9-pattern agentic architecture — complete
All 9 standard agentic patterns now shipped: self-correction/reflection (#408), chain-of-thought (#433), tree-of-thought (#434, with a token-budget/empty-reply fix in #435), supervisor routing (#436), sub-agent spawning (#437) — on top of the tool registry, observability, HITL, and memory patterns shipped in v0.6.0.
Broad actionable agents
- Webhook, Slack, and email action senders (#438)
- LLM-driven action planner — the model can propose a real action, always gated through the existing approval flow (#441)
Security
- Fixed 7 stack-trace-exposure alerts and 4 unflagged raw-exception leaks in the API (#439, #440)
- Runtime-created AI Employee roles are now auto-detected as sensitive if their name/tags say so, closing a guardrail gap (#453)
- Docker Compose now binds all service ports to localhost by default (#459)
- Approval replies (YES/NO) now only count from the configured owner; WhatsApp/Telegram webhooks fail closed without a valid signature (#460)
- New optional
RAGLEAP_API_KEY— global middleware auth for the whole API, off by default (#485)
Contributor readiness
- Automated consistency check so a half-added AI Employee role can't ship unguarded (#442)
- New "Adding an AI Employee" guide in CONTRIBUTING.md (#454)
- Improved short-query language detection — external contribution by @hardik47278 (#452)
Cost control
- Usage ledger and token budget caps, global and per-role, covering streaming responses too (#455, #456)
Community
- Repo clone-count badge in the README (#465–469)
- ~35 community-contributed README translations
Related releases (separate packages, own cadence)
ragleap-tools v0.1.0 (+ search_documents tool), ragleap-vectorstores v0.5.0 (OpenSearch backend) / v0.5.1 (fix), ragleap-rag-java v0.6.0 (FaissBackend), ragleap-observability Promtail cross-namespace DNS fix.
Full test suite: 477 passing.