Known limitations
BetaWrengle is in beta. Every part of it sits at a different stage of readiness: some features are finished, some are still changing, and a few exist only as direction. This page spells out exactly where each one stands.
File preview limits
The workspace can preview PDFs, interactive HTML, common images, text/code,
CSV/TSV, and supported audio/video. These viewers are read-only; Office files,
PDF annotation, OCR, and source editing are not available. For previews other
than HTML, use Refresh to reload files changed outside Wrengle. Previewing
attachments does not add sync support for them. Interactive HTML opens
full-bleed without a preview toolbar,
can contact HTTPS services, and cannot read sibling files or other vault content;
pages must be self-contained or use HTTPS resources. Scripts can send page data
to those HTTPS services. localStorage and IndexedDB persist per vault path in
the system webview's app data; they are not vault-backed, synced, or included in
vault backups. There is no per-preview clear control, and many distinct HTML
paths can consume storage up to the webview or operating system's limits.
Renaming or moving a file starts a new scope, while deleting and recreating the
same path can inherit old state. WebKit may share a deliberately scoped
Domain=localhost cookie between preview hosts, so cookie isolation is not
guaranteed. If the saved local preview port is already occupied when Wrengle
starts, HTML previews remain unavailable until that process releases it; Wrengle
does not rotate the port and silently strand existing storage. See File previews for
behavior and size limits. CSV search covers at most the first 10,000
records and 500 columns. Wide tables show fewer than 200 rows per page to bound
rendering work. Individual lines and cells longer than 32,768 characters are
shown in navigable text windows; find still searches their full loaded contents.
Saved preview positions apply only to open tabs with session
restoration enabled; searches and PDF passwords are not persisted.
PDF outlines and printed page labels depend on metadata in the source document;
scanned PDFs without text are not searchable without external OCR.
Finder drag-and-drop copies regular files and directory structure, but does not preserve hidden entries, filesystem links, special files, permissions, extended attributes, or resource forks. Arbitrary imported files are local to this Mac and do not gain sync support merely by being placed in the vault. Name conflicts create a numbered copy instead of overwriting or merging the existing item. Filesystem drag-and-drop follows Wrengle's maintained macOS platform support; Windows and Linux remain outside v1. Moving or renaming a generic attachment does not automatically rewrite links to it in notes. Folders under Notes, Projects, or People cannot cross that managed-root boundary as a single move.
Workflow limits
- Workflows use one local desktop builder. There is no hosted workflow execution, webhook ingress, provider subscription service, cloud scheduler, or second Connected authoring mode. Wrengle and the matching vault must be open for scheduled work.
- The Action picker lists enabled custom actions and trusted local plugin actions by name, plus Gmail → Create draft under Apps. Disabling or removing a selected target leaves the saved step visibly unavailable instead of choosing a replacement.
- Check Gmail and Connect Gmail are readiness controls inside the opened Action picker. Startup can preload an already-configured Gmail token pair into the native session cache, but opening the picker performs no additional Keychain read or provider request. Readiness alone authorizes nothing; the Gmail action separately requires an exact preview and manual approval.
- Gmail uses native desktop OAuth and the OS keychain. The readiness control represents one primary Gmail connection; multiple-account selection is not available.
- A Gmail draft configures recipient and subject and takes the exact body from upstream workflow output. It is currently reached through Dry run: upstream AI or Fetch output is simulated, while approving the displayed Gmail request is real. Wrengle shows all three before approval, persists the encrypted effect and full recovery snapshot before contacting Google, and creates a draft only—it never sends mail. The upstream body is limited to 100,000 characters; MIME or provider limits can make the effective maximum smaller, and an oversized full recovery snapshot is refused before provider contact. Approval expires after 24 hours and can be reopened after restart with the same vault open. Recovery discovery is limited to the newest 20 items and revokes older waiting grants rather than hiding them. The encrypted workflow/configuration, objective, artifact bodies and paths, review/audit state, and exact request can remain for seven days; only the new bridge's content-safe plaintext metadata, opaque keyed request bindings, and receipts can remain for 90 days. Recipient and subject remain in normal local workflow settings until edited or deleted. Legacy preview-authored definitions and revisions can retain plaintext names, descriptions, and action configuration until explicit app-data cleanup or uninstall and are not governed by the seven-day payload rule.
- Action, Terminal, and Coding agent steps remain human-gated and make a workflow ineligible for unattended Run or automation. Gmail drafts therefore cannot run on a schedule. Configured and plugin actions still require the matching approval-gated access policy.
- The in-app scheduler supports daily or selected-weekday starts only. It is not an operating-system daemon, retains one capped latest-execution summary rather than general durable run history, and has no general automatic retry or crash resume. Gmail's durable waiting approval, intent, and safe receipt metadata are a narrow exception rather than full workflow history.
- Jira issue creation is editor-only in v1. Jira workflow actions, MCP actions, broad workflow-definition migration, and full durable run history remain deferred.
Assistant and external-agent limits
-
Assistant approval defaults to Ask. Vault-scoped MCP reads and searches are non-permissioned under every policy; Ask pauses on protected material actions. Note work can automatically decide eligible note create/edit/selection previews. Low risk adds only exact
pwdwith no arguments andlswith no path operand and only-a,-l,-la,-al,--all, or--long. Full Auto can approve any policy-eligible ACP permission, including destructive commands, only when the request offers exactly one unambiguous Allow once choice; requests without that shape still ask. Full Auto requires a one-time risk acknowledgement, remains visibly indicated, and can be lowered from the composer between turns or paused in Settings. ACP agents supply typed protocol option kinds; Wrengle validates and interprets those kinds, retains transport-ambiguous acknowledgements for exact retry, and restores a request to manual review when a policy reduction makes automatic approval ineligible. It does not bypass vault, stale-write, validation, or active-session guards. -
The composer combines reviewed intent presets with an Advanced view of the independent Wrengle approval and agent-mode layers. Ask me, Auto approve, Plan only, and Full access are enabled only when Wrengle knows the exact approved external-agent package version and the live session advertises the exact mapped mode ID. Built-in OpenAI and Anthropic expose only Ask me and Auto approve. Unknown versions, missing modes, and custom agents stay Custom and require raw Advanced choices; Wrengle never infers a permission meaning from an agent-supplied display label.
-
The durable global approval setting is a hard ceiling for raw conversation overrides. A named Auto approve or Full access transition can raise it only after confirming the durable Settings change, then reconnects the same conversation and revalidates its exact advertised modes. A failed elevation lowers the host policy first and returns to the reviewed ask mode or disconnects the session. Preset and Advanced-menu changes are unavailable during an active turn; Stop requests cancellation without changing either permission layer. After the turn, choose Ask me in the composer or use the persistent Settings Pause control to lower Full Auto.
-
Full access is not a sandbox escape toggle created by Wrengle; it selects a reviewed external agent's own bypass mode and Full Auto together. It has a separate durable warning acknowledgement, and native code rejects that reviewed bypass mode until the warning is acknowledged. The external process already retains ambient operating-system authority regardless of the selected preset.
-
Assistant connection and turn execution have no elapsed-time cutoff. Cancellation is explicit: Cancel abandons an opening request, Stop requests cooperative turn cancellation, and Force stop explicitly tears down after Stop is pending. Wrengle does not force-stop assistant work after 60 seconds or any other interval. Provider or subprocess work already dispatched may not be recallable.
-
Force stop and a mid-turn disconnect atomically save the visible partial transcript against the captured pre-turn context. That tail is display-only and excluded from future model context. A failed save must be retried before reconnecting; an interrupted external continuation is marked with a context gap or becomes transcript-only.
-
The bundled Wrengle renderer is a trusted policy controller. Native validation treats the external ACP agent and its permission labels/input as untrusted, but approval policy is not a security boundary against code already running in Wrengle's own renderer: such code can issue a manual approval or invoke the dedicated policy setter.
-
Inline Assist is selection-only in this release. It opens from the selection toolbar or Mod+Enter only when an editable note has a non-empty selection; caret-only prompting is not available. It reuses the current assistant backend, effective model, active conversation, admission path, and edit-review workflow rather than creating a separate AI workflow or private inline transcript. Its current note and selection remain mandatory exact context, each capped at 6,000 characters when needed; Add context can also attach multiple searchable notes as exact, turn-scoped Resource paths. Typing a path does not grant access.
-
Only one assistant turn can be active. While one is active, sending from Inline Assist replaces the Assistant destination's one latest pending turn with the complete isolated Inline draft. It waits for the active transcript commit before admission, and stopping or removing it returns the complete pending turn to its originating Inline draft. Inline Assist remains blocked while an AI edit preview awaits a decision or local recovery needs attention. An edit proposal moves to the existing Accept, Reject, and Retry preview. A turn that proposes no edit stays compact with Retry and Open Assistant and does not automatically open the panel or show conversational prose inline.
-
Built-in OpenAI and Anthropic Inline Assist turns disable note listing/search and restrict tool reads and writes to exact structured current-note or Resource paths; selected text cannot grant another path. The exchange remains in the shared visible transcript but is excluded from later built-in model history so a deferred instruction cannot activate after ordinary note access returns. That enforcement does not sandbox an external ACP subprocess or alter its opaque continuation. An external agent retains ambient OS permissions and can act on prompt-injection instructions in imported or untrusted selected text outside Wrengle's mediated tools.
-
Built-in OpenAI and Anthropic conversations restore a capped suffix of settled user-and-assistant text. Retired local-provider conversations are transcript-only. Pending permissions, live tool calls, thoughts, and other unsettled protocol state are not resumed. New Thread starts without earlier context.
-
Image prompts work only with compatible models in Wrengle's curated OpenAI and Anthropic catalog, or with an external ACP agent that explicitly advertises image prompt support. Unknown or unreviewed model capabilities fail closed; Wrengle blocks the send rather than dropping an attached image or choosing another backend.
-
Image input is limited to four static PNG, JPEG, or WebP images per turn, 5 MiB each and 20 MiB total. Width and height are each limited to 8,192 pixels, with at most 4,194,304 pixels per image, 16,777,216 pixels per turn, and a 32 MiB decoded-buffer limit per image. Normalization is serialized and budgets 64 MiB for the decoded source plus a full orientation or color-conversion frame; codec overhead, the encoded IPC string, and the bounded encoded output are separate. Animated, unsupported, malformed, truncated, mismatched, or over-limit images are rejected. Accepted images are fully decoded, orientation-normalized, and re-encoded without embedded EXIF, XMP, color-profile, or text metadata before dispatch. Opaque WebP input is normalized to JPEG and transparent WebP input to PNG, so opaque WebP pixels can change slightly. This avoids the supported WebP encoder's full encoded-frame buffer, which cannot be constrained by the output writer. The attachment UI shows metadata cards rather than decoding or rendering raw local pixels.
-
Anthropic's effective image limit is stricter: at most 8,000 pixels on either edge in its normal image-size regime. Wrengle caps each outbound Anthropic request at 20 image blocks to stay in that regime, preserving current-turn images and omitting the oldest historical images first with a model-visible marker. It preflights the initial request against the provider's 32 MB body limit with base64 growth, JSON escaping, and provider/tool envelope room included, then rechecks the fully accumulated conversation before every tool-loop continuation. An oversized current prompt is blocked before dispatch; if accumulated tool results make a continuation too large, the turn stops before that continuation is sent. Request-only image omission does not immediately release the original bytes from local live history.
-
The process-wide live image-residency limits are separate from the per-turn limits: 64 images, 40 MiB of normalized encoded data, and 33,554,432 decoded pixels across all staged images, requests in flight, and retained live histories in the running desktop app. New attachments fail closed when any limit is full. Start a new thread or close live image conversations to release capacity, or continue without new attachments until old image turns fall outside the bounded history of at most ten completed pairs and 24,000 characters; one conversation history also keeps no more than 20 MiB/16,777,216 pixels of images. An unsent native staging draft expires five minutes after its latest staged image and is removed by scheduled or later opportunistic cleanup, including when renderer cleanup is lost during a reload.
-
Normalized image bytes are available for compatible live-session follow-ups but are not saved in Wrengle's conversation record. The saved transcript contains only a safe format-and-dimensions descriptor and an Image not retained placeholder, so reopening or restarting requires reattachment. A retained image can be retransmitted on a built-in cloud follow-up and on multiple provider calls during one tool-using turn, with provider exposure, logging, retention, billing, and rate limits applying to each request. Providers and external agents have their own retention policies, and cancelling cannot recall image bytes already dispatched.
-
While a built-in OpenAI or Anthropic conversation retains an image, model-requested note listing and searching, and reading or editing unrelated notes, fail closed. Explicitly attached note, selection, and resource context remains available. A create-only write proposal may still request explicit approval without first probing whether its path exists; the atomic write fails if the path is not new. Attach the intended context before sending, or start a fresh conversation before asking the model to explore unrelated notes. This does not restrict an external agent's ambient operating-system permissions.
-
Renderer checks enforce ordinary attachment limits before staging, but desktop IPC receives and deserializes the base64 attachment string before the native command applies its encoded-size limit. That native check is not a transport-layer allocation cap. Temporary encoded and normalized buffers are memory-only, not a guarantee of secure erasure from runtime copies, operating-system memory, swap, or crash state.
-
External ACP continuation depends on capabilities advertised by that agent. Wrengle tries
sessionCapabilities.resume, then top-levelloadSession. If neither is available or continuation fails, the saved transcript remains visible but the agent starts a fresh session behind an explicit transcript-only notice. -
A confirmed conversation deletion is authoritative for Wrengle's local save. If current-vault authorization or local deletion fails, Wrengle reports that failure and keeps or restores the conversation. While a matching external session is live, Wrengle also requests
session/close; a failed acknowledgement is shown in the app, but Wrengle cannot guarantee deletion from the external agent or its provider. Inactive remote sessions remain subject to that agent's retention controls. -
In Assistant and Inline Assist, only external agents with HTTP MCP support receive Wrengle's named
list_notes,read_note,read_note_blocks,search_notes,write_note,edit_blocks, andreplace_selectiontools. Without HTTP MCP they remain limited to scoped ACP filesystem callbacks. Plugin Builder is separate: it disables ACP filesystem callbacks and exposes only Builder capability tools over authenticated HTTP MCP or a bounded stdio fallback. -
MCP reads and search are vault-scoped and need no approval from the MCP tool itself. Material MCP creates, edits, and selection replacements require Wrengle's preview and approval-policy flow, the editor's own serialization, stale-base conflict checking, and current-vault validation; an already-satisfied
convertis a local no-op with no preview or write. -
In Assistant and Inline Assist, Wrengle-mediated permissions are not a subprocess sandbox. An external agent runs with the desktop user's OS file, command, process, and network authority and can use it without a Wrengle approval card. Wrengle clears the app environment and passes a small platform/configuration allowlist and a validated login
PATH. The approved Claude Code preset uses its app-scoped account login and does not inheritANTHROPIC_API_KEY; Gemini CLI receives only its documented Gemini/Google API and Vertex variables; Codex receives no ambientOPENAI_API_KEY. Unrelated app tokens, proxy variables, and custom CA variables are not forwarded. Allowed home/profile and config variables still expose the CLI's own login/config. Plugin Builder instead uses scratch configuration, workspace, XDG, and temporary directories; its reviewed Claude runtime preserves nativeHOMEfor macOS Keychain discovery. It excludes ambient API keys, ADC, and service-account credentials, and exposes only Builder MCP tools through exact pinned adapter options enforced by the host. The upstream adapter does not provide runtime policy acknowledgement. Ordinary descendants are process-tree managed, but a deliberately detached Unix session/process group can escape where the applicable sandbox permits it, and already-dispatched remote work cannot be recalled. -
Wrengle can run terminal-authentication methods advertised by an approved ACP agent. Selecting one automatically opens a transient Terminal session with the desktop user's normal OS authority; Wrengle launches the reviewed preset and advertised login arguments directly, without shell interpolation. The CLI or identity provider owns credential entry, storage, account selection, quotas, and billing. Wrengle does not persist the login terminal in restored sessions, command history, agent transcripts, logs, or telemetry, although output can remain visible through Show Terminal for the current app runtime after a failed or cancelled attempt. This is not secure erasure from process or operating-system memory, swap, crash data, or CLI/provider storage. Exit success reconnects the same conversation without replaying its failed prompt; cancellation or failure returns to the authentication card for explicit retry. Agents that do not advertise terminal authentication still require their documented manual CLI login followed by reconnecting in Wrengle.
-
Shared-auth Plugin Builder routes reuse the existing app-scoped account sign-in from Assistant or Builder; the Keychain discovery fix does not require another login. Only users who have not signed in since moving to the app-scoped identity need one fresh account sign-in through Assistant or Builder. The current exact reviewed policy covers Claude Code 0.70.0. Gemini CLI and Codex fail closed with a typed unsupported result and remain Assistant-only. Assistant and Builder share only the selected agent's app-scoped secure-store identity; Builder does not import an ordinary CLI-home login or ambient API-key, ADC, or service-account environment. Missing, inaccessible, or unsupported authentication stops before prompt dispatch, creates no generated draft, restores the editable submission, and never retries automatically. Authentication expiry after generation begins instead preserves any generated draft and visible progress for review, but still requires an explicit new action.
-
Renderer/webview ownership is explicit and has no time-based expiry. Orderly window close waits without an elapsed-time cutoff for the renderer's stable atomic conversation-save tail, then runs a native recovery barrier; an active turn or a failed save keeps the window open for explicit Stop/retry, while an opening connection is generation-fenced and its exact renderer workflow plus any pending native-open cleanup are drained first. After reload or a webview crash, a replacement renderer must fence and drain old opening handshakes and sessions before another assistant session opens. If final operating-system window destruction fails after native shutdown, the surviving renderer retires its stale session handle and reconnects the same durable conversation after reclaiming ownership. A native-captured Force Stop boundary is settled exactly, other interrupted turns receive a display-only recovery marker against their clean pre-turn context, and an interrupted external continuation becomes transcript-only. Pixels or text that existed only in the crashed renderer cannot be reconstructed. Before a host terminal proposal runs, Wrengle durably records an Outcome unknown fallback; the final outcome replaces it after settlement, so interruption requires review before retry.
-
External-agent
node --versionandnpx --versionsetup probes are process-tree managed, cancellation-aware, and capped at 10 seconds each. They receive the validated loginPATHand bootstrap-only platform/configuration variables, but no preset or provider credentials. A broken or slower probe is reported as an unavailable Node/npx environment; this setup bound is separate from assistant connection and turn execution, which have no elapsed-time cutoff. -
Approved external-agent presets use exact top-level package versions from Wrengle's reviewed ACP registry snapshot: Claude Code 0.70.0 and Codex 1.6.2 require Node 22+, while Gemini CLI 0.57.0 requires Node 20+. A pin prevents npm's
latesttag from changing the selected top-level distribution between Wrengle releases, but npm still resolves and verifies the dependency tree that distribution declares. Wrengle forces the public npm registry for the default and approved package scopes and ignores worktree/home npm configuration during bootstrap. In Plugin Builder, npm materialization runs as a separate short-lived phase with scratchHOMEthat disables package lifecycle scripts and may write only Builder scratch plus the selected Wrengle-owned cache; the verified adapter then starts under a cache-read-only, scratch-write-only runtime profile. Builder additionally requires an exact reviewed shared-auth and MCP-only policy; currently that policy is available for Claude Code 0.70.0, while Gemini CLI and Codex fail closed as unsupported and remain Assistant-only. Bootstrap policy is stripped before the adapter starts, so package commands it later runs can use ordinary project/home npm configuration where the destination's sandbox permits them. First use and Repair and reconnect normally require network access. Repair quarantines only the affected app-owned cache generation, switches that preset and version to a new generation, and makes one reconnect attempt; it does not touch the user's global npm cache or CLI login. The two newest quarantined generations are retained; an older generation is reclaimed only after its OS-backed live-session lease is no longer held, including when a later repair removes an unlocked marker left by a crash. Repair cannot recall dispatched work or guarantee secure erasure. -
ACP note approvals still commit one note payload at a time, in the editor's own serialization. Within that note, one structured edit can contain several compatible operations, and
convertcan change 1–100 editable top-level paragraph, quote, heading, bullet, numbered, or checklist blocks in place while preserving their text and order. A stale, duplicate, nested, read-only, unsupported, or unsafe conversion target rejects the whole conversion. Multi-note edits and existing-note frontmatter rewrites remain unavailable until they can be represented as separate safe writes.
Startup access limits
- The startup gate asks for macOS microphone access and preloads configured app-owned secure items before the workspace opens. System audio is not requested at startup. On macOS 14.2 or later, the explicit Enable and test action plays a short tone and is the only path that can request or verify the lower System Audio Recording Only permission. A Keychain with several configured items can still show several item-specific dialogs. Allow covers one read; Always Allow is the persistent choice for the current app identity.
- macOS exposes no reliable prompt-free status API for audio-only recording. Wrengle can remember that a test succeeded for the same backend and signing identity, but it cannot prove later that the grant remains enabled. A failed tone test is therefore Needs attention, not a definitive permission denial: a muted, disconnected, or changed output route can produce the same result. Opening System Settings or changing output device requires another explicit test.
- Apple has acknowledged reports that Core Audio process taps can continue delivering callbacks containing only zeros during long sessions on some macOS 26 releases. Wrengle cannot distinguish that condition from legitimate silence and does not reset the tap or widen permission automatically. Stop the meeting, choose Use legacy screen-capture permission in Desktop access, grant the upper Screen & System Audio Recording permission, and start a new recording if this occurs.
- Wrengle holds successfully read secrets only in a session cache its native side owns and scrubs from memory when it is released. The part of the app that draws your screen receives capability state, not secrets. External Keychain changes made after startup are intentionally observed on the next launch or explicit reconnect rather than through a surprise runtime read.
- A denied/locked secure-item read, denied/restricted supported capture grant, or some platform errors produce granular Limited mode. Local vault and note features remain available. Cleanly missing, unconfigured, disconnected, and revoked credentials instead stay unavailable in their own feature surfaces without making the whole startup Limited.
- Explicitly saving, replacing, or removing an AI or transcription key while Wrengle is focused can show its item-specific macOS Keychain dialog. Denying or canceling it fails closed and revokes the affected session capability. Background token rotation, automatic cleanup, and ordinary feature use remain prompt-free. A restart retries only items whose non-secret metadata still authorizes startup access; broker failed-mutation tombstones are never used to rediscover an old value.
- If
settings.jsonor a routing-critical saved provider/backend value is malformed or unreadable, assistant and voice starts pause behind a retryable settings error. Wrengle does not overwrite the file or guess Local, Off, or a cloud destination; repair or restore the saved settings before retrying. - The unpackaged Windows desktop build cannot reliably request or report per-app microphone or system-audio consent. Startup therefore reports native capture permission as Not required; it does not probe a device, detect the global desktop-app microphone switch, or enter Limited mode merely because that switch is off. A later device-open attempt fails prompt-free if the global switch or selected device prevents capture. Settings → Privacy & Data → Desktop access always links to Windows microphone privacy settings for recovery.
Account sign-in limits
- Beta accounts support email and Google only. They provide identity and profile management. Signing in alone does not upload vault content or unlock local features; sync is off by default and is turned on per vault in Settings.
- Sign-in, sign-up, desktop OAuth, and first-time provisioning fail closed if the production Clerk tenant or the required Google, verified-email, public registration, or self-service deletion configuration is unavailable.
- Wrengle requires a verified email. Google addresses containing
+,=, or#are rejected for account-alias security. - Direct Developer ID releases use the system browser. A Mac App Store submission remains blocked until an appropriate native or system authentication session is designed and verified.
Live document sync limits
- Sync is optional and off by default. Turned on per vault from Settings → Account, it keeps that vault's notes, charts, whiteboards, whiteboard images, note frontmatter, and folder structure the same on your own computers, including documents you do not have open. Attachments outside whiteboards do not sync.
- Team workspaces require an enabled deployment and current desktop release. Admins access all team vaults; members access only assigned vaults. No guests, viewers, personal-to-team transfers, paid seats, or pooled AI credits. Deleting an individual account preserves team-owned content; removal cannot erase downloaded files.
- Opening a synced vault on another computer needs an empty folder. Where sharing is enabled, a vault has one owner and up to 20 editors; no read-only viewers, remote cursors, presence UI, or browser/mobile client. Sync runs in the desktop app only.
- Shared-vault access removal stops future sync within five seconds. Downloaded files remain, and deleting the owner's account deletes their remote shared vaults. The owner's subscription and storage allowance cover the vault. No ownership transfer.
- Server copies are encrypted in transit and at rest, but Wrengle can technically read them to operate the service. Turning sync off keeps your local files and does not delete existing server copies; Remove from server keeps the server copy for 30 days, then deletes it. Keep an independent backup and do not mirror a Wrengle-synced vault with another file-sync service. See Sync across your computers.
Whiteboard limits
- Whiteboards are
.wrboardvault documents with live split-pane updates and optional sync across your own computers, including referenced images. There are shared vaults where the deployment enables sharing, but no remote cursor or presence service, shared room UI, or browser editor. - Whiteboard images are limited to PNG, JPEG, GIF, and WebP, with an 8 MiB,
8,192-pixel-per-side, and 16,777,216-pixel limit per image, plus at most 16
retained image references per board. The editor also bounds the total decoded
pixels loaded at once and rejects animated GIF or WebP files. Deleted images
continue counting after reopening so another computer can still undo deletion.
Wrengle copies images into
assets/images/; a.wrboardfile without those referenced assets is not a complete visual backup. Missing, invalid, or over-budget images are reported as unavailable without preventing the rest of the board from opening. - Excalidraw drawing exchange accepts
.excalidrawfiles and PNG/SVG files containing editable scene data, up to 128 MiB. Existing board and image limits still apply. Unsupported elements, missing image data and ordinary SVG insertion are rejected. Editable exports require all referenced images; ordinary image snapshots can leave unavailable images blank with a warning. - Reusable libraries belong to one vault and support shapes, text and groups,
not images.
.excalidrawlibexchange is limited to 16 MiB. Include the hidden.app/folder in backups to keep the library; Git history and live sync do not include it. - Mermaid insertion is local and one-way. Flowchart and sequence diagrams produce editable shapes. Other accepted class, ER and state diagrams must produce supported vector elements; image fallbacks are rejected. Excalidraw AI generation and web embeds are not available.
- Local CRDT recovery can restore recent unsaved whiteboard changes after a renderer reload or ordinary crash. It is not a collaboration or cross-device synchronization service, and an identity or recovery conflict fails closed instead of replacing the saved projection silently.
The table below covers other areas of the app, from downloads and accounts to plugins, charts, whiteboards, meetings, and dictation.
| Area | Status | Limitation |
|---|---|---|
| Public downloads | Beta | wrengle.com/download offers only the expected exact-named macOS DMG in the configured GitHub release. v0.0.18 and later require Apple Silicon and macOS 13.4 and continue on the signed updater-v2 channel. v0.0.17 is the final universal Intel-compatible build and receives no later fixes. Presence in release metadata is not itself a local checksum or signature verification. Windows, Linux, and mobile installers are not v1 targets. |
| Accounts and billing | Beta | Optional account sign-up and sign-in are available through email or Google and add identity; sync between your own computers is separate and off by default. Polar checkout and receipts are available only on deployments with complete Polar and safe credit-pack configuration, independently of managed generation. Team workspaces are available only where enabled; paid seats and pooled AI credits are unavailable. Licenses, gated downloads, and subscription pricing remain unavailable. |
| Search across this documentation | Planned | These pages have no search of their own in v1. Use your browser's in-page find, or the sidebar and the documentation index. |
| Plugins | Beta | Local folders can contribute trusted WASM actions, sandboxed views, and manifest-declared UI entries. Declarations are requests, not grants: every positive grant is bound to the exact manifest, WASM, and view bytes captured at reload, so changed code needs fresh approval. Writes remain app-mediated proposals. Every view has a mandatory offline policy; direct networking and external resources are blocked, while httpHosts gates only host-mediated WASM calls. Marketplace distribution, remote installation, process plugins, and compatibility guarantees are not in v1. |
| Integrations and custom actions | Beta | The documented executable paths are Gmail draft creation in Dry run, Jira issue creation from the editor with account-backed Atlassian OAuth, configured webhook actions, and — in production-verified builds — Google Calendar meeting context. Jira is editor-only in v1; every ticket selects its site, project, and issue type and sends the reviewed summary and description to Atlassian. New Jira API-token custom actions are unavailable, while legacy definitions remain visible only for disable/removal. Calendar reads only owned timed default events from the primary calendar, keeps cached rows for up to seven days, and does not support secondary calendars, attendees, descriptions, editing, RSVP, push, or hosted sync. Calendar disconnect is local-only; use Google Account settings for full project revocation, which can also affect Gmail. Linear remains a settings preview and HubSpot is unavailable. Provider-backed actions can send selected context or configured payload data to the external service you choose. Custom actions join the local action registry only when enabled. |
| Terminal | Beta | The embedded terminal runs a local shell with normal OS permissions and is not sandboxed by Wrengle. Per-vault launch profiles, environment overrides, restore metadata, recent commands, and selected-output captures are local app state with capped retention. Workflow terminal drafts run only after explicit user submission. |
| Retired local model files | Beta | Wrengle no longer downloads or runs generative models. Older app-owned GGUF files can be reviewed and deleted explicitly from Settings; the cleanup does not touch Local Whisper, embedding indexes, or an independently installed Ollama service. |
| Editor media and semantic blocks | Beta | Media blocks copy local files into vault-relative assets/ folders and reject remote, absolute, traversal, or malformed asset paths. Semantic workflow blocks round-trip through Markdown plus sidecar metadata; unsupported sidecar or block payloads can be rejected by persistence guards. |
| Local editor recovery | Beta | Wrengle keeps local-only CRDT recovery state under .app/crdt.db for recent editor state. This database remains local; separately enabled live document sync sends validated open-note and chart state, without presence or collaboration. If recovery metadata becomes inconsistent with note paths, Wrengle can block opening, moving, deleting, saving, or switching vaults with a repair-needed message rather than silently discarding local CRDT state. If recovered note content is malformed, or a historical recovery bug stored a Wrengle-managed region as degraded raw source, Wrengle shows the saved Markdown read-only and offers an explicit, note-scoped Reset local recovery action. Resetting discards only that note's unsaved recovery and leaves its Markdown file unchanged. |
| Chart documents | Beta | Wrengle supports local chart files for desktop diagrams, with shape and connector editing, a searchable responsive Shapes library, direct drag-to-canvas placement, and stable contextual formatting controls. Chart files are local vault documents; split panes attached to the same local chart mirror edits live, including in-progress object moves. Hosted collaboration is available through shared vaults only where sharing is enabled. Remote presence is not included. Grouping, layers, comments, and reusable document templates are not included in this release. Existing chart files are not migrated or automatically restyled by the redesigned editor. Browser editing and analytical spreadsheet charts are not part of this release. |
| Meeting capture | Beta | Recording support depends on platform permissions and hardware. Mic + System is the default when supported; system audio remains platform-dependent. One meeting owns process-wide capture, finalization, save, and automatic-report admission at a time. After Stop, Wrengle seals the encrypted audio timeline and releases the physical devices, but Record and voice capture wait until that lifecycle settles. There is no advertised maximum meeting duration yet: long-session qualification is an internal macOS target, not a public eight-hour guarantee. |
| Meeting transcripts | Beta | Calendar context, elapsed timestamps, copy controls, and bounded local finalization are supported. Speaker attribution is channel-based (You vs Participants), not individual diarization, and cloud-finalized transcripts have no speaker labels. ElevenLabs is dictation-only. During capture Wrengle stores independently authenticated encrypted audio blocks in private operating-system app data, outside the vault and its Git/sync boundary, while keeping only a short rolling memory window. Local finalization decrypts bounded two-minute ranges. Cloud finalization sends contiguous silence-aligned chunks of at most eight minutes to the fixed selected provider/model. Each chunk gets one provider attempt; any failed or ambiguous provider attempt stops for attention without automatic resend, provider switching, or local substitution. Recover is the explicit action that can authorize a route-bound retry. Recovery transcript state and exact-range finalization progress are paged into bounded files under .app/live/; replaceable partial captions remain memory-only. Available disk, model speed, sleep, provider limits, and interruption recovery still affect long sessions. |
| Meeting reports | Beta | Wrengle creates one six-field final report after the transcript: summary, decisions, action items, follow-up, discussion, and open questions. Automatic schedules it after transcript save; Manual waits for Generate report. Long transcripts are covered by contiguous shards rather than sampled windows: evidence is checkpointed per shard, deterministic lists are combined across every shard, and narrative fields are reduced hierarchically. User-owned note context remains complete through 8,000 characters; above that cap, the user-owned note uses a five-window Condensed representation. During-capture preparation remains bounded and route-attested; ambiguous provider exposure is never automatically replayed. Report generation requires an explicit supported cloud route disclosed under Cloud meeting report access: direct OpenAI or Anthropic, or a selected text-only Wrengle AI tier. No generative report route runs on-device, and a report failure never switches provider or managed tier. Selecting a cloud model is your consent to send the complete transcript in bounded contiguous shards, bounded user-owned meeting-note text, and meeting title/prompt context directly to the selected BYOK provider, or through Wrengle to OpenAI for a managed tier. A long action can make multiple sequential provider calls for its shards and hierarchical reductions. The report path never sends meeting audio, and transcript save does not depend on report availability. |
| Dictation and voice control | Beta | Quick Dictation treats trigger words as text; exact stop and “scratch that”/“undo that” phrases remain a fixed set of controls. Voice Control requires exact trigger words for editor, workspace, configured-agent, and terminal commands, so there is no automatic bare-speech command classification. Toggle capture uses Cmd/Ctrl+Shift+V and Hold to Dictate uses Cmd/Ctrl+Shift+D until release. Node labels, connector labels, swimlane lane headers, and page names accept dictation when focused; only node labels accept paragraph breaks. Explicit button and shortcut stops preserve the current partial even when live preview is off; whole-utterance spoken stop phrases end the session without committing an unfinalized partial. Blocked text has Insert here, Return to original, Copy, and Discard recovery paths. A microphone picker, local five-second input test, active level meter, and device errors are available. Verbatim and Light edit cleanup plus Fast, Balanced, and Deliberate response speeds are available. Quick Dictation with Verbatim cleanup bypasses analysis; other paths require a supported cloud analysis route: direct OpenAI or Anthropic, or a selected text-only Wrengle AI tier. Light edit is contextual editing, not summarisation: it can atomically revise the current utterance and up to four recent dictated sentences from the same voice session, all captured within one exact target: the note, assistant draft, Plugin Builder prompt, or chart text field. While one in-progress phrase and its exact target remain active, Light edit may analyze provisional transcript snapshots that can later be superseded or cancelled, but no more often than once every 1.5 seconds; each request can use provider quota or billing, or Wrengle AI credits. Turning live preview off suppresses those during-speech calls; final cleanup still runs. Accepted corrections to earlier dictated sentences are one undoable atomic change, while the current unfinalized phrase remains grey ghost text until finalization. Recognition language, a limited set of vocabulary hints, and optional exact spoken punctuation are configurable, but the UI and built-in control phrases remain English. Local speech stays on-device; Light edit and Voice Control analysis use the configured direct OpenAI or Anthropic provider, or send text through Wrengle to OpenAI on a selected managed tier. OpenAI, Deepgram, or ElevenLabs cloud dictation streams microphone audio and can send supported vocabulary hints to the selected provider. For Voice Control commands, cloud analysis can send the current utterance, active note title, up to 40 folder paths, and up to 15 recent note paths. Cloud Light edit does not send target identity, microphone audio, or separately read or attach arbitrary typed text, the note body, or surrounding chart content; its payload is bounded to the eligible current and recent dictated slots. Keys, consent, billing, and provider policies apply independently. Analysis failures never switch provider, managed tier, or local model. Cloud reconnect buffering is capped. Deletes are confirmation-gated; shell commands and external-agent sends require button/keyboard confirmation and are not covered by voice Undo. Voice and meeting capture cannot run at the same time. macOS-first, following meeting-capture platform support. |
| External agents | Beta | External agents share the Assistant transcript and review workflow, but continuation and MCP tools remain capability-qualified. Unsupported or failed continuation opens the saved transcript in transcript-only mode with a fresh agent session. In Assistant and Inline Assist, MCP-mediated writes are approval-gated but the subprocess's ambient OS permissions are not sandboxed by Wrengle. Plugin Builder is different: it requires a contained scratch work profile, the macOS process sandbox, a supported app-scoped secure-store account identity, and host-enforced MCP-only options for an exact pinned adapter. It excludes ambient API-key, ADC, and service-account credentials and fails closed before prompt dispatch when any required boundary is unavailable; the upstream adapter does not attest to the policy at runtime. |
| Plugin Builder AI composer | Beta | Builder uses the shared advanced composer and model catalog but owns its route, permission intent, draft, one latest pending turn, and conversation. Exact note Resources are selected through the searchable picker and apply only to that turn; typed paths grant nothing. Separate conversation-wide note access still requires its permission card. PNG, JPEG, and WebP prompts are normalized natively, sent as model references, and staged as managed draft assets. Ask, Auto approve, Plan only, and Full access are supported, but validation, preview, containment, and the human Add/Update step remain mandatory. The current external route uses Claude Code 0.70.0 and reuses the app-scoped secure-store identity from an existing Assistant or Builder sign-in. Gemini CLI and Codex fail closed with a typed unsupported result and remain Assistant-only. Builder never automatically retries a failed submission: a preflight auth or policy failure creates no generated draft, while auth expiry after work begins preserves the generated draft and visible progress for review. Generated plugins stay offline even when bounded Builder MCP capabilities perform approved execute, fetch, or network work during generation. |
| Workflow automations | Beta | A workflow is the auto-saved local graph; an automation adds one daily or specific-days trigger and a pinned live workflow version, and can be Active or Paused. Draft changes aren't live until the user explicitly updates that version; editing recurrence does not publish the draft, and layout-only moves do not create execution drift. Only Goal, Fetch, AI step, Write note, and Final review steps can run unattended; Action, Terminal, and Coding agent steps remain human-gated. Pinned external-agent backends are not supported for live workflow execution. The scheduler is in-app and vault-bound: Wrengle and the matching vault must be open. A manual Run is bound to the vault open when it starts, so vault switching cannot redirect its note write. Within one app process, only one user-started foreground workflow execution per current vault is accepted across manual Run and automation Run now; a reopened Workflows view reconnects to either kind and continues compact status checks. Run now immediately shows an in-progress execution and retains terminal detail in the current workflow UI; scheduled state moves from queued to running and then terminal. Activation, resume, and trigger edits establish a cadence baseline and wait for the next matching occurrence, so there is no catch-up from before activation or while paused. If an already-active automation misses an occurrence because the app or matching vault is unavailable, the most recent missed occurrence may catch up once. Accepted automations use isolated background tasks, so one slow run does not block other triggers or the scheduler's next scan. A finite automation admission queue feeds bounded heavy-work capacity: excess due occurrences remain eligible for a later scan and accepted work can stay queued for up to 10 minutes. Manual Run, automation Run now, and scheduled executions each have a fixed 30-minute limit. Stop requests cancellation at safe boundaries, but already-started provider, fetch, or note work may finish; Hide only closes the local detail view. For unattended executions, terminal state can appear before cleanup finishes, so editing and duplicate/overlap guards remain locked until that work drains. Compact terminal status releases those locks as soon as cleanup is complete; best-effort full terminal detail loading does not extend them. Within one running Wrengle app process, a duplicate overlapping run for the same automation is rejected; there is no cross-process overlap guarantee. The scheduler scans at startup and about every 60 seconds, so a run can be claimed almost a minute after its configured time and then wait in the queue. There are no cron, webhook, file/note, meeting/calendar, or multiple triggers. Runs have no durable execution history; only one capped, content-free latest-execution summary persists. There is no general automatic retry; a terminal status-save failure is retried locally without rerunning workflow steps. An app interruption before terminal state can leave the current occurrence eligible for bounded catch-up; it restarts rather than resumes and may repeat earlier side effects. Pausing or deleting prevents future unclaimed runs but cannot cancel claimed work; queued or running execution can continue. Different automations can still write the same managed output region, where the last completed write wins. Current releases persist sanitized, content-free outcome categories, including timeout and interruption; at the next app launch, unknown error text in recognized records from an older release is sanitized before display and rewritten in the local settings file while unknown raw records are preserved. |
| Mobile apps | Not in v1 | Mobile clients are not part of v1. |
| Browser-first workspace | Not in v1 | Wrengle is desktop-first. The web surface provides public marketing, downloads and docs plus account identity and profile management, not a hosted browser workspace. |
| Analytics on this site | Beta | Basic cookieless analytics counts views and leaves on successfully rendered, reviewed public routes unless you object. It sends canonical paths without query strings or fragments, referring origin, and coarse browser, OS, and device details through t.wrengle.com to PostHog EU; it sends no page content or interactions and leaves no PostHog identity in browser storage. The browser sends no session or window ID, and PostHog assigns cookieless visitors and sessions during ingestion when Cookieless server hash mode is enabled. Enhanced analytics opt-in adds Web Vitals and strictly allowlisted structural interactions on the same routes: metric name/value/delta/rating and interaction event type/tag/bounded sibling positions. Text, attributes, classes, IDs, selectors, link destinations, and custom augmentation are removed. Authentication, account, callback, admin, API, error, and unknown routes remain excluded; URLs stay canonical, campaign identifiers are removed, and person profiles, feature flags, heatmaps, dead-click capture, and session replay remain disabled. Both lanes disable Beacon and use credentialless fetch. The project must discard IP data and retain analytics for no more than 12 months. Website diagnostics is a separate Sentry opt-in. Global Privacy Control, Do Not Track, a basic objection, and Decline all stop every website telemetry lane. |
Enhanced Web Vitals describe only the hard navigation and remain bound to the successfully rendered public route that loaded the document. SPA transitions do not produce or claim a new hard-navigation metric, and a document loaded on an excluded route stays ineligible. Metrics generated by a back-forward-cache restore are rejected. If a browser blocks verified PostHog-state deletion after withdrawal, capture stays off; later analytics cannot start until the site can verify cleanup and preserve that fail-closed state, or the visitor clears this site’s browser data.
On Unix, Recovery discovery can re-attest a released owner lease when a remount changed only the device identifier of the same lock file. The repair holds that file's exclusive lock, advances the generation, and leaves the saved note binding untouched. Fresh or unreadable ownership and replaced lock files still fail closed. Independent synced copies remain outside the locking guarantee and must not be recovered concurrently.
For a saved transcript of 32,000 characters or less, Wrengle makes one OpenAI or Anthropic report call. It can request up to 16,384 completion tokens, has a 32,000-character response cap, and can run for up to 60 seconds. A longer transcript can make multiple sequential calls in one visible action: one for each contiguous shard followed by hierarchical reduction calls. Deterministic decisions, action items, and open questions are combined across every shard, while narrative fields are reduced hierarchically. User-owned note context is complete through 8,000 characters; above that cap, the user-owned note uses a five-window Condensed representation. Every long-path call has its own 60-second deadline, 3,000-output-token cap, and 12,000-response-character cap. Bounded note and title/prompt context can accompany each call, so aggregate runtime, transmitted context, provider logging or retention exposure, usage, and billing scale with the call count; 60 seconds is not an action-wide limit. Rolling preparation and the Stop-tail drain retain their separate budgets. Each explicit retry is another potentially billable attempt and may make another sequence of calls; Wrengle never automatically repeats an ambiguous or failed provider request. After the 30-second in-memory transcript display expires and any already attached bounded reconnect lease expires, the complete transcript remains in the saved meeting note. Current builds read the earlier coarse report-failure reason. Rolling back to an older build after a newer actionable reason is written can make that temporary report-recovery item fail closed until it is opened by a current build.
Dictation speech and the built-in assistant can use Auto. Connected keys that Wrengle can read from the operating-system keychain make their cloud providers eligible, while Cloud voice features Off remains sticky. Auto speech checks the most recently connected provider, then OpenAI, Deepgram, and ElevenLabs before Local Whisper. Assistant and voice-analysis Auto check the most recently connected or successfully verified AI provider, then OpenAI and Anthropic; without a usable key they require provider setup. Other non-chat generation requires a supported direct OpenAI/Anthropic model or a selected Wrengle AI tier. Legacy explicit local-AI choices remain retired and are never silently routed to cloud. These defaults do not change meeting behavior: live captions and default meeting transcription remain local-first, and cloud meeting final-pass transcription remains separately opt-in. This availability check does not contact the provider; invalid, revoked, or quota-limited keys can still fail when a request starts.
Local recovery format compatibility
Opening a vault with a release that uses CRDT identity schema v2 automatically
migrates well-formed older v1 note identities up to the 16 MiB identity-metadata
safety limit while preserving their vault and document IDs. Oversized or
malformed identity state fails closed. The migration is a downgrade boundary:
older Wrengle builds that only understand v1 will fail closed for that vault
afterward. Do not delete or copy individual CRDT identity files to work around
this check. Back up and restore the full vault, including the complete .app/
tree, so the v2 identity index, migration and advancement journals, and CRDT
database stay together. A short-lived advancement journal lets startup finish
an interrupted published v2 identity update, or safely discard one that was
only prepared.
The local CRDT database has a 256 MiB safety limit. If an unverified interrupted-replace backup remains, Wrengle leaves it untouched and fails closed instead of guessing between it and any saved image. Automatic snapshot compaction is not available in this build, so local recovery history can grow to that limit. Where a recovery banner offers Reset local recovery, the reset removes that document's local recovery payload, not its saved Markdown or chart projection.
Resetting a note advances that vault's local CRDT identity index to schema v3 so older builds cannot silently drop the reset lineage. A build that only understands v2 can report local recovery as unavailable for that vault; the saved Markdown remains intact. Return to the resetting build or a newer build instead of deleting app-managed identity files.
Some older builds could lose one identity-index mapping during concurrent document opens while leaving that document's local CRDT payload intact. A Markdown file has no durable document ID, so Wrengle leaves both copies untouched and offers Recover local state; only that explicit choice can attach the historical payload. A chart can reconnect automatically only when its saved projection carries the same document ID as the exact database-owned payload. Either path also requires an existing same-vault identity index with no path, kind, tombstone, or pending-operation conflict. Candidate lookup, secure file revalidation, and the identity update run under the app-owned store locks. Wrengle never creates a replacement ID for an existing payload. A missing whole index or any ambiguity still fails closed.
During-recording report preparation
Prepare final transcript while recording is on by default for eligible local transcription. It keeps a capped, final-quality transcript cache on device and is independent of report generation mode and report preparation. Turning report preparation off, choosing Manual, or losing report-route eligibility does not disable this local Stop-time optimization.
After Stop is the clean-install preparation default. Report preparation: Auto is an opt-in advisory performance optimization for Automatic reports, not a live-note or recovery feature. Committed captions immediately produce a capped, conservative Live draft without a report-provider request, and refinement corrects the same caption's contribution. Eligible rolling provider state can replace it with a Live AI draft. At Stop, the current preview stays visible as Final report draft; a UI reload can reattach while the active desktop process retains the session. All three previews are read-only, copyable, memory-only, may change, and are cleared at a terminal outcome or desktop restart. Preview content is never written to recovery, another disk file, logs, or telemetry.
The final transcript display state may remain in memory for up to 30 seconds after terminal cleanup so a crossing UI reload can converge. It is scoped to the exact vault-open session and clears on vault switch, expiry, or desktop restart.
Auto keeps one capped six-field report state in memory, serializes updates, and coalesces transcript frontiers instead of creating an unbounded queue. Only OpenAI and Anthropic report routes execute; retained local routes are inert and require a new cloud selection. Eligible cloud preparation can make multiple text requests, each subject to provider billing, logging, and retention. After Stop makes no report-provider request during capture.
Wrengle writes a content-free durable exposure claim under .app/live/
before each cloud preparation request, bound to the exact route and
destination. Prepared report content remains memory-only. If request
completion cannot be proven after an interruption, automatic provider work
stays stopped and the meeting requires an explicit manual retry.
Before a new post-Stop provider is prepared, Wrengle checks whether the report region is edited or has malformed metadata. Check note and retry repeats that provider-free check after review. While either problem remains, Wrengle preserves the note and makes no provider request.
At Stop, the worker receives only a bounded tail drain window in a detached task. Transcript persistence proceeds independently instead of waiting for a slow preparation request; report generation waits for the tail decision. Stop closes ordinary rolling requests. A request that started before Stop may still settle. If complete final coverage is still missing, a prewarmed provider may then receive at most one full six-field tail when the entire remaining span fits one update.
Wrengle accepts prepared state only when it covers the exact final transcript
frontier and all route and save bindings remain current. Before a tail starts,
an invalid remainder uses the saved-transcript fallback. After one
starts, no second automatic request is sent; ambiguous exposure or changed note
context requires manual retry. Preparation is never persisted under
.app/live/.
Strict meeting recovery records under .app/live/ can include paged committed,
refined, and final transcript text, the exact saved note target, provider
exposure state, a report attempt revision, and checkpointed report evidence.
That evidence can contain derived summaries, decisions, action items, follow-up,
discussion, and open questions, but the complete rendered report draft remains
memory-only. Replaceable partial captions remain memory-only, and these vault
records contain no raw meeting audio. Ordinary app-owned meeting-note reads and
writes remain capped at 16 MiB.
A content-free owner lease refreshes every 15 seconds and becomes recoverable after the same filesystem's clock sees it as at least two minutes stale. It is not a distributed lock: configured sync or backup can copy the temporary files, but independently clocked replicas have no cross-device fencing guarantee. On Unix, Recovery can re-attest a released lease when a remount changed only the device identifier of the same lock file; the repair advances the generation and does not rebind the saved note target.
OpenAI and Anthropic models use native structured output with strict response validation. Automatic report readiness follows the durable note and recovery-metadata writes without waiting for the best-effort whole-vault Git snapshot.
Meeting privacy boundaries
Cloud meeting-report consent is implicit: selecting a cloud model is your consent for that route, so there is no separate authorization gate, grant, or revoke step. Settings → Meetings → Reports → Cloud meeting report access discloses the exact resolved provider, effective model, and destination before report input is dispatched. Selecting a cloud model is your consent to send the complete meeting transcript in bounded contiguous shards, bounded user-owned meeting-note text, and meeting title/prompt context directly to OpenAI or Anthropic, or through Wrengle to OpenAI on a selected managed tier. Report requests send text, not meeting audio. Changing the resolved provider, model, or destination cancels an in-flight request bound to the old route. A request whose completion cannot be proven is not automatically replayed and requires manual retry. Dispatch begins only once the selected direct key or managed account route is ready under Settings → Models.
Ordinary document and editor-sidecar operations, plus privacy-sensitive recovery inputs, reject hardlinked files as well as unsafe symlink/reparse paths and parent or target identity swaps. This single-link/no-follow rule is scoped to those app-managed document, sidecar, and recovery paths; it does not describe every file a user may keep in a vault.
Reading feature labels
- Available means the behavior is documented for the current build.
- Beta means the behavior is usable but may change.
- Planned means design direction.
- Not in v1 means deliberately excluded from the first version.