Skip to content

What changed, and when.

Dated entries, grouped by month, tagged added, improved, fixed or security. Every item says what it does and what it still will not do.

01 — Changelog / 12 entries

  • 5 Added
  • 3 Improved
  • 2 Fixed
  • 2 Security

September 20263 entries

AddedSeeded — not a shipped release

Time-saved rationale on every card; Closeout pack details

Every listing was supposed to carry a published eval. That harness is not in this catalog: no product record has a dataset, sample size, or measured result. What every card does publish is time_saved_hours plus time_saved_rationale — hours at a stated volume, with the arithmetic written next to the number (for example 18h from 800 tickets/month × 1.5 min). Named failure mode, autonomy level, and whether human approval is available stay on the page. Finance listings still default approval to on.

Those hours are catalog math. They are not hours recovered in a customer's shop, and they are not a measured accuracy. A published eval (dataset, sample, dated result) is planned and not present. The try-it-on-your-own-data control stays above checkout. Checkout in this build is still waitlisted; the trial is the completable path.

Closeout, the close pack, is the listing this rule is easiest to lie about. Setup time is 120 minutes. The card keeps 120. Packs take longer than a single agent. Closeout will not file the return, replace FloQast if FloQast is already running the close, or click send on the board pack. If close still lives in a spreadsheet and a Slack channel, the checklist is the starting point.

Also in this drop: model-provider changes are changelog events, not silent behavior changes. Until an eval harness exists we will not print an accuracy figure to defend. The model is an implementation detail we own. You should get that entry. You should not get a migration project.

SecuritySeeded — not a shipped release

Public subprocessor list and data-handling block on every listing

A controller reads data-handling before the catalog. The Trust page was already in global navigation. This release puts a data-handling block on every product page and publishes the subprocessor list at /legal/subprocessors.

The block is four sentences with product-specific values: what is read, where it is processed, the retention window, and whether a human at nox.markets can see it. The fifth sentence is the same on every listing: customer data is not used to train models. Connected products hold scoped OAuth tokens. Self-hosted listings state that the file stays in the customer's environment.

If a vendor is not on the public subprocessor list, we are not allowed to use them on customer data. Adding a vendor that processes personal data will get a dated notice on that list.

Honest compliance status, unchanged and not punched up: SOC 2 Type II is in progress. ISO 27001 and HIPAA are not claimed.

Encryption and tenancy copy is not new in this drop (TLS 1.3 in transit, AES-256 at rest, hosted in Nuremberg, Germany, on every tier). SAML from Growth and SCIM from Scale remain the identity path; they are not a certification. Request our DPA remains the security CTA. Demo remains the path when an MSA requires a human.

FixedSeeded — not a shipped release

Fix: revoke connection left agents retrying dead grants

Revoke connection is supposed to be the off switch for connected products. The grant disappeared in the identity provider and in workspace integrations, but scheduled agents could still wake, find a stale token, and retry until a per-run ceiling stopped them. That looked like the product was still acting. It was not writing to the system of record; it was burning credits on failed auth.

The scheduler now treats a missing or revoked grant as a hard stop for every listing that named that integration. The next tick does not start. The run history records the stop as authorization revoked, not as a generic failure. Credits are not charged for that skipped tick.

Dashboard copy is aligned. Pause still means the product will not run until you resume it; data already in the system of record is unchanged. Revoke still means connected products that needed that system cannot act. The integrations empty state remains: no connections; connected products cannot act until you authorize a system on the card.

This does not auto-resume if you reconnect later. You reconnect, then resume, then the next schedule fires. Finance listings still stop at a draft for a human. We did not change scopes. If a reconnect fails because scopes are missing, the existing error stands: the system did not grant the scopes the product needs; an admin on that system has to approve them.

August 20263 entries

SecuritySeeded — not a shipped release

Audit log export, by product and by workspace

A controller needs an audit trail they can take with them. Logging existed. Export did not. This release adds export from the product run history and from workspace security.

The file is an open format (CSV and JSON). Each row is an action: product slug, run id, actor (user or the product itself), autonomy level, approval state, source document id where one exists, destination system, timestamp. It does not include raw file bytes. Those follow the retention line on the product page, not the audit retention line.

Retention of the log itself follows the plan: 30 days on Starter, 12 months on Growth, 36 months on Scale. Enterprise retention is on the paper, not implied here. Exporting does not extend retention. If you need the file to never leave the network, self-hosted licensing is still the path; this export is for connected and hosted listings.

Only owner and admin can start an export. We email the work address when the file is ready. Large logs take a minute. The confirmation copy matches the microcopy library: export started; we will email you.

Customer data is not used to train models. This export does not change that sentence. SOC 2 Type II is in progress. We do not hold a report you can attach to an MSA.

ImprovedSeeded — not a shipped release

Hard spend ceiling on by default at grant plus 50 percent

Unattended agents run when nobody is at the keyboard. That is the point, and it is also how a credit grant turns into a surprise bill. The hard spend ceiling is now on by default at monthly grant plus 50 percent.

When the ceiling hits, further runs do not start. The banner in the dashboard is the same sentence as the error catalog: hard spend ceiling reached (grant + 50%). Nothing else will run until an admin raises it. That is the feature. The first 10% over the monthly grant remains a grace band billed at the tier rate if you have no purchase credits in the bank. Past the hard ceiling, billing stops and so do runs.

Per-run ceilings on the product card are unchanged. Hitting a per-run ceiling still stops that run only. A separate circuit breaker still pauses an account that passes 3× its monthly grant until we talk; that clause is in the contract, not only in the banner.

Admins set the ceiling under billing. Owners see it on the invoice preview. Approvers and members do not override it. The USD equivalent sits next to the credit numbers, same as the June card change.

This does not lower list prices and does not add a free agent tier. Trial workspaces use the 25,000-credit Growth grant for fourteen days; the same ceiling math applies to that grant. When the trial ends without billing, runs end. There is no downgrade to a permanent free unattended tier.

AddedSeeded — not a shipped release

Sales & Revenue shelf: research, follow-up, and quoting handoff

Finance & Back-Office is no longer the only category with listings. Sales & Revenue is on /products and on /categories/sales-revenue. The jobs on this shelf are the hours between a CRM record and cash, and the hours before that: research, follow-up, quoting handoff, pipeline hygiene. It is not a second invoice generator. Ledgerline stays in finance.

Listings that ship in this drop include Veinlist, Stepladder, Gatepass, Yeshold, Fieldkeep, Callsheet, Offerbook, Reqdesk, Keepwatch, Pipebrief, and Rivalcard. Types are the same four: tool, agent, workflow, pack. Filters by type, deployment, and connected system work the way they do on the finance shelf.

Connectors named on these cards include HubSpot and Salesforce where the product record lists them. Those logos mean the OAuth grant, not a partnership announcement and not a customer logo wall.

Hours on each card remain catalog math at the volume printed next to them. They are not a win rate, a pipeline-coverage ratio, or cash collected. Rivalcard will not publish a competitor page without a click. Offerbook will not invent discounting your price list does not allow. If a job on your floor is not on this shelf, the category page stays thin rather than filling with "coming soon" names.

Starter and Growth stay self-serve. Demo remains the path for Scale, Enterprise, or a security review. No engineering ticket for purchase or setup on the self-serve tiers.

July 20262 entries

FixedSeeded — not a shipped release

Fix: included-in-plan badge on the wrong product cards

Each listing carries tier_included_from: the plan at which that slug is included rather than sold as an add-on. The catalog was drawing "Included in your plan" from the product record's badge field in some views, and from the workspace entitlement in others. Those two sources diverged. A Growth workspace could see a Scale-threshold slug marked included. A Starter workspace could see a one-time license with no included path marked as if it were in the grant.

Both surfaces now use one check: workspace tier compared to tier_included_from, after any one-time license in that workspace. If the slug is included, the card reads "Included in your plan" and checkout does not add a second license line. If it is not, members never pay list on out-of-tier one-time products (25% off). If it is a subscription add-on, the monthly line is visible. Usage overage is still not the headline.

Pause and resume were not affected. A paused included product still does not run. Cancelling a plan still drops tier inclusions at period end; purchased licenses and purchase credits still survive churn.

We did not attach a count of affected workspaces. That number would look like a usage metric we do not have. If a card still disagrees with /pricing for your tier, send the slug and the workspace id to support. The rule is the catalog field, not the marketing badge new / popular / enterprise.

AddedSeeded — not a shipped release

Team invites and roles: owner, admin, approver, member

A workspace is no longer a single login. An owner or admin can send an invite to a work email. Personal inboxes stay blocked on signup and on invite accept. The invite names the role, expires on a printed date, and is bound to that address. Accepting does not consume a seat. There is no seat SKU. Unlimited seats remain on Starter, Growth, Scale, and Enterprise.

Roles in this release:

  • Owner — billing, plan changes, workspace deletion.
  • Admin — invites, integrations, product pause/resume, spend ceiling.
  • Approver — finance drafts (bills, invoices, reminders, payroll previews). Cannot change billing.
  • Member — run hosted tools they are entitled to; cannot approve money movement and cannot revoke OAuth.

The empty state on the team page is the line we already use in product copy: only you; invite the person who actually approves the bills. That person is usually not the founder who bought the listing.

Invites can be revoked before accept. After accept, an admin can change role or remove the person. Removing someone does not unwind work already in QuickBooks, HubSpot, or a mailbox. Their outstanding approval queue reassigns to an admin until another approver is named.

This is not an identity-provider sync. SAML from Growth and SCIM from Scale are plan features described on /security; they are not how invites work in this release. The source of truth for who is in the workspace is the invite list.

June 20262 entries

ImprovedSeeded — not a shipped release

Credits on cards now show the USD equivalent

Plans still meter work in credits. What changed is the label the operator sees. Every product card now shows credits per run and the USD equivalent at the workspace's included rate. Starter, Growth, Scale, and Enterprise each have a published rate. The number on the card is that rate times that run, not a blended average and not a customer result.

Run confirmations use the same sentence: this uses N credits (USD at your rate), ceiling M. If a run hits the published per-run ceiling, it stops. It does not keep charging. Customers never see a token count, a model name, or a context window. Credits exist so an unattended agent run has a unit. They are not there to hide the price.

Usage remains overage only. It is not the headline price on a listing. One-time licenses still work as before: you own the logic, the UI, and the connectors for that slug in that workspace; runs still spend credits. Purchase-credit back on one-time spend is unchanged: 40% of the one-time price lands in the credit bank and does not expire.

This release does not change plan prices (Starter $290/mo, Growth $990/mo, Scale $2,900/mo, Enterprise from $7,500/mo) or included monthly grants (10,000 / 50,000 / 200,000 / 1,000,000). Those figures stay on /pricing. If the USD line and the credit line disagree on a card, treat that as a defect and tell support.

ImprovedSeeded — not a shipped release

Human approval is the default on finance runs

Finance & Back-Office agents and workflows already stated an autonomy level. This change makes the default match the copy: human approval is on unless a workspace admin turns it off for a named product.

A run now stops at a draft. Billtray opens a draft bill. Ledgerline stages an invoice. Duesday queues a reminder. Payready builds a payroll preview. A named person in the workspace clicks, or they send it back to exceptions. The product does not click "Submit payroll," mark a bill paid, or invent a late fee the contract does not allow.

Extracted amounts and dates cite the source page of the file. If the file cannot be read, it sits in the exception queue. It is not posted. Confidence below the product's threshold follows the same path. We do not claim runs are never wrong. The product page names the failure mode; a measured error rate on a published eval is planned and not present. You are approving, not trusting.

The approval record is part of the audit trail: who saw the draft, what they approved, which source document was attached, and when. Export of that trail is not in this release; it follows later.

This default applies to finance-backoffice. It does not silently apply to every category. Sales and marketing listings keep the autonomy level printed on their own pages. If a workspace needs a finance product to run without a click, that is an explicit setting, not the out-of-the-box path.

May 20262 entries

AddedSeeded — not a shipped release

Connected products: QuickBooks Online, Xero, and Bill.com OAuth

Connected products act in the customer's system of record through OAuth grants the customer can revoke. This release ships the first three connectors that Finance & Back-Office listings actually use: QuickBooks Online, Xero, and Bill.com.

The setup preview is still three steps: connect, configure, run. Connect means the OAuth consent screen for that system, with the scopes the product page lists. You do not map invoice fields, vendor names, or chart-of-accounts codes as a project. Where a product proposes a GL code, it uses that vendor's last twelve months in the connected books and sends new vendors to an exception queue. It will not invent a vendor you have never paid.

These marks are systems we connect to. They are not customers. QuickBooks is not a reference. Neither is Xero. Neither is Bill.com.

If authorization is cancelled, the product cannot act in that system. If the identity provider does not grant the scopes on the product page, an admin on that system has to approve them. Revoke lives in the identity provider and in workspace integrations. Revoking the grant stops the product. Work already written to the books stays in the books; we do not unwind a draft bill because you disconnected later.

Hosted products still run on nox.markets with no OAuth. Self-hosted products still run in the customer's environment under license. The deployment model remains on the card before purchase.

AddedSeeded — not a shipped release

The catalog opens: Finance & Back-Office, first-party

This is the first public changelog entry for nox.markets. The buying surface is a catalog, not a canvas: browse, compare, buy, connect. Listings at this date are first-party. We built them, we integrate them, and we pick up the phone. "Marketplace" here means that buying experience. It does not mean a crowd of third-party sellers.

The opening shelf is Finance & Back-Office. Cards now in the catalog include Ledgerline (customer invoices), Billtray (vendor bills from a mailbox into a draft in Bill.com or QuickBooks Online), Duesday (past-due reminders from the AR mailbox), Outlay (receipt to coded expense), Bidline (a quote that matches the later invoice), Floatcast (thirteen-week cash from bank and books), Seatcheck (SaaS seat waste), Tiedown (bank rec), Nexusmap (sales-tax packet), Payready (payroll prep), and Closeout (close pack). Product types on those cards are tool, agent, workflow, or pack. Deployment is hosted, connected, or self-hosted, written in that language.

Each card publishes setup_minutes as a promise, time_saved_per_month as hours at a stated volume (catalog math, not a customer study), and a named failure mode. Closeout's setup time is 120 minutes. We will not round that down to "under an hour." Nothing in this catalog posts a bill as paid. Finance products default to human approval: they draft; a named person clicks.

Checkout in this build is waitlisted. The completable path is the 14-day Growth trial: 25,000 credits, no card. Unlimited seats on every plan. We charge for work done, not people watching.