WrengleWrengle
Known limitations

Known limitations

Beta

This page separates shipped behavior from product direction.

Workflow limits

  • Workflows use one local desktop builder. There is no hosted workflow execution, webhook ingress, provider subscription service, cloud scheduler, or second Connected authoring mode. Wrengle and the matching vault must be open for scheduled work.
  • The Action picker lists enabled custom actions and trusted local plugin actions by name, plus Gmail → Create draft under Apps. Disabling or removing a selected target leaves the saved step visibly unavailable instead of choosing a replacement.
  • Check Gmail and Connect Gmail are readiness controls inside the opened Action picker. Startup can preload an already-configured Gmail token pair into native process memory, but opening the picker performs no additional Keychain read or provider request. Readiness alone authorizes nothing; the Gmail action separately requires an exact preview and manual approval.
  • Gmail uses native desktop OAuth and the OS keychain. The readiness control represents one primary Gmail connection; multiple-account selection is not available.
  • A Gmail draft configures recipient and subject and takes the exact body from upstream workflow output. It is currently reached through Dry run: upstream AI or Fetch output is simulated, while approving the displayed Gmail request is real. Wrengle shows all three before approval, persists the encrypted effect and full recovery snapshot before contacting Google, and creates a draft only—it never sends mail. The upstream body is limited to 100,000 characters; MIME or provider limits can make the effective maximum smaller, and an oversized full recovery snapshot is refused before provider contact. Approval expires after 24 hours and can be reopened after restart with the same vault open. Recovery discovery is bounded to the newest 20 items and revokes older waiting grants rather than hiding them. The encrypted workflow/configuration, objective, artifact bodies and paths, review/audit state, and exact request can remain for seven days; only the new bridge's content-safe plaintext metadata, opaque keyed request bindings, and receipts can remain for 90 days. Recipient and subject remain in normal local workflow settings until edited or deleted. Legacy preview-authored definitions and revisions can retain plaintext names, descriptions, and action configuration until explicit app-data cleanup or uninstall and are not governed by the seven-day payload rule.
  • Action, Terminal, and Coding agent steps remain human-gated and make a workflow ineligible for unattended Run or automation. Gmail drafts therefore cannot run on a schedule. Configured and plugin actions still require the matching approval-gated access policy.
  • The in-app scheduler supports daily or selected-weekday starts only. It is not an operating-system daemon, retains one bounded latest-execution summary rather than general durable run history, and has no general automatic retry or crash resume. Gmail's durable waiting approval, intent, and safe receipt metadata are a narrow exception rather than full workflow history.
  • Jira workflow OAuth, MCP actions, broad workflow-definition migration, and full durable run history remain deferred.

Assistant and external-agent limits

  • Built-in Wrengle Local, OpenAI, and Anthropic conversations restore a bounded suffix of settled user-and-assistant text. Pending permissions, live tool calls, thoughts, and other unsettled protocol state are not resumed. New Thread starts without earlier context.
  • External ACP continuation depends on capabilities advertised by that agent. Wrengle tries sessionCapabilities.resume, then top-level loadSession. If neither is available or continuation fails, the saved transcript remains visible but the agent starts a fresh session behind an explicit transcript-only notice.
  • A confirmed conversation deletion is authoritative for Wrengle's local save. If current-vault authorization or local deletion fails, Wrengle reports that failure and keeps or restores the conversation. While a matching external session is live, Wrengle also requests session/close; a failed acknowledgement is shown in the app, but Wrengle cannot guarantee deletion from the external agent or its provider. Inactive remote sessions remain subject to that agent's retention controls.
  • Only external agents with HTTP MCP support receive Wrengle's named list_notes, read_note, read_note_blocks, search_notes, write_note, edit_blocks, and replace_selection tools. Agents without it remain file-only through ACP filesystem callbacks.
  • MCP reads and search are vault-scoped and need no approval. MCP creates, edits, and selection replacements always require Wrengle's preview and approval flow, canonical editor serialization, stale-base conflict checking, and current-vault validation.
  • Wrengle-mediated permissions are not a subprocess sandbox. An external agent retains the ambient OS file, command, process, and network permissions of its launched command and can use them without a Wrengle approval card.
  • ACP note approvals still commit one editor-canonical note payload at a time. Multi-note or batch edits and existing-note frontmatter rewrites remain unavailable until they can be represented as separate safe writes.

Startup access limits

  • The startup gate asks for macOS microphone and screen/system-audio capture access and preloads configured app-owned secure items before the workspace opens. A Keychain with several configured items can therefore show several item-specific dialogs. Allow covers one access; Always Allow is the persistent choice for the current app identity.
  • Wrengle holds successfully read secrets only in a zeroizing native Rust session cache. The renderer receives capability state, not secrets. External Keychain changes made after startup are intentionally observed on the next launch or explicit reconnect rather than through a surprise runtime read.
  • A denied/locked secure-item read, denied/restricted supported capture grant, or some platform errors produce granular Limited mode. Local vault and note features remain available. Cleanly missing, unconfigured, disconnected, and revoked credentials instead stay unavailable in their own feature surfaces without making the whole startup Limited.
  • Explicitly saving, replacing, or removing an AI or transcription key while Wrengle is focused can show its item-specific macOS Keychain dialog. Denying or canceling it fails closed and revokes the affected session capability. Background token rotation, automatic cleanup, and ordinary feature use remain prompt-free. A restart retries only items whose non-secret metadata still authorizes startup access; broker failed-mutation tombstones are never used to rediscover an old value.
  • If settings.json or a routing-critical saved provider/backend value is malformed or unreadable, assistant and voice starts pause behind a retryable settings error. Wrengle does not overwrite the file or guess Local, Off, or a cloud destination; repair or restore the saved settings before retrying.
  • The unpackaged Windows desktop build cannot reliably request or report per-app microphone or system-audio consent. Startup therefore reports native capture permission as Not required; it does not probe a device, detect the global desktop-app microphone switch, or enter Limited mode merely because that switch is off. A later device-open attempt fails prompt-free if the global switch or selected device prevents capture. Settings → Privacy & Data → Desktop access always links to Windows microphone privacy settings for recovery.
AreaStatusLimitation
Public downloadsBetawrengle.com/download checks the latest GitHub release and offers only expected exact-named desktop assets that are uploaded there. This confirms release metadata and presence, not a signature or checksum; beta installers are unsigned. A missing platform asset is shown as unavailable instead of linking to a stale alias. Linux is not a v1 shipping target.
Accounts and billingBetaIndividual sign-up, sign-in, account management, deletion, and optional desktop sign-in are available across the website, including these documentation pages. Accounts do not sync vaults. Checkout, licenses, organizations, gated downloads, and active pricing remain unavailable.
Search across this documentationPlannedThese pages have no search of their own in v1. Use your browser's in-page find, or the sidebar and the documentation index.
PluginsBetaLocal developer plugin folders can contribute trusted WASM actions, sandboxed plugin views, and manifest-declared UI entries for palette, slash, context-menu, keybinding, status-bar, settings-page, and docked-panel surfaces; local plugin code remains trusted local code. Capability declarations are not grants; grants are local to this app install, and write capabilities create app-mediated write proposals. UI policy can disable or re-enable contributions after reload/snapshot refresh. View JavaScript direct network is not controlled by httpHosts. Marketplace distribution, remote installation, process plugins, and compatibility guarantees are not in v1.
Integrations and custom actionsBetaJira, Linear, Webhook, Google Calendar, Gmail, HubSpot, and template-based custom actions are configured locally. Provider-backed actions can send selected context or configured payload data to the external service you choose. Custom actions are template-based and join the local action registry only when enabled.
TerminalBetaThe embedded terminal runs a local shell with normal OS permissions and is not sandboxed by Wrengle. Per-vault launch profiles, environment overrides, restore metadata, recent commands, and selected-output captures are local app state with bounded retention. Workflow terminal drafts run only after explicit user submission.
Local modelsBetaWrengle-managed local agent models are Qwen3-family GGUF downloads from Hugging Face. Downloads require network access, enough disk space, checksum verification, and enough system memory for the selected tier. Machines below the smallest RAM threshold cannot use the local agent path.
Editor media and semantic blocksBetaMedia blocks copy local files into vault-relative assets/ folders and reject remote, absolute, traversal, or malformed asset paths. Semantic workflow blocks round-trip through Markdown plus sidecar metadata; unsupported sidecar or block payloads can be rejected by persistence guards.
Local editor recoveryBetaWrengle keeps local-only CRDT recovery state under .app/crdt.db for recent editor state. This is not server sync, presence, or cross-device collaboration. If recovery metadata becomes inconsistent with note paths, Wrengle can block opening, moving, deleting, saving, or switching vaults with a repair-needed message rather than silently discarding local CRDT state. If recovered note content is malformed, or a historical recovery bug stored a Wrengle-managed region as degraded raw source, Wrengle shows the saved Markdown read-only and offers an explicit, note-scoped Reset local recovery action. Resetting discards only that note's unsaved recovery and leaves its Markdown file unchanged.
Chart documentsBetaWrengle supports local chart files for desktop diagrams, with shape and connector editing, canvas quick-add, and inline object actions. Chart files are local vault documents; split panes attached to the same local chart mirror edits live, including in-progress object moves. Hosted collaboration, remote presence, grouping, layers, comments, and templates are not included in this release. Existing chart files are not migrated or automatically restyled by the redesigned editor. Browser editing and analytical spreadsheet charts are not part of this release.
Meeting captureBetaRecording support depends on platform permissions and hardware. Mic + System is the default when supported; system audio support remains platform-dependent. Only one meeting capture lifecycle is supported at a time; its slot remains owned through final transcription, note save, and any detached automatic report. A timed-out managed-local cold load is the bounded exception: non-abort-safe setup can continue quiescing after the report settles and logical ownership is released, so a newly admitted capture may briefly overlap that cleanup.
Meeting transcriptsBetaCalendar context, elapsed timestamps, copy controls, and chunked local finalization are supported. Speaker attribution is channel-based (You vs Participants), not individual diarization, and cloud-finalized transcripts have no speaker labels. ElevenLabs is dictation-only in this release. Strict temporary recovery records live inside the vault under .app/live/; configured filesystem sync or backup can copy them to its service or another device while they exist. They contain committed, refined, and final transcript records, exact save/report bindings, a durable automatic-report request, content-free exposure/owner claims, and a contiguous report attempt revision, not replaceable partial captions, raw audio, or memory-only prepared report state. A content-free lease refreshes every 15 seconds through capture, finalization, save, and detached automatic report work. Its monotonic generation and OS file lock fence cooperating Wrengle processes only when they open the same underlying lock-capable filesystem object in one clock domain. Orderly completion makes a prompt non-blocking release attempt after a bounded helper drain; if that cannot finish, recovery becomes eligible when that filesystem's clock observes the last heartbeat as at least two minutes old. Ordinary synced replicas are separate, potentially stale objects, not a distributed lock. Independently clocked or future-skewed replicas are outside the fencing guarantee, so the same temporary item must not be recovered concurrently on synced devices. Power-loss recovery is bounded by completed records, so the active incomplete write can still be lost. Descriptor-bound meeting-note reads and app-owned meeting-note writes fail closed above 16 MiB. Recovery reads and directory scans have hard safety caps: a malformed or oversized session is isolated as unsupported/discard-only, a session with an unreadable or oversized owner lease stays hidden while valid siblings still scan, and a root-wide session overflow fails closed until excess app-managed entries are removed.
Meeting reportsBetaWrengle creates one six-field final report after the transcript: summary, decisions, action items, follow-up, discussion, and open questions. Automatic mode schedules it after transcript save; Manual waits for Generate report. Auto preparation may build a capped, memory-only report during capture. At Stop, its bounded tail drain runs detached from transcript persistence; report generation waits for the tail decision and accepts prepared state only when the final frontier, schema, revision, note target, provider route, and destination all still match. During-capture report preparation additionally requires a saved note target, local final transcription with sufficient background decode capacity, and a capture-safe report route. Before any Stop-tail request is admitted, a mismatch, gap, timeout, cap violation, restart, recovery path, or provider/parse failure uses the canonical saved-transcript fallback, so reduced Stop-to-report latency is not guaranteed. Once a Stop-tail request is admitted, an ambiguous outcome is never automatically replayed and instead requires manual review and retry. That fallback is complete through 32,000 transcript characters; longer inputs use five bounded windows across the beginning, interior, and end. User-owned note context is complete through 8,000 characters and uses the same five-window strategy above that cap. The context is labeled Condensed whenever either cap applies. Local routes stay on-device and current local report backends wait until Stop. Provider preparation is cancellation-aware and capped at 8.5 seconds for explicit Ollama or 20 seconds for other routes; Ollama model discovery is one direct, no-proxy request capped at three seconds and 1 MiB. For a cloud report, Settings → Meetings → Reports → Cloud meeting report access first discloses the exact resolved provider, effective model, and destination. Selecting a cloud model is your consent to send report input—bounded transcript excerpts or text, bounded user-owned meeting-note text, and meeting title/prompt context—to that provider before it is dispatched; model selection is under Settings → Models, the report path never sends meeting audio, and switching to a local model keeps report generation on device. Changing a bound route input or destination cancels an in-flight request bound to the old route. Each during-recording cloud request is durably claimed before dispatch and marked complete after it settles. If completion remains ambiguous, the request is not automatically replayed and provider work stops at Manual retry required. Transcript save does not depend on report availability. An automatic-report request is retained across an initial save failure and resumes only after a successful user retry/recovery and current policy revalidation. An edited or malformed report region is preserved and shown as review required. Before a new post-Stop provider is prepared, Wrengle checks that region locally. Check note and retry repeats this provider-free check; while the issue remains, it makes no provider request.
Dictation and voice controlBetaQuick Dictation treats trigger words as text; exact stop and “scratch that”/“undo that” phrases remain bounded controls. Voice Control requires exact trigger words for editor, workspace, configured-agent, and terminal commands, so there is no automatic bare-speech command classification. Toggle capture uses Cmd/Ctrl+Shift+V and Hold to Dictate uses Cmd/Ctrl+Shift+D until release. Explicit button and shortcut stops preserve the current partial even when live preview is off; whole-utterance spoken stop phrases end the session without committing an unfinalized partial. Blocked text has Insert here, Return to original, Copy, and Discard recovery paths. A microphone picker, local five-second input test, active level meter, and device errors are available. Verbatim and Light edit cleanup plus Fast, Balanced, and Deliberate response speeds are available. Quick Dictation with Verbatim cleanup bypasses analysis; other paths require the selected local or cloud analysis dependency. Recognition language, bounded vocabulary hints, and optional exact spoken punctuation are configurable, but the UI and built-in control phrases remain English. Local speech and analysis stay on-device. OpenAI, Deepgram, or ElevenLabs cloud dictation streams microphone audio and can send supported vocabulary hints to the selected provider; cloud analysis sends transcribed utterance text, the active note title, up to 40 folder paths, up to 15 recent note paths, and the previous sentence for cleanup, but not note bodies. Keys, consent, billing, and provider policies apply independently. Cloud reconnect buffering is bounded. Deletes are confirmation-gated; shell commands and non-local agent sends require button/keyboard confirmation and are not covered by voice Undo. Voice and meeting capture cannot run at the same time. macOS-first, following meeting-capture platform support.
External agentsBetaExternal agents share the assistant transcript and review workflow, but continuation and MCP tools remain capability-qualified. Unsupported or failed continuation opens the saved transcript in transcript-only mode with a fresh agent session. MCP-mediated writes are approval-gated; the subprocess's ambient OS permissions are not sandboxed by Wrengle.
Workflow automationsBetaA workflow is the auto-saved local graph; an automation adds one daily or specific-days trigger and a pinned live workflow version, and can be Active or Paused. Draft changes aren't live until the user explicitly updates that version; editing recurrence does not publish the draft, and layout-only moves do not create execution drift. Only Goal, Fetch, AI step, Write note, and Final review steps can run unattended; Action, Terminal, and Coding agent steps remain human-gated. Pinned external-agent backends are not supported for live workflow execution. The scheduler is in-app and vault-bound: Wrengle and the matching vault must be open. A manual Run is bound to the vault open when it starts, so vault switching cannot redirect its note write. Within one app process, only one user-started foreground workflow execution per current vault is admitted across manual Run and automation Run now; a reopened Workflows view reconnects to either kind and continues compact status checks. Run now immediately shows an in-progress execution and retains terminal detail in the current workflow UI; scheduled state moves from queued to running and then terminal. Activation, resume, and trigger edits establish a cadence baseline and wait for the next matching occurrence, so there is no catch-up from before activation or while paused. If an already-active automation misses an occurrence because the app or matching vault is unavailable, the most recent missed occurrence may catch up once. Admitted automations use isolated background tasks, so one slow run does not block other triggers or the scheduler's next scan. A finite automation admission queue feeds bounded heavy-work capacity: excess due occurrences remain eligible for a later scan and admitted work can stay queued for up to 10 minutes. Manual Run, automation Run now, and scheduled executions each have a fixed 30-minute limit. Stop requests cancellation at safe boundaries, but already-started provider, fetch, or note work may finish; Hide only closes the local detail view. For unattended executions, terminal state can appear before cleanup finishes, so editing and duplicate/overlap guards remain locked until that work drains. Compact terminal status releases those locks as soon as cleanup is complete; best-effort full terminal detail loading does not extend them. Within one running Wrengle app process, a duplicate overlapping run for the same automation is rejected; there is no cross-process overlap guarantee. The scheduler scans at startup and about every 60 seconds, so a run can be claimed almost a minute after its configured time and then wait in the queue. There are no cron, webhook, file/note, meeting/calendar, or multiple triggers. Runs have no durable execution history; only one bounded, content-free latest-execution summary persists. There is no general automatic retry; a terminal status-save failure is retried locally without rerunning workflow steps. An app interruption before terminal state can leave the current occurrence eligible for bounded catch-up; it restarts rather than resumes and may repeat earlier side effects. Pausing or deleting prevents future unclaimed runs but cannot cancel claimed work; queued or running execution can continue. Different automations can still write the same managed output region, where the last completed write wins. Current releases persist sanitized, content-free outcome categories, including timeout and interruption; at the next app launch, unknown error text in recognized records from an older release is sanitized before display and rewritten in the local settings file while unknown raw records are preserved.
Mobile appsNot in v1Mobile clients are not part of v1.
Browser-first workspaceNot in v1Wrengle is desktop-first. The web surface provides public marketing, downloads and docs plus account identity and profile management, not a hosted browser workspace.
Analytics on this siteBetaOptional website analytics and redacted diagnostics stay off until explicit opt-in. The PostHog EU event payload contains only allowlisted manual fields and a random pseudonymous identifier that the browser stores only in memory; the identifier is sent with events and retained under the stated analytics retention. PostHog also receives request-delivery metadata, and the production project must discard IP data. Sentry EU receives minimized errors. Footer privacy choices can withdraw consent. No note content, transcript text, or vault data is collected.

Dictation speech, voice analysis, and the built-in assistant default to Auto. Connected keys that Wrengle can read from the operating-system keychain make cloud providers eligible, while explicit Local choices and Cloud voice features Off remain sticky. Auto speech checks the most recently connected provider, then OpenAI, Deepgram, and ElevenLabs before Local; Auto voice analysis and assistant routes check the most recently connected or successfully verified AI provider, then OpenAI and Anthropic before Wrengle Local. These defaults do not change meeting behavior: live captions and default meeting transcription remain local-first, and cloud meeting final-pass transcription remains separately opt-in. This availability check does not contact the provider; invalid, revoked, or quota-limited keys can still fail when a request starts.

Local recovery format compatibility

Opening a vault with a release that uses CRDT identity schema v2 automatically migrates well-formed older v1 note identities up to the 16 MiB identity-metadata safety limit while preserving their vault and document IDs. Oversized or malformed identity state fails closed. The migration is a downgrade boundary: older Wrengle builds that only understand v1 will fail closed for that vault afterward. Do not delete or copy individual CRDT identity files to work around this check. Back up and restore the full vault, including the complete .app/ tree, so the v2 identity index, migration and advancement journals, and CRDT database stay together. A short-lived advancement journal lets startup finish an interrupted published v2 identity update, or safely discard one that was only prepared.

The local CRDT database has a 256 MiB safety limit. If an unverified interrupted-replace backup remains, Wrengle leaves it untouched and fails closed instead of guessing between it and any canonical image. Automatic snapshot compaction is not available in this build, so local recovery history can grow to that limit. Where a recovery banner offers Reset local recovery, the reset removes that document's local recovery payload, not its saved Markdown or chart projection.

Resetting a note advances that vault's local CRDT identity index to schema v3 so older builds cannot silently drop the reset lineage. A build that only understands v2 can report local recovery as unavailable for that vault; the saved Markdown remains intact. Return to the resetting build or a newer build instead of deleting app-managed identity files.

Some older builds could lose one identity-index mapping during concurrent document opens while leaving that document's local CRDT payload intact. A Markdown file has no durable document ID, so Wrengle leaves both copies untouched and offers Recover local state; only that explicit choice can attach the historical payload. A chart can reconnect automatically only when its saved projection carries the same document ID as the exact database-owned payload. Either path also requires an existing same-vault identity index with no path, kind, tombstone, or pending-operation conflict. Candidate lookup, secure file revalidation, and the identity update run under the app-owned store locks. Wrengle never creates a replacement ID for an existing payload. A missing whole index or any ambiguity still fails closed.

During-recording report preparation

Prepare final transcript while recording is on by default for eligible local transcription. It keeps a bounded, final-quality transcript cache on device and is independent of report generation mode and report preparation. Turning report preparation off, choosing Manual, or losing report-route eligibility does not disable this local Stop-time optimization.

After Stop is the clean-install preparation default. Report preparation: Auto is an opt-in advisory performance optimization for Automatic reports, not a live-note or recovery feature. Committed captions immediately produce a bounded, conservative Live draft without a report-provider request, and refinement corrects the same caption's contribution. Eligible rolling provider state can supersede it as a Live AI draft. At Stop, the current preview stays visible as Final report draft; a UI reload can reattach while the active desktop process retains the session. All three previews are read-only, copyable, process-memory-only, may change, and are cleared at a terminal outcome or desktop restart. Preview content is never written to recovery, another disk file, logs, or telemetry.

The canonical final transcript display state may remain in process memory for up to 30 seconds after terminal cleanup so a crossing UI reload can converge. It is scoped to the exact open-vault epoch and clears on vault switch, expiry, or desktop restart.

Auto keeps one capped six-field report state in memory, serializes updates, and coalesces transcript frontiers instead of creating an unbounded queue. Current local report backends wait until after Stop when they cannot prove request-specific cancellation has quiesced before transcription resumes. Eligible cloud preparation can make multiple text requests, each subject to provider billing, logging, and retention. After Stop makes no report-provider request during capture.

Each cloud preparation request gets a content-free durable exposure claim under .app/live/ before dispatch, bound to the exact route and destination. Prepared report content remains memory-only. If request completion cannot be proven after an interruption, automatic provider work stays stopped and the meeting requires an explicit manual retry.

At Stop, the worker receives only a bounded drain window in a detached tail task. Transcript persistence proceeds independently instead of waiting for a slow preparation request; report generation waits for the tail decision. Stop closes ordinary rolling dispatch. A request admitted before Stop may settle. If complete final coverage is still missing, a prewarmed provider may then receive at most one full six-field canonical tail when the entire bounded remainder fits one update.

Wrengle accepts prepared state only when it covers the exact final transcript frontier and all route and save bindings remain current. Before a tail starts, an invalid remainder uses the bounded saved-transcript fallback. After one starts, no second automatic request is sent; ambiguous exposure or changed note context requires manual retry. Preparation is never persisted under .app/live/.

Compatible OpenAI and Anthropic models, plus Wrengle Local, use native structured output; legacy, custom, and other routes retain strict JSON validation. Automatic report readiness follows the durable note and recovery-metadata writes without waiting for the best-effort whole-vault Git snapshot.

Meeting privacy boundaries

Cloud meeting-report consent is implicit: selecting a cloud model is your consent for that route, so there is no separate authorization gate, grant, or revoke step. Settings → Meetings → Reports → Cloud meeting report access still discloses the exact resolved provider, effective model, and destination before use, and report input is dispatched only once a key is configured for that provider under Settings → Models.

Ordinary document and editor-sidecar operations, plus privacy-sensitive recovery inputs, reject hardlinked files as well as unsafe symlink/reparse paths and parent or target identity swaps. This single-link/no-follow rule is scoped to those app-managed document, sidecar, and recovery paths; it does not describe every file a user may keep in a vault.

Reading feature labels

  • Available means the behavior is documented for the current build.
  • Beta means the behavior is usable but may change.
  • Planned means design direction.
  • Not in v1 means deliberately excluded from the first version.
docs / known-limitationsAll documentation