Files
PaperClipAI/ui/src/pages/InstanceExperimentalSettings.tsx
DottaandPaperclip dd777f4b73 feat(dot): complete onboarding and expand governed Runner capabilities (#15414)
## Thinking Path

> - Paperclip manages AI agents, their work, and their permissions.
> - Paperclip Runner supplies the same admitted tool authority to each
provider.
> - The Dot provider in #15402 needs reliable onboarding and useful
agent capabilities.
> - An idle Dot could not start work, assign a human, read skills, or
produce a workspace artifact.
> - Pairing also relied on a second configuration save before ordinary
admission could work.
> - This pull request adds governed idle admission and shared Runner
tools, and completes pairing atomically.
> - Operators can test Dot with fresh data while keeping normal company,
approval, budget, and run ownership checks.

## Linked Issues or Issue Description

**Subsystem affected**

Paperclip Runner, dedicated Dot MCP access, OAuth onboarding,
experimental settings, and empty worktree startup. This PR builds on
merged provider PR #15402. It reuses the merged MCP gateway from #14846
and assistant connection work from #14933 and #15380.

**Problem or motivation**

An idle Dot could see assignments but could not act on a conversation
request until someone created a task first. Its Runner catalog could not
assign tasks to humans or read pinned skills and workspace files.
First-time OAuth discovery and pairing also needed browser fixes, and a
completed pairing did not persist its binding reference on the agent.

**Proposed solution**

Keep Dot within the existing Runner. Admit a visible agent-authored
intake task for idle requests. Add people, human assignment, cross-task,
skill, and optional sandbox workspace tools through shared authority.
Relay assigned app calls through the configured MCP gateway. Add lease
renewal and follow-up references. Save pairing and its configuration
revision atomically. Show prerequisites and provide a complete copy
prompt.

**Roadmap alignment**

This extends the experimental provider in #15402. It uses the existing
governed gateway, task model, skills, artifact path, and native Runner.
It adds no separate execution subsystem.

## What Changed

- Add a standalone OpenAI Dot agent choice with an independent
experimental opt-in. It works with the general Runner option off.
Require Assistant connections (MCP), authenticated sign-in, and public
HTTPS for pairing.
- Use Dot’s own option for company package import. Allow an unpaired Dot
configuration to save after external billing acknowledgement; task
admission still requires pairing. Prepare the shared dev binary for
Dot-only opt-in.
- Label saved Dot agents as OpenAI Dot. Use prerequisite-check copy in
setup and runtime configuration.
- Route Dot creation directly to pairing after explicit external billing
acknowledgement. Hide local CLI, model, and harness setup for Dot.
Preserve the shared Runner implementation and canonical API type. Other
Runner providers still require their general opt-in.
- Add an empty worktree option with fresh signing keys and no production
data copy.
- Fix public-client OAuth negotiation, discovery compatibility, and
optional separate browser authorization origin.
- Add one-use pairing consent preview, clear copied setup instructions,
and atomic binding persistence and cleanup.
- Add idle request admission with stable request IDs and normal
scheduling, permissions, budgets, and task ownership.
- Add identity and people discovery, human task assignment and
reassignment, and authorized cross-task comments and documents.
- Read assigned skill files from pinned manifests. Relay assigned app
calls through the merged gateway without exposing credentials.
- Add an off-by-default workspace bridge. Constrain paths and writes.
Run commands in a deny-by-default OS sandbox with no network or injected
credentials. Reserve mutations before effects and never blindly repeat
uncertain work.
- Add rolling lease renewal, task pagination, bounded operation limits,
and deduplicated follow-up references without comment bodies in
webhooks.
- Add an off-by-default attachment reading setting. Restrict reads to
files on the current assigned task. Verify size and hash, cache bounded
verified copies per run, paginate text or binary bytes, and recheck live
authority before returning.
- Keep file grants operator-owned. Reject agent self-grants across
configuration routes. Preserve attachment consent in create/import
forms. Close generic API file bypasses while retaining current-run
response snapshots and permitted uploads.
- Keep provider limits explicit. Do not inherit a Dot binding,
attachment permission, or workspace permission when hiring another
agent.
- Include the required Markdown format in cross-task document writes and
validate the API title limit. Verify real creation and revision
persistence.
- Restrict command execution to Linux bubblewrap with descendant
containment. macOS retains workspace file tools and artifact publishing,
while refusing command calls. Explain the platform limit in setup.
- Exclude Paperclip instance state from workspace files, uploads,
artifact publication, and sandbox commands. Protect nested directories
and case variants. Fail closed when the directory protection scan
exceeds 4,096 directories.
- Add static UI compression for slow public tunnels. Document setup, the
complete tool inventory, and qualification limits.

## Verification

- Merge preparation on `00ca2c75b` integrates merged base #15402 and
master `fc6304dfe`. The ancestry commit preserves the reviewed follow-up
source tree. The subsequent security fix excludes instance state from
file tools, uploads, artifact publication, and sandbox commands. It
preserves private task authorization and task monitors. It regenerates
the combined tool catalog, seeded catalog digest, and protocol manifest.
Workspace typecheck, full build, and UI token gates pass. All sixteen
real Dot broker cases and 93 company import cases pass after the review
fixes and creator-attribution test correction. The exported
human-assignment catalog and Unicode page boundaries are also fixed. All
ten catalog tests and nine workspace/skill bridge tests pass. All 35
workspace bridge and authority tests passed after the instance-state
fix, including real macOS commands in that intermediate version. The
subsequent document and descendant-containment fixes pass 44 focused
tests across bridge, authority, and setup UI, with six Linux command
cases skipped on macOS. Real cross-task documents pass the route
validator and persist two revisions. macOS refuses command execution and
does not advertise the tool. Full workspace typecheck and build, changed
server/UI typechecks, and token gates pass again on the final commit.
Greptile rates final head 00ca2c75b 5/5 and its completed check
concludes success; all review threads are resolved. All 58 current-head
checks are complete: 54 passed and 4 intentionally skipped. This
includes full tests, typecheck, build, Runner, browser E2E, release
verification, and Canary Dry Run. The older full local root attempt
finished with 16,602 passes, 93 skips, and ten failures across two
suites: it began before source edits and retained earlier imported
implementations while loading later tests. Both suites pass a clean
final-head rerun (25 passed, six Linux-only command cases skipped on
macOS). This mixed-source full attempt is not a final-head full-suite
pass; use the fresh CI evidence below.
- Full workspace typecheck and build pass for the standalone Dot change
on head `392d54f80`. UI token gates are clean. The full workspace
typecheck passed before the final importer UI edit; the changed UI
typecheck, build, and token gates pass again on the final commit. The
server build passes for its unchanged final source.
- Standalone selection, creation, settings, harness visibility,
inventory, and runtime admission checks pass. OAuth onboarding and the
real Rust/PostgreSQL broker suite pass 27 cases with the general Runner
option disabled. Dot and MCP revocation still block pairing; other
Runner providers remain disabled. Create, hire, conversion, and
inherited-hire route regressions pass 68 cases. The runtime selection
suite passes 20 cases. The setup UI suite passes 50 cases. Company
import and dev binary checks pass 97 cases. Import UI checks pass 29
cases, including Dot-only selection, preservation of imported Dot
agents, generic Runner fallback, canonical configuration serialization,
and required billing acknowledgement. A read of the synthetic instance
reports the native binary required with Dot enabled, the general rollout
disabled, and no persisted native work.
- The latest attachment, operator-consent, generic API file-guard, and
bridge checks pass 80 tests. Cache and native lifecycle checks pass 550
tests; create/import builders pass 45 tests; attachment setup UI checks
pass 16 tests. The real Rust/PostgreSQL Dot broker suite passes 15
cases.
- Earlier authority, human assignment, pinned skill, confinement,
cancellation, inheritance, onboarding, replay, OpenAPI, and gateway
regressions pass their focused rechecks. Workspace writes reject
concurrent stale hashes.
- In the live empty test-drive, turn the general Runner option off and
leave Dot and MCP on. Add agent shows a separate OpenAI Dot choice.
Create rejects missing billing acknowledgement, saves the canonical Dot
configuration, and opens pairing. The existing paired Dot remains ready
and passes its prerequisite checks. No new plugin pairing was needed for
this UI change. The final browser import preview keeps a Dot source
agent as OpenAI Dot, falls back a generic Runner agent while its switch
is off, and offers Dot independently.
- Real Dot completed OAuth, signed MCP Events readiness, and an
event-only assigned document task in an empty synthetic instance.
Pairing saved its binding without a second configuration save.
- Real Dot verified human assignment, cross-task comments and documents,
pinned skill reading, sandbox commands, lease renewal, follow-up input,
and a downloaded artifact whose bytes and hash matched its receipt. An
idle conversation request created an intake, created a task for its
human owner, continued after a definite missing-file read error, and
finalized Done with exit code 0.
- After operator approval, real Dot read a synthetic assigned-task
attachment and wrote its file-only random proof into an agent-authored
document. Its first test required accepting review because the existing
document tool removed the final newline.
- On head `2626c8f9b`, real Dot read a 13,849-byte synthetic attachment
in two pages, used `expectedSha256` on page two, saved exactly its final
random marker, verified readback, and finalized Done with exit code 0. A
direct inbox check was required for this attachment qualification; it
does not claim event-only delivery.
- Previous head `392d54f80` passes all 55 checks (53 passed, two
intentionally skipped), including the full test, typecheck, build,
native Runner, browser, and release verification gates. Greptile rates
this head 5/5; all review threads are resolved.
- Head `2626c8f9b` passed all 56 checks: 54 passed and two intentionally
skipped. This includes full typecheck, build, native Runner, server
tests, serialized suites, browser E2E, and Canary Dry Run. The unchanged
Cursor managed-runtime test exceeded its five-second deadline on the
first attempt; its focused local suite passed all eight cases, and the
single CI rerun plus dependent verify gate passed.
- A prior full local serial test attempt reported 19 failures (16,141
passed, 88 skipped) and stopped before later wrapper groups. It began
before the final source edits. Every failed suite has a passing fresh
recheck; the macOS snapshot stress case passes alone in 227 seconds. The
previous head `000fb9261` passed all 56 CI checks. PRs leave
`pnpm-lock.yaml` unchanged; CI and the refresh bot own dependency
resolution.

## Risks

- Dot remains off by default. Its own opt-in does not enable other
Runner providers. It still requires the MCP option; disabling Dot blocks
new work while keeping existing recovery and saved bindings.
- Dot requires a stable public HTTPS origin. Its base provider in #15402
is merged. Temporary tunnels are useful for testing but are not
permanent deployments.
- Idle intake creates a visible agent-authored task. It does not
fabricate a human message or bypass ordinary admission.
- Workspace commands require Linux bubblewrap with a private PID
namespace; deployment qualification is still needed. macOS file tools
and artifact publishing remain available, but commands are disabled
because sandbox-exec does not contain detached descendants. There is no
unrestricted fallback. Command protection fails closed above 4,096
workspace directories. The historical macOS command walkthrough does not
qualify the current Linux implementation.
- Provider model choice, token usage, cost, native thread control, and
global external stopping remain unavailable. Known Paperclip budget
gates still apply.
- The workspace bridge and attachment reader are separate opt-in
settings. Reading assigned task files sends their contents to OpenAI.
Revocation prevents future reads but cannot withdraw bytes already sent.
Files are read on request; automatic inbound attachment staging remains
disabled.
- An existing event registration can retain earlier instructions that
prohibit extra tasks. Dot asked for permission before a second intake
after the final event-only bootstrap; that extra no-nudge continuation
is not live-qualified under that earlier registration. The later
attachment qualification submitted normally through the composer. The
revised onboarding prompt describes the new idle entry point, and its
protocol polling path is tested.
- OpenAI event delivery can be delayed; a webhook acknowledgement is not
proof that Dot has begun work.
- A running Dot can retain an old plugin catalog after tool refresh.
Refresh and actual tool exposure must be checked before using new
top-level actions.
- Hosted and remote controller modes are not qualified.

## Model Used

OpenAI Codex, based on GPT-6. The exact deployment ID and context window
size are not exposed in this session. Capabilities used: reasoning,
repository editing, code execution, test inspection, and browser
control.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either linked existing issues or described the issue in-PR
following the relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused suites and all
fresh failure rechecks pass; the earlier full attempt is disclosed
above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-07 19:44:17 -05:00

760 lines
38 KiB
TypeScript

import { useEffect, useState, type ReactNode } from "react";
import { useMutation, useQuery, useQueryClient } from "@tanstack/react-query";
import { AlertTriangle, FlaskConical, Lock, Play } from "lucide-react";
import type {
InstanceExperimentalSettings,
InstanceExperimentalSettingsWithManaged,
InstanceFeatureKey,
ManagedSettingMetadata,
PatchInstanceExperimentalSettings,
} from "@paperclipai/shared";
import { experimentalSettingKey } from "@paperclipai/shared";
import { instanceSettingsApi } from "@/api/instanceSettings";
import { useHiddenSettings } from "@/hooks/useHiddenSettings";
import { getWorktreeInstanceId, isWorktreeRuntime } from "../lib/worktree-branding";
import { useBreadcrumbs } from "../context/BreadcrumbContext";
import { queryKeys } from "../lib/queryKeys";
import { ToggleSwitch } from "@/components/ui/toggle-switch";
import { Badge } from "@/components/ui/badge";
import { Button } from "@/components/ui/button";
import { Card } from "@/components/ui/card";
import { Link } from "@/lib/router";
type WorktreeRunExecutionDisplayState =
| { kind: "off" }
| { kind: "armed"; activatedAt: string }
| { kind: "fail_closed"; reason: "missing_cutoff" | "missing_instance_id" | "instance_mismatch" };
/**
* Mirror of the server's `resolveWorktreeRunExecutionActivation` fail-closed
* ladder (server/src/services/instance-settings.ts) so the card never claims a
* copied/legacy row is arming execution. The derived fields are display-only —
* the PATCH the toggle sends still writes just the boolean.
*/
function resolveWorktreeRunExecutionDisplayState(
settings:
| Pick<
InstanceExperimentalSettings,
| "enableWorktreeRunExecution"
| "worktreeRunExecutionActivatedAt"
| "worktreeRunExecutionActivationInstanceId"
>
| undefined,
currentInstanceId: string | null,
): WorktreeRunExecutionDisplayState {
if (settings?.enableWorktreeRunExecution !== true) return { kind: "off" };
if (!settings.worktreeRunExecutionActivatedAt) return { kind: "fail_closed", reason: "missing_cutoff" };
if (!currentInstanceId) return { kind: "fail_closed", reason: "missing_instance_id" };
if (settings.worktreeRunExecutionActivationInstanceId !== currentInstanceId) {
return { kind: "fail_closed", reason: "instance_mismatch" };
}
return { kind: "armed", activatedAt: settings.worktreeRunExecutionActivatedAt };
}
function formatActivationTimestamp(iso: string): string {
const parsed = new Date(iso);
if (Number.isNaN(parsed.getTime())) return iso;
return parsed.toLocaleString(undefined, { dateStyle: "medium", timeStyle: "short" });
}
// PAP-11233: keep Conference Room code intact, but hide the user-facing opt-in for now.
const SHOW_CONFERENCE_ROOM_EXPERIMENTAL_SETTING = false;
function ManagedByCloudBadge() {
return (
<Badge variant="outline" className="text-muted-foreground">
<Lock aria-hidden="true" />
Managed by Paperclip Cloud
</Badge>
);
}
function ExperimentalToggleCard({
title,
description,
footnote,
checked,
onCheckedChange,
disabled,
settingKey,
managed,
ariaLabel,
}: {
title: string;
description: string;
footnote?: ReactNode;
checked: boolean;
onCheckedChange: (checked: boolean) => void;
disabled: boolean;
/** Flag key backing this card; operator-hidden keys render nothing. */
settingKey: InstanceFeatureKey;
managed?: ManagedSettingMetadata;
ariaLabel: string;
}) {
const { hidden: hiddenSettings } = useHiddenSettings();
const isManaged = managed?.managed === true;
if (hiddenSettings.has(experimentalSettingKey(settingKey))) return null;
return (
<Card className="block bg-transparent p-5">
<div className="flex items-start justify-between gap-4">
<div className="space-y-1.5">
<div className="flex flex-wrap items-center gap-2">
<h3 className="text-sm font-semibold">{title}</h3>
{isManaged ? <ManagedByCloudBadge /> : null}
</div>
<p className="max-w-2xl text-sm text-muted-foreground">{description}</p>
{footnote ? <p className="max-w-2xl text-xs text-muted-foreground">{footnote}</p> : null}
</div>
<ToggleSwitch
checked={checked}
onCheckedChange={(next) => {
if (isManaged) return;
onCheckedChange(next);
}}
disabled={disabled || isManaged}
aria-label={ariaLabel}
/>
</div>
</Card>
);
}
export function InstanceExperimentalSettings() {
const { setBreadcrumbs } = useBreadcrumbs();
const queryClient = useQueryClient();
const { hidden: hiddenSettings } = useHiddenSettings();
const [actionError, setActionError] = useState<string | null>(null);
useEffect(() => {
setBreadcrumbs([
{ label: "Settings", href: "/company/settings" },
{ label: "Experimental" },
]);
}, [setBreadcrumbs]);
const experimentalQuery = useQuery({
queryKey: queryKeys.instance.experimentalSettings,
queryFn: () => instanceSettingsApi.getExperimental(),
});
const toggleMutation = useMutation<
InstanceExperimentalSettingsWithManaged,
Error,
PatchInstanceExperimentalSettings,
{ previousSettings?: InstanceExperimentalSettingsWithManaged }
>({
mutationFn: async (patch: PatchInstanceExperimentalSettings) =>
instanceSettingsApi.updateExperimental(patch),
onMutate: async (patch) => {
await queryClient.cancelQueries({ queryKey: queryKeys.instance.experimentalSettings });
const previousSettings = queryClient.getQueryData<InstanceExperimentalSettingsWithManaged>(
queryKeys.instance.experimentalSettings,
);
if (previousSettings) {
queryClient.setQueryData<InstanceExperimentalSettingsWithManaged>(
queryKeys.instance.experimentalSettings,
{ ...previousSettings, ...patch },
);
}
return { previousSettings };
},
onSuccess: async (updatedSettings) => {
setActionError(null);
queryClient.setQueryData(queryKeys.instance.experimentalSettings, updatedSettings);
await Promise.all([
queryClient.invalidateQueries({ queryKey: queryKeys.instance.experimentalSettings }),
queryClient.invalidateQueries({ queryKey: queryKeys.adapters.all }),
queryClient.invalidateQueries({ queryKey: ["built-in-agents"] }),
queryClient.invalidateQueries({ queryKey: queryKeys.health }),
queryClient.invalidateQueries({ queryKey: ["apps"] }),
]);
},
onError: (error, _patch, context) => {
if (context?.previousSettings) {
queryClient.setQueryData(queryKeys.instance.experimentalSettings, context.previousSettings);
}
setActionError(error instanceof Error ? error.message : "Failed to update experimental settings.");
},
});
if (experimentalQuery.isLoading) {
return <div className="text-sm text-muted-foreground">Loading experimental settings...</div>;
}
if (experimentalQuery.error) {
return (
<div className="text-sm text-destructive">
{experimentalQuery.error instanceof Error
? experimentalQuery.error.message
: "Failed to load experimental settings."}
</div>
);
}
const inWorktree = isWorktreeRuntime();
// Present only on cloud-managed instances: keys the managed overlay controls
// render locked with the "Managed by Paperclip Cloud" badge. Self-hosted
// responses carry no `managedKeys`, so every card stays editable.
const managedKeys = experimentalQuery.data?.managedKeys ?? {};
const enableWorktreeRunExecution = experimentalQuery.data?.enableWorktreeRunExecution === true;
const worktreeRunExecutionManaged = managedKeys.enableWorktreeRunExecution?.managed === true;
const worktreeRunExecutionState = resolveWorktreeRunExecutionDisplayState(
experimentalQuery.data,
getWorktreeInstanceId(),
);
const enableEnvironments = experimentalQuery.data?.enableEnvironments === true;
const enableNativeRunner = experimentalQuery.data?.enableNativeRunner === true;
const enableChatConnectors = experimentalQuery.data?.enableChatConnectors === true;
const enableManagedSandboxOnly = experimentalQuery.data?.enableManagedSandboxOnly === true;
const enableIsolatedWorkspaces = experimentalQuery.data?.enableIsolatedWorkspaces === true;
const enableIsolatedWorkspacesByDefault =
experimentalQuery.data?.enableIsolatedWorkspacesByDefault === true;
// Streamlined left navigation is now the standard sidebar (PAP-12472); the
// experimental opt-out was retired, so it no longer surfaces a toggle here.
const enableStreamlinedUi = experimentalQuery.data?.enableStreamlinedUi !== false;
const enableConferenceRoomChat = experimentalQuery.data?.enableConferenceRoomChat === true;
const enableClassicTaskInterface = experimentalQuery.data?.enableClassicTaskInterface === true;
const enableIssuePlanDecompositions =
experimentalQuery.data?.enableIssuePlanDecompositions === true;
const enableExperimentalFileViewer =
experimentalQuery.data?.enableExperimentalFileViewer === true;
const enableExternalObjects = experimentalQuery.data?.enableExternalObjects === true;
const enableBuiltInAgents = experimentalQuery.data?.enableBuiltInAgents === true;
const enableBetaSkills = experimentalQuery.data?.enableBetaSkills === true;
const enableSummaries = experimentalQuery.data?.enableSummaries === true;
const enableStatusCards = experimentalQuery.data?.enableStatusCards === true;
const summariesManaged = managedKeys.enableSummaries?.managed === true;
const statusCardsManaged = managedKeys.enableStatusCards?.managed === true;
const statusCardsBlockedByManagedSummaries = summariesManaged && !enableSummaries;
const summariesRequiredByManagedStatusCards = statusCardsManaged && enableStatusCards;
const enableDecisions = experimentalQuery.data?.enableDecisions === true;
const enableGoalsSidebarLink = experimentalQuery.data?.enableGoalsSidebarLink === true;
const enableCases = experimentalQuery.data?.enableCases === true;
const enableServerInfoDebugView = experimentalQuery.data?.enableServerInfoDebugView === true;
const enablePaperclipDeveloperMode =
experimentalQuery.data?.enablePaperclipDeveloperMode === true;
const enableSimplifiedEnglishInteractions =
experimentalQuery.data?.enableSimplifiedEnglishInteractions === true;
const enableFirstTaskPlanProposal =
experimentalQuery.data?.enableFirstTaskPlanProposal === true;
const enableSmokeLab = experimentalQuery.data?.enableSmokeLab === true;
const autoRestartDevServerWhenIdle = experimentalQuery.data?.autoRestartDevServerWhenIdle === true;
const isVisible = (key: InstanceFeatureKey) => !hiddenSettings.has(experimentalSettingKey(key));
const showWorktreeRunExecution = inWorktree && isVisible("enableWorktreeRunExecution");
const showDeveloperSection = showWorktreeRunExecution || ([
"autoRestartDevServerWhenIdle",
"enableManagedSandboxOnly",
"enablePaperclipDeveloperMode",
"enableServerInfoDebugView",
"enableSmokeLab",
"enableIssuePlanDecompositions",
] satisfies InstanceFeatureKey[]).some(isVisible);
const showLegacySection = isVisible("enableClassicTaskInterface") || isVisible("enableGoalsSidebarLink");
return (
<div className="max-w-6xl space-y-6">
<div className="space-y-2">
<div className="flex items-center gap-2">
<FlaskConical className="h-5 w-5 text-muted-foreground" />
<h1 className="text-lg font-semibold">Experimental</h1>
</div>
<p className="text-sm text-muted-foreground">
Opt into features that are still being evaluated before they become default behavior.
</p>
</div>
<div
role="alert"
className="rounded-lg border border-amber-500/30 bg-amber-500/5 px-4 py-3"
>
<div className="flex items-start gap-3">
<AlertTriangle className="mt-0.5 h-4 w-4 shrink-0 text-amber-700" />
<div className="space-y-1 text-sm">
<p className="font-medium text-foreground">Experimental features may break at any time.</p>
<p className="text-muted-foreground">
These features are opt-in and come with no compatibility guarantees. They may change, break, or be
removed without notice. Avoid relying on them for critical or production workflows.
</p>
</div>
</div>
</div>
{actionError && (
<div className="rounded-md border border-destructive/40 bg-destructive/5 px-3 py-2 text-sm text-destructive">
{actionError}
</div>
)}
<section className="space-y-3" aria-labelledby="experimental-features-heading">
<div className="space-y-1">
<h2 id="experimental-features-heading" className="text-sm font-semibold">
Experimental features
</h2>
<p className="text-sm text-muted-foreground">
Optional product features that are still being evaluated.
</p>
</div>
<ExperimentalToggleCard
title="Agent Chat"
description="Talk to each agent in one ongoing conversation. Clarify goals and create tasks for execution. Chat leads the Work group and opens an agent rail beside the nav, and each chat's side panel shows the agent's tasks and artifacts as cards."
footnote="Turning this off preserves conversations and lets active runs finish, but prevents new messages."
checked={experimentalQuery.data?.enableAgentChat ?? false}
onCheckedChange={(checked) => toggleMutation.mutate({ enableAgentChat: checked })}
disabled={toggleMutation.isPending}
settingKey="enableAgentChat"
managed={managedKeys.enableAgentChat}
ariaLabel="Toggle agent chat experimental setting"
/>
<ExperimentalToggleCard
title="Assistant connections (MCP)"
description="Connect Codex, Claude, and other assistants to your Paperclip organization. People sign in, select an organization once, and approve access to review work, delegate tasks, and add feedback."
footnote={<>Requires an authenticated instance with a configured public URL. Takes effect immediately. Turning this off blocks assistant calls and event delivery; work already delegated continues.{experimentalQuery.data?.enablePublicMcp && <> <Link className="underline" to="/apps/assistant-connection">Set up an assistant connection</Link></>}</>}
checked={experimentalQuery.data?.enablePublicMcp === true}
onCheckedChange={(checked) => toggleMutation.mutate({ enablePublicMcp: checked })}
disabled={toggleMutation.isPending}
settingKey="enablePublicMcp"
managed={managedKeys.enablePublicMcp}
ariaLabel="Toggle assistant connections experimental setting"
/>
<ExperimentalToggleCard
title="Beta skills"
description="Allow agents to pin beta releases of the Paperclip core skill. Disabling this returns every agent to the default live skill without removing saved pins."
checked={enableBetaSkills}
onCheckedChange={(checked) => toggleMutation.mutate({ enableBetaSkills: checked })}
disabled={toggleMutation.isPending}
settingKey="enableBetaSkills"
managed={managedKeys.enableBetaSkills}
ariaLabel="Toggle beta skills experimental setting"
/>
<ExperimentalToggleCard
title="Built-in Agents"
description="Show Paperclip-managed built-in agent surfaces, including built-in roster badges, the Built-in agents tab, and built-in agent setup controls."
checked={enableBuiltInAgents}
onCheckedChange={(checked) => toggleMutation.mutate({ enableBuiltInAgents: checked })}
disabled={toggleMutation.isPending}
settingKey="enableBuiltInAgents"
managed={managedKeys.enableBuiltInAgents}
ariaLabel="Toggle built-in agents experimental setting"
/>
<ExperimentalToggleCard
title="Cases"
description="Durable work products (blog posts, tweet storms…) that tasks create and iterate on. Adds the Cases tab and the agent case API."
footnote="Turning Cases off hides the tab and blocks the case API; existing case data is kept."
checked={enableCases}
onCheckedChange={(checked) => toggleMutation.mutate({ enableCases: checked })}
disabled={toggleMutation.isPending}
settingKey="enableCases"
managed={managedKeys.enableCases}
ariaLabel="Toggle cases experimental setting"
/>
<ExperimentalToggleCard
title="Chat connectors"
description="Connect agents to Slack, GitHub, Discord, Microsoft Teams, and Telegram conversations."
footnote="Turning this off hides experimental chat setup and connected-task controls. Existing chat connections keep running. AgentMail, GitHub tools, and other tool connectors stay available."
checked={enableChatConnectors}
onCheckedChange={(checked) => toggleMutation.mutate({ enableChatConnectors: checked })}
disabled={toggleMutation.isPending}
settingKey="enableChatConnectors"
managed={managedKeys.enableChatConnectors}
ariaLabel="Toggle chat connectors experimental setting"
/>
<ExperimentalToggleCard
title="Combined Inbox + Task List"
description="Fold Inbox into Tasks. One Tasks row carries the unread badge, and a Views menu reaches every inbox view (Mine, Unread, Blocked, Recent, Everything) and every task view."
footnote="Old Inbox links redirect to the matching view. Turning this off restores the separate Inbox; no data changes."
checked={experimentalQuery.data?.enableCombinedInboxTasks ?? false}
onCheckedChange={(checked) => toggleMutation.mutate({ enableCombinedInboxTasks: checked })}
disabled={toggleMutation.isPending}
settingKey="enableCombinedInboxTasks"
managed={managedKeys.enableCombinedInboxTasks}
ariaLabel="Toggle combined inbox and task list experimental setting"
/>
{SHOW_CONFERENCE_ROOM_EXPERIMENTAL_SETTING ? (
<ExperimentalToggleCard
title="Conference Room Chat"
description="Adds a Conference Room — one chat where you and your whole team work together — plus the live activity feed and the redesigned onboarding. Also restyles task threads as chat bubbles. Turn off anytime to restore the classic UI."
checked={enableConferenceRoomChat}
onCheckedChange={(checked) => toggleMutation.mutate({ enableConferenceRoomChat: checked })}
disabled={toggleMutation.isPending}
settingKey="enableConferenceRoomChat"
managed={managedKeys.enableConferenceRoomChat}
ariaLabel="Toggle conference room chat experimental setting"
/>
) : null}
<ExperimentalToggleCard
title="Decisions"
description="Show the Decisions item in the main sidebar — the attention home that surfaces the tasks awaiting your input — while the surface is still being evaluated."
checked={enableDecisions}
onCheckedChange={(checked) => toggleMutation.mutate({ enableDecisions: checked })}
disabled={toggleMutation.isPending}
settingKey="enableDecisions"
managed={managedKeys.enableDecisions}
ariaLabel="Toggle decisions experimental setting"
/>
<ExperimentalToggleCard
title="Enable Environments"
description="Show environment management in company settings and allow project and agent environment assignment controls."
checked={enableEnvironments}
onCheckedChange={(checked) => toggleMutation.mutate({ enableEnvironments: checked })}
disabled={toggleMutation.isPending}
settingKey="enableEnvironments"
managed={managedKeys.enableEnvironments}
ariaLabel="Toggle environments experimental setting"
/>
<ExperimentalToggleCard
title="Enable External Objects"
description="Detect external URLs in issues and show resolved status for pull requests, tickets, and other referenced work objects."
checked={enableExternalObjects}
onCheckedChange={(checked) => toggleMutation.mutate({ enableExternalObjects: checked })}
disabled={toggleMutation.isPending}
settingKey="enableExternalObjects"
managed={managedKeys.enableExternalObjects}
ariaLabel="Toggle external objects experimental setting"
/>
<ExperimentalToggleCard
title="Enable Isolated Workspaces"
description="Show execution workspace controls in project configuration and allow isolated workspace behavior for new and existing task runs."
checked={enableIsolatedWorkspaces}
onCheckedChange={(checked) => toggleMutation.mutate({ enableIsolatedWorkspaces: checked })}
disabled={toggleMutation.isPending}
settingKey="enableIsolatedWorkspaces"
managed={managedKeys.enableIsolatedWorkspaces}
ariaLabel="Toggle isolated workspaces experimental setting"
/>
<ExperimentalToggleCard
title="Experimental File Viewer"
description="Show task detail controls for browsing and previewing workspace files relative to a task."
checked={enableExperimentalFileViewer}
onCheckedChange={(checked) => toggleMutation.mutate({ enableExperimentalFileViewer: checked })}
disabled={toggleMutation.isPending}
settingKey="enableExperimentalFileViewer"
managed={managedKeys.enableExperimentalFileViewer}
ariaLabel="Toggle experimental file viewer setting"
/>
<ExperimentalToggleCard
title="First task: propose with a plan document"
description="When the user's first request is a single task, the chief of staff writes a short plan document and a checkbox card instead of a one-card confirmation. Applies to organizations created after the toggle is flipped."
checked={enableFirstTaskPlanProposal}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableFirstTaskPlanProposal: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableFirstTaskPlanProposal"
managed={managedKeys.enableFirstTaskPlanProposal}
ariaLabel="Toggle first task plan proposal experimental setting"
/>
<ExperimentalToggleCard
title="Memory connectors"
description="Connect Mem0, Zep, Supermemory, Cognee, and Honcho for long-term memory and context."
footnote="Turning this off hides setup for these connectors. Existing connections keep running."
checked={experimentalQuery.data?.enableMemoryConnectors === true}
onCheckedChange={(checked) => toggleMutation.mutate({ enableMemoryConnectors: checked })}
disabled={toggleMutation.isPending}
settingKey="enableMemoryConnectors"
managed={managedKeys.enableMemoryConnectors}
ariaLabel="Toggle memory connectors experimental setting"
/>
<ExperimentalToggleCard
title="OpenAI Dot"
description="Add OpenAI Dot as a standalone agent choice. Pair your Dot and verify event delivery before assigning work."
footnote="Requires Assistant connections (MCP) and an authenticated instance with a public HTTPS URL. Turning this off blocks Dot calls and new work; saved connections are kept."
checked={experimentalQuery.data?.enableOpenAiDot === true}
onCheckedChange={(checked) => toggleMutation.mutate({ enableOpenAiDot: checked })}
disabled={toggleMutation.isPending}
settingKey="enableOpenAiDot"
managed={managedKeys.enableOpenAiDot}
ariaLabel="Toggle OpenAI Dot experimental setting"
/>
<ExperimentalToggleCard
title="Paperclip Runner"
description="Allow new Codex agents to select the experimental Rust Paperclip Runner, including authenticated runner ingress when a sandbox requires it. Onboarding continues to use legacy adapters. Turning this off hides the choice without affecting existing native runs."
checked={enableNativeRunner}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableNativeRunner: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableNativeRunner"
managed={managedKeys.enableNativeRunner}
ariaLabel="Toggle Paperclip Runner experimental setting"
/>
<ExperimentalToggleCard
title="Simplified English Interactions"
description="Instruct agents to write user interactions (plan confirmations, questions, suggested tasks, checkbox prompts) in ASD-STE100 Simplified Technical English, with brief context on what information the decision needs and what happens for each choice."
checked={enableSimplifiedEnglishInteractions}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableSimplifiedEnglishInteractions: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableSimplifiedEnglishInteractions"
managed={managedKeys.enableSimplifiedEnglishInteractions}
ariaLabel="Toggle simplified english interactions experimental setting"
/>
<ExperimentalToggleCard
title="Status Cards"
description="Enable the experimental shared status-card board and its gated API. Existing card data is kept when this is disabled."
footnote="Enabling Status Cards also enables Summaries."
checked={enableStatusCards}
onCheckedChange={(checked) =>
toggleMutation.mutate(
checked
? { enableSummaries: true, enableStatusCards: true }
: { enableStatusCards: false },
)
}
disabled={toggleMutation.isPending || statusCardsBlockedByManagedSummaries}
settingKey="enableStatusCards"
managed={managedKeys.enableStatusCards}
ariaLabel="Toggle status cards experimental setting"
/>
<ExperimentalToggleCard
title="Streamlined UI"
description="Use the simplified main sidebar, shared Tasks and Inbox presentation, focused task detail layout, and contextual navigation across Agents, Routines, Skills, and Settings."
footnote="Turning this off restores the legacy shell and navigation. Task and page data are unchanged."
checked={enableStreamlinedUi}
onCheckedChange={(checked) => toggleMutation.mutate({ enableStreamlinedUi: checked })}
disabled={toggleMutation.isPending}
settingKey="enableStreamlinedUi"
managed={managedKeys.enableStreamlinedUi}
ariaLabel="Toggle Streamlined UI experimental setting"
/>
<ExperimentalToggleCard
title="Summaries"
description="Show Summarizer-generated status slots on project and workspace pages, with on-demand refresh and revision history. Existing summary data is kept when this is disabled."
footnote="Status Cards requires Summaries. Disabling Summaries also disables Status Cards."
checked={enableSummaries}
onCheckedChange={(checked) =>
toggleMutation.mutate(
checked || !enableStatusCards
? { enableSummaries: checked }
: { enableSummaries: false, enableStatusCards: false },
)
}
disabled={toggleMutation.isPending || summariesRequiredByManagedStatusCards}
settingKey="enableSummaries"
managed={managedKeys.enableSummaries}
ariaLabel="Toggle summaries experimental setting"
/>
{enableIsolatedWorkspaces && (
<ExperimentalToggleCard
title="Use Isolated Workspaces By Default"
description="Treat a project that has no execution workspace policy of its own as if it selected isolated workspaces, so its tasks get a per-task worktree instead of sharing the project checkout. A project that carries its own policy keeps it."
checked={enableIsolatedWorkspacesByDefault}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableIsolatedWorkspacesByDefault: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableIsolatedWorkspacesByDefault"
managed={managedKeys.enableIsolatedWorkspacesByDefault}
ariaLabel="Toggle isolated workspaces by default experimental setting"
/>
)}
</section>
{showDeveloperSection ? (
<section className="space-y-3" aria-labelledby="developer-mode-heading">
<div className="space-y-1">
<h2 id="developer-mode-heading" className="text-sm font-semibold">
Paperclip Developer Mode
</h2>
<p className="text-sm text-muted-foreground">
Internal tools for developing, testing, and debugging Paperclip.
</p>
</div>
<ExperimentalToggleCard
title="Auto-Restart Dev Server When Idle"
description="In `pnpm dev:once`, wait for all queued and running local agent runs to finish, then restart the server automatically when backend changes or migrations make the current boot stale."
checked={autoRestartDevServerWhenIdle}
onCheckedChange={(checked) =>
toggleMutation.mutate({ autoRestartDevServerWhenIdle: checked })
}
disabled={toggleMutation.isPending}
settingKey="autoRestartDevServerWhenIdle"
managed={managedKeys.autoRestartDevServerWhenIdle}
ariaLabel="Toggle guarded dev-server auto-restart"
/>
<ExperimentalToggleCard
title="Managed Environment Only"
description="Hide the local environment and run all agents in the platform-managed environment."
checked={enableManagedSandboxOnly}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableManagedSandboxOnly: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableManagedSandboxOnly"
managed={managedKeys.enableManagedSandboxOnly}
ariaLabel="Toggle managed environment only experimental setting"
/>
<ExperimentalToggleCard
title="Paperclip Developer Mode"
description="Show internal Paperclip maintainer tools and observability links, including Honeycomb trace queries on run pages."
checked={enablePaperclipDeveloperMode}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enablePaperclipDeveloperMode: checked })
}
disabled={toggleMutation.isPending}
settingKey="enablePaperclipDeveloperMode"
managed={managedKeys.enablePaperclipDeveloperMode}
ariaLabel="Toggle Paperclip developer mode experimental setting"
/>
{showWorktreeRunExecution ? (
<Card className="block bg-transparent p-5">
<div className="flex flex-col gap-4">
<div className="flex items-start justify-between gap-4">
<div className="space-y-1.5">
<div className="flex flex-wrap items-center gap-2">
<h3 className="text-sm font-semibold">Run tasks in this worktree</h3>
{worktreeRunExecutionManaged ? <ManagedByCloudBadge /> : null}
</div>
<p className="max-w-2xl text-sm text-muted-foreground">
This is an isolated git-worktree preview instance. Turn this on to let the scheduler execute runs
here. Only tasks created after enabling will run automatically — copied/pre-existing tasks stay
parked. Toggling off and on resets the cutoff.
</p>
</div>
<ToggleSwitch
checked={enableWorktreeRunExecution}
onCheckedChange={(checked) => {
if (worktreeRunExecutionManaged) return;
toggleMutation.mutate({ enableWorktreeRunExecution: checked });
}}
disabled={toggleMutation.isPending || worktreeRunExecutionManaged}
aria-label="Toggle worktree run execution setting"
/>
</div>
{worktreeRunExecutionState.kind === "armed" ? (
<div className="flex items-center gap-2 rounded-md border border-emerald-500/30 bg-emerald-500/5 px-3 py-2 text-sm text-foreground">
<Play className="h-4 w-4 shrink-0 text-emerald-600" />
<span>
Running tasks created after{" "}
<span className="font-medium">
{formatActivationTimestamp(worktreeRunExecutionState.activatedAt)}
</span>
.
</span>
</div>
) : null}
{worktreeRunExecutionState.kind === "fail_closed" ? (
<div className="flex items-start gap-2 rounded-md border border-amber-500/30 bg-amber-500/5 px-3 py-2 text-sm">
<AlertTriangle className="mt-0.5 h-4 w-4 shrink-0 text-amber-700" />
<div className="space-y-0.5">
<p className="font-medium text-foreground">Execution is suppressed — effectively off.</p>
<p className="text-muted-foreground">
{worktreeRunExecutionState.reason === "instance_mismatch"
? "This setting was armed in a different instance and copied here, so no tasks run automatically."
: "This setting is missing its activation cutoff, so no tasks run automatically."}{" "}
Toggle it off and back on to arm execution for tasks created here.
</p>
</div>
</div>
) : null}
</div>
</Card>
) : null}
<ExperimentalToggleCard
title="Server Info Debug View"
description='Show a "Server" section in the account drawer with the current server restart time and running commit.'
checked={enableServerInfoDebugView}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableServerInfoDebugView: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableServerInfoDebugView"
managed={managedKeys.enableServerInfoDebugView}
ariaLabel="Toggle server info debug view experimental setting"
/>
<ExperimentalToggleCard
title="Smoke Lab"
description='Add a "Smoke Lab" tab under Apps → Developer and an "Integration smoke" card on the dashboard for exercising every integration path against deterministic local fixtures (fake OAuth provider + loopback MCP servers). Private (non-public) deployments only.'
checked={enableSmokeLab}
onCheckedChange={(checked) => toggleMutation.mutate({ enableSmokeLab: checked })}
disabled={toggleMutation.isPending}
settingKey="enableSmokeLab"
managed={managedKeys.enableSmokeLab}
ariaLabel="Toggle smoke lab experimental setting"
/>
<ExperimentalToggleCard
title="Task Plan Decomposition"
description="Show accepted-plan decomposition history on task detail pages. Intended for debugging and validating subtask creation behavior while the presentation is still being refined."
checked={enableIssuePlanDecompositions}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableIssuePlanDecompositions: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableIssuePlanDecompositions"
managed={managedKeys.enableIssuePlanDecompositions}
ariaLabel="Toggle task plan decomposition panel experimental setting"
/>
</section>
) : null}
{showLegacySection ? (
<section className="space-y-3" aria-labelledby="legacy-heading">
<div className="space-y-1">
<h2 id="legacy-heading" className="text-sm font-semibold">
Legacy
</h2>
<p className="text-sm text-muted-foreground">These features are going to be removed.</p>
</div>
<ExperimentalToggleCard
title="Classic Task Interface"
description="Restores the previous task detail page: the page-level header with inline description editing, the plain comment thread, and the fixed Properties sidebar. Chat-only features — streaming activity folding, inline plan and question cards, the three-mode composer — are unavailable in the classic view."
footnote="Switching takes effect immediately. No task data is affected."
checked={enableClassicTaskInterface}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableClassicTaskInterface: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableClassicTaskInterface"
managed={managedKeys.enableClassicTaskInterface}
ariaLabel="Toggle classic task interface experimental setting"
/>
<ExperimentalToggleCard
title="Goals Sidebar Link"
description="Restore the Goals item in the main sidebar while the goals surface is being evaluated."
checked={enableGoalsSidebarLink}
onCheckedChange={(checked) =>
toggleMutation.mutate({ enableGoalsSidebarLink: checked })
}
disabled={toggleMutation.isPending}
settingKey="enableGoalsSidebarLink"
managed={managedKeys.enableGoalsSidebarLink}
ariaLabel="Toggle goals sidebar link experimental setting"
/>
</section>
) : null}
</div>
);
}