[{"slug":"ZV-2026-2022","server_name":"trydock.ai","severity":"breaking","title":"trydock.ai: Enum value unlisted removed from visibility on update_workspace.","summary":"[safe] Description of add_column changed (6% word delta). [safe] Description of append_doc_section changed (7% word delta). [safe] Description of bulk_update_rows changed (4% word delta). [safe] Description of create_file_upload changed (3% word delta). [safe] Description of create_surface changed (16% word delta). [safe] Description of create_video_upload changed (3% word delta). [safe] Description of create_workspace changed (2% word delta). [safe] Description of delete_file changed (12% word delta). [safe] Description of delete_workspace changed (11% word delta). [risky] Description of downgrade_plan changed (31% word delta). [safe] Description of get_file changed (11% word delta). [risky] Description of get_workspace changed (39% word delta). [safe] Description of get_workspace_schema changed (5% word delta). [risky] Description of list_files changed (35% word delta). [safe] Description of list_recent_files changed (12% word delta). [safe] Description of list_surfaces changed (22% word delta). [safe] Description of list_workspaces changed (23% word delta). [safe] Description of move_rows changed (2% word delta). [risky] Description of request_limit_increase changed (52% word delta). [risky] Description of request_rotate_agent_key changed (48% word delta). [safe] Description of revoke_file_share changed (18% word delta). [safe] Description of share_file changed (10% word delta). [safe] Description of update_doc changed (12% word delta). [safe] Description of update_surface changed (7% word delta). [safe] Description of update_workspace changed (10% word delta). [breaking] Enum value unlisted removed from visibility on update_workspace. [breaking] Enum value public removed from visibility on update_workspace.","changes":[{"kind":"description_changed","tool":"add_column","after":"Append a single column to a workspace's table schema. Position is auto-computed as next-after-max so the contiguity invariant holds. Key collision (409) if a column with the same key already exists. Editor role required. Use this for per-column additions; use get_workspace_schema + update_surface with `columns` for full schema replacement or reordering. Multi-surface workspaces accept `surface_slug` to target a specific table sheet (use `list_surfaces` to enumerate); omit to fall through to the workspace's primary table surface.","before":"Append a single column to a workspace's table schema. Position is auto-computed as next-after-max so the contiguity invariant holds. Key collision (409) if a column with the same key already exists. Editor role required. Use this for per-column additions; use get_workspace_schema + update_workspace_columns (PUT on /columns) for full schema replacement or reordering. Multi-surface workspaces accept `surface_slug` to target a specific table sheet (use `list_surfaces` to enumerate); omit to fall through to the workspace's primary table surface.","detail":"Description of `add_column` changed (6% word delta).","severity":"safe","descriptionDelta":0.06451612903225812},{"kind":"description_changed","tool":"append_doc_section","after":"Append a chunk of Markdown to the END of a workspace's doc body. Designed for crons + ingest agents that produce content in timestamped chunks (changelog updates, daily standups, batch summaries). Same markdown surface as update_doc: supports CommonMark, GFM, **`![alt](url)` inline images** (an HTTPS URL; for a local file get one with `create_file_upload`), **lone video URLs** (`.mp4`/`.webm`/`.mov`/`.mkv`/`.m4v` → native `<video>` player; for a local video get one with `create_video_upload`, up to 100 MB), ```mermaid diagrams, $math$/$$math$$ KaTeX, > [!NOTE]/[!TIP]/[!IMPORTANT]/[!WARNING]/[!CAUTION] callouts, ```svg sanitized embeds, <details><summary>X</summary>...</details> toggles, [[slug]] cross-references, [@Label](dock:mention/<kind>/<id>) @-mentions of users + agents, and lone-URL embeds (YouTube/Vimeo/Loom/Figma/CodePen/gists). Server fetches the current body, splices the new blocks on, and writes the result through the same path as update_doc with the same auth, same events, same byte/depth/node-count guard. Append is non-idempotent by design (every call adds content); the caller is responsible for dedupe. @-mentions inside the appended chunk fire `doc.mention_added` + inbox/email fan-out for newly-added mentions only — appending a chunk that re-mentions someone already mentioned earlier in the doc won't re-fire. Requires editor role. Multi-surface workspaces optionally accept `surface_slug` to append to a specific doc surface.","before":"Append a chunk of Markdown to the END of a workspace's doc body. Designed for crons + ingest agents that produce content in timestamped chunks (changelog updates, daily standups, batch summaries). Same markdown surface as update_doc: supports CommonMark, GFM, **`![alt](url)` inline images** (any publicly-reachable HTTPS URL; for a local file get one with `create_file_upload`, or `create_video_upload` for video), **lone video URLs** (`.mp4`/`.webm`/`.mov`/`.mkv`/`.m4v` → native `<video>` player, 5 GB per file), ```mermaid diagrams, $math$/$$math$$ KaTeX, > [!NOTE]/[!TIP]/[!IMPORTANT]/[!WARNING]/[!CAUTION] callouts, ```svg sanitized embeds, <details><summary>X</summary>...</details> toggles, [[slug]] cross-references, [@Label](dock:mention/<kind>/<id>) @-mentions of users + agents, and lone-URL embeds (YouTube/Vimeo/Loom/Figma/CodePen/gists). Server fetches the current body, splices the new blocks on, and writes the result through the same path as update_doc with the same auth, same events, same byte/depth/node-count guard. Append is non-idempotent by design (every call adds content); the caller is responsible for dedupe. @-mentions inside the appended chunk fire `doc.mention_added` + inbox/email fan-out for newly-added mentions only — appending a chunk that re-mentions someone already mentioned earlier in the doc won't re-fire. Requires editor role. Multi-surface workspaces optionally accept `surface_slug` to append to a specific doc tab.","detail":"Description of `append_doc_section` changed (7% word delta).","severity":"safe","descriptionDelta":0.07453416149068326},{"kind":"description_changed","tool":"bulk_update_rows","after":"Update many existing rows in ONE call — the bulk version of update_row. Use this instead of looping update_row when changing more than a few rows (much lower latency + token cost for sheet edits). Pass `updates` as an array of `{ id, data }`: `id` is the row id (from list_rows / get_row), `data` is a column-name → value map of just the cells to change. Each row's data is MERGED into the existing row (last-write-wins per field), so you only send the cells you're changing. Up to 500 rows per call. ALL-OR-NOTHING: if any id is missing or in another workspace the whole batch is rejected and nothing is written, so on error you can safely resend the entire batch. Values are coerced to each column's type. Returns `{ updated, rows }`.","before":"Update many existing rows in ONE call — the bulk version of update_row. Use this instead of looping update_row when changing more than a few rows (much lower latency + token cost for sheet edits). Pass `updates` as an array of `{ id, data }`: `id` is the row id (from get_rows / query_rows), `data` is a column-name → value map of just the cells to change. Each row's data is MERGED into the existing row (last-write-wins per field), so you only send the cells you're changing. Up to 500 rows per call. ALL-OR-NOTHING: if any id is missing or in another workspace the whole batch is rejected and nothing is written, so on error you can safely resend the entire batch. Values are coerced to each column's type. Returns `{ updated, rows }`.","detail":"Description of `bulk_update_rows` changed (4% word delta).","severity":"safe","descriptionDelta":0.043010752688172005},{"kind":"description_changed","tool":"create_file_upload","after":"Get a one-time upload link for a file that is on YOUR machine (a PDF, image, spreadsheet, audio, archive, anything over ~3 MB), so you can put it into Dock without a public host. Returns a ready `curl` command: run it with your file path in place of `<path to your file>`; its JSON response has a `url`. Then call `upload_file` with that `url` (plus `surface_slug` and `filename`). The link accepts ONE upload of an allowed file type up to 100 MB (your plan's per-file cap still applies) and expires in 15 minutes. For a video surface use `create_video_upload` instead. Editor role required.","before":"Get a one-time upload link for a file that is on YOUR machine (a PDF, image, spreadsheet, audio, archive, anything over ~3 MB), so you can put it into Dock without a public host. Returns a ready `curl` command: run it with your file path in place of `<path to your file>`; its JSON response has a `url`. Then call `upload_file` with that `url` (plus `surface_slug` and `filename`). The link accepts ONE upload of an allowed file type up to 100 MB (your plan's per-file cap still applies) and expires in 15 minutes. For a video tab use `create_video_upload` instead. Editor role required.","detail":"Description of `create_file_upload` changed (3% word delta).","severity":"safe","descriptionDelta":0.025000000000000022},{"kind":"description_changed","tool":"create_surface","after":"Create a new surface inside a workspace. `kind` picks `table`, `doc`, `html`, `files`, or `video`. Optional `slug` (lowercase kebab-case, 3-64 chars); when omitted the server slugifies `name` and appends a numeric suffix on collision. Optional `columns` sets a `table`'s starting columns; without it the table starts EMPTY and your first row write creates the columns its data needs. Ignored for other kinds. `html` surfaces start with an empty body — write content via `update_html`. `files` surfaces start empty; browse them with `list_files` / `get_file` / `list_recent_files`, and add files with `upload_file` (for a file on your own machine or over ~3 MB, call `create_file_upload` first). `video` surfaces hold one or more videos people flip through (variants, cuts): add each with `add_video` from an https URL (mp4, webm, mov or m4v); for a video on your own machine, get that URL with `create_video_upload`. Editor role required. Emits `surface.created` so live listeners on the workspace stream see the new surface without a refetch.","before":"Create a new surface (tab) inside a workspace. `kind` picks `table`, `doc`, `html`, `files`, or `video`. Optional `slug` (lowercase kebab-case, 3-64 chars); when omitted the server slugifies `name` and appends a numeric suffix on collision. Optional `columns` overrides the default Title/Status/Notes triple for `table` kinds; ignored for `doc` and `html`. `html` surfaces start with an empty body — write content via `update_html`. `files` surfaces start empty; browse them with `list_files` / `get_file` / `list_recent_files`, and add files with `upload_file` (for a file on your own machine or over ~3 MB, call `create_file_upload` first). `video` surfaces hold one or more videos people flip through (variants, cuts): add each with `add_video` from an https URL (mp4, webm, mov or m4v); for a video on your own machine, get that URL with `create_video_upload`. Editor role required. Emits `surface.created` so live listeners on the workspace stream see the new tab without a refetch.","detail":"Description of `create_surface` changed (16% word delta).","severity":"safe","descriptionDelta":0.15652173913043477},{"kind":"description_changed","tool":"create_video_upload","after":"Get a one-time upload link for a video file that is on YOUR machine (one you rendered, edited or downloaded), so you can put it on a video surface. `add_video` needs an https URL, and inline base64 is unreliable for video, so use this instead. Returns a ready `curl` command: run it with your file path in place of `<path to your file>`; its JSON response has a `url`. Pass that `url` to `add_video`. The link accepts ONE upload of an mp4, webm, mov or m4v file up to 100 MB and expires in 15 minutes. Editor role required.","before":"Get a one-time upload link for a video file that is on YOUR machine (one you rendered, edited or downloaded), so you can put it on a video tab. `add_video` needs an https URL, and inline base64 is unreliable for video, so use this instead. Returns a ready `curl` command: run it with your file path in place of `<path to your file>`; its JSON response has a `url`. Pass that `url` to `add_video`. The link accepts ONE upload of an mp4, webm, mov or m4v file up to 100 MB and expires in 15 minutes. Editor role required.","detail":"Description of `create_video_upload` changed (3% word delta).","severity":"safe","descriptionDelta":0.02941176470588236},{"kind":"description_changed","tool":"create_workspace","after":"Create a new workspace in the caller's org. Works for both user and agent callers; agent-created workspaces attribute to the agent and enroll the agent's owning user as a co-owner so the human sees it in their dashboard. The new workspace is seeded with one primary surface matching `mode`: `doc` → a Notes surface (for prose), `table` → a Sheet surface (for records), `html` → a Mockup surface (sandboxed HTML preview). Decide the surface before you create: prose (briefs, notes, summaries, drafts) → `doc`; records with shared columns (tasks, leads, rows) → `table`; a deliverable that IS html (a page, mockup, dashboard, or visual meant to be seen or shared) → `html`, then write it with `update_html` — never to a local file, which the human can't see. If you omit `mode`, pass `initial_markdown` to signal a `doc`; with neither `mode` nor `initial_markdown`, an agent caller gets a guided error asking it to choose `doc` or `table` (so you never silently land on the wrong surface). An explicit `mode` is always honored. `html` is opt-in — never inferred for ambiguous content — so pass it explicitly when the deliverable is html (a mockup, page, or dashboard the user asked for), and only then. Add more surfaces of any kind later via `create_surface`. Agent-created workspaces default to org-visibility so sibling agents in the same org aren't 403'd. For prose content (briefs, summaries, changelogs) pass `initial_markdown` to seed the doc body in one call; the markdown is converted server-side, no need to hand-build ProseMirror JSON.","before":"Create a new workspace in the caller's org. Works for both user and agent callers; agent-created workspaces attribute to the agent and enroll the agent's owning user as a co-owner so the human sees it in their dashboard. The new workspace is seeded with one primary surface matching `mode`: `doc` → a Notes tab (for prose), `table` → a Sheet tab (for records), `html` → a Mockup tab (sandboxed HTML preview). Decide the surface before you create: prose (briefs, notes, summaries, drafts) → `doc`; records with shared columns (tasks, leads, rows) → `table`; a deliverable that IS html (a page, mockup, dashboard, or visual meant to be seen or shared) → `html`, then write it with `update_html` — never to a local file, which the human can't see. If you omit `mode`, pass `initial_markdown` to signal a `doc`; with neither `mode` nor `initial_markdown`, an agent caller gets a guided error asking it to choose `doc` or `table` (so you never silently land on the wrong surface). An explicit `mode` is always honored. `html` is opt-in — never inferred for ambiguous content — so pass it explicitly when the deliverable is html (a mockup, page, or dashboard the user asked for), and only then. Add more tabs of any kind later via `create_surface`. Agent-created workspaces default to org-visibility so sibling agents in the same org aren't 403'd. For prose content (briefs, summaries, changelogs) pass `initial_markdown` to seed the doc body in one call; the markdown is converted server-side, no need to hand-build ProseMirror JSON.","detail":"Description of `create_workspace` changed (2% word delta).","severity":"safe","descriptionDelta":0.021582733812949617},{"kind":"description_changed","tool":"delete_file","after":"Soft-delete a file by id. Moves to a 30-day trash window before the cleanup cron hard-deletes + refunds the storage quota. Restorable via the REST PATCH endpoint (`PATCH /api/workspaces/{slug}/files/{id} body: {restore:true}`); a PATCH-equivalent MCP tool ships in Phase 6. Editor role required.","before":"Soft-delete a file by id. Moves to a 30-day trash window before the cleanup cron hard-deletes + refunds the storage quota. Restorable via the REST PATCH endpoint (`PATCH /api/workspaces/{slug}/files/{id} body: {restore:true}`); a PATCH-equivalent MCP tool ships in Phase 6. Editor role required. Gated behind FILES_SURFACE_ENABLED + per-user allowlist.","detail":"Description of `delete_file` changed (12% word delta).","severity":"safe","descriptionDelta":0.12244897959183676},{"kind":"description_changed","tool":"delete_workspace","after":"Archive a workspace. Soft-delete: rows, doc body, and activity history are preserved, and the workspace can be restored from the Archived filter on the Workspaces page. Every member loses access immediately. Idempotent: calling on an already-archived workspace returns its current archivedAt without changing anything. Requires the owner role on the workspace. Pass `mode: \"web\"` to surface a click-to-approve URL for the human (recommended for any non-trivial workspace); the first call returns { status: 'approval_required', approval_url, polling_url }; print approval_url in chat, user clicks + approves, you poll polling_url for the result. Without `mode: \"web\"` the call executes immediately.","before":"Archive a workspace. Soft-delete: rows, doc body, and activity history are preserved, and the workspace can be restored from Settings · Archived. Every member loses access immediately. Idempotent: calling on an already-archived workspace returns its current archivedAt without changing anything. Requires editor role on the agent. Pass `mode: \"web\"` to surface a click-to-approve URL for the human (recommended for any non-trivial workspace); the first call returns { status: 'approval_required', approval_url, polling_url }; print approval_url in chat, user clicks + approves, you poll polling_url for the result. Without `mode: \"web\"` the call executes immediately on the agent's editor role.","detail":"Description of `delete_workspace` changed (11% word delta).","severity":"safe","descriptionDelta":0.10526315789473684},{"kind":"description_changed","tool":"downgrade_plan","after":"⛔ RETIRED PLAN SYSTEM — not Dock's pricing, and it does not change your human's per-person plan or credits. Schedules the caller's ORG to drop from a retired org plan (Pro or Scale, which only set resource caps) to Free at the end of the current billing period; the org keeps those caps until then. No-op when already on Free. Consent-gated. Two consent surfaces, you pick via `mode`: (1) `chat` (default): FIRST call returns { status: 'confirmation_required', confirm_token, message, expires_in }; surface to your user and re-call within 60s with `confirm_token` set. (2) `web`: FIRST call returns { status: 'approval_required', approval_url, polling_url }; print approval_url in chat, user clicks + approves, then poll polling_url for the result.","before":"Schedule a downgrade to Free at the end of the current billing period. The org keeps its current plan (Pro or Scale) and paid limits until the period ends. No-op when already on Free. Consent-gated. Two consent surfaces, you pick via `mode`: (1) `chat` (default): FIRST call returns { status: 'confirmation_required', confirm_token, message, expires_in }; surface to your user and re-call within 60s with `confirm_token` set. (2) `web`: FIRST call returns { status: 'approval_required', approval_url, polling_url }; print approval_url in chat, user clicks + approves, then poll polling_url for the result.","detail":"Description of `downgrade_plan` changed (31% word delta).","severity":"risky","descriptionDelta":0.3076923076923077},{"kind":"description_changed","tool":"get_file","after":"Fetch metadata + a download URL for a single file by id. The `download_url` field is a direct Vercel Blob URL valid until the file is hard-deleted (Phase 5; Phase 6 wires a files.trydock.ai signed-URL minter with 5-min TTL + auth re-check). Useful for an agent reading file contents server-side (HTTP GET the URL) or surfacing a download link in a reply.","before":"Fetch metadata + a download URL for a single file by id. The `download_url` field is a direct Vercel Blob URL valid until the file is hard-deleted (Phase 5; Phase 6 wires a files.trydock.ai signed-URL minter with 5-min TTL + auth re-check). Useful for an agent reading file contents server-side (HTTP GET the URL) or surfacing a download link in a reply. Gated behind FILES_SURFACE_ENABLED + per-user allowlist.","detail":"Description of `get_file` changed (11% word delta).","severity":"safe","descriptionDelta":0.1071428571428571},{"kind":"description_changed","tool":"get_workspace","after":"Get details about a specific workspace by its slug, including columns of its primary table surface, member count, and row count. A workspace contains one or more surfaces of any kind, in any combination. Use `list_surfaces` to enumerate every surface, then that surface's own tools (`list_rows`, `get_doc`, `get_html`, ...) to read or write it.","before":"Get details about a specific workspace by its slug, including columns of its primary table surface, member count, and row count. A workspace contains one or more surfaces (tabs): any combination of `table` (rows + columns) and `doc` (TipTap body) kinds, one or many of either. Use `list_surfaces` to enumerate every tab; fetch /rows or /doc to read or write a specific one.","detail":"Description of `get_workspace` changed (39% word delta).","severity":"risky","descriptionDelta":0.38888888888888884},{"kind":"description_changed","tool":"get_workspace_schema","after":"Return a table surface's column definitions so an agent knows what keys create_row/update_row will accept. Each column has `key` (the field name in row.data), `label` (human-readable), `type` (text | longtext | number | status | person | date | url | checkbox | select), `position`, and, for status/select columns, the allowed `options`. Empty array on doc-only workspaces; callers should still be able to write rows (columns auto-seed on first write). Multi-surface workspaces accept `surface_slug` to scope to a specific table sheet (use `list_surfaces` to enumerate); omit to fall through to the workspace's primary table surface.","before":"Return a table surface's column definitions so an agent knows what keys create_row/update_row will accept. Each column has `key` (the field name in row.data), `label` (human-readable), `type` (text | longtext | url | status | owner | date | number), `position`, and, for status/owner columns, the allowed `options`. Empty array on doc-only workspaces; callers should still be able to write rows (columns auto-seed on first write). Multi-surface workspaces accept `surface_slug` to scope to a specific table sheet (use `list_surfaces` to enumerate); omit to fall through to the workspace's primary table surface.","detail":"Description of `get_workspace_schema` changed (5% word delta).","severity":"safe","descriptionDelta":0.052631578947368474},{"kind":"description_changed","tool":"list_files","after":"List the folder + file children of a Files surface (kind='files'). Folders sorted first by position then name; files sorted by name. Returns folders[], files[] with cuids agents can pass to `get_file` / `delete_file`. `parent_folder_id` defaults to null (= root of the surface); pass a folder id to descend into a sub-folder.","before":"List the folder + file children of a Files surface (kind='files'). Folders sorted first by position then name; files sorted by name. Returns folders[], files[] with cuids agents can pass to `get_file` / `delete_file`. `parent_folder_id` defaults to null (= root of the surface); pass a folder id to descend into a sub-folder. Gated behind FILES_SURFACE_ENABLED + per-user allowlist (in beta on socrates@vector.build; other accounts get -32000 'not available').","detail":"Description of `list_files` changed (35% word delta).","severity":"risky","descriptionDelta":0.34615384615384615},{"kind":"description_changed","tool":"list_recent_files","after":"List the 50 most recently updated files in a Files surface, sorted by `updatedAt` descending. Flat surface-wide list; ignores folder structure. Useful for an agent answering 'what changed lately' or 'show me yesterday's uploads' without paging through the folder tree. Folders are omitted from this view.","before":"List the 50 most recently updated files in a Files surface, sorted by `updatedAt` descending. Flat surface-wide list; ignores folder structure. Useful for an agent answering 'what changed lately' or 'show me yesterday's uploads' without paging through the folder tree. Folders are omitted from this view. Gated behind FILES_SURFACE_ENABLED + per-user allowlist.","detail":"Description of `list_recent_files` changed (12% word delta).","severity":"safe","descriptionDelta":0.12244897959183676},{"kind":"description_changed","tool":"list_surfaces","after":"List the surfaces inside a workspace. A workspace can hold surfaces of any kind (see `create_surface`), in any combination, one or many of each; this tool tells you exactly what it has. Each surface has its own slug used in surface-scoped tool calls. Order matches the on-screen surface order. Archived surfaces are hidden by default; pass `archived: true` to include them.","before":"List the surfaces (tabs) inside a workspace. A workspace can hold any combination of `table` (rows + columns) and `doc` (TipTap body) surfaces, one or many of either kind; this tool tells you exactly what it has. Each surface has its own slug used in surface-scoped tool calls. Order matches the on-screen tab strip. Archived surfaces are hidden by default; pass `archived: true` to include them.","detail":"Description of `list_surfaces` changed (22% word delta).","severity":"safe","descriptionDelta":0.22033898305084743},{"kind":"description_changed","tool":"list_workspaces","after":"List all workspaces the authenticated principal has access to. Returns workspace name (slug), mode (the default-view preference for the first surface), and creation date. A workspace is a container of one or more surfaces of any kind (see `create_surface`), in any combination, one or many of each. Use `list_surfaces` to see what a given workspace actually contains.","before":"List all workspaces the authenticated principal has access to. Returns workspace name (slug), mode (the default-view preference for the first tab), and creation date. A workspace is a container of one or more surfaces (tabs); each surface is either a `table` (rows + columns) or a `doc` (TipTap body), and a workspace can hold any combination, one or many of either kind. Use `list_surfaces` to see what a given workspace actually contains.","detail":"Description of `list_workspaces` changed (23% word delta).","severity":"safe","descriptionDelta":0.2321428571428571},{"kind":"description_changed","tool":"move_rows","after":"Atomically move N rows from their current sheet(s) to a target sheet inside the same workspace. Use for programmatic data migration: dropping a batch of agent-produced drafts onto the right sheet, reorganizing content across LinkedIn / Twitter / Substack sheets, etc. All-or-nothing: if any rowId doesn't belong to this workspace, the entire batch fails before any write fires. Idempotent: rows already on the target sheet are skipped (returns `skipped` count). Rows land at the destination sheet's tail in the order rowIds was supplied. Emits one `row.moved_surface` event per row that actually moved. Up to 500 rows per call.","before":"Atomically move N rows from their current sheet(s) to a target sheet inside the same workspace. Use for programmatic data migration: dropping a batch of agent-produced drafts onto the right sheet, reorganizing content across LinkedIn / Twitter / Substack tabs, etc. All-or-nothing: if any rowId doesn't belong to this workspace, the entire batch fails before any write fires. Idempotent: rows already on the target sheet are skipped (returns `skipped` count). Rows land at the destination sheet's tail in the order rowIds was supplied. Emits one `row.moved_surface` event per row that actually moved. Up to 500 rows per call.","detail":"Description of `move_rows` changed (2% word delta).","severity":"safe","descriptionDelta":0.024691358024691357},{"kind":"description_changed","tool":"request_limit_increase","after":"Ask Dock to raise an org limit (agents, workspaces, rows, or other). We record the signal on the admin side; there's no reply loop. Use this whenever you hit one of those caps. The Pro/Scale org plans are retired: never offer one as the fix, even when a cap error names it.","before":"Ask Dock to raise a plan limit (agents, workspaces, rows, or other). We record the signal on the admin side; there's no reply loop. Use this when you hit a cap you can't resolve with upgrade_plan (e.g. you're already Pro but need a custom limit).","detail":"Description of `request_limit_increase` changed (52% word delta).","severity":"risky","descriptionDelta":0.5161290322580645},{"kind":"description_changed","tool":"request_rotate_agent_key","after":"Ask the human owner to rotate ANOTHER agent's active API key (mint a new one + revoke the old). Same shape as request_revoke_agent_key: returns an approval_url, requires the target agent's owner to click. On approval the old key stops working at once. The new key's plaintext is INTENTIONALLY not returned to you, and Dock does not currently show it to anyone else either, so expect the target agent to lose API access just as with a revoke. Use when you've spotted leakage.","before":"Ask the human owner to rotate ANOTHER agent's active API key (mint a new one + revoke the old). Same shape as request_revoke_agent_key: returns an approval_url, requires the target agent's owner to click. The new key plaintext is INTENTIONALLY not returned to the requesting agent; the plaintext is surfaced only to the human owner via Settings → Agents, who hands it to the target agent out of band. Use when you've spotted leakage and the target needs a clean credential without going dark mid-task.","detail":"Description of `request_rotate_agent_key` changed (48% word delta).","severity":"risky","descriptionDelta":0.4810126582278481},{"kind":"description_changed","tool":"revoke_file_share","after":"Soft-revoke a share token minted via `share_file`. The public `/share/files/<token>` URL stops resolving immediately. Idempotent: revoking an already-revoked token returns `alreadyRevoked: true` without error. Editor role required.","before":"Soft-revoke a share token minted via `share_file`. The public `/share/files/<token>` URL stops resolving immediately. Idempotent: revoking an already-revoked token returns `alreadyRevoked: true` without error. Editor role required. Gated behind FILES_SURFACE_ENABLED + per-user allowlist.","detail":"Description of `revoke_file_share` changed (18% word delta).","severity":"safe","descriptionDelta":0.17647058823529416},{"kind":"description_changed","tool":"share_file","after":"Mint a public share token for a file. Returns a `url` of the form `https://trydock.ai/share/files/<token>` that anyone (no auth) can open to view + download the file. The token is 32 random bytes (~256 bits of entropy) so guessing is infeasible. Revoke later with `revoke_file_share`. Editor role required. Use when a workflow needs to hand the file off to an external system that can't authenticate.","before":"Mint a public share token for a file. Returns a `url` of the form `https://trydock.ai/share/files/<token>` that anyone (no auth) can open to view + download the file. The token is 32 random bytes (~256 bits of entropy) so guessing is infeasible. Revoke later with `revoke_file_share`. Editor role required. Gated behind FILES_SURFACE_ENABLED + per-user allowlist. Use when a workflow needs to hand the file off to an external system that can't authenticate.","detail":"Description of `share_file` changed (10% word delta).","severity":"safe","descriptionDelta":0.10169491525423724},{"kind":"description_changed","tool":"update_doc","after":"Replace a workspace's doc body. Takes EITHER TipTap JSON (`content`) OR Markdown (`markdown`): pass markdown when you're producing prose from scratch (CommonMark + GFM is the format every LLM emits natively), pass TipTap JSON when you need structural edits to an existing doc (round-trip from get_doc, mutate, write back). Beyond CommonMark + GFM, the markdown layer recognizes:\n\n- **![alt text](https://…)** → inline image. Use an HTTPS URL (HTTP fires browser mixed-content warnings; data: URIs are rejected by `allowBase64: false`). For an image on your own machine, call `create_file_upload`, run the curl it returns and use the `url` from its response; never ask for a public host. Renders block-feeling via CSS (max-width 100%, rounded corners, drop shadow) even though the underlying node is inline. The `alt` text is the accessible label and shows in place of the image if the URL fails to load — always include it.\n- A **lone video-file URL on its own line** (extension `.mp4` / `.m4v` / `.webm` / `.mov` / `.mkv`, signed-params + timestamp fragments tolerated) → native HTML5 `<video controls preload=\"metadata\">` player. Source URL is referenced directly: no iframe, no transcoding, no quality loss. Any HTTPS URL to the video file works. For a video on your own machine, call `create_video_upload` (one file, up to 100 MB), run the curl it returns and use the `url` from its response. Sample shape: a paragraph containing only that URL. Mid-paragraph URLs stay as plain links — surrounding prose disqualifies the auto-promotion (matches the oEmbed convention).\n- **```mermaid** fenced code → diagram (15 sub-types: flowchart, sequence, gantt, ER, state, class, mindmap, timeline, pie, quadrant, sankey, XY-chart, packet, block, journey)\n- **$x$** inline math, **$$x$$** block math (LaTeX, KaTeX-rendered, scripts/href disabled)\n- **> [!NOTE]** / **[!TIP]** / **[!IMPORTANT]** / **[!WARNING]** / **[!CAUTION]** GFM-style callouts\n- **```svg** fenced code → sanitized SVG embed (the universal escape hatch for custom diagrams; scripts and event handlers stripped at write time)\n- **<details><summary>X</summary>BODY</details>** → collapsible toggle\n- **[[slug]]** / **[[org/slug]]** / **[[slug#surface-slug]]** / **[[slug#row-id]]** / **[[slug|display]]** → cross-references to another workspace, surface, or row. Resolved against your accessible workspace set; targets you can't see render as plain text on the reader's side (no info leak). Every cross-ref creates a Backlink row so the target's 'referenced from' sidebar shows this doc.\n- **[@Label](dock:mention/<kind>/<id>)** → @-mention of a user or agent. `<kind>` is `agent` or `human`; `<id>` is the principal id. Optional query params `?org=<slug>` (agents) or `?email=<addr>` (humans) for renderer hints. Mentioning a human writes a `doc_mention` row to their inbox + sends a deep-link email; mentioning an agent fires the `doc.mention_added` webhook so the agent service can wake up and reply. Re-saving a doc that already mentions someone does NOT re-fire — only newly-added mentions notify (computed from a diff against the previous body). Use this to ping a person or agent when a doc you wrote needs their eyes.\n- A **lone URL on its own line** from a safelisted provider (YouTube, Vimeo, Loom, Figma, CodePen, GitHub gists) → sandboxed iframe embed. Other URLs stay as regular links. Surrounding prose disqualifies the auto-embed.\n\nPer-format caps: max 50 Mermaid diagrams (30 KB source each), max 500 math expressions (8 KB source each), max 50 SVG blocks (100 KB source each post-sanitize), max 200 cross-refs per doc, max 500 @-mentions per doc, max 20 embeds per doc, max 20 videos per doc, max 200 images per doc. Last-write-wins; no CRDT merge. Emits doc.updated + doc.heading_added + doc.mention_added events as applicable. Requires editor role. Multi-surface workspaces optionally accept `surface_slug` to write to a specific doc surface; omitted writes the primary doc surface. Append-only updates have a dedicated `append_doc_section` tool that doesn't require fetching the body first.","before":"Replace a workspace's doc body. Takes EITHER TipTap JSON (`content`) OR Markdown (`markdown`): pass markdown when you're producing prose from scratch (CommonMark + GFM is the format every LLM emits natively), pass TipTap JSON when you need structural edits to an existing doc (round-trip from get_doc, mutate, write back). Beyond CommonMark + GFM, the markdown layer recognizes:\n\n- **![alt text](https://…)** → inline image. Use ANY publicly-reachable URL (HTTPS preferred — HTTP fires browser mixed-content warnings; data: URIs are rejected by `allowBase64: false`). For a file on your own machine, get such a URL with `create_file_upload` (or `create_video_upload` for a video): run the curl it returns and use the `url` from its response. Renders block-feeling via CSS (max-width 100%, rounded corners, drop shadow) even though the underlying node is inline. The `alt` text is the accessible label and shows in place of the image if the URL fails to load — always include it. To attach a user-uploaded file, hit `POST /api/workspaces/:slug/upload-image` from the human-side UI first to get a Vercel Blob URL, then reference that URL in the doc markdown.\n- A **lone video-file URL on its own line** (extension `.mp4` / `.m4v` / `.webm` / `.mov` / `.mkv`, signed-params + timestamp fragments tolerated) → native HTML5 `<video controls preload=\"metadata\">` player. Source URL is referenced directly: no iframe, no transcoding, no quality loss. Vercel Blob is the canonical hosting (5 GB per file, served with HTTP range requests so 4K masters stream cleanly), but ANY publicly-reachable HTTPS URL works. For a file on your own machine, get such a URL with `create_file_upload` (or `create_video_upload` for a video): run the curl it returns and use the `url` from its response. Sample shape: a paragraph containing only `https://cdn.dock.ai/2025-launch-walkthrough.mp4`. Mid-paragraph URLs stay as plain links — surrounding prose disqualifies the auto-promotion (matches the oEmbed convention).\n- **```mermaid** fenced code → diagram (15 sub-types: flowchart, sequence, gantt, ER, state, class, mindmap, timeline, pie, quadrant, sankey, XY-chart, packet, block, journey)\n- **$x$** inline math, **$$x$$** block math (LaTeX, KaTeX-rendered, scripts/href disabled)\n- **> [!NOTE]** / **[!TIP]** / **[!IMPORTANT]** / **[!WARNING]** / **[!CAUTION]** GFM-style callouts\n- **```svg** fenced code → sanitized SVG embed (the universal escape hatch for custom diagrams; scripts and event handlers stripped at write time)\n- **<details><summary>X</summary>BODY</details>** → collapsible toggle\n- **[[slug]]** / **[[org/slug]]** / **[[slug#tab]]** / **[[slug#row-id]]** / **[[slug|display]]** → cross-references to another workspace, surface, or row. Resolved against your accessible workspace set; targets you can't see render as plain text on the reader's side (no info leak). Every cross-ref creates a Backlink row so the target's 'referenced from' sidebar shows this doc.\n- **[@Label](dock:mention/<kind>/<id>)** → @-mention of a user or agent. `<kind>` is `agent` or `human`; `<id>` is the principal id. Optional query params `?org=<slug>` (agents) or `?email=<addr>` (humans) for renderer hints. Mentioning a human writes a `doc_mention` row to their inbox + sends a deep-link email; mentioning an agent fires the `doc.mention_added` webhook so the agent service can wake up and reply. Re-saving a doc that already mentions someone does NOT re-fire — only newly-added mentions notify (computed from a diff against the previous body). Use this from agent code to ping a teammate when a doc you wrote needs their eyes.\n- A **lone URL on its own line** from a safelisted provider (YouTube, Vimeo, Loom, Figma, CodePen, GitHub gists) → sandboxed iframe embed. Other URLs stay as regular links. Surrounding prose disqualifies the auto-embed.\n\nPer-format caps: max 50 Mermaid diagrams (30 KB source each), max 500 math expressions (8 KB source each), max 50 SVG blocks (100 KB source each post-sanitize), max 200 cross-refs per doc, max 500 @-mentions per doc, max 20 embeds per doc, max 20 videos per doc (5 GB per file at upload time), max 200 images per doc. See /docs/doc-formats for examples. Last-write-wins; no CRDT merge. Emits doc.updated + doc.heading_added + doc.mention_added events as applicable. Requires editor role. Multi-surface workspaces optionally accept `surface_slug` to write to a specific doc tab; omitted writes the primary doc surface. Append-only updates have a dedicated `append_doc_section` tool that doesn't require fetching the body first.","detail":"Description of `update_doc` changed (12% word delta).","severity":"safe","descriptionDelta":0.11855670103092786},{"kind":"description_changed","tool":"update_surface","after":"Rename, reslug, reorder, OR replace the column schema of a surface. Pass any subset of `name`, `new_surface_slug`, `position`, `columns`. Position is 0-based and is normalised across siblings so positions stay contiguous. Editor role required. Emits `surface.updated`.\n\n**Column schema (`columns`)**: table surfaces only. Pass a full ColumnDef[] to REPLACE the existing schema atomically (no per-column add/remove churn, no row data loss — existing row.data keys that are no longer mapped are preserved on disk and surface in future writes' `unmapped_fields`). Each ColumnDef = `{ key, label, type, position, width?, hidden?, description?, options? }`. Type ∈ text | longtext | number | status | person | date | url | checkbox | select; `options` lists the allowed values of a status/select column. Reject 400 with a `table-only` error if the surface is a doc or html kind. Use `get_workspace_schema` first to fetch the current shape, mutate it, send it back.","before":"Rename, reslug, reorder, OR replace the column schema of a surface. Pass any subset of `name`, `new_surface_slug`, `position`, `columns`. Position is 0-based and is normalised across siblings so positions stay contiguous. Editor role required. Emits `surface.updated`.\n\n**Column schema (`columns`)**: table surfaces only. Pass a full ColumnDef[] to REPLACE the existing schema atomically (no per-column add/remove churn, no row data loss — existing row.data keys that are no longer mapped are preserved on disk and surface in future writes' `unmapped_fields`). Each ColumnDef = `{ key, label, type, position, width?, hidden?, description?, options? }`. Type ∈ text | longtext | url | status | owner | date | number; `options` is required on status/owner. Reject 400 with a `table-only` error if the surface is a doc or html kind. Use `get_workspace_schema` first to fetch the current shape, mutate it, send it back.","detail":"Description of `update_surface` changed (7% word delta).","severity":"safe","descriptionDelta":0.06930693069306926},{"kind":"description_changed","tool":"update_workspace","after":"Rename a workspace, change its slug, switch its default-view mode, or change its visibility (private | org). Pass any subset of `name`, `new_slug`, `mode`, `visibility`; fields you omit are left unchanged. Slug renames preserve old URLs via WorkspaceSlugAlias so previously-shared links keep resolving. Visibility flips disconnect every live SSE subscriber so reconnects re-authenticate against the new visibility. Editor role required; only the workspace owner can change visibility. Emits `workspace.renamed` and/or `workspace.visibility_changed`. Visibility WIDENING (private → org) is consent-gated: pass `consent_mode: \"web\"` to return an approval_url the user clicks; otherwise the call returns `consent_required` and you must re-issue with consent_mode set. Narrowing (org → private) and non-visibility updates execute immediately.","before":"Rename a workspace, change its slug, switch its default-view mode, or flip its visibility (private | org | unlisted | public). Pass any subset of `name`, `new_slug`, `mode`, `visibility`; fields you omit are left unchanged. Slug renames preserve old URLs via WorkspaceSlugAlias so previously-shared links keep resolving. Visibility flips disconnect every live SSE subscriber so reconnects re-authenticate against the new visibility. Editor role required. Emits `workspace.renamed` and/or `workspace.visibility_changed`. Visibility WIDENING (private → org/unlisted/public, org → unlisted/public, unlisted → public) is consent-gated: pass `consent_mode: \"web\"` to return an approval_url the user clicks; otherwise the call returns `consent_required` and you must re-issue with consent_mode set. Visibility narrowing + non-visibility updates execute immediately on the agent's role.","detail":"Description of `update_workspace` changed (10% word delta).","severity":"safe","descriptionDelta":0.09890109890109888},{"kind":"enum_value_removed","path":"inputSchema.properties.visibility","tool":"update_workspace","before":"unlisted","detail":"Enum value `unlisted` removed from `visibility` on `update_workspace`.","severity":"breaking"},{"kind":"enum_value_removed","path":"inputSchema.properties.visibility","tool":"update_workspace","before":"public","detail":"Enum value `public` removed from `visibility` on `update_workspace`.","severity":"breaking"}],"published_at":"2026-10-10T02:20:14.211Z"},{"slug":"ZV-2026-1120","server_name":"trydock.ai","severity":"breaking","title":"trydock.ai: Tool admit_waitlist was removed.","summary":"[breaking] Tool admit_waitlist was removed.","changes":[{"kind":"tool_removed","tool":"admit_waitlist","detail":"Tool `admit_waitlist` was removed.","severity":"breaking"}],"published_at":"2026-09-16T18:32:15.788Z"},{"slug":"ZV-2026-0751","server_name":"trydock.ai","severity":"breaking","title":"trydock.ai: Tool get_support_ticket was removed.","summary":"[breaking] Tool get_support_ticket was removed. [breaking] Tool list_support_tickets was removed. [safe] Tool list_my_support_tickets was added.","changes":[{"kind":"tool_removed","tool":"get_support_ticket","detail":"Tool `get_support_ticket` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"list_support_tickets","detail":"Tool `list_support_tickets` was removed.","severity":"breaking"},{"kind":"tool_added","tool":"list_my_support_tickets","detail":"Tool `list_my_support_tickets` was added.","severity":"safe"}],"published_at":"2026-09-05T22:31:17.406Z"}]