DocsInstallCLI ReferenceChangelogCommunityGitHub ↗
Changelog

What's new in Foreman.

Every release, with the details that matter. Upgrade any time with npm install -g foreman-agent@latest or brew upgrade foreman-agent.

v2.3.0latest
npm foreman-agent@2.3.0

Run your agents like a company, and approve from your phone with no terminal open.

Nothing breaks. After upgrading, run foreman agent hook install claude-code once (it rewrites Claude Code's hook so it can't fail open) and foreman service install again if you use the service.

GitHub release · CHANGELOG · npm

Several roles on one agent

  • foreman agent add backend --type codex (or --type claude-code) adds another instance of Codex or Claude Code for another role, and it now works as its own agent.
  • When Foreman hands an instance work, it runs Codex or Claude Code as that instance: with its own Foreman MCP server for that run and its identity token in an owner-only file, never on the command line. It is told its org.yaml role.
  • What an instance posts and hands on is attributed to it, as trusted, so instances can talk to each other through Foreman.
  • Your own Claude Code and Codex config is left alone by agent add, agent rewire and doctor. Before, work given to an instance never ran, and adding one took the agent's identity away.

Role library and per-role permissions

  • Set up your team in the setup wizard: a new optional last step, Your team, lets you tick ready-made roles or add your own (title, instructions, what it may do), each on its own Claude Code or Codex, written to org.yaml.
  • foreman org roles lists ready-made roles: manager, developer, code-reviewer, researcher, writer, analyst, support and assistant.
  • foreman org add-role <id> --preset <role> adds one with its title, instructions and permissions. Without --agent, a new Claude Code or Codex instance named after the role fills it (--runs-on picks which).
  • Your own role: --describe "what it does, in your words"; the agent is told this when Foreman hands it work.
  • --can read,write,shell,network (or can: in org.yaml) limits what a role's agent may do with its own tools. It is checked before policy.yaml: a reviewer that may only read is refused a file write whatever the policy says. A broken org.yaml that sets can fails closed.

Approvals with no terminal open

  • The background service (foreman service install) now runs the whole gateway, not just the daemon: approvals go to your Telegram, Slack or Discord and your taps come back; /foreman from chat, schedules, the daily digest and budget alerts run there too.
  • foreman start attaches to the running service and shows the TUI only (the header says attached). Quitting it leaves the service running. Exactly one gateway runs per Foreman home.
  • foreman service status and foreman doctor (a new gateway row) say which process runs the gateway and where approvals go.

Chat

  • One Telegram bot is enough: when no chat agent (Hermes, OpenClaw) reads your bot, Foreman reads it itself, and the same bot carries notifications, approval buttons and /foreman. listener: foreman | agent in notify.yaml overrides the choice.
  • Plain messages to the bot are questions for Foreman (report me, what is claude-code doing?), from your own chat only. Plain text only reads; stop, write and integration commands need /foreman.
  • /foreman report and report me give today's company report when Foreman's LLM is off, over budget or failing, instead of an error.

Security

  • Claude Code's hook no longer fails open when Foreman isn't on its PATH. It now names Node and the hook by absolute path, and any exit other than allow or block becomes a block ("Foreman's hook could not run"). Run foreman agent hook install claude-code once after upgrading; foreman doctor warns about a hook that relies on PATH.
  • foreman agent add no longer prints the agent's private key. --key-out <file> still writes it (0600).

Also new

  • foreman agent hook install claude-code --project [dir] adds the hook to one project's .claude/settings.json only.
  • A new mascot: a small pixel-art beaver foreman with a hard hat, 20 columns wide in every terminal. chafa is no longer used.

Fixes

  • Setup: an API key is never swapped for a browser sign-in; API key or subscription is an explicit choice, with API key highlighted.
  • Setup: a chat app is turned on only when its token and chat id or channel are set; the wizard asks where Slack and Discord bots post; a Slack or Discord set up there now receives approvals, alerts and the digest.
  • Setup: a value that fails its format check isn't saved on the first Enter, and running setup again keeps your two-way chat settings.
  • A task given to Hermes, OpenClaw or ZeroClaw keeps its streamed reply, and the agent runs as itself (org chart and budget checks apply).
  • The install script warns when new terminals won't find foreman (an older nvm default), and install.sh --uninstall removes the service and each agent's wiring, not just the package.
  • Homebrew 7 needs brew trust --formula tuzlu07x/foreman/foreman-agent before brew install.
v2.2.0
npm foreman-agent@2.2.0

The daemon at login, Foreman's model on Ollama, Claude Code's hook from setup.

Nothing breaks. foreman service install is optional, and setup now asks before adding Claude Code's hook.

GitHub release · CHANGELOG · npm

The daemon at login

  • foreman service install | uninstall | status runs the local daemon in the background at every login, so agents and the Claude Code hook no longer need foreman start or foreman daemon open in a terminal to use it.
  • macOS: a LaunchAgent in your gui/<uid> domain, restarted on a crash, logging to <state dir>/daemon.log. Linux and WSL2: a systemd user unit. Without systemd (common on WSL) install says so and changes nothing. Native Windows isn't supported.
  • It runs the absolute paths of the Node binary and Foreman CLI you installed it with. Run install again after upgrading Node or Foreman; status warns when a path is gone.
  • foreman start works alongside it: agents stay on the running daemon, and their approvals still appear in the TUI.
  • foreman doctor's daemon row warns when the service is installed but the daemon isn't running. The daemon's socket and token are unchanged.

Foreman's model on Ollama or an OpenAI-compatible endpoint

  • Verification and daily summaries can run on Ollama or any OpenAI-compatible endpoint, not only Anthropic, OpenAI or Gemini. No new dependency.
  • In foreman setup, Ollama asks for its base URL (default http://localhost:11434) and lists the pulled models; Custom offers presets (DeepSeek, OpenRouter, Groq, …) or your own endpoint.
  • Ollama calls cost $0 against the budget; an OpenAI-compatible endpoint is billed at the most expensive known price, so the budget is never under-counted.
  • Base URLs must be http(s), redirects are refused so the key only goes to the configured endpoint, and foreman doctor checks the URL.

Claude Code's hook from the first setup

  • The setup wizard's agents step asks "Also check Claude Code's own tools before they run? (recommended)", yes by default, and adds the PreToolUse hook to ~/.claude/settings.json, keeping your other settings and hooks.
  • Say no and the Done screen still shows foreman agent hook install claude-code.

Security

  • The Gemini API key no longer appears in the setup wizard's error text: model listing sends it in a header, and model discovery errors never include a URL's query string.
  • Refused Slack and Discord interactions (a tap or /foreman from someone not in allowed_user_ids) are audited as notify:interaction-refused, rate-limited per user and overall.

Fixes

  • The audit log names who decided an approval in Slack or Discord: user:slack:<member id> / user:discord:<user id> instead of just user:slack.
  • foreman notify slack-interactive --off and discord-interactive --off also remove owner_user_ids, so turning two-way mode back on no longer brings back an old owner list.
v2.1.1
npm foreman-agent@2.1.1

Shell risk rules score what a command does.

A security fix. In 2.1.0 some reworded destructive shell commands ran with risk 0 while plain rm -rf asked. Upgrade if you run 2.1.0.

GitHub release · CHANGELOG · npm

Security

These now reach at least the medium bucket, so they ask for approval under the default policy:

  • rm -r -f, rm --recursive --force and rm -r, not only rm -rf.
  • find -delete, find -exec rm and xargs rm.
  • Interpreter one-liners that delete files: python -c "shutil.rmtree(…)", node -e "fs.rmSync(…)" and others.
  • git push --force, reset --hard, clean -f and filter-branch; a destructive git command no longer gets the benign-git discount.
  • echo … | base64 -d | sh.
  • Every rule also checks each command a line runs: through &&, ; and |, through sudo / env / nice / timeout / xargs, inside bash -c, eval and find -exec. Benign lines score as before.
v2.1.0
npm foreman-agent@2.1.0

Integrations, a local daemon and a model picker.

No breaking changes. While foreman start runs, agents and the Claude Code hook use its daemon (FOREMAN_NO_DAEMON=1 keeps the old in-process path).

GitHub release · CHANGELOG · npm

Integrations

  • foreman integrations: GitHub, GitLab, Jira & Confluence, Trello, Linear and Notion as managed MCP hub servers.
  • add takes the token from a hidden prompt (or --token-stdin) or runs the browser sign-in, saves the integration disabled, reviews and pins its tools, then enables it for the agents you choose.
  • Read-only by default: write tools are denied until --read-write; merges and pushes need a person on every call.
  • An Integrations page in the TUI (i), an optional step in the setup wizard, and /foreman integration commands from Slack, Discord and the Telegram approval bot. Credentials never go through chat.

One daemon for every agent

  • While foreman start runs, agents' foreman mcp-stdio and the PreToolUse hook connect to its daemon; foreman daemon runs it without the TUI.
  • Each MCP hub stdio server starts once for all agents; each agent still sees only what its access list and org.yaml allow.
  • The hook answers in about 30 ms instead of about 200 ms (p50 on an Apple-silicon Mac).
  • Owner-only Unix socket with a per-boot token, never TCP. Fails closed: if the daemon stops during a call, the hook blocks it.

MCP hub access lists and confirm rules

  • access: { agents, departments } limits a server to those agents and department members.
  • tools.confirm: a person answers every call; no allow rule, always-allow or low score approves it.
  • Running agents follow mcp.yaml and org.yaml changes live; a call approved after its server was disabled never runs.
  • Integration credentials can't be read by any agent through secrets/get, whatever policy.yaml says.

Also new

  • Model picker in the TUI (m on Settings and Agents).
  • foreman doctor has a daemon row and reports integrations that can't work.

Fixes

  • Approvals whose caller is gone are cancelled (denied) within about 30 seconds instead of waiting up to 10 minutes.
  • A busy database no longer kills foreman mcp-stdio or foreman start; the audit batch is kept and retried.
  • foreman agent remove takes Foreman's MCP entry and hook out of the agent's config.
  • ? opens help on every TUI page; setup wizard wording fixed after terminal QA; current default models; LLM budget pricing for unknown models errs on the expensive side.
v2.0.0
npm foreman-agent@2.0.0

Identity tokens, MCP Hub, Foreman Org and approvals from chat.

The first release since 0.1.6. Several interfaces and defaults changed; read the breaking changes before upgrading.

CHANGELOG · npm

Breaking changes

  • Node 22.12+ is required (Node 20 is end-of-life).
  • Agent identity tokens: agents wired before 2.0 run as untrusted:<id> until you run foreman agent rewire --all and restart them.
  • Webhook signatures cover <timestamp>.<body>; Slack / Discord webhook URLs and ntfy servers must be https://.
  • foreman agent remove keeps the agent's program unless --uninstall; foreman report prints a table (--json for scripts).
  • Relayed /foreman commands that change Foreman wait for your approval; a broken policy.yaml stops foreman start with the file, line and reason.

MCP Hub

  • Connect upstream MCP servers once and every agent gets them, each call mediated. A curated catalog of 19 servers.
  • Secrets referenced as ${secret:…} stay out of agent configs; OAuth for hosted MCP servers.
  • Tool-poisoning scanner, tool pinning with rug-pull detection, a result guard that redacts secrets and flags injected instructions, and lazy tool discovery to save tokens.

Approvals and the TUI

  • Approval queue, command console (:) and inbox in the TUI.
  • Telegram approval bot that only Foreman holds; two-way Slack (Socket Mode) and Discord (Gateway) with HMAC-tagged buttons.
  • Email (SMTP) and ntfy phone push for alerts.

Foreman Org

  • Departments, roles and reporting lines (startup, software-team, solo templates); delegation enforced along the chart and MCP access scoped per department.
  • Department channels, spend reports, budgets and approval escalation to a manager agent (advice only).

Security

  • The Claude Code hook fails closed, applies policy.yaml and writes audit rows; it also gates Grep and Glob.
  • Tamper-protection risk rule for agents touching Foreman's database, keys, policy or their own wiring.
  • LLM verdicts can only make Foreman stricter; secrets redacted from notifications and the audit log; config and state files owner-only.

Also new

  • foreman demo: a sandboxed company of agents in the real TUI.
  • Standalone binaries (Node.js single executable, about 130 MB) for macOS and Linux, with SHA256SUMS.
  • npm releases published with provenance; end-to-end QA suite in CI.
This page summarises each release. The full notes are in CHANGELOG.md; tagged releases and standalone binaries are on GitHub Releases. Versions 0.1.6 and earlier are listed on npm.