← Back to Otello ADP

What's new in Otello ADP

The features added to Otello ADP, most recent first.

Name an ORest service by its path, and get exactly that

When you ask for a service by its path — "show this hotel's value for sett/local/curr" — the answer now comes from that path, titled by it, instead of a related tool on the same topic. The two can legitimately disagree: a hotel's master record may say USD while its local-currency setting says LAK, and you get the one you asked for.

Try it: "Show this hotel's value for sett/local/curr" — the answer is headed by the path it called.

A domain switch shows its progress, and holds the hotel list still

Switching domain re-signs you in, reloads your hotels and reopens the conversation. The status bar now says which of those is running — Switching domain…, Loading hotels…, Loading messages… — and the hotel selector is disabled until it is done, so a hotel picked mid-switch can no longer land on the previous domain's list. The switch also opens on a real hotel of the new domain, and the domain list itself shows only active domains, on every backend.

If a hotel is in your selector, you can work on it

For Hotech staff signed in with a master account, the hotels you may change are decided by Otello — the same answer that fills your hotel selector — not by a copy kept on Ogent's side. Adding a website to a customer's hotel after a domain switch used to fail; it no longer does.

New conversations carry your name, not your first question

A new chat is now titled <your code> - Chat rather than the opening message, so the history stops reading as a wall of questions. Rename it with the pencil when it deserves a real name. Smaller tunings on the same day: the members button is labelled Chat Members, and the profile card shows Emp.Code and drops the duplicate Username line (your e-mail is your username).

A failure tells you what went wrong

Where the chat used to show a bare "HTTP 500" or advise "try again", it now shows the reason — a permission refusal on the RAG Store, a rejected request, a backend that is down — so you know whether to retry, ask for a right, or report it.

Two new user types: SUPER_VISOR and HOTEL_VISOR

People who hold the supervisory OGENT.canS right in Otello without being a super user now have their own user types. A supervisor signs off other people's work — approvals, skills, notifications, the RAG store — without administering the platform.

Access is two questions: what you may do, and where

Every admin panel now decides on the axis it cares about. What: super users open every panel including Settings; supervisors open exactly five — Approvals, Background, RAG Store, Skills, Notifications. Where: super-hotel users get the domain list and every hotel; everyone else works in their own Otello hotel list. The six user types are just the six combinations — see the User Guide §6 for the table.

Panels you cannot use are hidden, and the server refuses them independently — a bookmarked link fails too.

Every refusal names your user type

A message that denies access — a panel, a domain switch — now ends with Your User Type: …, so you know what you are before asking what you need. Your profile shows the same type and whether you hold the supervisor right; the System Information dialog shows it beside Otello's own Role, because the two routinely differ.

The Translate button appears only when it would do something

A reply already in your language no longer offers to translate itself. The server now reports the language it actually answered in — detected from the text, not assumed from your setting, so a Turkish question answered in Turkish under an English profile still gets the button when it needs it.

Collapse the admin menu from the bottom too

The sidebar's collapse toggle sits a little clearer of the Ogent mark at the top, and a second one now waits at the foot of the menu, so a long panel list can be folded from wherever your cursor is.

A master account is not gated by the visited hotel's Ogent licence

Hotech staff signed in with a master account can switch into a customer's domain and work on any of its hotels, whether or not that property has bought Ogent — the licence that applies is Hotech's. The per-user access right still applies: master login says where you may work, not that you hold the right.

Your Ogent user type, in System Information

The System Information dialog's Login Info section gains a USER TYPE row beside Otello's Role. They are different things — Receptionist in Otello can be SUPER_ADMIN in Ogent — and showing both stops one passing for the other.

A failed domain switch says why

Instead of one catch-all message, a domain switch that does not go through now names its cause: the target backend could not be reached, the sign-in there was refused, or the domain's address is not routable.

An attached screen can come with instructions

Applications that send Ogent a screenshot or a data view alongside a question can now also say how to read it — "compare Friday against last week" — separately from the question itself. A client that attaches a screen and says nothing still gets a sensible default. (Integrators: the context fields were renamed ctxImage/ctxData/ctxMsg; client and server deploy together.)

See what's new, without asking

Both Otello ADP addresses now carry a ChangeLog link beside the Login button, opening a dated list of the features added to the platform. It is the same list on ogent.hotech.systems and adp-labs.com, because it is the same product, and it needs no login — you can send the link to a colleague who has not been given an account yet.

Where: the top of the page at ogent.hotech.systems or adp-labs.com, just before Login.

A second front door: adp-labs.com

Otello ADP now has its own public address. adp-labs.com opens an intro page explaining what the platform does, what it is worth, and — organised by process area — the kinds of questions it can actually answer, with a Login button straight into the chat. It is the same product behind the same login as ogent.hotech.systems; only the front door and the branding differ.

Which ORest backend am I on?

The System Information dialog's Domain Info panel now names the ORest backend serving the current hotel and the version it is running. With multi-property domains a user's hotels can sit on different backends, so this answers "which one am I actually talking to" without asking an administrator.

Every list shows how many

The count that used to sit in a card's title as text — "Skills · 1" — is now a badge beside the title, and it appears on every listing that had none: Skills, Chips, Background Jobs, RAG Sources, Audits, Conversations, Ratings, Sessions, Users, Tenants, Tenant Types and the Change Log.

The LLM tier list stops hiding its own options

Opening the Tier name or Model dropdown in Settings now shows the whole list every time, instead of filtering itself down to whatever text was already in the box.

Tier name and model are pick-lists, not free text

The LLM tier editor now offers the tier names Ogent actually resolves, the providers it can build, and each provider's models read live from the gateway — so a tier can no longer be saved against a misspelled name or a model the gateway will reject.

A tier change survives a restart

An LLM tier edited from the Settings panel now persists: previously the value was correct until the pod restarted, at which point it silently reverted to whatever was set at deploy time.

A restored conversation shows what happened to its proposal

Reopening a conversation whose write proposal has since been executed, rejected or failed no longer shows the frozen "PENDING — say Confirm" text. The reply now reports what the proposal became — including the created record's id and who decided it — and stops inviting a confirmation that no longer exists.

A skill keeps the name you gave it

Saving a skill no longer rewrites its name with a hotel or scope prefix. The name is stored exactly as typed (normalised to lowercase and hyphens), so the /command a person chose is the one that works, and the Scope column carries the ownership information the prefix used to duplicate.

Skills and Chips, one panel at a time

The Skills page now has a Skills/Chips selector at the top and shows the editor instead of the list when adding or editing, rather than below it — so "Add skill" no longer opens a form a screenful under the button. Saving returns to the list.

Pages whose content sits inside an embed are now readable

A guide page that keeps its body in an embedded document — Google Sites pages do this — used to ingest as an empty shell, and pasting one into the chat produced "the page is empty". Both the knowledge-base ingester and the chat's page reader now follow the embed and read the real content.

The crawl page limit is an admin setting

How many pages a website ingest will crawl is now editable from the Settings panel (default 100, maximum 500) instead of living in pod configuration only DevOps could change, and a new value takes effect on the next crawl.

A chip you send is visible in the conversation

Sending a --name chip now shows the chip's actual content inline in the chat, open by default and scrollable if it is long, instead of a pill that has to be tapped to reveal what was sent.

Conversation history opens from a history icon

The chat's conversations drawer now opens from a history icon (a clock with an arrow) rather than a hamburger, so it reads as "past conversations" rather than a general menu.

One hotel's answers never become another's examples

Curated question/answer examples are now scoped to the hotel they came from. A thumbs-upped answer containing one property's real numbers can no longer turn up as a worked example while another property is being answered.

Switching domains no longer re-asks for a password

Moving between hotels that live on different backends now reuses the session the person already has, instead of performing a fresh password login behind the scenes.

Explain a thumbs-up or thumbs-down

Rating a reply now offers an optional "Tell us why" box under the 👍/👎, so a rating can carry a short explanation instead of just a bare vote. A rated reply keeps a small button to add or edit the words afterward.

Three new panels for SuperHotel admins

A super/portal administrator can now see three cross-tenant listings that ordinary hotel admins cannot: every rating left across every hotel with its explanation, a change log of who edited what with the field-by-field detail behind each entry, and the full user registry with each person's login/session history.

SSO into Ogent's chat page from another already-logged-in app

A client that already has its own user logged in (OWeb, NavaPMS, or a Flutter app) can now send that person straight into ogent.hotech.systems/chat without asking them to log in again — the browser only ever sees a short-lived, single-use code, never a credential.

Ask about a screenshot or chart, not just plain text

A chat message can now come with an attached screenshot or chart plus a note on where it came from (which screen, which tool), so Ogent answers about what's actually on screen instead of a disconnected question. An image it can't read fails the message clearly rather than guessing.

RAG documents can be renamed, and folders are now real

A document in the knowledge base can be renamed directly from the RAG panel. Folders are no longer just a text label on a file — they're a real, editable tree with New/Rename/Move/Delete, and an item owned by the portal/super hotel can be shared with every property (and taken back) with one toggle.

A tenant can be fully deleted

Removing a tenant now actually removes everything it owns — records, uploaded files, cached usage — in one guarded action, restricted to super/portal admins and requiring the tenant's number to be typed back as confirmation before it runs.

All seven tenant settings, editable and visible in one place

The Tenants panel now shows and edits every per-tenant override (provider, approval mode, active, vision fallback, web-page privacy filter, and batch size) from one row — previously three of these were only reachable from a separate Settings page. An override that was stuck "on" with no way back to the default can now genuinely be cleared.

The anomaly alert can be customized per tenant

The wording an anomaly alert uses is now editable from the Notify panel, with the built-in default shown as a placeholder so an operator can see exactly what will be sent before changing anything.

Uploaded photos and videos are kept on disk

A photo or video attached in chat now has its bytes written to the tenant's own folder on disk, the same way document uploads already were — rather than only living inside the database.

Login and logout history

Every sign-in and sign-out is now recorded, so there's a real history of when someone accessed Ogent instead of a session simply expiring or being abandoned with no trace left behind.

Approvals show the actual reviewer, not "agent"

The approvals panel used to attribute almost every write proposal to a generic "agent" — a stored placeholder from when the write tools first queued the row. It now shows the real person's code, resolved live, so a renamed or re-coded user's older proposals display correctly too, not just new ones.

Decide many pending write proposals at once

The approvals panel can now select several pending proposals and approve or reject them together in one action, with a single shared reason applied to a batch rejection — instead of a separate click and confirmation dialog for every row. Each one is still checked individually, so a batch can partially succeed and reports exactly which ones went through.

See why a proposal was approved or rejected

A decided write proposal now shows the reviewer's own note explaining the decision, not just the outcome — useful when checking why something was rejected, or signed off, after the fact.

Bulk proposals show their real record count, flagged if it disagrees

A proposal that queues many records at once now shows a count badge next to it, taken from the actual data rather than repeated from its own summary text. If the written description claims a different number of records than the proposal really contains, the badge is flagged so a reviewer isn't approving a number nothing guarantees.

Background jobs panel shows how many are running

The Background jobs nav item now carries a badge showing how many jobs are currently queued or running, so there's no need to open the panel just to check whether anything is in flight.

Long-running skills as background jobs

A named skill can now be run as a background job instead of inside a single chat turn — useful for something like importing hundreds of records from a website. It's tracked in the Background jobs panel, can be cancelled, and drives itself through the whole task one item at a time until the work is genuinely finished.

Uploaded files now persist and can be managed

A file attached in chat is no longer only extracted for its text — the original file itself is now kept, and can be listed, downloaded, replaced, or deleted through the RAG panel. Uploads are automatically purged after a set retention window rather than accumulating indefinitely.

Video: upload, transcribe, and ask about what was said

A video attached in chat now has its audio transcribed and added to the knowledge base, so Ogent can answer questions about what was said in a recording, not just what appears on screen. The composer gained a dedicated video option and, on desktop, real webcam recording; on mobile it uses the device's own camera. A deployment without this set up refuses the upload with a clear reason instead of silently accepting a file it can't process, and asking "what's the upload limit?" now gets a real, deployment-specific answer.

One-click copy on ids shown in chat and the admin panels

An id shown anywhere — a background task id in a chat reply, a skill name, a record's key in an admin panel — now carries a small copy button, so acting on "how is <id> doing?" no longer means selecting text by hand. Ordinary values beside them are deliberately left plain so the buttons stay meaningful rather than becoming visual noise.

A record's code fills in from its description when left blank

Inserting a record that needs both a short code and a description no longer blocks on a missing code — Ogent derives one from the description's own words (Turkish included) and notes on the proposal that it did so. An explicitly typed code is never overwritten.

The scheduled-email sender address is editable without a redeploy

The "from" address used for the daily brief and pending-writes reminder emails can now be changed from the Settings panel and takes effect on the next send, instead of requiring a new deployment to fix a wrong address.

Fuller task confirmation

A created task's confirmation now also shows its MID, note and assigned departments beside the transaction number, plus the id and caption of any attached file. These were being hidden by rules that are correct for other records but wrong for a task.

Lost & found: found-item defaults and photo attachment

A lost & found record created from chat is filled in as a found item — who found it, when, and the correct Otello status — without the model needing to know Otello's status codes. The photograph is attached to the record exactly as it is for a maintenance task.

Per-table export button

Each table in a reply carries its own export button, exporting just that table: to Google Sheets when the tenant has a connected account, otherwise as an Excel file. The per-message export menu is unchanged and still exports the whole reply.

Cached answers about Ogent itself

Questions about what Ogent is and how it works are answered from cache rather than re-asked of the model each time. Only capability questions qualify — anything time- or data-dependent is never cached, and an answer is stored only when the turn used no tools.

Quick actions from a photo

After a photo is described, two buttons offer to create a maintenance task or a lost & found record from it directly. Each sends an ordinary chat turn, so the resulting write still goes through the usual approve-before-execute path.

Licensed tool domains

Tool areas a tenant is not licensed for are hidden rather than offered and then refused. A tenant without the POS module no longer sees POS tools at all.

Clear a user's cached login

An administrator can clear a user's cached login from the Sessions panel, forcing the next request to re-read that user's details from Otello. Useful when someone's Otello record changes mid-session.

The created record is shown after approval

Confirming a write proposal now shows what was actually created — the record's key and the fields Otello stored — rather than only a success tick. The values are read back from Otello, so they reflect the stored record rather than the request.

Over-long values are trimmed, and the trim is disclosed

A field longer than its Otello column now gets shortened at proposal time, with a note on the proposal saying what was cut. Previously Otello rejected the whole write with an error naming no field.

Background tasks

Long-running work — scanning thousands of records — now runs in the background instead of inside a chat turn: started from chat, tracked in an ⏳ Background jobs admin panel, and cancellable there. Every task reaches a definite end state, including when the pod that was running it dies.

Live progress documents

A background task mirrors its progress into a Google Sheet that updates while the job runs, so progress can be watched by someone without access to the admin panel. Rows are buffered rather than written per record, and losing the sheet never affects the job itself.

Settings, RAG, History and chat polish

Four requested interface improvements landed together (OGT.02/04/05/09): an editable description on RAG documents, a clearer export icon, and two History changes including dropping the redundant EMP column.

Tool-selection phase shown while it runs

The chat status line now shows which tool areas are being searched before the answer begins, instead of a silent gap. It reports the actual outcome — how many tools of the total, and which domains.

Every configuration value in Settings

All 65 configuration values are now listed, separated into those editable at runtime and those that need a restart. Previously only a chosen subset was visible, so an operator could not tell whether a setting existed at all.

Per-tab login sessions

Different browser tabs can hold different logins at the same time, so one person can work as two users without signing out. Sessions are per tab rather than shared across the whole browser.

Duplicate skip on bulk insert

A bulk insert can be told to skip records that already exist, checked server-side against Otello rather than by the model reading each row back. Re-running an import therefore adds only what is genuinely missing.

Bulk insert

Many records can be created in one call rather than one call per row, batched at a size each tenant can configure. This is what makes an import of a few hundred rows practical in a single conversation.

Per-tenant PII redaction on fetched pages

Whether Ogent masks personal data in a fetched web page is now a per-tenant choice rather than a fixed rule, and when it does redact it says so. Without the disclosure a masked page looked like a page that simply had no contact details.

Booking-engine links

A new tool returns the internet booking engine link for a tenant, or a link that opens a specific reservation. Useful for sending a guest straight to their own booking.

Per-message translation, shown beside the original

Translation moved from whole-conversation to per message, rendered next to the source text rather than replacing it, and streamed so long conversations appear progressively. The original is always kept visible, so a translation can be checked against what was actually said.

Google Docs creation

Ogent can now create a Google Doc, not only a Sheet — a document with paragraphs and real tables, built from the same report data as the spreadsheet export. It uses the same per-tenant credential, delegation, sharing and folder configuration as Sheets.

Maintenance task from a photograph

A photo uploaded in chat is read by a vision model and turned into a drafted maintenance task (tstrans): what is wrong, where, and how urgent. It is a proposal like any other write — a human still approves it before anything reaches Otello.

Settings page (per-tenant)

A new Settings page collects per-tenant configuration that previously had no interface: the Google Workspace connection, feature grants, and the vision-fallback choice. Everything on it was previously reachable only by direct API call.

Super Admin section

Deployment-wide settings are now visible in one place, with those that can be changed at runtime editable and the rest shown read-only. Restricted to the super/portal account, since these apply to every tenant at once.

Chat uploads filed by source

Files attached in chat are now filed in the knowledge store under chat/<source> — separating a camera photo from a document upload — so a tenant's own documents stay distinguishable from conversational attachments.

Per-message export menu

Each assistant reply carries an export menu offering Word (DOCX), Excel (XLSX), Google Docs and Google Sheets. The Google options are shown only when the tenant has a connected Google account.

The photo is attached to its task in Otello

The photograph that produced a maintenance task is now uploaded to Otello and linked to that task, so the record carries the picture rather than only a description of it. It is uploaded after approval, so a rejected proposal never leaves an orphaned file.

Link-following on web fetch

fetchWebPage can follow links from the page it was given, to a depth the user asks for, across any domain. Every followed link is re-checked by the same safety guard as the first, and the crawl is capped at three levels and twenty pages.

Google Sheets: sharing and folder placement

A created Sheet is now shared with the recipients configured for the tenant and filed into its configured Drive folder, instead of being left in the service account's own space. Both are best-effort: if sharing or placement is refused the document is still returned, with a warning naming what did not happen.

Conversation translation in History

A conversation in the History panel can be translated into the reader's own Otello language, so a manager can read a chat that took place in another language. Translations are cached per turn, so re-opening a conversation does not pay for the same translation twice.

Live web-fetch tool (off by default, granted per user/hotel)

Ogent can fetch and read a live web page when asked to, disabled by default and, when enabled, guarded against reaching internal/private network addresses.

Typed tools for higher-risk actions; image downscaling and camera capture

Nine new dedicated tools were added for specific higher-risk Otello actions, including irreversible e-invoice/e-archive submissions, which now require the model to name every document and ask before sending. Images attached in chat are downscaled automatically before upload, and a desktop user can capture a photo directly from their camera.

RAG sources show who added them, and mutations are audited

The RAG admin panel shows which user added each knowledge source, and every action that changes the knowledge store is recorded in an audit trail with the acting user.

Live progress narration during a chat turn

While Ogent works on a reply, the chat UI shows what stage it's in — understanding the question, checking a skill, retrieving knowledge, planning tools, running a specific tool, or composing the answer — instead of a static "Thinking..." with no further feedback.

Confirm/Reject and feedback survive a page reload

If a chat is reloaded after a write was proposed, the confirm/reject buttons for that pending item reappear instead of vanishing, and thumbs-up/down feedback on past replies is restored correctly.

Export reports to a downloadable spreadsheet

Any of Ogent's report tools can now be exported as a real Excel (.xlsx) file, delivered to the chat as a download link, instead of only being readable as text in the reply.

Create Google Sheets from reports (gated off by default)

The same report data can be written directly into a Google Sheet in the hotel's own Google Drive. Off by default pending Google Cloud setup, using one service account per hotel rather than per-user Google logins.

Temporary "just for this chat" attachments

Files attached in chat can be marked as temporary: scoped to that one conversation and removed afterward, instead of permanently joining the hotel's shared knowledge base.

Docked conversation-history panel

Viewing a past conversation's transcript in the admin History panel now opens a collapsible panel docked to the bottom of the window, rather than appending it below the table.

Dedicated reminder tool

Ogent can create a proper Otello reminder (not a task or another record type standing in for one) when asked for one in chat, in either English or Turkish, with a related tool to link a reminder to a record.

Ogent's own usage metrics available as a chat tool

A tool lets a user ask Ogent to summarize its own usage for a hotel — turns, tokens, tool calls, average response time, and thumbs-up rate over a recent window (up to 31 days) — previously visible only in an admin dashboard.

Self-service password reset link

Users can request a link to reset their own password rather than needing an admin to change it for them, scoped strictly to the caller's own account.

Write proposals show which tool made them

A pending write proposal now records and displays the actual tool that created it, not just a generic "write" label — useful for catching cases where the model picked the wrong kind of record.

Folders for organizing the RAG knowledge store

Knowledge sources in a hotel's RAG store can be filed under a folder (e.g. Front Office, Housekeeping, Finance) instead of sitting in one flat list — organizational only, it doesn't change what's retrievable.

Live progress when adding or updating a website in RAG

Adding a website, re-ingesting one, or editing its URL now streams progress (page-by-page crawl count, then embedding progress) instead of a silent wait until the whole crawl and embed finishes.

Namespaced skill names

Skill names now carry a prefix showing where they came from: a hotel's own skills are prefixed with that hotel's short code, and global skills are prefixed ogent-, so a hotel skill can no longer silently shadow a same-named global one.

Full Turkish/English translation of the admin UI

Every admin panel and the shared chrome (access-denied screen, System Info dialog, topbar, chat) is now fully localized. Previously only parts of the UI respected the language toggle.

Edit a RAG website source's URL in place

A knowledge-base source that points at a website can now have its URL corrected and re-crawled in place, instead of requiring the source to be deleted and re-added when a site moves or a URL was mistyped.

Named "Skills": reusable custom instructions for chat

Operators can author named "skills" — reusable blocks of instruction text that the chat assistant follows on request, invoked in chat without any code deploy. A skill can be defined globally or per-hotel, and grants no extra authority — every tool call it triggers still goes through the caller's own permissions and HITL write rules.

Public Otello/ORest status tools (no login required)

Three new tools let Ogent answer basic questions about the underlying Otello/ORest backend — its version, a live health check, and domain/hotel discovery — without requiring a login.

Configurable, multi-brief daily reports

The daily brief evolved from three fixed hardcoded lines into a fully configurable feature: a hotel can define any number of named briefs, each covering a chosen mix of business sections with its own editable analysis instructions, send time, and delivery channels/audience — managed from a new admin panel (create, edit, duplicate, delete, preview, test-send).

Ogent avatar and pending-approvals count in notifications

Outgoing Google Chat notifications now carry an Ogent avatar image, and a per-hotel count of pending write approvals so recipients can see at a glance how many actions are waiting for sign-off.

Runtime-managed API keys

API keys for accessing Ogent can be created, listed, and revoked at runtime from an admin panel, with the raw key shown only once at creation — previously keys were fixed in server configuration and changing them required an env-var edit and redeploy.

Rate-limit override pickers

The rate-limit override form in the admin panel now offers pickers for real users and hotels instead of free-text entry prone to typos, plus a bulk-add option to apply an override to every active user at once.

Tenant "active" flag now actually disables a hotel's chat

The Tenants admin panel's "Active" toggle now works as a real kill switch — turning it off blocks that hotel's chat turns with a clear message, while leaving it unset or unreachable never locks a hotel out by accident.

Admin panels scoped to the caller's own hotels

An admin's "All hotels" view in the approvals, audit, sessions, and knowledge panels now shows only the hotels they themselves have access to, not every hotel in the system — full cross-property visibility is reserved for a designated super-hotel account or the static admin key.

Unified React admin UI

A single-page admin application replaced the earlier static admin pages, giving one shared login, one navigation shell covering all admin areas, and a rebuilt approvals page — the foundation the rest of July's admin-panel work builds on. Chat moved to /chat, admin to /admin.

Runtime-editable rate limiting with an admin panel

Rate limits (master on/off switch, window size, per-key/tenant/user defaults, and per-identity overrides) can be changed at runtime from a new admin panel and take effect immediately — previously they were fixed at server startup and required a redeploy to change.

Upload a document into chat and have it added to the knowledge base

Users can attach a file directly in the chat window and have it extracted (including scanned/image text via OCR) and ingested into the RAG knowledge store for that hotel, so future questions can draw on it.

"Docs" mode for chat, and approve/reject writes with the feedback buttons

A "Docs" toggle makes a chat turn answer strictly from the ingested knowledge base instead of calling Otello tools. The existing thumbs-up/down buttons now double as one-click Confirm/Reject controls on a pending write proposal.

Guided reservation creation with availability and pricing

Ogent can look up room-type availability and quote an estimated total price for a stay, and follows a guided playbook when creating a reservation — searching for the guest and asking for confirmation before anything is inserted, rather than inserting speculatively.

Per-hotel licensing gate and master-user domain switcher

Logging in now checks that the hotel is licensed for Ogent and that the user has the Ogent access right, with a clear message distinguishing the two kinds of denial. A "master" user (recognized by email domain) can list and switch between Otello domains from the chat UI.

Writes attributed to the real user, with STAGED/DIRECT per-hotel approval mode

Every approved write now executes under the actual logged-in employee's own Otello identity rather than a shared service account, and pending approvals are stored durably so they survive a restart. A hotel can be configured for "DIRECT" mode, where a proposed action executes immediately on a simple "yes" instead of requiring a separate approval step, while "STAGED" mode still requires manager sign-off.

Proactive per-hotel notifications, including a daily brief

Ogent can push notifications on its own rather than only responding to chat — a scheduled job sends per-hotel alerts (initially a daily occupancy/arrivals brief) over Google Chat, in-app inbox, and email. Off by default per hotel until configured.

MCP Prompts and Resources

The MCP server now also publishes ready-to-run canned prompts (daily operations brief, guest lookup, pending-writes review) and read-only resources (service info, live tool catalog) to any connected client, not just callable tools.

Fifteen more one-click write actions

Fifteen curated, typed propose-and-approve tools were added for common front-desk and back-office actions — amend/extend-stay/early-checkout and room assignment for reservations, invoice/account payments, loyalty bonuses and card upgrades, RFM limit updates, housekeeping autofill, and survey answers.

Chat responses stream live, step by step

Chat replies now stream to the browser as the model works, showing each tool call's progress on its own line instead of waiting for the full answer — this also fixes a "failed to fetch" error some mobile browsers hit waiting on a long non-streamed reply.

RAG admin page, LLM performance dashboard, and pending-writes approver panel

Three new admin surfaces went live: a page to manage the knowledge store's ingested sources, a page to see LLM performance stats, and an approver panel where a manager can review, approve, reject, or execute pending write proposals from a browser instead of only in chat.

Audit trail, chat-history panel, and session-management panel

Ogent now persists and exposes a full audit trail of actions taken, plus two new admin pages: one to browse tenant-scoped chat history, and one to manage active login sessions.

Room housekeeping-state actions

Propose-and-approve tools let staff change a room's housekeeping state (clean, dirty, do-not-disturb, house-use, out-of-order, out-of-service) through the same human-approval workflow as other writes.

Connector sign-out

Users signed in through the Claude Desktop/connector (OAuth) path can explicitly log out, which revokes both the access and refresh tokens and forces re-authentication next time.

System Info shows model capacity

The System Info panel in chat now shows the model's parallel-request slots and context-window size (when the serving backend reports them), next to the existing reasoning-model line.

Self-status tool, generic insert/update/delete, FK auto-resolution, per-user access rights, counts

The assistant can answer "what's your status" in a chat turn (version, uptime, Otello connectivity, which features are enabled). Generic insert, partial-update, and delete tools let any entity be created/edited/removed through the same propose-and-approve write flow instead of needing a bespoke tool per entity — deletes get a pre-flight "can this be deleted" check, and inserts/updates can resolve a typed name or code to its internal ID automatically, asking the user to pick if it's ambiguous. Per-user, per-module Otello access rights are now enforced, and a new "how many" counting tool answers record-count questions directly.

Claude custom-connector (OAuth) support

Ogent can be added as a custom connector in Claude (web and Desktop) via OAuth, rather than requiring a manually-configured API key — Claude registers as a pre-approved client and authenticates the end user against their real Otello credentials. The Claude mobile app does not support this connection, an Anthropic-side limitation rather than an Ogent one.

Generic "search any entity" tool; feedback PII redaction

A generic search tool lets the assistant search any Otello entity by free-text fields and a date range, without needing an entity-specific tool written for it — later hardened to validate requested fields against the entity's real schema. Separately, PII is now stripped from stored user feedback before it can influence the few-shot learning library.

Client SDK for chat and writes

A dependency-free Java SDK (ogent-sdk) let external applications call Ogent's chat and human-in-the-loop write endpoints without hand-rolling HTTP calls, quickly broadened to cover the full REST surface.

End-user login, multi-tenancy, and per-tenant LLM/billing

Ogent gained an optional per-user login mode (instead of only a shared service account), a multi-tenancy foundation that isolates data per hotel property, per-tenant selection of which LLM provider serves a given hotel, an admin API for provisioning/configuring tenants at runtime, and per-tenant usage/billing metering. Nearly everything here ships gated off by default, enabled per deployment.

Agent2Agent protocol, smarter RAG, and the first subagents

Ogent became able to speak the Agent2Agent protocol, both as a server other agents can call and a client that can delegate to peer agents. It also gained a smarter retrieval-gate-plus-reranker RAG pipeline, and its first specialized subagents (reservation/finance/housekeeping) coordinated by a planning orchestrator that can break a task into steps and run them.

Resilience, full entity coverage, safety guardrail, tracing, and the full feedback loop

A circuit breaker now protects every Otello API call so a slow/flapping backend fails fast instead of hanging every tool call. Fourteen more ORest entities (stock/inventory and HR) became tool-searchable, essentially completing broad API coverage. A prompt-injection guardrail now screens every chat message before it reaches the LLM or any tool, and tool-call/chat spans are exported as OpenTelemetry traces.

Automated evaluation, feedback analytics, audit trail, and role-based tool access

Ogent shipped its first automated tool-contract evaluation suite (runs in CI), a few-shot example library that improves chat answers over time, an analytics endpoint surfacing which tools/questions get negative feedback, a structured per-turn audit trail, and role-based tool access — an API key can now carry a role that restricts which tools it can use.

Human-in-the-loop writes go live (gated)

A propose/approve/reject/execute scaffold for write actions shipped, and — building on it the same day — write proposals began actually executing against live Otello when explicitly enabled: reservation cancellation, guest-contact updates, and reservation check-in/check-out/hold all became real (opt-in, human-approved) actions rather than read-only lookups.

RAG goes live with real embeddings; five more tool sets; first ops guardrails

Layer 4 RAG was wired to a real embedding model and Redis vector store (still gated off by default) and seeded with ORest's own field-schema docs so the assistant grounds answers in the actual data model. Five more tool sets shipped: hotel info, date-range reservation search, room-state search, invoices, and core finance entities. Chat errors now return clear, structured messages instead of bare 500s, and Ogent gained a Prometheus metrics endpoint with a Grafana stack, automatic PII redaction in logs, and a load test simulating 50 concurrent MCP sessions.

API-key protected MCP server, Docker deployment, and gated RAG/chat layers

/mcp and the REST API are now secured behind a Bearer API key by default. Ogent ships as a Docker image with Redis, and the groundwork landed for two major (still-off-by-default) capabilities: a knowledge/RAG layer that can retrieve grounding documents, and a reasoning/chat layer (/api/v1/chat) that lets an end user hold a conversation with tool-calling built in, defaulting to Claude.

Self-hosted LLM option for reasoning

Ogent's chat/reasoning layer can be pointed at Hotech's own self-hosted LLM gateway instead of only a cloud provider, useful for dev/test environments without external API costs.

Five more tool sets: events, room types, sales actions, contracts, tasks

Reservation events, room types, sales actions, contracts, and staff tasks became queryable, rounding out the early tool coverage beyond the original vertical slice.

First read-only tool set and MCP server

Ogent stood up its Model Context Protocol server and shipped its first AI-callable tools: searching and looking up reservations, guests/contacts, rooms, companies (agencies), folios, folio transactions, and point-of-sale data. This is the first point an AI assistant could actually ask Ogent real hotel questions.

Identity layer against Otello

Ogent can log in to a live Otello ERP as a service account, keep its session token refreshed automatically, and detect when a login requires two-factor authentication. Foundational plumbing with nothing user-facing yet, but the ERP connection itself now works end to end.