What's changed
Every update to this app, newest first — what it added, what it changed, and what it fixed. Written for whoever has to use the thing, not derived from the commit log.
Version 0.20 This build is A page that shows how the app is built, released 01 October 2026.
A page that shows how the app is built
0.20 01 Oct 2026Explaining this app meant drawing the same diagrams on a whiteboard every time. They are now a page: what talks to what, where the figures and the words come from, the path a report takes, and what can happen to it afterwards.
New
-
An Architecture page, under About
Six diagrams: the layers the app is built in, where fund figures and narrative each come from, how a report is made from the form to the archive, which of three places decides the template, everything that can happen to a report and who may do it, and what an unattended scheduled run would look like. The last of those is marked as planned, as is anything else on the page that does not exist yet.
-
Infrastructure diagrams, alongside the code ones
Where the app actually runs — one New Zealand VPS, nginx in front, the app reachable only from the machine itself, the database a file on the same disk, and the only traffic leaving being outbound. Plus how a push to master becomes a deploy, and what state lives on the box. They say what shape the deployment is without printing server paths, the internal port or the service account, none of which help the reader and all of which are on a page open to anyone.
-
The lifecycle diagram is drawn from the rules themselves
The statuses, the arrows between them and the table of who can do what all come from the same code the review screen enforces, so the picture cannot describe a lifecycle the app does not have. If a rule changes and the drawing has not caught up, the page says so underneath rather than leaving the move off.
Funds are somewhere you can look
0.19 01 Oct 2026A fund used to be a line in a dropdown. There is now a Funds section: every fund the app can report on, with a page each saying what it is and what a report from it would be built from. It is the first piece of giving each fund its own reporting setup.
New
-
A Funds section
Every fund that can be reported on, in one list — the ones defined in code and the ones typed in under Admin, marked so you can tell which is which, with how many reports each has produced and when the last one was.
-
A page for each fund
Its type, benchmark, manager and key; the holdings its research step looks up; and the figures a report would be built from today, at every level the data carries. The figures are shown by the same code that shows them on a report's own page, so a fund and a report from it cannot disagree about what the numbers are.
-
Each fund can have its own default template
Set it on the fund's page. A report for that fund is built with it unless the request asks for something else, and the generate form opens on it when you pick the fund. A fund that chooses nothing keeps using the app-wide default, so nothing needs setting up before it can be reported on. This is what a scheduled run will read: there is nobody at the form to choose a layout, so the fund has to carry one.
Changed
-
The fund list as data moved to /api/funds
“/funds” is now the page people read. Nothing in the app was using the JSON version; a caller that was will need the new address.
Every report says how it was made, and what it was made from
0.18 01 Oct 2026A report's own page in the app now answers the two questions the document is the wrong place for: which words are whose, and what the fund's figures were before the page reduced them to what fits on two pages.
New
-
Where each passage came from
Every macro driver, market reaction and commentary section is listed with who wrote it — a person, the model, or the model with an analyst's edits — and the sources it rests on. The Sources list answers “what does this source hold up”; this answers it from the other end, which is the question you have when you are reading the report and doubt a sentence. A model-written passage resting on nothing is called out where you can see it.
-
The fund's figures, including the ones the report leaves out
A country or holding table in the document is a reduction: the eight countries with the largest effect on return, and the holdings chosen on the generate form. The fund's data carries 25 countries and 45 holdings, and until now the rest were visible nowhere. They are all on the report's page in the app, at every level the data has — returns, attribution and positioning by sector, country and holding — with the rows the document never named marked as such. None of it goes into the document.
-
A way in to all of that, from where you already are
“How it was made” now sits on the review screen, next to Read the document. Generating a report lands you there, and that is where a report gets approved, so it is where the question of what a sentence rests on actually comes up — but it had no link to the answer. Past reports says it too: opening a row has always gone to that page, and now the page says so before you click.
Shorter AI writing in the two-page layout
0.17 30 Sep 2026With Fund report (short) chosen, the market reactions and commentary are drafted to fit two pages: about 60 words per holding and 90 per commentary section.
New
-
A notice when a passage is still too long
If a drafted passage comes back well over its limit, the report's notices say which one and how long it is, so it can be shortened before approval.
Changed
-
Market reactions and commentary fit the two-page layout
Each holding's market reaction is kept to about 60 words, and market commentary, attribution commentary and outlook to about 90 words each. The drafts also stop describing what the searches did or did not find, and keep to the reporting period. The Standard fund report is unchanged.
The two-page fund layout is a template you can pick
0.16 30 Sep 2026Fund report (short) now appears in the Template list on the fund form, and the form opens on it. Fund reports were still coming out in the long layout; choosing the short one now always gets it.
Changed
-
Templates lists the short layout
It shows as built in and for fund reports only, with a preview and Copy and edit like the standard one. It is not offered on Research a subject: subject notes keep their About this report section.
Fixed
-
Fund reports come out in the two-page layout
The short layout was meant to apply on its own, and in practice never did. It is now listed on the fund form as Fund report (short) and selected by default, unless an admin has made another template the default. Whatever is selected is what renders, and Past Reports names it.
Room to work on a desktop, and the real attribution tables
0.15 25 Sep 2026The app is used on a desktop nearly all of the time, and it was drawn for a phone: three bars of chrome before anything started, and every screen squeezed into a column a third of the width of the window. Both are fixed. Underneath, the attribution and positioning tables now come from real country and security figures rather than a single sector line.
New
-
Fund reports open with a returns chart
A fund-versus-benchmark bar chart by period, matching the same figures as the Fund returns table beneath it. Same image in both Word and PDF.
-
A How to page
Under About. The tasks people come here for, step by step: make a report, research a subject, find a report, change the words, get it approved and published, read the markings, templates, and what each Admin tab is for. The About page is brought up to date with it: the review flow is on the screen now, and funds can be added by hand.
-
Add a fund without a deploy
A Funds tab in Admin. Name a fund, its type and benchmark, list the holdings worth researching, and paste its returns, attribution and positioning as lines of text — a paste from a spreadsheet works as it is. It then appears on the generate form like any other fund, and its reports go through research, provenance and review the same way. The report says the figures were typed in. A bad line is refused with its line number; a fund can be retired and brought back.
-
Choose which holdings the attribution table names
A drawer on the generate form, pre-ticked with the largest contributors and detractors for the period. Tick or clear any name to feature it or hold it back.
-
Attribution and positioning by country and by security
The Global Equity report now carries country and security tables alongside the sector one, in both Word and PDF, built from the fund's holdings rather than a single placeholder line.
Changed
-
One type scale on every screen
Text came in fifteen sizes across the app, several a half-pixel apart. It now comes in seven: fine print, hints, labels and tables, body, the line under a heading, section headings and page titles. Hints are a touch larger than they were, and the odd half-size is gone.
-
A one-line footer on the working screens
The four-column brand footer now appears only on About, How to and What's changed. Every other screen ends with one line: the version and date of this build, and links to What's changed and How to.
-
The generate forms are shorter, and the button stays in view
Fund and reporting period share the first row, with Last month, Last quarter and Last 12 months as one-click chips beside the dates. Word or PDF is chosen next to the Generate button, which now stays at the foot of the form while the drawers above it are open. The same on Research a subject.
-
A saved message is shown once, then gone
After saving a fund, an audience, a prompt guide, a setting or a template, the confirmation used to sit in the page's address, so a refresh said 'Saved' again and a copied link carried it to whoever opened it. It is now shown on the next page only. Retiring, restoring and making a template the default say so as well; they were silent.
-
One house style for everything the model writes
The three drafting prompts each carried their own copy of the language rules, and they had drifted: one banned em dashes and two did not, and the same rule was worded three ways. There is now one house style, included in all three: New Zealand English, past tense for the period, the fund called by its name or 'the fund' and never 'we' or 'our portfolio', percentages as digits with a % sign, dates as day month year, no em dashes. The parts a machine can settle are applied to every passage as it comes back, so a dash, a curly quote or a 'per cent' is fixed whether or not the model listened.
-
AI-drafted commentary no longer hedges with "it's not X, it's Y"
The house style now rules out antithesis-style framing, alongside em dashes and the rest: the model states the point plainly instead of setting it up against what it is not.
-
Fund reports use a shorter, two-page layout
The About this report notices are left off fund reports specifically, at Booster's request; subject notes and any custom template still carry them, unaffected. The written analysis, macro drivers, market reactions and commentary, now leads the document, with the attribution and positioning tables afterward.
-
Sector, country and holding tables are one table each, not two
The attribution and positioning tables for the same sectors, countries or holdings are now combined into a single table, matching the shape Booster's own attribution export already uses. Nothing is dropped, the two tables' columns just sit together in one row per entry instead of two separate tables.
-
Less to read before you can act
The explanatory text on every working screen is cut to what you need to fill the field in front of you: about half as many words on the generate forms, the review screens, the editor and Past reports, and a third fewer in Admin. The reasoning that was there now lives on the How to and About pages, where it can be read once.
-
The working screens use the width of the window
Past reports, the review queue, a report's page, the templates list and the admin screen now fill a desktop window instead of an 840-pixel column. The report's name, the actions and the dates each have a column of their own again, and the admin tabs fit on one line. Prose pages and the generate forms keep the narrower column that reads well.
-
One navigation bar instead of three
The Secure23 site links are a single quiet line at the top; the sections and the pages within the one you are in share one bar underneath, with the pages drawn as a switch beside the section they belong to. Content starts roughly a hundred pixels higher on every screen.
-
The sources sit beside the text in the editor
The panel that used to be below the whole form is a column on the right that stays in view while you scroll the passages. Each "Rests on" line under a passage is now a link: follow it and the panel scrolls to that source and marks it.
-
Rows are links, and headers stay put
In Past reports, the review queue and the templates list, clicking anywhere on a row opens it and the row lights up under the pointer to say so. Column headers stay in view while a long table scrolls, so the third screen of the usage log still says which column is cost.
-
Who you are acting as is a chip in the top bar
The review screens used to open with a card asking who you are, and the same paragraph explaining why, before the work started. The name and role now sit at the right of the navigation bar; click it to switch, and the explanation is there for anyone who wants it.
-
Past reports is a table you can scan
Type, status and any provenance warning each have a column of their own instead of being badges crowded beside the name. Clicking anywhere on a row opens the report's run log. The search box stays on screen; the six other filters are in a drawer beneath it whose label says which are set, so a narrowed list never passes for the whole archive.
-
The same thing looks the same on every screen
A report's status, the badges beside a name, the buttons, the banners that say something went wrong or was saved, and the empty-list message were each drawn slightly differently on five or six screens. They are now defined once, so an approved report, a retired template and a clean run share one look, and "in review" is amber everywhere rather than brown on blue.
Fixed
-
The review screens showed times in UTC
The queue's "changed" time, the version and history tables on a report's page, its published time, when a source was retrieved or signed off, and a template's updated date were the stored UTC clock rather than New Zealand time — twelve or thirteen hours out, and sometimes the wrong day. They now match every other time in the app.
-
The editor no longer says every section has been removed
A note meant for a section you had taken out was showing on all of them, with a Put it back button that did nothing useful. It appears only on a section that is actually removed.
-
Past reports date filters mean New Zealand days
"Generated from" and "Generated to" used to be read as UTC, so a report made on the evening of the 8th could fall under the 9th. They are calendar days in Pacific/Auckland now, matching the times shown in the list.
-
Two reports starting at once no longer trip over the schema
The first request after a fresh start creates the tables; a second request arriving in the same moment used to try as well and fail. That is locked now.
The report is written here, and its sources are kept beside it
0.14 08 Sep 2026The editor is now the place a report is changed rather than a way of correcting a typo: sections can be written, moved and taken out, and every save says what changed and why. The sources came out of the document at the same time — they are held with the report and read on screen, next to the passages resting on them.
New
-
Write, reorder and remove commentary sections in the app
Add a section and it is marked as written by a person. Move one, take one out, undo your changes to a passage, and see the word count as you write. The document never has to leave the app to be edited, which is the point: a report rewritten in a Word file somewhere has none of this behind it.
-
Editing is offered everywhere a report is
An Edit button the moment a run finishes, on every row of past reports, on the report's own page, and on every editable row of the queue — which is now called Edit & review, because that is what it is for. Opening the editor on a report that has not been sent to review sends it, rather than asking somebody to learn that step before they are allowed to change a sentence. The editor also warns you before you leave with unsaved changes, and saves on Ctrl+S.
-
Say why you changed it
An optional line kept on the version. What changed is worked out for you and recorded either way; why is the one thing nothing here can infer, and the one a person reading the history in six months actually wants.
Changed
-
The review screens say what to do next, not what is possible
A report's page used to open with every lifecycle action at once, most of them greyed out with a reason, above four tables. It now leads with one line — who the report is waiting on and the single next thing to do to it — and the button that does it, with the reason underneath when a rule is in the way. The other moves, the sources, the versions and the history are still all there, one click down. The queue reads the same way: every row says whose move it is, and the ones waiting on you say so.
-
Every screen says where a report has got to, before you press anything
Past reports and the run log used to offer Edit on every report, including the ones an approver was reading — and the only way to find that out was to press it and be told "cannot edit a report that is 'in_review'". Each row now carries the state it has reached, and a report that is past editing links to where it is instead of offering a button that will refuse. The refusals themselves are in English and carry the way out: a report with an approver can be withdrawn, an approved one can have its approval revoked, and a published one is corrected by a new report. The withdraw button now sits next to that sentence on the report's own page rather than behind a disclosure.
-
Past reports reads as a list again
Five actions, four columns and a row of badges were competing for the same 840 pixels, and the report's own name lost — it wrapped over three lines while Word and PDF sat on one. The name and the badges that qualify it are back on a single line, the period is said as “1–31 Aug 2026” rather than spelled out over three, the template joins the row's other facts instead of holding a column of its own, and the four ways of getting a report back out are a quiet second line under the one action you came for.
-
Sources are attached to the report, not printed in it
The reference list and the little [1] markers are gone from the Word file and the PDF. Sources now live on the review screen and beside the text in the editor, with what they were taken from, when, and which passages rest on them — a list printed into a document is a copy, and it goes stale the moment a sentence is rewritten.
-
A source nothing rests on says so
Rewriting a passage can leave the source it used behind. The sources panel now names it, so nobody signs off evidence for a claim the report no longer makes.
-
A Sources heading in an uploaded template is left out
Importing a house report used to freeze that document's reference list into the template, and every report made from it carried a bibliography belonging to another report. The section is dropped and the import says so.
The report says a person read it, and a reviewer can change the words
0.13 08 Sep 2026Every report now ends with a plain statement of what the machine did, what it was never asked, and that a person approves it before it goes anywhere. And when the reviewer wants a sentence changed, they change it here rather than in a copy of the document with none of this behind it.
New
-
Every report closes with how it was made and who checked it
A short standing section above the sign-off: assembled by an automated system, a draft until a person approves it, and the model never asked what the fund returned. It follows what the report actually contains — a report with no model-written text says so, and one a person has rewritten says that too. Word and PDF alike, word for word.
-
A reviewer can edit the report without leaving the app
The commentary, the market reactions and the notes under the macro drivers, in a form, with the sources each passage rests on shown beside it. Saving writes a new version against your name and leaves the one before it untouched, so what was changed and by whom stays on the record.
-
Rewriting model-drafted text relabels it, without being asked
A passage the model drafted and a person rewrote is marked AI-drafted, analyst edited. It stays model-derived, because that is where the words started, and the report says a person has been through it.
Changed
-
Only the prose is editable, and that is deliberate
Figures, the sources a passage cites and the notices about how the report was made are shown but fixed. A wrong number is fixed in the data and the report generated again; a footnote anyone can retype is how a sentence ends up citing a source that never said it.
-
Templates saved before this build gain the new section
The closing statement is not optional and cannot be removed or reworded from the template screen. Every template already saved picks it up on its next use, above the closing line rather than under it.
Bring your own material, and say how you want it written
0.12 08 Sep 2026Two things a report was missing. You can attach the documents it should rest on, and the instructions that get good work out of the model are no longer buried in the code: admin keeps a library of prompt guides, and every generate form has them in a box you can write in.
New
-
Prompt guides: standing instructions for the drafting
The things that change with the client and the month — prefer the announcement to the article about it, name the publication, say when a figure is as at a date other than the period end. Written on the Prompt guides tab, sent with every research call the report makes.
-
Drafting instructions you can edit on the report itself
Both generate forms carry a box of instructions and a picker beside it. Picking a guide fills the box; what you do to it after that is up to you. Add a line for this month, cut the half that does not apply, or ignore the library and write your own. The box is what the model is told, so emptying it means the app's own rules and nothing else — which is what every report was before this.
-
The run log keeps the instructions, not just their name
A report can be drafted under words written for it alone, so the name would point at nothing a month later. The full instructions are stored with the report and shown on its run log, and a report drafted under an edited guide says which one it started from.
-
Attach documents to a report and have them read
The manager's own commentary, a factsheet, a board paper, the transcript of a call — up to five files on either generate form. The research reads them alongside what it finds online, and a sentence drawn from one carries the passage it rests on, the same as a sentence drawn from a web page. PDF, Word, text, Markdown, CSV, JSON or HTML.
-
A supplied document always needs signing off
Nobody here can vouch for where an uploaded file came from, so every claim resting on one lands in the review list and a person has to check it before the report can be published. Nothing written inside a document is treated as an instruction, whatever it says.
-
The files are kept with the report
Whole and unchanged, downloadable from the run log. A reviewer checking a claim six months from now gets the document the report actually rested on, not our reading of it. A report generated with AI drafting off says on its face that the documents were not read.
Changed
-
The generate forms ask for what only you can answer
The fund and the period are on the page. Everything else — reader profile, template, drafting instructions, which sources may be searched, documents to attach — has a sensible default and now sits in a drawer, with what it is set to written on the outside. Two drawers instead of a screenful of settings and the paragraphs explaining them.
-
A guide changes how a report is written, never what it says
Guidance reaches the model after the sourcing rules, labelled as instruction rather than as evidence. Nothing typed into it can authorise a claim no source made, a figure no result gave, advice, or a forecast.
Written for a reader, with the research on the record
0.11 08 Sep 2026A report now says who it is for, and every report keeps an account of what the AI research step actually did while it was being made.
New
-
Reader profiles: a report is written for someone in particular
Admin keeps the list — a name, where the reader sits between most and least technical, and notes describing them. The notes reach the model, so the same figures come back explained the way that reader wants them.
-
A reader profile is chosen on each report as it is generated
Both generate forms carry the picker, and the archive remembers which profile a report was written for.
-
A run log for every AI-drafted report
Which research calls ran, which came back with something, which were declined or failed and why, what they searched, which sources they cited, how long they took and what they cost. Reachable from any row in Past reports, and from the run that just finished.
-
A thin report now says why it is thin
A call that was declined, one that drafted with nothing to cite, and one that never ran used to read the same at the end. They no longer do.
Changed
-
Report times are shown in New Zealand time
Everywhere, not only in the archive list — the same instant no longer appears as two different times on one page.
-
Notice boxes and headings follow the Secure23 brand
Questrial headlines, Lato section headers, and the brand palette on the coloured boxes.
-
Cost and pricing are no longer part of the admin screens
The spend cap and the pricing behind it are unchanged and still enforced; they are simply not on show.
Fixed
- The balanced fund no longer opens on the wrong fund type
-
Research calls work on the non-Opus models again
One request option is accepted only by the Opus family, and sending it to anything else had the model refuse the call outright.
Navigation in two levels
0.10 06 Sep 2026Eight tabs across the top had stopped being a menu and become a list. They are now five sections, with the pages inside one on a strip underneath it.
New
-
A second row showing the other pages in the section you are in
Drawn only where there is something to choose between, so Templates and Admin look as they did.
Changed
-
Tabs are grouped: Generate, Reports, Templates, About, Admin
Generate holds the fund report and subject research, Reports holds the archive and the review queue, About holds this page. Nothing was removed — everything is one click in.
What's changed
0.9 06 Sep 2026This page. Updates were arriving with no way for anyone using the app to find out what had moved.
New
-
A What's changed tab, with an entry for every update
New, changed and fixed, in the words of someone using the app rather than the words of a commit message.
-
The page names the build you are looking at
The list ships inside the app, so it describes the copy answering the request — it cannot advertise a release that has not reached this server.
Fixed
-
The navigation bar no longer overflows once a tab is added
Eight tabs fit on one line; a ninth wraps to a second rather than pushing off the edge.
-
The provisioning script can be run on a fresh server
It went into git without its execute bit, and root needs one to run a file however much else it is allowed to do.
-
Provisioning works on a current Ubuntu
It asked for a graphics library under a name retired three releases ago, which the PDF renderer had stopped needing even earlier.
Review and approval
0.8 06 Sep 2026The lifecycle, the two-person rule and the provenance gate have been in the codebase since the start with nothing able to reach them. This is the door on them.
New
-
A review queue at /review
Every report under review, with a count per status and a chip to filter by one.
-
A lifecycle page for each report
Where it is, what can be done to it, its sources, its versions, and everything that has happened to it.
-
Send to review, from Past reports
The same fund and period twice becomes a second version, not a second report.
-
An acting-as selector, standing in for sign-in
Three demo people: an analyst, an approver, an administrator. It makes no security claim, which is exactly why every action is recorded against the name that took it.
-
Signing off an open-web source
Approvers and administrators only. An analyst vouching for the sources they cited is the self-certification the gate exists to prevent.
Changed
-
A blocked action now explains itself instead of disappearing
An approver looking at their own work still sees Approve, disabled, saying why it cannot be pressed.
-
Refused actions are kept in the audit trail
An attempted self-approval is worth more on the record than off it.
Migrations, and a deploy that can reach a fresh server
0.7 06 Sep 2026Nothing visible moved. The database can now change shape without losing what is in it, which had to happen before there was anything in it worth losing.
New
-
A test that fails when a model and the migrations disagree
So forgetting to write a migration is caught before the deploy, not during it.
-
A provisioning script for a brand-new server
And a deploy preflight that says what is missing and how to fix it, rather than failing on a permissions error.
Changed
-
The schema is under migrations
Alembic, run as part of the deploy. A database that predates migrations is adopted rather than rebuilt.
Report templates, and an archive of everything generated
0.6 06 Sep 2026Reports stopped being one fixed layout, and stopped being thrown away once downloaded.
New
-
Report templates you can build, edit and preview
Section order, your own text blocks, and branding. The blocks a report may not go out without are re-appended whatever you do to the order.
-
Importing structure from an existing .docx
The upload's headings are read, matched, and the file is thrown away. Every inferred match is flagged as a guess.
-
Past reports: everything the app has produced, searchable
Filter by type, template, date, whether AI drafted it, and whether it has provenance problems.
Changed
-
A stored report is the report, not the file
So one asked for as Word can come back as PDF, and re-downloading renders it again rather than handing back a stale blob.
Background generation, and an admin screen with cost tracking
0.5 05 Sep 2026A report that researches half a dozen subjects takes minutes — longer than a browser, a proxy or an impatient person will hold a request open.
New
-
An admin screen: settings, diagnostics, mail and audit
Anything that would loosen a control is shown read-only with its environment variable, because there is no sign-in yet.
-
Spend tracking against the Anthropic API
Every call is costed at the rates in force when it was made and written down, whether it succeeded or not.
Changed
-
Reports generate in the background
The form returns straight away with a job to poll, so a long research run cannot be lost to a timeout.
Research a subject
0.4 05 Sep 2026Reporting on something the app holds no data for — a manager, a company, a theme — with the same provenance rules applied.
New
-
Ad-hoc subject notes
Name an entity, get a researched note. Sources and origins are recorded exactly as they are for a fund report.
AI drafting, with citations that come from the passages used
0.3 05 Sep 2026The model can draft the commentary. What it cannot do is say something with nothing behind it.
New
-
AI-drafted market, attribution and outlook commentary
Off by default per report, and a failed research run degrades the report into a notice rather than failing the request.
Changed
-
Citations come from the passages the sentences were built on
Not from a list of pages the model says it visited.
-
Sites that block the search agent were dropped from the list
An approved site that can never be read is a promise the app cannot keep.
The demo looks like the business it belongs to
0.2 05 Sep 2026Branding, copy, and the layout fixes that came with them.
New
- Super Amazing Fund Management branding and logo
Changed
- Colours, fonts and footer matched to the Secure23 site
Fixed
- Footer logo and heading alignment
- A renderer indentation bug that mis-drew nested sections
Provenance and the report lifecycle
0.1 04 Sep 2026The first release with the rule that shapes everything else: every claim has to be able to answer where it came from.
New
-
Fund reports as Word or PDF, from two independent renderers
Neither converts the other's output, which is where formatting reliably falls over.
-
Every piece of prose records who wrote it and what it rests on
Human, AI-drafted, or AI-drafted-then-edited.
-
Model-written text with no citation is a blocking defect
It stops a report being approved. It is not a warning someone can click past.
-
Statuses, roles and transitions, with an append-only audit trail
Including the two-person rule, waiting for a screen to reach it.
This list ships inside the app, so what you are reading is the changelog of the copy answering this page — not of whatever is newest elsewhere.
