What's new
A factual summary of what has been built, by roadmap phase. The tracker (roadmap) holds the status of every item and the decisions record why. Items that are only partly done are marked as such there; this page lists what works.
Phase 0: foundation
Section titled “Phase 0: foundation”- A monorepo (
api/,admin/,front/) with the 50 PHP packages vendored underapi/packagesand noescolalms/*dependency: Monorepo, API packages. - Laravel 13 on PHP 8.4 (with Passport 13 and a data migration for every tenant), and the
recommenderpackage removed. - Styling with CSS custom properties only; the shared component library
@ulams/uiwith a component playground in this site. - Multi-tenancy by host with one command to create, list and delete tenants: Tenancy, Tenants, First tenant.
- H5P as a separate Node service, with the PHP H5P server removed: H5P for operators.
- Security work: payment and Jitsi callbacks verified, LRS tokens verified, upload hardening, no committed secrets
(Security);
ulams:upgrade, one idempotent per-tenant upgrade command (Upgrades); a scheduler that runs each minute once even on several nodes (ADR 0068, Queues and scheduler). - Smaller admin and front images on unprivileged nginx (Images, Container images).
- Demo mode with seeded admin, tutor and student users and an hourly reset: Demo mode.
- This documentation site, the brand identity (Brand) and the CI that checks them (CI).
Phase 1: content formats and integrations
Section titled “Phase 1: content formats and integrations”- LiaScript topics with versions and a preview: LiaScript.
- Adapt Learning: import a built package, and build from JSON source with an admin screen for sources, versions and build status: Adapt.
- LTI 1.3, both as a platform (launch external tools, grade passback, deep linking, Names and Role Provisioning
Services) and as a tool for Moodle or Canvas, with client-side OIDC through
postMessagestorage and monthly key rotation: LTI, LTI tools, LTI launch. - cmi5 with one-time launch tokens and playback from the content origin: cmi5.
- Upload hardening and an isolated content origin for SCORM, Adapt, LiaScript and cmi5, with same-site cookie hardening, exact-Origin checks, sandboxing and a CSP that reports first and then enforces: Content origin, Security headers.
- H5P multi-tenancy, learner state through a proxy, and cleanup of unused content: H5P, H5P for operators.
Phase 2: AI Course Builder
Section titled “Phase 2: AI Course Builder”- An LLM layer with a model per task chosen in configuration, validated structured output, prompt caching, per-call logging of model, tokens and cost, and hard limits: LLM layer.
- Ingestion of PDF, Markdown and DOCX into source documents with stable fragment ids, treated as untrusted input.
- An interview with defaults (“decide for me”), an editable course brief, then objectives, outline, lessons, quizzes and metadata that the author approves, each element citing its source fragments: Course builder, Administering the builder.
- Element-level chat editing as reviewable patches, versions with diffs and undo, and live progress over an AG-UI event stream: Course builder API, Generative UI.
- Long runs on dedicated queue connections with their own
retry_after: Performance.
Phase 3: Living Course
Section titled “Phase 3: Living Course”- Sources that stay connected to a course: upload, URL and Git connectors, with change detection by webhook, poll or manually and a fragment-level diff.
- Impact analysis through citations, update proposals reviewed as one diff, progress rules that keep completion on a minor edit, staleness signals, learner notices and an audit trail: Living Course (admin), Living Course (developers).
- Inbound webhooks and their signatures: Webhooks.
Phase 7: CLI, MCP server and API
Section titled “Phase 7: CLI, MCP server and API”ulamsCLI with one command registry for humans and agents: a stable JSON contract and exit codes, profiles, device login, a command for every API endpoint (504 of 547 operations covered, the rest excluded with a reason), uploads for every topic type, declarativeapply, andulams tenantsfor platform hosts: The CLI, CLI reference, Course-as-code examples.- Course builder and Living Course commands with NDJSON events: Build courses from the command line.
- MCP server
ulams mcpover stdio and Streamable HTTP, with toolsets, read-only mode and confirmation tokens for destructive tools: ulams for AI agents, Claude Code. - Scoped API tokens (
ulams_pat_), the agent audit log, idempotency keys, request ids, device login in the RFC 8628 shape, andGET /api/meta: Scoped tokens, Rate limits, API tokens (admin), My tokens, CLI sign-in. - Platform tenant API for queued tenant provisioning, off by default: Platform tenant API.
- OpenAPI and
@ulams/sdkregenerated from the API, including the builder and Living Course: OpenAPI and SDK, SDK usage.