Run your agents like a company, and approve from your phone with no terminal open.
Nothing breaks. After upgrading, run foreman agent hook install claude-code once (it rewrites Claude Code's hook so it can't fail open) and foreman service install again if you use the service.
Several roles on one agent
- foreman agent add backend --type codex (or --type claude-code) adds another instance of Codex or Claude Code for another role, and it now works as its own agent.
- When Foreman hands an instance work, it runs Codex or Claude Code as that instance: with its own Foreman MCP server for that run and its identity token in an owner-only file, never on the command line. It is told its org.yaml role.
- What an instance posts and hands on is attributed to it, as trusted, so instances can talk to each other through Foreman.
- Your own Claude Code and Codex config is left alone by agent add, agent rewire and doctor. Before, work given to an instance never ran, and adding one took the agent's identity away.
Role library and per-role permissions
- Set up your team in the setup wizard: a new optional last step, Your team, lets you tick ready-made roles or add your own (title, instructions, what it may do), each on its own Claude Code or Codex, written to org.yaml.
- foreman org roles lists ready-made roles: manager, developer, code-reviewer, researcher, writer, analyst, support and assistant.
- foreman org add-role <id> --preset <role> adds one with its title, instructions and permissions. Without --agent, a new Claude Code or Codex instance named after the role fills it (--runs-on picks which).
- Your own role: --describe "what it does, in your words"; the agent is told this when Foreman hands it work.
- --can read,write,shell,network (or can: in org.yaml) limits what a role's agent may do with its own tools. It is checked before policy.yaml: a reviewer that may only read is refused a file write whatever the policy says. A broken org.yaml that sets can fails closed.
Approvals with no terminal open
- The background service (foreman service install) now runs the whole gateway, not just the daemon: approvals go to your Telegram, Slack or Discord and your taps come back; /foreman from chat, schedules, the daily digest and budget alerts run there too.
- foreman start attaches to the running service and shows the TUI only (the header says attached). Quitting it leaves the service running. Exactly one gateway runs per Foreman home.
- foreman service status and foreman doctor (a new gateway row) say which process runs the gateway and where approvals go.
Chat
- One Telegram bot is enough: when no chat agent (Hermes, OpenClaw) reads your bot, Foreman reads it itself, and the same bot carries notifications, approval buttons and /foreman. listener: foreman | agent in notify.yaml overrides the choice.
- Plain messages to the bot are questions for Foreman (report me, what is claude-code doing?), from your own chat only. Plain text only reads; stop, write and integration commands need /foreman.
- /foreman report and report me give today's company report when Foreman's LLM is off, over budget or failing, instead of an error.
Security
- Claude Code's hook no longer fails open when Foreman isn't on its PATH. It now names Node and the hook by absolute path, and any exit other than allow or block becomes a block ("Foreman's hook could not run"). Run foreman agent hook install claude-code once after upgrading; foreman doctor warns about a hook that relies on PATH.
- foreman agent add no longer prints the agent's private key. --key-out <file> still writes it (0600).
Also new
- foreman agent hook install claude-code --project [dir] adds the hook to one project's .claude/settings.json only.
- A new mascot: a small pixel-art beaver foreman with a hard hat, 20 columns wide in every terminal. chafa is no longer used.
Fixes
- Setup: an API key is never swapped for a browser sign-in; API key or subscription is an explicit choice, with API key highlighted.
- Setup: a chat app is turned on only when its token and chat id or channel are set; the wizard asks where Slack and Discord bots post; a Slack or Discord set up there now receives approvals, alerts and the digest.
- Setup: a value that fails its format check isn't saved on the first Enter, and running setup again keeps your two-way chat settings.
- A task given to Hermes, OpenClaw or ZeroClaw keeps its streamed reply, and the agent runs as itself (org chart and budget checks apply).
- The install script warns when new terminals won't find foreman (an older nvm default), and install.sh --uninstall removes the service and each agent's wiring, not just the package.
- Homebrew 7 needs brew trust --formula tuzlu07x/foreman/foreman-agent before brew install.