2026-09 · Intelligence release
Date: 2026-09-13
Theme: the platform explains itself, judges instead of listing, and can be asked.
Administrator action: OAIA is off per tenant until switched on from the A.I Model card; Security Watch is off until its master switch is on. Superusers may withhold OAIA per tenant on AI Keys & Tenant Limits.
OAIA — Omaya AI Assistant (/admin/oaia)
- Heartbeat on the tenant's schedule (2, 4, 6, 8, 12 or 24 h): gateways offline or weak signal, ingestion gone silent, batteries, devices off their reporting pattern, environment off baseline. Detectors detect; the model narrates only what changed (new, escalated, cleared) and every admin is told.
- Daily review (every 1, 2, 3 or 7 days): proposes rules, safety and comfort improvements and configuration fixes — conditioned on sense (a comfort alert for a meeting room only while someone is in it). Accept opens the rule pre-filled; dismiss and done are remembered.
- Findings can be acknowledged, snoozed, reopened or marked won't-fix; cleared findings are hidden but retrievable (filters: open / muted / cleared 7d / won't fix).
- Chat knows the tenant, the local clock and the asker's role.
/compact folds a long conversation; /new starts over. A working indicator shows while the model runs.
- Actions with approval: the assistant drafts one of eight catalogued actions (venue hours, zone capacity, rule on/off, device zone, finding and suggestion states); a person with the permission applies it, once. Nothing is changed by the model itself.
- Guardrails: one tenant per assistant through read-only
oaia_* views with the tenant baked in; a read-only database account per tenant (200 rows, 5 s per query); credentials redacted; no shell, no file system, no other tenant. Red-teamed with prompt injection, jailbreak, raw-table and cross-tenant requests.
- Off means off: with the tenant switch off, the menu entry is hidden, the page shows an off-state, and every OAIA endpoint refuses. Superusers can withhold OAIA per tenant (
oaia_allowed), which locks the tenant's switch.
- Console redesign: light and dark, chat on the left, decluttered header, scan-eye emblem.
Security Watch (app-store module, Your Apps → Security Watch)
- A guard-facing app (app users,
/{tenant}/apps/security-watch) with a Live board in two modes — Traditional (every zone and incident) and Adaptive (one status: green / orange / red, then only the zones that earned it, then incidents) — remembered per device.
- Detectors (every 5 minutes): panic button, after-hours presence, restricted-zone entry (allowed by entity tag), unknown device lingering, coverage lost, environmental danger (heat level or hour-over-hour rise). Assets never count as people.
- Out of habit, judged by AI: a person somewhere they have never been in 30 days, or a room in use at an hour it never is with no booking, is a candidate; the model weighs the context (usual zones, the zone's regulars, who else is present, the booking, the hour) and only "abnormal" becomes an incident. Every verdict is recorded and shown on the settings page. No per-person zone lists to maintain.
- Incidents: new → acknowledged → attending → resolved (genuine / false alarm / expected), with an AI assessment and a suggested first step; push to guards; escalation to named people (app users and admins) by email, SMS or WhatsApp, plus a Telegram chat.
- Admin settings: master switch (off by default), watched zones with tag pills, armed hours (Mon–Sun toggles), detectors, whitelist windows, recipients, AI judgements log.
OAIA hears every app — and manages what a person approves
One assistant for the whole organisation. Each app you switch on plugs into OAIA through one adapter (app/Services/Oaia/Modules, one class and one registry line per app): its read-only views, its section of the daily review with its own gaps, its heartbeat detectors, its catalogued actions, the records another page can put in front of the chat, and what the model is taught. All of it keyed on whether the app is switched on for the tenant in the app store — an app you have not enabled is never mentioned, so the assistant cannot be led to speculate about it. Every app keeps working on its own without OAIA; every app's settings page gains Ask OAIA where OAIA is on.
- Security Watch — incidents and out-of-habit judgements (guard ids and raw evidence excluded).
security_7d: incidents by type and zone, how guards closed them, median minutes to acknowledge, what is open, the same alarm closed as false three times. Heartbeat: an incident unacknowledged 30 min (critical after an hour) or open 4 h. Actions: whitelist a person or device, set armed hours. Never acknowledges, resolves or re-judges an incident. Your Apps → Security Watch gains an Incidents — last 7 days card with Ask OAIA per row.
- Meeting Room — rooms, bookings, calendar events and sync (booker ids, organiser emails and tokens excluded).
meetings_7d per room: bookings, no-shows, walk-ins, booked hours beside the hours the room's own sensor counted it occupied. Heartbeat: a calendar that stopped syncing, bookings stuck open. Actions: release a no-show booking, set automatic release, make a zone bookable. Never books, cancels or moves a meeting.
- Facility Management — work orders (with an
assigned flag; assignee, vendor, CMMS ids and metadata excluded), assets, service records, schedules. facility_7d: opened by source, closed with median hours and on-time rate, the backlog's overdue, stale and unassigned orders, assets past service. Heartbeat names the five most overdue urgent orders and rolls the rest into one line. Actions: open, re-prioritise, cancel a stale order. Never marks work done.
- Toilet Hygiene — toilets, incidents, cleaning schedules (rosters, shifts, absences excluded).
toilets_7d per toilet: score and band, target, last clean, orders and on-time rate, SLA breaches, dedicated cleaner and schedule, fixtures out of order. Heartbeat: a toilet in the orange or red with no cleaning order open. Actions: dispatch a clean now (to the nearest available cleaner, as the high-traffic trigger does), set the target score, set the high-traffic threshold. Never marks a clean done or touches a shift.
- Energy — readings (raw payload excluded).
energy_7d per meter: the week's kWh, open-hours versus closed-hours draw in the venue's own hours, kWh per occupied hour. Heartbeat: power left on after hours — 70 % of the daytime draw an hour after closing. No action of its own: the saving is a rule on the building controls, which the review now proposes with the watts and the weekly kWh.
- Connectors (a platform feature, on for every tenant) — health and counts only; the credential column, webhook URLs and secrets, payloads and response bodies are excluded, and any URL inside an error message is replaced with
[endpoint]. Heartbeat: an enabled connector whose latest error is newer than its latest success (critical once a working one has gone a day without success), saying what stopped — alerts, automations, gateway data; webhook deliveries that died today. Actions: re-send a webhook's dead deliveries, pause or resume a webhook. Never changes an endpoint, a key or a mapping.
- Visitor Management — visits, hosts and companies; on-site now, awaiting approval, the week by status and channel. Joins the same review, heartbeat and chat.
- Compliance — standards, rules, profiles, assessments (payload, hash and author excluded), findings, calibrations (certificate references and document paths excluded).
compliance_7d: each profile's latest verdict with the findings behind it, calibrations overdue and due. Heartbeat: a profile without a current assessment, lapsed calibrations. Actions: run an assessment (7, 30 or 90 days), switch a profile on or off. Never edits a standard, a rule or a finding.
- Roll Call — events, attendances, badge reliability (actor ids and the IP-bearing audit trail excluded).
rollcall_90d: drill cadence and days since the last drill, the last drill's counts and who was missing with the zone their badge was last heard in, events left running, badges too unreliable to muster. Heartbeat: drill overdue, a roll call still running after six hours. No action — a roll call is a live safety operation run by a person on the spot.
- Approve one Autopilot action at a time. The Autopilot card is now a ledger like the findings: one row per pending action (not one per heartbeat), opening to the reasoning and the before-snapshot, with Approve, Undo, Open proposal and Ask about this. In Shadow mode, Approve is how you try Autopilot one action at a time before switching to Act — it goes through the same path, is marked done by you, and undoing your own approval never pauses Autopilot. Held-by-limit rows no longer appear in Shadow, where nothing is spent.
- The OAIA page puts the chat on the whole left column, the numbers strip folds away (counts stay in its header), and Recent heartbeats sits under Autopilot.
- Autopilot stays the only automation. No app action can ever be an Autopilot kind (a test pins it): whitelist, release, dispatch, cancel, retry and the rest wait for a person to click Apply whatever the mode, and with Autopilot off OAIA changes nothing on its own. Switching Autopilot to Act, and making it available to a tenant, now confirm in words that it is beta and can get one wrong.
- Fix on the way: Roll Call stamped every event, attendance and audit row with
tenant_id = 'default' on the admin path and read presence from the wrong tenant's cache when recomputing attendance; it now uses the active tenant, and existing rows were restamped inside each tenant's own database.
- Audit pass: an app the tenant has not enabled is now invisible to the model end to end — its views are dropped from
DescribeSchemaTool and refused by the SQL guard, not just left out of the prompt; the app-store gate is remembered per tenant for a minute (48 landlord queries per chat prompt → 2); and the OAIA page shows every time in the tenant's timezone rather than the browser's, like every other admin page.
- The About page and Capabilities page describe the assistant across every app and Autopilot (English and Malay).
- Administrator action: the read-only database users need SELECT on the new views —
php artisan oaia:provision --print-grants prints the script; run it once as the database root user. Views for an app enabled later are added at the next heartbeat.
OAIA Autopilot (beta, off by default)
- The reversible subset of OAIA's proposals applied without waiting for a person, behind three switches: the platform grants it per tenant (AI Keys & Tenant Limits), the tenant picks Off / Shadow / Act on the A.I Model card, and turns on tiers — Draft (create proposed rules switched off), Configure (zone capacity, venue hours, assign an unassigned device), Operate (cooling on when a room is hot or humid with people in it, an equipment room passes 30 °C, or a booked room is hot 15 minutes before the meeting; fans on for stale air; lights on for people in a dark room; everything off when the radar says a room has been empty ten minutes or the venue has been closed half an hour with nobody counted). Configure also learns a capacity for a zone that has none from 14 days of counter data.
- Guardrails in code: 3 actions per heartbeat, 20 per day, an hour per target, never flipping a device back within 30 minutes, setpoints inside 20–28 °C, no locks/sirens/scenes, no enabling rules, no deletes. Every action is listed on the OAIA page with Undo; an undo pauses that kind for a day, three in a week drop Act to Shadow. Administrators are told of each action.
Home Assistant / building control
- Rules could already call any Home Assistant service on any entity (light, switch, cover, climate, fan, scene, …) through the Smart Home Bridge connector, with extra service data such as brightness or temperature.
- New metric
radar_vacant — "Area Empty For (radar)", the mirror of radar_dwell — so a rule can switch lights, air-conditioning and blinds off ten minutes after the last person leaves, not the instant the radar reads zero. Available in the rule builder and to the AI rule author.
- OAIA proposes rules that act. The daily review now sees the tenant's mapped building controls and drafts automations on them — lights and air-con off after the room has been empty ten minutes, air-con on when it is hot and someone is in, blinds closed in the afternoon, everything off at closing. Only entities mapped on the Mappings page can be drafted (the same check the rule editor applies), and a draft is saved inactive for a person to switch on. Arbitrary endpoints (HTTP, MQTT) and record writes stay form-only.
- A contract test now guards generated rules: every word the assistant is taught exists, and every draft the validator accepts is accepted by the rule save endpoint.
AI Reporting, keys and limits
- Ask for a report in plain language (
/admin/report/ai); table and chart come from the same data as every other report. Credential chain: tenant's own key (BYOK) → platform key → environment.
- Token caps: tenants on Omaya's shared AI service have a monthly cap (per-tenant value, else the platform default, else 500,000 tokens); a tenant's own key is never capped. Superusers set caps and the platform default on AI Keys & Tenant Limits.
- Omaya Platform Usage (
/admin/usage): what the tenant consumed this month — AI tokens per provider (shared vs own key, against the cap), SMS, WhatsApp, email (alerts, OTP, reports, portal, module mail), webhooks, in-app alerts — with recent failures. Backed by a message log written inside every sender.
Sensing, positioning and reports
- Radar people counting (MSR01-A): positions persisted and used; coverage calibration panel and gate; Right Now fuses radar and sensor counts over tags; Room Usage Map report; radar ground truth pairs a lone tag with the radar dot every minute.
- Space Utilisation report (all zones against capacity); anomaly detection revived (episode dedup, tags get a 3-day threshold).
- Cross-floor routing (floor links: lifts and stairs as real links between plans) for the visitor app's indoor navigation; 3D floor plan widget on TV dashboards sharing the admin 3D geometry.
- MOKO B2 button decoder; per-tenant detection speed presets.
Integrations and access
- Calendar integration (Google and Microsoft 365) per tenant, feeding Meeting Room bookings.
- Admin SSO (OIDC per tenant): per-tenant link, email-domain routing, SSO-only option, group→role mapping; MFA skipped after SSO.
- Public API docs at
/documentations/api.
What's new page
/admin/about/whats-new renders these notes; linked from the About page and the capability reference.
Housekeeping
- Anomalies page shows who acknowledged, by name ("by pang", or "by system" with the note).
- Auth pages use the white wordmark.
/admin/config#ai opens the A.I Model card directly.
/admin/about and /admin/about/capabilities rewritten with an Intelligence section, nine worked scenarios, seven drawn illustrations; the full page in Malay.