<p>A version number is a promise. For months, Elyra Workspace has been 0.something, and "0.something" has a way of letting you off the hook. It means: this works, mostly, and if it doesn't, well.</p><p>1.0 is us taking that off the table. Not because everything is finished, but because the things that go wrong in a tool that runs coding agents all day have a specific shape, and we've spent the last few releases closing them one by one. 1.0 is the release where we're comfortable saying: leave an agent working, close the lid, and come back to something you can trust.</p><p>So this isn't a release about a big new feature. It's about five small questions, and an answer to each.</p><h2>"Did it actually test what it built?"</h2><p>Agents are good at writing a flow and bad at noticing it doesn't work. They'll tell you the cart is fixed, because the code looks right.</p><p>Since 0.2, Workspace has had a browser in the tools panel, and agents could look at a local page: its structure, elements and styles, the console, the network calls, a screenshot. In 1.0 they can use it, the way you would:</p><ul><li><p>click, by selector or by visible text,</p></li><li><p>fill in fields, by selector, label or placeholder (selects and checkboxes too),</p></li><li><p>press keys, and</p></li><li><p>wait for something to appear.</p></li></ul><p>So you can ask, in one message:</p><blockquote><p>Open localhost:5173, check why the cart total is wrong, fix it, then add two items, apply the code SUMMER and check the total.</p></blockquote><p>The agent fixes the bug, then goes and does the thing: adds two items, types the code, presses &lt;kbd&gt;Enter&lt;/kbd&gt;, waits for the total, and tells you what it saw. That's the difference between "I changed the code" and "I tried it".</p><p>Clicking and typing is a different kind of power from reading, so there are guard rails:</p><ul><li><p><strong>The first time, you're asked.</strong> <strong>Don't allow</strong>, <strong>Allow once</strong> or <strong>Allow for this thread</strong>. While it's allowed, a bar above the page says so, and <strong>Take over</strong> withdraws it. Threads in <strong>Full access</strong> aren't asked, because you've already said yes to everything.</p></li><li><p><strong>Local pages only.</strong> Agents can only open, read and use pages served from your own Mac: <code>localhost</code>, <code>127.0.0.1</code>, <code>[::1]</code>, and names ending in <code>.localhost</code>, <code>.test</code> or <code>.local</code>. Any other site is refused by the tools.</p></li><li><p><strong>No passwords, no scripts.</strong> Agents never read password fields, and they can't run their own scripts in the page.</p></li></ul><p>We also had to correct something we'd written. Our own page used to say agents "cannot click, type or run scripts in it". That was true in 0.2 and isn't now, so it's gone, and the new sentence says exactly where the lines are.</p><h2>"Did it really pass the checks?"</h2><p>In 0.10, <em>Done means green arrived</em>: give a project a check command, and after every turn that changed files it runs, and the thread isn't done until it passes.</p><p>That had a hole, and we found it the way you find most holes, by watching it happen. Whether a turn "changed files" was judged by comparing the working tree before and after. A quick agent could change something and put it back before the comparison, and the checks never ran for a change that had been real a moment ago.</p><p>In 1.0, the comparison is made against the snapshot taken before your message reached the agent. A quick agent can no longer slip a change past the checks.</p><p>A related fix: when an interrupted turn is resumed, the agent is first asked to check what already happened before it continues. Say a turn was halfway through renaming a set of files when the Mac went to sleep. It no longer redoes the half that was finished, because it's asked to look first. Nothing is done twice.</p><h2>"Can I leave it overnight?"</h2><p>This is the 1.0 question, and it's why two lines in the changelog matter more than the rest.</p><p><strong>Back to the previous version.</strong> Each update keeps the version it replaced. If a new version fails to start twice in a row, Elyra Workspace goes back to the previous one by itself, says so, and skips the broken version until the next release. You can also do it by hand: command palette → <strong>Go back to the previous version…</strong></p><p>If you run agents unattended, a self-updating app is a risk of its own: the night an update lands is the night a bad build can wedge your whole workflow. Now a bad build costs you a message that says "I went back", not a morning of lost work. (Running agents stop when it happens, and each thread can be resumed.)</p><p><strong>Every push runs the real app.</strong> Elyra Workspace is also tested end to end now, on every push. The app runs headless, with no window, Dock icon or update checks, in a throwaway home folder. A scripted agent drives it through the agent gateway, and the agent misbehaves on cue: it changes a file, changes nothing, crashes mid-turn, fails the turn, or waits to be stopped. The scenarios cover the turn's lifecycle, the checks after each turn, and stopping.</p><p>It sounds like an internal detail. But the bugs in a tool like this are rarely in the happy path; they're in what happens when an agent crashes halfway. Now the crash is a test, not an incident.</p><h2>"Will it work with the agent I switch to?"</h2><p>Workspace runs Claude Code, Codex, Elyra, Pi and any ACP agent. For a while, they weren't equal in one small way: Claude Code picks up your project's <code>.mcp.json</code> and its skills by itself, and the others didn't.</p><p>In 1.0, one setup serves every agent. A project's MCP servers and its skills (<code>.claude/skills</code>, <code>.agents/skills</code>, in the project and in your home folder) now reach Codex, Elyra, Pi and ACP agents too. Switch agents halfway through a project, and the tools come with you.</p><p>(One caveat from the docs: ACP agents don't take extra instructions, so they get the servers but not the skills list.)</p><p>There's a trust question hiding in here, and we want you to see it. <code>.mcp.json</code> runs commands from the repository. A file that comes with a repo you cloned yesterday can say "start this program", so it's shared only after you allow it in the <strong>Context</strong> tab, and you're asked again when the file changes. <strong>Stop sharing</strong> takes it back. We'd rather ask once too often than start somebody else's program silently.</p><h2>"Can the agent set up the boring part for me?"</h2><p>Ask in a thread:</p><blockquote><p>Check our dependencies every weekday night.</p></blockquote><p>With the agent gateway on, the agent doesn't just say "sure". It proposes the automation as a card in the thread: the schedule and the next run, the agent, the project, the prompt. Three buttons: <strong>Create</strong>, <strong>Edit…</strong> and <strong>Dismiss</strong>. <strong>Create</strong> schedules it as it is, <strong>Edit…</strong> opens it in the editor first, and <strong>Dismiss</strong> drops it.</p><p>Nothing is scheduled unless you accept. The point isn't that an agent now schedules things. It's that you no longer have to open an editor and type out what you just said.</p><h2>And a small thing for your laptop</h2><p>A narrow window used to let the conversation get squeezed into a sliver. Now it keeps at least 400 points, and the tools panel gives way first. Notices wrap instead of running into the panel, long tab titles end in "…", and the panel's own tabs scroll with a ▾ list when they don't fit. Not a headline, but it's the sort of thing you notice on the train.</p><h2>Why 1.0, then</h2><p>Because every item above is the same answer to the same question: what happens when I'm not watching?</p><ul><li><p>The agent tries what it built, with your permission, on your own machine.</p></li><li><p>The checks see every change, however fast.</p></li><li><p>An interrupted turn checks before it repeats itself.</p></li><li><p>A bad update undoes itself.</p></li><li><p>The crashy parts are tested on every push.</p></li></ul><p>That's what we think "1.0" should mean for a tool that runs other people's models on your code. Not "finished", but "ready to leave running".</p><h2>Try it</h2><p>Workspace 1.0 is out now. If you already have it, the app updates itself: it checks GitHub at launch and installs a new build only if its checksum matches, it's signed by the same Developer ID team as your copy, and Gatekeeper accepts it. And if that build ever fails to start twice, you'll now find the previous one back in place.</p><p>New here? It's a signed, notarized DMG for macOS 12 or later on Apple silicon, free and open source. Download it at <a target="_blank" rel="noopener noreferrer nofollow" href="https://elyracode.com/workspace">elyracode.com/workspace</a>, and see the full release notes at <a target="_blank" rel="noopener noreferrer nofollow" href="https://elyracode.com/docs/workspace/changelog">elyracode.com/docs/workspace/changelog</a>.</p>