Keep up with latest product news
System Explorer
Journals
Easier to use
Requires InterSystems IRIS or IRIS for Health 2026.2 or later. Upgrading from 1.0.7 keeps your agent definitions, conversations, settings and audit records.
Thank you to the QA team for testing the full IRIS setup and reporting the password-change failure. The previously selected IRIS Community 2026.2 image lacks a utility needed by its --password-file startup path. The optional IRIS stack now pins the tested 2026.1 image and validates the password before startup.
A fresh full-stack run now starts IRIS, connects Battery as _SYSTEM, reads 16 tasks, and confirms that an unreviewed task is blocked. Live changes remain disabled by default. The lightweight synthetic demonstration is unchanged.
For a retest after a failed initialization, use a fresh disposable Compose project rather than deleting an existing data volume.
Source: https://github.com/rbnbric/armada-battery
Passing live check: https://github.com/rbnbric/armada-battery/actions/runs/37143309190

IRIS Relay 0.5.1: the full operations UI, installed with IPM and served by IRIS. No external Node.js or Python server and no extra container are needed.
On IRIS 2026.2 with IPM and access to the public registry:
zpm "repo -r -n registry -url https://pm.community.intersystems.com/"
zpm "install iris-relay"
The first line configures the registry once on a fresh IPM 0.9+. Open /relay/index.html over HTTPS, or http://localhost:52773/relay/index.html on the IRIS machine, and sign in with your IRIS account and the documented permissions.
The full UI covers system overview, web applications, a 28-operation read-only REST explorer, permissions, security, scheduled tasks, current and archived log investigation, lexical similarity search with Embedded Python and IRIS Vector Search, audit summaries, baseline comparison and Markdown/JSON handover export. Changes use review, fresh-state checks, replay rejection and readback; IRIS still enforces authorization.
Version 0.5.1 addresses Robert Cemper's review: the new disposable Compose lab publishes the IRIS web server on 127.0.0.1:52773 and clears pre-expired lab passwords once. This lab bootstrap does not reset users in an IPM installation or the existing public demo. Relay sign-in offers a manual password-change form in the Node and IRIS-served UIs. In USER, a failed /api/relay sign-in returns 404 and the page cannot distinguish an expired password from a wrong one; Change password appears beside the sign-in error, with a Management Portal link. IRIS checks the current password and password rules. The public demo remains unchanged.
The 0.5.1 public-registry installation is now verified: Claude installed it on clean IRIS 2026.2 with IPM 0.10.9 after registry transport setup, then checked HTTP, the full IRIS-served UI in Chromium, guards, manual password change with disposable accounts and uninstall. Codex reviewed the evidence. There are 183 recorded checks, including 112 browser checks and wrapper records; they are not 183 independent behaviors or a production-readiness claim. Codex's earlier isolated VPS checks passed 69 JavaScript and 36 Python tests with zero skips; CI and Pages succeeded on the same source commit.
Source: https://github.com/rafaorlando3/iris-relay/commit/ebe392be0f6f96899c2fa94e65f4b75df3bf2aab
AI disclosure: Claude implemented and tested the changes; Codex reviewed, integrated and published them, and drafted this release-note update.
1.0.6 was not published here on its own, so these notes cover 1.0.6 and 1.0.7.
New
%Development and read access to the namespace's code, so a developer can use it without any administration role. Changing code also needs write access, and OcuPilot's own classes are refused.%All role itself can do it.Safety
%Manager, %Operator or any role that reaches %All or an %Admin_ resource, is now treated as a destructive change and marked as privileged in the Services editor.For judges
Requires InterSystems IRIS or IRIS for Health 2026.2 or later. Upgrading from 1.0.5 keeps your agent definitions, conversations, settings and audit records.
Thank you to the reviewer who built and tested the first release. This revision addresses the friction they found while keeping the traditional portal available.
The original demonstration remains available. A separate before-and-after video update shows the changes and the complete finding-to-receipt path.
The finding and assurance walkthrough use synthetic fixtures. Live IRIS remains read-only by default; this release does not claim qualified live mutations.
Source revision: 5ab2531

?run=…&step=…), so you can share exactly what you were looking at.ALL_MUST_SUCCEED join without building anything first.401 that came in before a token renewal no longer signs you out of the session. Before, this could freeze the live run view during long runs.h1. Long class names in the palette now wrap at the dots instead of overflowing.sentai-demo.mp4 / .webm).IRIS Relay 0.5.0 installs the full Relay UI through IPM and serves it directly from IRIS at /relay/index.html. No Node.js or Python server is needed outside IRIS. Relay Lite remains available at /relay/lite.html.
The IRIS-served UI includes management views, the 28-operation REST explorer, reviewed configuration changes, scheduled tasks, log paging and similarity search, audit summaries, baseline comparison and Markdown/JSON handover export. Changes use review, fresh-state checks and readback. IRIS authorization still governs each operation. HTTPS is required for remote use; HTTP is allowed only on loopback. The README documents operator roles, SQL grants, shared-origin risks and the tested Normal security configuration.
Reviewed source: 89b9d525f30c61c93ed294f1fe8c7d979df6c4bc. Codex independently ran 64 JavaScript and 29 Python tests on the isolated VPS checkout, with zero skips; GitHub CI and Pages succeeded on this commit. Claude's isolated-cloud validation passed 158 end-to-end checks using local IPM load, including 112 browser checks of the IRIS-served UI. Public registry installation will be verified independently after this release.
AI disclosure: Claude implemented and tested the IRIS-served UI; Codex reviewed, integrated and published it.
v1.0.3: added the AI-Powered Instance Monitor feature (Community Opportunity idea DPI-I-512).
Relay Lite is now served directly by IRIS after installing iris-relay 0.4.1 from IPM: open /relay/index.html over HTTPS (HTTP is allowed only on loopback). It lists log sources, pages through messages.log and rotations, and provides lexical similarity search over a bounded IRIS Vector Search index. The Lite UI needs no Node.js or Python server; the full management UI remains available through the existing Compose/Node setup.
The page requires an IRIS user with %Admin_Operate:U; search SQL permissions and index limits are documented in README. Credentials are blocked outside HTTPS or loopback, stale requests cannot overwrite a newer session, and /relay serves static files with CSP/automatic compilation disabled.
Reviewed source: 34ed98984f15fec85d54036104f1c93d9cdd474d. GitHub CI: 46 JavaScript and 29 Python tests passed. Claude tested local IPM load/uninstall and 15 browser groups in an isolated cloud IRIS; public registry installation will be checked independently after this release. The existing public demo is unchanged.
AI disclosure: Claude implemented and tested Relay Lite; Codex reviewed and published the change.

The image: docker pull ghcr.io/mxsalata/aperture:1.3.0
Changed container repository to the public one so that everyone can see it.

New editors
Clearer screens
Safety
Requires InterSystems IRIS or IRIS for Health 2026.2 or later. Upgrading from 1.0.4 keeps your agent definitions, conversations, settings and audit records.
OpsDeck 0.2.0 delivers the native IRIS-hosted operations console with responsive, available-width layouts.
Highlights:

Key Enhancements:
🧩 Closed Capability Catalog
A single allowlist of approved AI operations. The Copilot cannot invent or execute arbitrary operations.
📋 Rich Capability Metadata
Each capability declares examples, constraints, verification, and undo information, while privileges and risk come from the existing operation registry.
⏱️ Task Catalog
Ask natural-language questions about live IRIS tasks, including suspended tasks, errors, schedules, and run-as users — completely read-only.
🔎 Capability Discovery:
A read-only API exposes the currently approved capabilities and their metadata without exposing handlers or implementation details.
🧵 Structured Execution Trace
Planning and execution produce linked copilot. plan and copilot. execute traces connected to the underlying operation trace.
🛡️ Structured Failure States
Rejections and failures use machine-readable codes such as authorization_failed, resource_protected, verification_failed, and issue_still_detected.
🔐 Defense in Depth
AI output is only a proposal. Parameters are rebuilt server-side, authorization is rechecked, explicit confirmation is required, and every mutation is verified.
Disks and system operation

Migration of administrative areas (Processes, Users and Roles, Tasks, Web Applications, and Security) to the official InterSystems SysAdmin v2 API. Includes a new automated test suite validating read operations and actual mutations via the official API.

certificate-expiry-check (schedule it to be warned before a certificate expires), permissions-inventory and oauth-inventory. Read-only; no secret is ever read.Databases and namespaces

1.2.0: opening an entry of the Messages log now says how often its message was logged and since when, found with IRIS Vector Search, and Show similar entries lists them (nothing is indexed until you ask); in the online demo the index is ready from the start. Dependency updates now arrive monthly and each merged batch is a patch release of its own (1.1.1 was the first). The README links the video walkthrough and names every contest bonus.

1.2.0: opening an entry of the Messages log now says how often its message was logged and since when, found with IRIS Vector Search, and Show similar entries lists them (nothing is indexed until you ask); in the online demo the index is ready from the start. Dependency updates now arrive monthly and each merged batch is a patch release of its own (1.1.1 was the first). The README links the video walkthrough and names every contest bonus.
A regular app, easy to find. On macOS the app now has a Dock icon, so it can't get lost behind the notch any more.
Windows installer. ValhallISC-0.9.3-windows-x86_64-setup.exe installs per user without administrator rights. It adds a Start menu entry, an optional desktop icon and an uninstaller in Installed apps. The standalone executables are still available.
Source control. In namespaces under IRIS source control (for example git-source-control or CCR), checked-out classes and routines are marked:
Documents you can't edit are read-only. Check-out, check-in and commit stay in your usual tools; importing a file still goes through the server's source control hooks.
Profiles window, reviewed.
Harbor 1.1.0 adds IPM installation of the production frontend, bundled gateway dependencies and native extension. Node.js 22.12+ remains required; no npm or compiler is needed on the target host. Follow docs/HARBOR_IPM.md for installation, service setup and lifecycle operations.
The launcher requires explicit origin, cookie, instance and external data settings. It rejects relative or package-contained data locations, including symlinks. The extension installer refuses a route owned by another dispatch class or namespace. It creates no native accounts, credentials, grants or sample tasks. Package resources have application-specific names.
Validation: production build and 341 source tests plus two packaging tests. Isolated IRIS 2026.2/IPM 0.10.8 source and archive installations, native login and extension reads, retained records after uninstall/reinstall, conflicting-route refusal, desktop and 390px browser checks passed. External records remained byte-identical. Existing production data and earlier releases are unchanged.
IPM publication is requested through the existing Open Exchange application. Registry availability and bonus awards are separate from local package validation.