# GuestOps Release Notes ## 0.2.0 — Gate B release candidate This candidate freezes the implemented Gate B scope for controlled acceptance. It is not yet approved for live hotel operations and does not become a release until the exact commit is pushed, CI and operational evidence are retained, the supervised pilot is approved and the immutable `0.2.0` tag is created. ### Promoted scope - AI-assisted reply suggestions and staff-reviewed Gmail sending. - Approval-controlled OHIP PMS and NMI payment workflows. - FAQ automation controls, team invitations, password recovery, and stronger Google connection recovery. - No-send FAQ batch evaluation with false-positive and false-negative reporting before activation. - Release-bound automation and identity/privacy acceptance records covering training, provider decisions, retention ownership and known limitations. - Stable tenant-scoped inbox pagination beyond the former 500-message view, unsaved-draft guards including browser history navigation, consistent hotel-timezone timestamps across operational screens, and a release-bound desktop-parity acceptance record. - A bounded read-only sandbox capacity probe plus machine-validated, release-bound supervised-pilot run, go/no-go and incident-exercise records. - Backup, restore, opt-in systemd scheduling, deployment, persistence-drill, diagnostic, release-evidence, Google acceptance-record validation and rollback tooling. These capabilities still require their separately documented provider, host and operational acceptance. Google, PMS and payment-provider acceptance is not established by local automated tests. ### Known limitations and launch conditions - Gate A still requires a successful default-branch CI run, durable off-host release archive, target-Debian deployment, persistent storage/key validation, monitoring, and a successful restore/rollback exercise. - Gate B still requires real Google acceptance and supervised staff testing, including desktop-parity acceptance of pagination, draft protection, proxy-aware login throttling and saved-hotel-timezone rendering. - Gate C still requires the Rezlynx/Guestline adapter and independently accepted PMS/payment workflows, plus privacy, identity, capacity, and release approvals. - FAQ live mode and all external write actions must remain disabled until their corresponding acceptance gate has passed. See [MILESTONES.md](MILESTONES.md) for the gate assessment, delivery sequence, and remaining work. ## 0.1.0 — 29 September 2026 The `0.1.0` tag identifies the initial GuestOps Web foundation. It is not approved for live hotel operations. ### Foundation scope - Responsive shared inbox, search and status filters, saved reply drafts, approved hotel answers, activity history, and hotel settings. - ASP.NET Core authentication with protected cookies, password hashing, CSRF validation, login throttling, role checks, and server-derived hotel membership. - Tenant-scoped MongoDB storage with optimistic concurrency, unique mailbox/message indexes, OAuth state expiry, and worker leases. - Read-only Google OAuth and recent-message import foundation with checkpoint and duplicate protection. - Preview mode, Linux container definitions, Nginx HTTPS example, and automated backend/frontend verification. - Live email sending, PMS writes, payment workflows, and automatic FAQ replies were disabled in this foundation. ### Versioning The foundation remains tagged `0.1.0`. The .NET projects and frontend package now share candidate version `0.2.0`; create that immutable tag only after the exact commit, checksummed artifacts and Gate B acceptance evidence have been approved.