measurement rather than adding overlapping measurement windows. Active sources whose retained measurements are all archived stay visible as No active measurement instead of showing synthetic zeroes.
- Source cards remove the duplicate CLI-version badge and measurement-count metric. They show compact pricing-qualified runtime spend, identified waste and rate, attached-baseline change, activity timing, and evidence coverage; CLI version remains in Advanced source metadata.
- Source and Measurement Detail share the same current-economics and attached-baseline presentation. Delta labels distinguish changes from current values, show baseline to current, and express waste-rate movement in percentage points. Comparisons whose baseline pricing cannot be established are labeled unavailable instead of treating placeholder zeroes as exact values. Runtime spend remains workload-dependent and explicitly is not an invoice.
- Measurement Detail leads with Summary and spend/waste drivers, includes Performance only when two or more daily points support a trend, promotes one next action without repeating it below, and moves detailed pricing and detector eligibility into Coverage & methodology.
- Measurement History source-series rows no longer expose or copy the latest hosted measurement ID. Expanded individual measurements retain their IDs and comparison actions. Archive guidance appears only in Archived, independently of paid-history guidance.
- Hosted Push v7 ingestion and MCP preserve optional observed immediate parent-to-child agent-delegation paths. Agent totals remain authoritative, relationship spend is not added again, and historical measurements distinguish missing paths from unavailable attribution or an observed absence of delegation.
- Global Ask Xerg route context replaces redundant source- and measurement-specific Ask buttons. Focused measurement answers receive bounded agent totals and delegation paths from that measurement rather than borrowing them from a different latest result.
Refine Ask Xerg and dashboard presentation
- Ask Xerg moves out of primary navigation. Paid workspaces open it from the top-right Ask Xerg trigger, which relocates into the desktop drawer header while the drawer is open and returns when the standard right-panel close control is used.
- The desktop Ask Xerg trigger remains in a standalone sticky bar above each page title and its native controls. A subtle bottom divider separates that fixed bar from scrolling page content.
- The desktop navigation and Ask drawer widths are adjustable by pointer or keyboard from their vertical separators, and both chosen widths persist locally.
- The desktop drawer removes New chat, demo switching, the context-switch notice, and context/freshness chrome. The retained full-page and mobile
/dashboard/asksurface continues to provide those controls. - The drawer empty state uses the transparent Xerg triangle, the heading Ask about your agent fleet economics, and the Ask a question composer immediately below it without explanatory or freshness footer copy.
- Fractional values attached to supported percentage-rate labels render as percentages instead of raw decimals, including across Markdown emphasis, while unit-based rates remain unchanged. Identifier-like tokens of at least 32 characters shorten to 16 characters plus an ellipsis; the full value remains in a hover title and screen-reader text, and the shortened token is keyboard-focusable. Answer-copy and evidence-capsule chrome are removed, and at most two follow-up prompts remain.
- Dashboard narrative dollar amounts normalize to exactly two decimal places in Ask chat text, Finding, Signal, recommendation, and Optimization copy, including older stored summaries and copied Fix with Xerg tasks. Desktop workspace and Ask drawer headers remain divider-free, while the standalone Ask bar retains its boundary line.
- Sources removes the separate Runtime postures filter label and names the posture select’s default option All runtime postures while retaining its accessible filter name.
- Ask Xerg remains read-only, uses the same memory-only conversation and private response contract, and changes no entitlement, CLI command, public schema, pricing, Push v7, Event Payload v4, or package version.
Keep workspace-grounded guidance beside the work
- Paid workspaces can open a resizable Ask Xerg panel from every dashboard page. It shares space with the current page, survives route navigation, and uses the same conversation as the retained full-page Ask route; only panel width persists, while reload, logout, workspace changes, context switches, and New chat clear messages.
- Measurement, source, and Optimization details can prefill a focused question. Finalized answers render safe Markdown and keep evidence on the supporting message; evidence links navigate without resetting the open panel, including through the new nonmodal Optimization detail route.
- The composer stays visible, grows through eight lines, submits with Enter, preserves Shift+Enter, and exposes stop, retry, copy, jump-to-latest, reduced-motion, and screen-reader behavior. Free workspaces retain the locked Ask page and receive no panel affordance.
- The hosted chat accepts bounded, validated conversation and page context through a private contract. Its SSE path buffers Workers AI output, applies the existing pricing- and detection-coverage truth enforcement, and emits only the finalized answer. Demo requests remain isolated from workspace context, and no message or entity content is added to product analytics.
- Ask Xerg remains read-only. CLI commands, public schemas, pricing, Push v7, Event Payload v4, and package version 0.31.0 are unchanged.
Read the important audit truth first in any terminal
- Human audit output now defaults to a compact hierarchy: truth-critical limitations precede totals, followed by headline economics, prioritized actions, comparison state, and capped top findings, neutral signals, workflows, models, and agents. Omitted counts include the exact non-pushing
--detailscommand. --detailsadds the exhaustive human report toaudit,ingest, all threecollectcommands, anddoctor. It is separate from--verbose, which remains operational diagnostics on stderr; doctor retains its per-file extraction appendix on stdout.- A single presentation layer provides stream-aware color, display-width wrapping, hanging indentation, narrow-terminal stacking, ASCII structural status labels, and visible escaping of hostile terminal controls. Copyable commands, paths, URLs, identifiers, money, SQL, JSON, and TOML are never split or truncated.
- Help now derives from shared command metadata,
logout --helpno longer removes credentials, login is described as advanced recovery, and ingest help correctly identifies Event Payload v4 with versions 1 through 4 accepted. xerg explainreplaces embedded pretty JSON in human output with titled evidence and limitation sections.--jsonremains byte-compatible and is the supported automation interface.- JSON reports, multi-source envelopes, dry-run payloads, QM SQL, MCP JSON/TOML, print-example output, hidden exporter output, and bare version output remain byte-stable. Markdown is an exhaustive human projection and may gain sections; automation should use JSON.
- Standalone
pushexit5product conditions and the existingaudit --pushexit1compatibility difference are now documented without changing behavior. The existing multi-source last-source-wins threshold verdict also remains frozen and documented.
Send an evidence-backed Optimization to Linear
- Paid workspace admins can connect one Linear workspace with authorization-code OAuth, choose an accessible Linear team, and create an issue from an Optimization drawer.
- Xerg creates at most one Linear issue per Optimization. Repeated requests return the stored issue link, including after a provider response is lost, instead of creating duplicates.
- Issue title and description are built from the same content-free Fix with Xerg handoff. They include the bounded evidence summary, implementation checklist, estimate qualification, validation instructions, and Xerg link; prompts, responses, tool arguments or results, headers, arbitrary attributes, and embedded Cedar are not sent.
- The integration is deliberately one-way. It adds no automatic issue creation, webhooks, comments, bidirectional status synchronization, or automatic Xerg lifecycle transition.
@xerg/schemas0.30.0 adds theexternalIssueTrackingcapability and provider-neutral external-issue contracts. CLI commands, audit analysis, pricing, Push v7, and Event Payload v4 are unchanged.
Move active savings work through an evidence-backed lifecycle
- Optimizations keeps its prioritized list as the default and adds a URL-restorable Board view with Open, Implemented, and Validated columns. One bounded API request returns up to 25 cards per column, full counts, and View all links.
- The board excludes snoozed work by default while the list continues to include it. Both views provide an explicit include, exclude, or snoozed-only filter.
- Admins can move Open to Implemented, Implemented to Open or Validated, and Validated to Open. Moving to Validated opens the existing comparison selector first; provisional items are not draggable, and archive or restore remains an explicit menu action.
- Lifecycle controls require both the current organization role and Xerg’s stored workspace role to be admin. A mismatch produces a read-only board, while the API remains authoritative for every mutation.
- Cards preserve the distinction among qualified savings, recorded-but-unqualified validation, and unavailable legacy validation details. Compare’s evidence-recurrence columns remain derived and non-draggable. CLI commands, schemas, package version 0.29.0, Push v7, Event Payload v4, and pricing are unchanged.
Carry an evidence-backed fix from Xerg into a coding agent
- The existing Optimization drawer now calls its copy action Fix with Xerg and produces an agent-ready Markdown task from the same recommendation, checklist, policy suggestion, read-only Cedar note, and validation workflow.
- Paid hosted-MCP users receive an exact
xerg_get_optimization({ optimization_id })retrieval instruction. The new read tool returns one safe, versioned handoff and never changes code or policy. - Authenticated
GET /v1/optimizations/:idmakes Optimization links work outside the current filters or page while preserving workspace ownership and pushed-history entitlements. - Optimization list and detail responses add the latest immutable validation summary. Qualified savings, recorded-but-unqualified validation with its canonical reason, and absent legacy facts remain visibly distinct; a missing fact is never labeled pair-cap exhaustion.
- Free-history limits also apply to the current and baseline measurements referenced by each validation fact. Out-of-window audit IDs and monetary evidence are omitted, and a covering index keeps latest-fact selection bounded as validation history grows.
@xerg/schemasexportsOptimizationHandoffV1,OptimizationValidationSummary, and the canonical eleven-value validation-reason registry in the synchronized 0.29.0 release. CLI commands, Push v7, Event Payload v4, Cedar behavior, pricing, and automatic code mutation are unchanged.
Fail closed when identified-waste thresholds cannot be evaluated
- Earlier versions could exit
0for--fail-above-waste-rateor--fail-above-waste-usdwhen no active monetary detector assessed the source. That success result was non-conclusive and could allow CI to pass against a false zero. - Version 0.28.1 exits
5for that state across OpenClaw, Hermes, Claude Code, and other audit shapes. Existing pipelines may begin failing with exit5; improve evidence coverage, intentionally handle the unavailable result, or remove a threshold the available evidence cannot evaluate. - A partial or full result over positive eligible request evidence from at least one active monetary detector remains evaluable. A vacuous full row with zero eligible requests is not assessment. Threshold breaches remain exit
3,--require-detection-coverageretains its stricter behavior, and incomplete QM pricing continues to exit5.
Lead each expandable group with its complete list
- Optimizations now lists All Optimizations first, linking to the existing backlog before Policies (Alpha), consistent with All Sources appearing first under Sources.
- All Optimizations remains available on Free, while Policies retains its existing paid-capability lock. Dashboard routes, entitlements, APIs, CLI commands, schemas, and package versions are otherwise unchanged.
Prevent gateway and transcript double counting
- Earlier OpenClaw audits could count overlapping activity twice whenever both session transcripts and gateway logs produced calls, including auto-detected input, explicit
--log-fileplus--sessions-dir, SSH, and Railway audits. Version 0.28.0 uses session transcripts as the sole authority in that case. Gateway runs are excluded from totals, findings, signals, lineage, and local activity analysis instead of being added to transcript activity. - Mixed reports disclose the tradeoff before totals and in their notes: transcript evidence can omit gateway-only activity, so activity and spend may be understated and findings may differ from a fully reconciled view. Notes sent with an explicit push contain source kinds and counts, never local paths.
- Local doctor reports both call counts.
doctor --verboseseparates non-empty files excluded by source authority from genuinely empty or out-of-window files.--log-filealone and--sessions-diralone remain the explicit gateway-only and transcript-only paths. - Corrected local mixed audits use transcript comparison identity. SSH and Railway keys add a source-authority boundary, so the first 0.28.0 remote comparison does not present removal of the duplicate representation as savings; the next compatible run compares normally.
- Earlier measurements remain immutable. Re-audit the original evidence and push the corrected result when a hosted replacement is needed. Gateway-only, transcript-only, standalone OpenClaw trace, Hermes, QM, Claude Code, Cursor, and event-ingest audits are unchanged. Push v7 and Event Payload v4 are unchanged.
Make comparative percentages stable and visible
- Overview Department and Runtime posture waste-rate bars now use a fixed 0–100% plot with 25-point ticks. Rates inside that domain use literal widths and fleet-marker positions; higher values cap at the endpoint while retaining their numeric label and an explicit above-scale cue. Open plot space remains neutral rather than presenting a 100% efficiency complement.
- Exact rows exceed the exact fleet rate in warning color; lower bounds stay neutral, unavailable rates are named instead of resembling zero, and above-scale fleet references are distinguished from ordinary in-plot markers.
- Workflow, model, agent, and Compare spend shares keep their genuine part-to-whole 0–100% rails with a more visible neutral track and unchanged accessible percentage values.
- Audit data, APIs, schemas, Push v7, Event Payload v4, CLI behavior, pricing, entitlements, and public package version 0.27.4 are unchanged.
Compare spend, waste, and verified savings over one period
- Overview now applies one inclusive UTC date range to known spend, identified waste, verified savings, its daily chart, Department or Runtime posture comparison, and Source Performance. The last 7, 30, and 90 completed days plus custom ranges are URL-restorable; Free retains its existing 30-day history limit.
- Three keyboard-operable KPI tabs select the chart series without another request. Missing dates remain gaps, partial waste is a visible lower bound, and unavailable deltas explain why they cannot be compared. A numeric table mirrors the chart for nonvisual access.
- Overlapping rolling measurements are no longer added together. The period ledger selects the latest eligible daily evidence for each source and UTC activity date and retains every active source, including No data in period rows.
- A first measurement pushed today no longer opens into an empty default period. When the implicit completed-day default has no measurements but today does, Overview discloses an in-progress extension through today and suppresses deltas; explicit ranges never auto-extend.
- Verified savings now comes from prospective immutable validation facts. Identical validation evidence is idempotent, changed evidence creates a new fact, and later regression or archive does not rewrite the observed validation. A range crossing the fact-history start shows only recorded savings as a visible
≥lower bound and leaves earlier dates unavailable. Retained archived measurements can still support an accepted validation under the same entitlement and strict seven-day before/after evidence standard. - The additive
GET /v1/economic-ledger/periodresponse contains only known spend, identified waste, verified savings, coverage, daily series, and period source rows. The existing latest Economic Ledger, outcome views, Push v7, Event Payload v4, CLI behavior, pricing, entitlements, and public package version 0.27.4 are unchanged.
Assign runtime posture without inference
- Workspace admins can assign each active or archived source one current runtime posture: vpc, on-prem, saas, local, hybrid, or air-gap. Existing sources remain Not set until assigned.
- Xerg never infers posture from framework, brand, host, collection environment, or audit evidence. Later audit pushes preserve the workspace assignment and never set, clear, or overwrite it.
- Source Attributes shows stable active and all-source counts for every posture plus Not set. Sources adds posture filtering and assignment, while Overview can group identified-waste rates by Department or Runtime posture without changing fleet totals or lower-bound disclosures.
- Source list/detail and Economic Ledger source rows add nullable
runtimePosture.GET /v1/sources/runtime-posturesreturns entitlement-independent source-registry counts, and admin-onlyPUT /v1/sources/:id/runtime-postureassigns or clears the value. - CLI commands, package version 0.27.4,
@xerg/schemas, Push v7, Event Payload v4, pricing, audit identity, and entitlements are unchanged. Older clients remain compatible with the nullable hosted source field.
Put decisions and workspace evidence first
- The authenticated navigation now calls stored results Measurements, makes Sources and Optimizations independently expandable, and keeps Departments under the extensible Source Attributes area.
- Overview leads with what needs attention and distinguishes positive identified waste, a conclusive zero, and incomplete assessment. Measurement and source detail pages consolidate redundant next steps and use activity-period and measured-at language consistently.
- Optimizations starts with a counted status queue and source filter. Policies is explicitly a draft-only Alpha surface: policy drafts are not evaluated or enforced at runtime.
- Ask Xerg now identifies whether an answer uses workspace or explicit demo context, reports freshness, and links to supporting measurements, sources, and Optimizations. Explicit demo answers always use sample context, while empty workspaces no longer receive silently substituted sample data.
- Settings separates Workspace, Members, Billing, API Keys, and Integrations; client setup renders one configuration at a time, credential rotation warns about disconnected clients, and secrets stay out of visible and accessible configuration text.
- CLI pairing now emphasizes the selected workspace, requested action, and live expiry while moving identifiers and environment details into a disclosure. Member-limit recovery opens Members, and the second-measurement checklist links to the setup quickstart. APIs, pricing, audit analysis, Push v7, and Event Payload v4 are unchanged.
- Source cards now show one concise Date range instead of separate activity and measurement timestamps, and the Sources page removes redundant archive guidance. Department rows omit internal IDs, while the create action remains a single-line control.
Choose compact before-and-after measurements by source
- Compare now starts with a source, then presents concise activity periods for baseline and current measurements instead of one dense workspace-wide audit list.
- The newest measurement and nearest earlier compatible period are selected automatically when available. Recommended choices share the source key, environment, and comparison identity; reruns of the same period remain available outside that group.
- Existing
aandblinks remain valid, including archived selections. Advanced cross-source comparison remains available and opens automatically for an existing cross-source link. - Audit Detail and Optimization links place their single current measurement in B, preserving the B − A direction when a baseline is added.
GET /v1/auditslist items now add nullablecomparisonKeyidentity for compatibility-aware selection. Push v7, Event Payload v4, stored data, pricing, and comparison calculations are unchanged.
Distinguish a measurement from its activity period
- Measurement Detail now uses the source name as its sole heading and presents the activity period and measured-at timestamp as compact supporting metadata.
- Its breadcrumb is now Sources → source → Measurement, and copy/archive controls consistently refer to the stored result as a measurement.
- Source Detail labels measurement-history dates Activity period. Snapshot terminology remains limited to the immutable hosted identifier under Advanced metadata.
- Audit analysis, dashboard routes, API contracts, pricing, and stored identities are unchanged.
Separate verified savings from remaining waste
- Overview now leads with realized savings only when a validated Optimization has a same-source, fully measured seven-day before/after comparison, a matching resolved high-confidence finding, non-declining successful outcomes, and lower known spend. Otherwise it says no verified savings exist yet instead of showing
$0 saved. - Savings are deduplicated and capped by the observed spend reduction. Current identified waste remains a separate measure.
- Department bars now compare identified-waste rates on one common scale with a fleet marker while keeping exact waste and known-spend dollars visible.
- Audit Detail puts daily known-spend and waste-rate Performance directly below its KPIs and adds detector-attributed Workflow economics. Older audits keep workflow spend and label the waste breakdown unavailable.
- Audit Detail now leads with a decision summary: current economics and outcomes, compatible baseline change, and the next supported action. Findings and source-level actions are consolidated; informational Signals, detector evidence, the glossary, and support metadata stay collapsed until needed; and only one workflow, model, agent, or evidence breakdown renders at a time.
- A one-day audit shows compact daily values instead of drawing an empty trend line, while an audit with no daily evidence labels those metrics unavailable. Multi-day waste-rate charts preserve unavailable gaps rather than treating them as 0%, and unsupported Optimization scores and duplicate recommendation sections are no longer shown.
- Identified-waste-rate time-series on Audit Detail, Source Detail, and Compare now use a fixed 0–100% y-axis so the same rate occupies the same visual position across views.
- Source Detail now names the affected metric when spend and waste-rate coverage differ and explains that blank waste-rate days are unavailable values, not 0%.
- Collapsible dashboard rows now use directional chevrons instead of visible Expand/Collapse text while retaining descriptive screen-reader labels and expanded state.
- Source Detail now leads with current economics and outcomes, a compatible prior-measurement comparison, and the top open Optimization. Its daily charts and flat measurement history share one activity-date range and archive scope, overlapping windows are deduplicated by latest eligible measurement per UTC day, technical metadata moves under Advanced, and one-measurement series no longer show a redundant count badge.
- Push v7 additively includes the optional requested audit interval, workflow-waste totals, and detector-versioned finding changes. Verified savings uses the declared interval rather than inferring duration from days with activity. Older Push v7, v6, and stored history remain valid without these fields; the wire version and Event Payload v4 are unchanged.
Carry the current Xerg identity across public surfaces
- Browser tabs, bookmarks, saved iOS home-screen shortcuts, search metadata, and the marketing site now use the current Xerg symbol and logo.
- Authenticated dashboard chrome now identifies the active workspace with its Clerk organization logo and name, without a persistent Xerg mark, plan badge, or switcher chevron. The Clerk-backed workspace control switches organizations without carrying a workspace-specific route into the newly selected workspace.
- Default link previews now use the approved dark social card, and generated blog cards use the same current logo treatment.
- The public status page receives matching light- and dark-surface logo variants. APIs, pricing, entitlements, audit analysis, and wire contracts are unchanged.
Recognize existing QM source names
- Dashboard source branding now recognizes standalone QM identity markers used by existing sources such as Finance Operations.
- Those sources render the supplied QM mark across source and audit views, and Source Performance identifies their framework as YC Quarter Master instead of Unknown.
- Source Detail now keeps rename and full-ID copy actions in its overflow menu, groups environment, department, archive, and CLI badges below the title, and places range and push time on a separate line.
- Audit Detail uses the same header hierarchy, moves audit-ID copy into its icon-only overflow menu, and keeps detailed audit identifiers in Advanced metadata.
- Source identity, audit analysis, API responses, and wire contracts are unchanged.
See proven waste by department
- Overview now leads with a fleet conclusion and top recommendation, followed by known spend, identified waste, and cost-per-successful-run KPIs with server-computed seven-day comparable-source deltas.
- Identified waste by department uses one current department per source and renders incomplete measurement as a lower bound. It never treats the unclassified complement as efficient spend.
- Source Attributes lets workspace admins create, rename, and delete departments and assign active or archived sources. Members can read assignments, and the feature is available on Free and paid plans.
- Source Performance replaces the old ledger table. The standalone snapshot/action/trend row and Latest Audits were removed from Overview because Audits remains the dedicated history surface.
- Claude Code and QM now use their supplied source marks throughout source, audit, Compare, and Overview surfaces; unknown sources keep the neutral fallback.
- The CLI, schemas, Hermes observer, and canonical skill are synchronized at 0.27.3. CLI behavior, Push v7, Event Payload v4, pricing, and audit analysis are unchanged.
Make audit sources easier to recognize
- The marketing site and dashboard now use the current Xerg logo with its green symbol.
- Audit lists, audit series, Audit Detail, Compare, and Sources now show the supplied Claude Code, QM, and LangChain marks when their source metadata or visible source name identifies the runtime.
- LangChain branding applies to audits received through the existing generic event ingest contract. Audit analysis, source identity, API responses, and wire contracts are unchanged.
Render documentation currency as ordinary text
- Currency examples in hosted pricing and detector-coverage documentation now retain their literal symbols, spacing, and typography instead of being interpreted as mathematical notation.
- Documentation CI now rejects accidental math delimiters in prose while preserving shell commands and other code examples.
- Product pricing, metering, packages, and hosted behavior are unchanged.
Deliver queued MAAS lifecycle notices
- Threshold and billing-lifecycle notices now leave the pending queue on the scheduled delivery cycle instead of being rejected by the D1 compound selector.
- This corrects a hosted defect that could leave email, dashboard, and Slack delivery states pending even while metering and billing reconciliation continued normally.
- MAAS totals, commercial bands, checkout, grace periods, enforcement, pricing, and audit data are unchanged.
Review cross-runtime economics in one workspace ledger
- Overview now selects the latest entitled active audit per source and presents normalized spend, identified waste, outcome coverage, success rate, and known cost per successful run in one Economic ledger.
- Sources without outcome data stay visible and are excluded from outcome denominators. Free workspaces receive the same endpoint and dashboard view within the existing 30-day history window.
- Audit Detail adds outcome economics, and Compare adds cost-per-successful-run and success-rate rows while preserving Audit A as baseline and Audit B as current.
- Every Signal kind now includes suggested investigation guidance explicitly labeled as not a savings estimate. Signals remain non-monetary and create no recommendation, Optimization, or CI impact.
- The CLI, schemas, Hermes observer, and canonical skill are synchronized at 0.27.2 for coordinated distribution. CLI behavior, Push v7, Event Payload v4, D1 storage, and pricing are unchanged.
Review audit history beyond 90 days
- Audits now offers rolling 6-month and 12-month ranges plus all-time history on Team, Growth, Scale, and Enterprise workspaces.
- Free keeps its existing date choices through 90 days while the server continues to enforce the 30-day visible-history limit. The longer paid ranges remain visible and marked Team+.
- Active and Archived views share the same URL-restorable range, source, sorting, and bounded pagination behavior. Archiving and retention are unchanged.
Refresh supported runtime and build tooling
- Refresh the supported MCP runtime, dashboard and site build tools, CLI prompt libraries, and test tooling after compatibility validation across local and hosted surfaces.
- Keep repository CodeQL initialization and analysis aligned on one pinned v4 release.
- CLI commands, flags, exit codes, audit behavior, pricing, Push v7, Event Payload v4, migrations, and hosted API contracts are unchanged.
Make audit conclusions explicit and workflows easier to navigate
- Audit Detail now shows separate waste-assessment and pricing-coverage states before totals. Partial pricing is labeled “Known spend,” unpriced calls are never treated as zero, and incomplete assessment never presents a primary zero-dollar clean conclusion.
- Overview and audit-list cells use the same conclusion rules, including explicit “Not fully assessed,” “Not assessed,” and legacy pricing-completeness disclosures.
- Compare now calculates deltas as current B minus baseline A, pairs direction with text and arrows, and limits directional waste and recurrence claims to the same source-qualified comparison series when it also passes the existing compatibility decision.
- Empty Optimization backlogs now distinguish filters, no active audits, incomplete assessment, and a fully assessed no-opportunity result, with a relevant next action for each state. The additive
meta.emptyStateAPI field carries the same reason and audit counts. - Audit Detail adds sticky section navigation, an accessible glossary, grouped signal workflows, chart units and pricing-coverage captions, and text-plus-bar spend shares. Compare organizes compatible evidence into new, resolved, changed, and collapsed unchanged groups.
- Audits adds human-readable source selection, newest/oldest latest-push sorting, restorable filter/status/page URLs, one-snapshot simplification, and deduplicated “Earlier snapshots.” Archive copy now states that hidden history is neither deleted nor refunded from quota.
- Overview continues the existing onboarding card through the first two audits, and Sources adds clearer creation/display-name guidance, visible rename controls, and source-to-series-to-snapshot breadcrumbs.
- Push v7 additively includes optional human-readable signal scope labels. Earlier v7, v6, and stored v5 history remain readable without the field.
Clarify public release and QM setup documentation
- Public changelog, QM setup, machine-discovery, and bundled skill surfaces now focus on user-visible behavior, privacy boundaries, and operator approval requirements.
- CLI commands, exit codes, audit behavior, pricing, Push v7, Event Payload v4, and hosted contracts are unchanged.
Activate monthly audited agent spend pricing
- Hosted pricing is live with Free ($0 up to $2,000 MAAS), Team ($99 up to $10,000), Growth ($299 up to $50,000), Scale ($799 up to $250,000), and custom Enterprise above $250,000.
- Team, Growth, and Scale share the same paid capabilities and have no paid-band member limit. Free keeps its current restrictions.
- Checkout opens immediately. Metering begins at a clean UTC boundary and never bills, warns on, or enforces against earlier activity.
- The retired Pro catalog is archived.
Add day-level pricing coverage to pushed audits
- Push v7 and Event Payload v4 add day-level priced and unpriced call counts for coverage transparency. Push v6 remains accepted and meters with identical amount semantics.
- The CLI and schemas train supplies coverage detail only. Hosted MAAS metering already works from the daily known-spend values in Push v6.
Refresh supported dependencies and make release dates precise
- Runtime, build, database, email, and content dependencies are refreshed together after compatibility checks across the CLI and every hosted surface.
- Every historical changelog entry now includes a month, day, and year.
- CLI commands, exit codes, audit behavior, pricing, Push v6, Event Payload v3, and hosted data contracts are unchanged.
Show the complete custom-license label on npm
@xerg/clipublishes the unchanged Xerg CLI License Agreement as its top-level lowercaseeulafile, allowing npm’s required custom-license form,SEE LICENSE IN eula, to fit the package sidebar without an ellipsis.- The agreement text and xerg.ai/cli-license page are unchanged.
@xerg/schemasremains MIT-licensed, and no CLI command, exit code, audit behavior, Push v6, or Event Payload v3 contract changes.
Complete license terms in the package and on the web
@xerg/clinow ships the complete Xerg CLI License Agreement as its top-levelEULAfile and points npm consumers to it with the compactSEE LICENSE IN EULAmetadata.- The same canonical agreement is published at xerg.ai/cli-license and linked from the npm README, site Terms, footer, sitemap, and machine-discovery pages.
@xerg/schemasremains separately MIT-licensed. Push v6, Event Payload v3, CLI commands, exit codes, and audit behavior are unchanged.
Know what ran, what stayed local, and what reached the dashboard
- Hosted pairing and pushes use client-context v2 with the closed
skill,direct, andunknownsetup-method vocabulary. Existing durable funnel events move to schema v3, and heartbeat-backed activation attempts power explicit dashboard recovery states without guessing that a long audit failed. - A successful local-only audit always says “Saved locally. Dashboard unchanged.” Missing sources and noninteractive source selection make
activateexit2with distinct recovery;--connect-onlycontinues to exit0without source detection. - Setup copy is aligned across the site, dashboard, npm README, skill, and quickstart. The guarded value claim is “Audit data stays on your machine unless you choose to push it.”
- Generic ingest validation moves into the MIT
@xerg/schemaspackage without adding Zod as a public dependency. Event Payload v3 has a published JSON Schema andxerg ingest --print-example. @xerg/clinow points npm consumers to the packagedLICENSE.md. This scripted-behavior and published-artifact change is pre-1.0 and intentionally called out.
Continuous observer liveness and honest aggregate-only output
- The Hermes observer now eagerly creates a bounded mode-
0600per-process health sidecar, atomically refreshes it every 60 seconds, marks orderly shutdown, and becomes stale after 150 seconds. Heartbeats never grow the observer evidence ledger or affect coverage, retention, economics, or audit identity. xerg doctor --runtime hermes --require-observer-liveexits5unless a current observer process is running and its writer is not known unhealthy. Observer health is a continuous production-coverage concern, not only a test prerequisite, and no restart can reconstruct old activity.- CLI terminal/Markdown reports, dashboard audit/source pages, hosted MCP readers, Ask Xerg, and exported reports now put an aggregate-only warning before spend totals and conclusions whenever active waste-detector coverage is incomplete. Aggregate economics remain available where priced, while zero identified findings are explicitly non-conclusive.
- The Xerg skill hard-stops prospective observer-backed or sequence-dependent Hermes workloads on failed preflight, while still allowing already-existing and historical aggregate-economics audits after the mandatory warning.
- Hermes v0.20.1 auxiliary task charges such as
title_generationremain separately attributed aggregates because Hermes does not expose them through public per-request hooks. Their economics stay in totals, their sequence analysis is explicitly unavailable, and they no longer invalidate exact observer reconciliation for observable main and delegated requests.
Honest Hermes v0.20 terminal measurements
- Xerg and its optional observer support Hermes v0.17 through v0.20.1. State schemas 16 through 25 are certified; newer schemas are read best-effort with an explicit local warning.
- Hermes v0.20 bounds terminal output before the observer sees the tool result. Xerg 0.24.1 uses Hermes’s structured character total as a conservative UTF-8 byte floor, renders affected quantities as “At least,” and never reads or retains Hermes’s spill path.
- Returned bytes remain exact. Generated and truncated values are omitted when their basis cannot be established, including old observer ledgers without a measurement basis. Comparisons require exact values on both sides and never difference floors.
- A local read-only integrity check warns when affected Hermes usage tables omit
taskfrom the expected six-column primary key. Affected periods may have dropped rows, so totals may be floors for those periods; totals remain exact for rows Hermes recorded. The warning does not cross Audit Push Payload v6. - Xerg 0.24.0 was not certified for Hermes v0.20.x terminal mechanics and could understate generated or truncated bytes. State-only economics remained sound for rows Hermes successfully recorded; 0.24.1 is the compatibility fix.
Durable activation measurement without request coupling
- Explicit hosted pairing and push requests now include a fixed, content-free execution-context envelope. Local commands remain telemetry-free and make no new analytics call.
- Successful pairing approvals and distinct stored snapshots create separate, content-free activation events. Product responses, quota semantics, dashboard links, and CI exit behavior remain independent of analytics availability.
- Activation is the first distinct stored snapshot, with pairing as its preceding milestone. Events expire after 365 days, and PostHog receives only coarse, schema-versioned context.
Incremental snapshots stay together
- Overview, Audits, and source detail now group related incremental pushes into deterministic series. Rows expand in page-local state, show hidden active/archived snapshot counts, and offer per-series comparison using hosted snapshot IDs.
- Archive actions remain snapshot-specific. The dashboard labels copy actions as “Copy hosted snapshot ID”; the separate analysis fingerprint moves under Advanced metadata, and internal series keys never appear in dashboard text or browser URLs.
- New series-list and series-snapshot API endpoints filter before ranking and paginate series rather than raw snapshots. Status-filtered and status-agnostic counts retain the Free history cutoff and every other eligibility filter.
- Trends add the explicit
latestSnapshotPerSourceDaybasis. MCP and Ask Xerg use it so incremental pushes from one source/day do not inflate totals; the legacypushDaybasis and pre-1.0 omitted-basis default are unchanged.
Window-aware remote identity
- SSH and Railway comparison keys now include the normalized
--sincewindow. Equivalent spellings such as024hand24hshare identity, omitted windows useall, and different windows no longer share comparison or hosted dedup history. - Cached remote snapshots retain correct source metadata because Xerg strips the versioned window suffix before reconstructing the target.
- The first upgraded remote push intentionally crosses an identity boundary and may consume one Free snapshot or receive the existing at-quota response. Pre-0.22 remote snapshots are never compared or deduplicated with the new format.
Agent-safe first run
- The npm README now gives terminal-capable agents the canonical
set up https://xerg.ai/skill.mdprompt before the human positioning copy. - The interactive
initquickstart is explicitly labeled as the human path. Agents are directed to the skill’s permission-gatednpx --yes @xerg/cli@latest doctor --jsonworkflow instead of a TTY prompt. - The canonical skill recognizes a cold fetch reached through the npm listing and preserves the placement and meaning of both handoffs.
Evidence drill-down and argument-aware activity
- New
xerg explain <item-id-or-prefix>retrieves digest-only local evidence for findings, signals, and qualifying repeated tool chains. Eight-character IDs and package-runner-safe, audit-pinned hints appear in terminal and Markdown reports; grouped Claude runs retain every contributing main/sidechain source locator locally, while raw tool arguments and results are never retained or pushed. - Claude Code now reconstructs progressive streaming records by
(sessionId, messageId), merges usage component-wise, unites tool calls by ID, and correlates tool results. Irreconcilable records remain count-only and are excluded from ratios and exact detectors. - Tool-name repetition is a neutral diagnostic, not a monetary conclusion.
deep-loop-activitycan carry chain occurrences, fingerprint coverage, and a distinct tool-input ratio through Push v6. High diversity is consistent with fan-out; low diversity is a reason to inspect. Neither proves waste, recoverability, or success. - Claude Code does not synthesize state/progress evidence and therefore cannot emit monetary
tool-loopfindings. The legacytool_sequence_repetition_v1name-only method is retired; stale snapshots receive an explicit rerun warning. - Opus 5 has a reviewed first-party global standard rate matrix for input, output, cache reads, five-minute cache writes, and one-hour cache writes. Aggregate cache writes use the documented five-minute default and disclose possible one-hour underestimation. Billing mode, inference geography, and partner-platform dimensions remain explicit limitations when source records omit them.
- Pricing updates are vendored, deterministic, reviewed weekly, and never fetched during an audit. The catalog automation opens a PR and never auto-merges.
xerg doctor --jsonnow gives agents one common readiness contract and a shell-safe recommended command. The Claude Code skill uses the latest CLI, explains every monetary finding before remediation, and treats chain signals as neutral observations.- The obsolete
xerg focusCLI tombstone is removed; it and retired audit flags now receive normal unknown-command/option errors. Hosted rejection of legacy FOCUS pushes and permanent retirement documentation remain. - Thanks to a Xerg user whose real-world corpus exposed the streaming-reconstruction caveat, name-only repetition failure, and Opus pricing gap.
Evidence-strict findings and neutral signals
- Current Xerg releases emit three monetary findings only: correlated
retry-waste, exact no-progresstool-loop, and net-negativecache-thrash. Seven other observed patterns are separate neutral signals with no avoidable amount, recommendation, Optimization, or CI impact. - A component-level claim ledger prevents overlapping detectors from double-counting model charges or cache premiums. Recommendations derive savings exclusively from detector-owned
avoidableSpendUsd. - Push v6 separates findings from signals, adds affected/avoidable spend, evidence/impact basis, detector version, and per-detector coverage. V5 remains readable with a legacy-method badge and cannot recur into current Optimizations.
- Terminal, Markdown, and dashboard audits show ordered signal metrics, scope, observation confidence, explicitly non-waste associated spend with cost basis, and separate 3+7 detector coverage. Public product language is standardized on Findings, Signals, and Optimizations/Recommendations.
- Generic event ingest v3 accepts stable request/cost IDs and content-free tool, result, state, and cache fingerprints. Older payloads remain readable without gaining detector coverage they did not supply.
- The Agent Spend Modeler is registry-driven and exposes one hypothetical slider for each of the three monetary findings and seven neutral signals. It leads with the 7.5% monetary-finding subtotal, treats the 18.5% signal-associated subtotal as spend requiring review, and shows the 26% combined scenario only if runtime evidence confirms the signal-associated spend is recoverable. Only the edited rate is clamped at the 50% combined interface ceiling. Signal-associated spend remains neutral until runtime evidence supports a conclusion. Platform and mode selections are descriptive and do not change the rates.
Production QM support
- QM is a first-class explicit Xerg runtime through a host-independent
qm-snapshot/v1adapter. Strict direct collection uses a dedicated view-only reader; certified Fly collection uses a pinned one-shot exporter inside QM core. - Fly’s broad managed reader is not used. Fly snapshots disclose a process boundary and
databaseLeastPrivilege: false; strict direct mode rejects base-table, write, owner/create, membership, inheritance, or RLS-bypass authority. Both use bounded read-only queries and HMAC pseudonyms before persistence. - Positive QM cost is observed; explicit deterministic models may be catalog-estimated. Negative placeholders and unresolved
openrouter/autousage remain unpriced, cannot create false$0spend or savings, and make monetary gates exit5. - Request-versus-aggregate reconciliation, harness-specific timestamp semantics, open/drifted snapshot state, orphan preservation, and current retained tool activity are explicit. Tool activity outside QM’s one-hour source window and continuous follow capture are not supported.
- Pseudonymous QM summaries are recognized across the hosted dashboard, trends, comparisons, Optimizations, Ask Xerg, Slack, and hosted MCP after an explicit push. The audit push contract remains v5.
- In 0.19.0 a QM Slack agent can explain setup and audit an authorized pre-created snapshot in a private scope; continuous follow capture, durable tool-history capture beyond QM’s retention window, and live Slack-triggered collection are not supported.
- Offline QM Slack audits accept only an authorized pre-created snapshot. The CLI must be explicitly approved, provisioned, and version-verified by an operator in the administrator’s private runtime; agents must not install it implicitly or initiate live collection. The runtime receives no database URL, identity key, Fly token, provider credential, or Xerg credential.
- Browser activation can require an exact Clerk organization with
--organization-id. The approval page shows the full organization ID, live plan, and environment; the API rejects mismatches, the CLI verifies live entitlements, and stored credentials remain bound to their approved API environment. activate --connect-onlycompletes exact-workspace pairing and exits before source detection, auditing, or pushing. The browser displays the credential-only action, preserving a separate approval boundary for later hosted writes.- Workspace and membership provisioning now enforces uniqueness under concurrent requests while preserving existing customer data and roles.
Stateless MCP v2 runtime
- The hosted
/mcpendpoint now uses the stateless MCP SDK v2 server and supports the MCP 2026-07-28 protocol revision. - Existing stateless clients remain compatible through the same endpoint, Bearer authentication, allowed-origin policy, and 11-tool contract. No FOCUS tool was added.
- Browser clients may send the v2 method, tool-name, and declared tool-parameter headers through the existing allowlisted CORS boundary.
Runtime-audit consolidation
- Provider-generated FOCUS ingestion, validation, local comparison, and hosted push were retired. Xerg does not convert runtime audits to FOCUS and does not currently ingest or reconcile provider invoices.
xerg focus ...remains a no-op compatibility tombstone for the 0.18 train. It exits before reading paths, authenticating, or accessing the network, and Xerg never deletes customer CSV, Parquet, manifest, snapshot, or historical hosted data.- Runtime push wire versions 1–5 remain compatible. Legacy v4/v5 FOCUS pushes receive
410 focus_support_retiredwithout consuming quota or creating hosted state. - Active audits, sources, trends, Ask Xerg, MCP, Optimizations, Slack, quota, onboarding, and activation accounting are runtime-only; direct historical FOCUS reads return the retirement response.
- Public TypeScript FOCUS exports were removed from
@xerg/coreand@xerg/schemasas a breaking0.xminor change. The stable retirement note contains migration guidance.
Operable Hermes request coverage
- The first-party Hermes observer now records its version, startup, retention, freshness, and dropped-event health without storing prompts, tool arguments, or results.
xerg doctor --runtime hermesdistinguishes absent, installed-but-not-loaded, fresh, stale, retention-pruned, incomplete, conflicting, and full observer states, then gives the exact restart/new-session/verification sequence.- Historical aggregate sessions remain aggregate-only. Xerg never claims that enabling the observer can reconstruct request order that Hermes did not retain.
- Live
state.dbreads use a consistent transaction, retry brief economic changes, and mark unresolved drift or open source periods.
Detector coverage and Push v5
- Every runtime detector reports content-free total and eligible request/spend measures plus bounded missing-data reasons. Identified-waste rate continues to divide by total spend and always shows “assessed $X of $Y.”
- Push v5 separates a stable
economicAuditIdfrom the analysisauditId, so observer enrichment can preserve economics while storing a distinct analysis. V1-v4 retry deduplication remains unchanged. - Dashboard lists, detail, sources, Compare, trends, Ask Xerg, hosted MCP, and Slack carry coverage. Incompatible waste rates become unavailable/null; compatible total-spend comparisons remain.
- New
--require-detection-coverage full|partialexits5when CI receives less request-sequence evidence than required.
Aggregate audit truthfulness
- Customer-facing output now says “Identified waste” and distinguishes “none found under full coverage” from “request-sequence waste was not assessed.”
- Aggregate-only Hermes audits retain spend, request count, cumulative token/cache economics, workflow/model/tool totals, and delegated-workload totals.
- First-request cost, initial context, request-level growth, retry sequences, and identical-input loops are unavailable unless directly observed. Same-tool-name streaks are no longer described as identical-input loops.
Browser-approved first-audit activation
- New
xerg activatepairs a CLI to a workspace through a ten-minute browser approval, then detects, runs, and pushes the first local audit.--push-latest, explicit runtime, Cursor CSV, ingest-file, replacement, and no-open variants preserve the existing CLI controls. - A P-256 ECDH and HKDF-derived AES-GCM envelope delivers the existing single workspace key only to the initiating CLI. Codes and polling secrets are hashed in D1; transient ciphertext is cleared after acknowledgement or expiry; the key never appears in a URL, browser, terminal, log, or analytics event.
- Get Started opens Clerk SignUp directly and lands in the normal dashboard waiting state. The approval URL and pairing code survive SignUp, SignIn, and automatic organization creation.
- The canonical skill and getting-started docs use
activateas the one normal connection path. Maskedloginis an Advanced recovery option, andXERG_API_KEYis the documented CI path. - A workspace without a first push may receive one transactional recovery email containing the skill prompt and
activatecommand; it does not create a marketing contact. - Free snapshot-limit messaging is hidden during the initial empty state and first successful push. Existing quota enforcement and structured remedies remain unchanged afterward.
FOCUS 1.4 billing compatibility
- New
xerg focus init,focus doctor, andfocus auditcommands discover and audit provider-generated FOCUS 1.4 Cost and Usage, Contract Commitment, Invoice Detail, and Billing Period datasets from local CSV or Parquet. - Exact decimal ingestion, deterministic currency subunits, bounded Parquet windows, a local ephemeral join store, strict CI validation, invoice reconciliation, commitment coverage, billing-period validation, and like-for-like local comparison keep billing analysis reproducible.
- Raw artifacts and row-level billing data stay local. Explicit hosted sync uses Audit Push Payload v4 with an audit-kind discriminant and a USD-only privacy-bounded FOCUS aggregate.
- Hosted audits, trends, dashboard detail, Ask Xerg, and MCP are audit-kind aware. FOCUS creates no runtime-waste findings, Optimizations, recommendations, or Slack deliveries, and runtime estimates are never combined with provider billing.
- Local FOCUS support is free. Free hosted workspaces use the existing 30-day and 100-snapshot-per-UTC-month limits; Pro adds full history plus Ask Xerg and hosted MCP; Enterprise adds guided onboarding and organizational requirements.
Signup-first activation
- The primary Free journey now creates a workspace before guiding the user through source selection, secure CLI login, the exact audit command, and a live waiting state for the first push.
- The onboarding state survives refreshes and sign-ins, records durable activation milestones without CLI telemetry, and includes deliberate snapshot-limit recovery.
- Secure setup uses
xerg login --replace, which verifies a new workspace key before atomically replacing any existing stored credential. - The homepage now pairs its primary workspace CTA with one terminal-agent setup prompt and a separate no-agent CLI fallback.
- Xerg’s canonical skill supports cold fetches, and both current and legacy well-known discovery formats serve byte-identical skill content with generated integrity metadata.
Certified Hermes trace enrichment
- New
xerg collect hermescommand receives traces-only OTLP/HTTP protobuf on loopback for the exact certifiedbriancaffey/hermes-otelcommit. Xerg prints configuration but never installs or modifies the plugin. - Hermes captures require
state.dband use a persistent owner-only correlation key. Identifiers are HMACed before persistence; a moved capture without its key remains descriptive and cannot split economics. - The sanitizer drops prompts, responses, conversation content, invocation parameters, arguments/results, commands, paths, goals, summaries, approval text, skill paths, user IDs, and arbitrary attributes even if upstream privacy settings are wrong.
- The first-party observer stays primary. Trace evidence can enrich ancestry, approvals, skills, tools, and delegation; observer/trace request conflicts restore the original state aggregate.
- Certified plugin prompt totals are normalized into uncached input plus separate cache-read/write buckets before reconciliation. Optional observer and trace enrichment stay outside the audit comparison identity, so exact evidence does not change the authoritative audit ID.
- The collector prints equivalent environment variables for non-default
HERMES_HOMEprofiles, where the pinned plugin’s fixed~/.hermesYAML lookup would otherwise miss profile-local configuration. - Audit Push Payload v3, hosted storage, dashboards, MCP, finding kinds, recommendations, and failure gates remain unchanged.
Common local analysis surface
- Hermes and OpenClaw now share explicit
analysisCoverage, neutraltoolActivity, andworkloadEconomicslocal blocks with deterministic lineage handling. - Complete first-party Hermes observer API evidence can split a
state.dbaggregate only when request count and input/output/cache buckets match exactly. Incomplete, dropped, ambiguous, or conflicting evidence stays aggregate. - Authoritative cost is allocated across exact requests without changing request totals, token buckets, spend, cost source, or audit ID. Only reconciled requests enter sequence-dependent detectors.
- Content-free prompt-size counters, tool-result byte evidence, compression counts, state-only tool inventory, and branch/delegation lineage improve local context and orchestration coverage.
- When no request sequence is eligible, reports say sequence-dependent monetary findings were not evaluated instead of implying no inefficiency.
Current OpenClaw evidence and isolated trace collection
- Modern OpenClaw session transcripts now retain ordered tool names, exact execution counts, serialized input/result byte sizes without content, compaction evidence, and root/child lineage with deterministic cycle handling.
- OpenClaw reports add separate local Tool activity and Workload economics sections. These neutral blocks do not create findings, recommendations, savings claims, waste totals, or CI failures.
- New
xerg collect openclawcommand receives traces-only OTLP/HTTP protobuf on loopback, sanitizes each request before persistence, and audits the bounded owner-only capture after shutdown. It never changes OpenClaw configuration or pushes automatically. - Existing captures can be audited with
--otlp-file. This source is isolated from transcripts, logs, other runtimes, and remote modes so economics cannot be double counted. - The collector enforces 16 MiB request, 256 MiB capture, and 100,000 span limits; hashes correlation IDs before persistence; rejects content attributes; preserves interrupted captures; and never overwrites an output file.
- Xerg Event Payload v2 adds optional
modelCallIdandtoolCallIdcorrelation with strict same-payload and same-run validation. Version 1 remains accepted. Audit Push Payload v3 and all hosted schemas remain unchanged.
Hermes state database and local mechanical analysis
- Xerg now reads Hermes v0.17 through v0.19
state.dbdirectly in query-only mode, including schema 16 session aggregates, schema 20 model usage, and schema 22 task usage. Unknown compatible future columns are ignored. - Aggregate request counts now reconcile with Hermes without multiplying aggregate token or cost values, and sequence-dependent monetary detectors ignore observations that cannot support sequence claims.
- Compression continuations become one logical run while branches and delegated sessions remain separate. Positive actual cost is observed; positive estimated cost is estimated; missing or zero cost is repriced where token data permits.
- The optional
xergai/hermes-observerplugin records content-free local tool, terminal, API-error, delegation, and lifecycle mechanics. It never adds economic calls or sends data to Xerg Cloud. - Hermes reports can include a separate local Mechanical efficiency section. Only directly observed repeated identical tool inputs and discarded terminal output can become findings; other shapes remain neutral metrics.
- Mechanical data is excluded from recommendations, audit gates, audit IDs, pushed payloads, hosted storage, and MCP. The public wire contracts remain unchanged.
- The minimum runtime is Node 22.13.0, the first Node 22 release where
node:sqliteno longer needs a startup flag.
Free hosted workspaces
- Xerg now has a Free plan: a hosted workspace for up to 2 members with the last 30 days of pushed audit history, up to 100 stored audit snapshots per month, and workspace API keys. Local audits stay unlimited and account-free.
- Pro ($29 per member per month) adds full pushed audit history, unlimited audit pushes, unlimited workspace members, Ask Xerg, hosted MCP, Slack, and optimization policy drafts. Enterprise remains available for SSO/SAML, self-hosted deployment, and custom contracts.
- The dashboard shows your plan, monthly snapshot usage, and history window, and paid features display an in-place upgrade path instead of redirecting away.
- After a successful local audit, the CLI occasionally suggests saving audits in a free workspace (at most once per week, never in CI or machine-readable output, and never with telemetry). Successful pushes print a direct dashboard link to the pushed audit.
xerg loginnow accepts Free workspace keys, and push errors explain member-limit or snapshot-quota issues precisely.@xerg/schemasgains theWorkspaceEntitlementswire contract backing the newGET /v1/entitlementsendpoint.- The design partner program has closed; see the pricing page for current plans.
Silent-source visibility and a canonical finding-kind registry
- Audits now tell you when a detected source file contributes nothing: a count-only note appears whenever OpenClaw, Hermes, or Claude Code files produce no included calls in the audit window, instead of those files silently vanishing from the report.
xerg doctor --verboselists those zero-call files with their full local paths so you can inspect them. Paths stay local and never cross the push wire.- Markdown reports from
xerg audit --markdownnow include the Notes section that was previously terminal-only. @xerg/schemasgains a canonical finding-kind registry (FINDING_KINDS,FINDING_KIND_META, and lookup helpers) as the single source for finding labels, categories, and implementation surfaces.- Terminal and markdown taxonomy output now labels cache carryover and max mode concentration findings instead of showing raw kind identifiers.
- Hosted workspace: pushes create and recur Optimization backlog items again (wire v3 payloads were stored but skipped backlog upserts between July 6 and July 11), and provisional backlog items now persist real category and surface data for every finding kind.
Cost per outcome and richer call economics
- New
xerg outcomecommand: declare a success or failure outcome for a run or workflow. Declarations are stored locally, apply to future audits, override derived outcomes, and unlock cost-per-outcome reporting. - Every normalized call now carries first-class economics fields across all sources: cache and reasoning tokens, stop reasons, tool names, and outcomes.
- Unified date-aware pricing engine with a much larger model catalog, replacing per-source pricing tables.
- Session-native waste detection: transcript-inferred retries, tool loops, context growth, cache thrash, and cadence-based idle spend.
- Push wire payload v3 adds token-economics and outcome rollups. Framework event payload v2 for
xerg ingest. xerg doctor --verbosenow reports field-extraction coverage per source, so you can see how much economic detail each source provides.
OpenClaw transcript parsing fixes
- Parse the modern OpenClaw session transcript format, including normalized
message.usagetoken fields. - Calls that report a cost of zero (common on subscription or OAuth billing) are now treated as unobserved and priced by estimation instead of being counted as free.
- Added newer Anthropic models to the pricing catalog.
- Trajectory support bundles are excluded from detection to avoid double counting.
xerg initreports cloud-setup failures as cloud-setup failures, noting that the local audit succeeded and is cached.
Claude Code, ingest for any framework, and per-agent spend
- Claude Code is now a first-class local source: Xerg audits session transcripts from
~/.claude/projects/, withinitanddoctorsupport. - New
xerg ingest --file <payload.json>command audits any framework through a versioned JSON event payload. - Per-agent spend attribution, including delegated sub-agent spend, in the CLI audit output, the hosted dashboard, and Ask Xerg.
- Content-addressed audit IDs make pushes idempotent; re-pushing the same audit no longer creates duplicates.
- The Xerg skill is now installable with
npx skills add xergai/skills. - Turnkey first run: a friendly Node version guard at startup, a non-blocking update notice when a newer CLI is published, Node 26 support, and
@latest-pinned install commands everywhere.
Slack integration
Pro workspaces can connect Slack from dashboard Settings: pick a channel, receive Optimizations and audit notifications, send a test message, and mute or disconnect at any time.Synced release train
- The CLI, schemas, and skill now publish on one synced version with automated drift checks.
- Refreshed npm, docs, and skill listing content.
Accuracy hardening and a lighter install
- Provenance-aware findings, more conservative retry and loop waste detection, and normalized compare output.
- Removed the native SQLite dependency: local compare snapshots are stored as JSON, installs no longer need a native build step, and prompt dependencies were narrowed to what Xerg actually uses.
- Clearer Cursor and runtime waste taxonomy documentation.
Skill runtime metadata
- Declared the Xerg skill runtime metadata used by registry security scans.
- Documented the local, remote, and hosted data-flow boundaries.
Action queue and recommendation contract v2
- Recommendation payload upgraded to v2: ranked recommendations with stable IDs and structured scope labels, included on the push wire format.
- The terminal audit output now ends with an Action queue summary of top
fix_now,test_next, andwatchitems. - The same v2 recommendations power the hosted Optimizations backlog.
Init-first onboarding
- New
xerg initinteractive first run: detects local sources, runs the first audit, caches a snapshot, and offers hosted follow-up. - New
xerg connectandxerg mcp-setupcommands with shared auth resolution across local and hosted flows. - Refreshed docs and skill messaging around free local audits with optional hosted setup.
Hermes support
- Hermes is now a first-class local runtime alongside OpenClaw, with
--runtimeselection and local auto-detection. - Runtime-aware compare and push labels, updated skill content, and refreshed docs.
Daily spend and waste series
Audit output and pushed payloads now include daily spend and waste series, expanding the dashboard-ready rollups without changing the hosted API contract version.Diagnostics improvements
--verboseprogress output fordoctorandaudit.- No-data guidance now points to explicit local paths plus SSH and Railway inspection flows.
- Better Railway diagnostics and package-runner hints, so
npxandpnpm dlxinstalls see the right follow-up commands.
Bundled agent skill
- The Xerg agent skill ships inside the npm package and is published to ClawHub with each CLI release.
- Supported Node runtime is 22 or newer.
Remote audits, push, and CI gates
- Remote OpenClaw audits over SSH and Railway: telemetry is pulled to your machine and analyzed locally.
- Public
@xerg/schemaspackage: the MIT-licensed wire contract for pushed payloads. xerg login,xerg logout, and standalonexerg pushfor explicit hosted sync.- Ranked recommendations in audit output.
- CI threshold flags with dedicated exit codes, including exit code 2 for no-data errors.
Initial public beta
- Local OpenClaw audits in dollars: spend rollups and waste findings from gateway logs and session transcripts.
xerg audit --comparefor before and after reporting against the previous snapshot.xerg doctorsource diagnostics.- Supply-chain hardening for the published package.