Breaking ChangesFeaturesImprovementsBugfixesDocumentationDeprecations and Removals
Breaking Changes
-
#7296: The event
broker, timer store, and remote model server are read only from
integrations.yml.event_broker:,timer_store:, andmodels:blocks inendpoints.ymlare now ignored, and startup logs a warning. Move them toevent_broker:,timer_store:, andrasa_model_server:inintegrations.yml. -
#7289: The orchestrator model group is named with
orchestrator.model_groupinagent.yml. Optionalorchestrator.max_prompt_tokensdefaults to 8000.integrations.ymlmust not contain anllm:section; define the group undermodel_groups. Existing projects need that name added and a retrain. -
#7217: Unknown top-level keys in
skill.mdfrontmatter are rejected at train. Remove the extra key.
Features
-
#7296: You can
configure the event broker, timer store, and remote model server under
integrations.ymlinstead ofendpoints.yml. Userasa_model_server:for the remote model server, not themodelslist inside a model group. With no local model,rasa runpoints atintegrations.yml. See Event broker, Timer store, and Remote model server. -
#7224: A tool can now hand
off to another skill by returning
ToolResult(next=[ActivateSkill(skill_id=...)]). The skill activates after the tool’s result is recorded, following the same rules as the LLM’sactivatetool. SeeActivateSkill. - #7217: JSON Schema for Mantle authoring files is published under Reference → Schemas, generated from the models that load those files, including skill frontmatter and preconditions.
Improvements
-
#7145:
on_model_request/modify_model_requestandon_model_response/modify_model_responsealso run on rephrase, confirm-rephrase, and the post-activateset_fieldsfill. A request-hook crash does not send that prompt.RetryModelon those calls discards the completion instead of starting another main-loop iteration. -
#7227:
rasa exportpublishes Mantle ProtoJSON when--integrationspoints at an existing integrations file (defaultintegrations.yml). Classic projects keep flat events. -
#7257: Training or validating a Mantle project that has no skills reports that no
skills/<id>/skill.mdfiles were found. - #7284: When training fails on a Mantle project, Copilot’s analysis now searches the Mantle documentation, as Copilot chat already does.
-
#7292: Mantle trackers now
record skill, block, and memory changes only as
skill_*,ordered_block_*,memory_set, andmemory_clearedevents; the classicflow_*andslot_setcopies are no longer written. Conversations recorded with those copies still load.
Bugfixes
- #7250: Resuming an older
paused skill with
activatepauses the task in progress and keeps newer paused tasks on the stack. Returning to that skill or to its block also keeps an earlier block of that skill that was parked by a block switch, and finishing the resumed block continues that earlier block. When the resumed task finishes, the user is offered to continue the nearest paused task. - #7145: When activating a skill lands on an ordered block that would immediately wait for the user, a collect or settable memory value already stated in that same message is recorded before the skill asks for it again.
Documentation
- #7275: A best-practices page covers what to put in memory, responses, constraints, and ordered blocks when a sentence in the skill body is not enough.
- #7272: Skill-writing guidance now says when to name another skill with
@skill.<id>so a related request stays part of the current task, and when to leave a topic change alone.
Deprecations and Removals
- #7284:
rasa tools runno longer offers thesearch_rasa_documentationtool, which searched the CALM docs. Your coding agent reads the Mantle docs in.rasa/docs/mantle/through themantle-docsskill; add them to an existing project withrasa tools init docs mantle.
Breaking Changes
- #7242: Tracing and
metrics are read only from
integrations.yml.tracing:(including Langfuse) andmetrics:blocks inendpoints.ymlare now ignored, and startup logs a warning. Move them totracing:andmetrics:inintegrations.yml.
Features
- #7242: You can configure
OpenTelemetry tracing (
otlporjaeger) and OTLP metrics underintegrations.ymlinstead ofendpoints.yml. List Langfuse and an OTLP or Jaeger tracer together undertracing:to use both. A Jaeger entry withusername/passwordmust setinsecure(falseexports over TLS). See Tracing and Metrics.
Breaking Changes
- #7156: Models trained before skill retrieval that still have independently startable skills must be retrained before they will load (or set
skill_retrieval.active: false). Omittingskill_retrievalleaves retrieval on. - #7189:
rasa trainrequires a non-empty skilldescription, rejects unknownskill.mdfrontmatter keys and non-stringname/description, and fails on incomplete@skill/@block/@tooltokens. Bundled default skills are checked the same way. Seeskill.md.
Features
- #7156: Mantle agents can now retrieve a subset of independently startable skills for routing.
skill_retrievalis on by default; setactive: falseto keep the full routing catalogue. - #7157: Skill retrieval can pin skills with
always_include_in_promptand keep recently started skills in the routing catalogue. A search outage fails the turn instead of listing every skill. This is not knowledge search (search_knowledge). - #7282: A collect step can accept keypad input via
dtmf, usinglengthorfinish_on_key. Setallow_audio_input: falseto ignore speech while digits are expected.
Improvements
- #7223: Inspector NextGen now shows Mantle conversation events in nested ProtoJSON form while still accepting classic flat event JSON. Mantle inspect tracker dumps and downloaded logs preserve the ProtoJSON envelopes for replay.
Bugfixes
- #7268: The first message of a new conversation no longer activates a skill before that message is visible.
- #7183: Skills can import an MCP tool when an unused shared tool has the same name without causing model loading to fail, including when that MCP tool is gated with
tool_constraintsor ordered-blocktools.
Documentation
- #7260: Builders can look up Mantle’s default skills and the wording of the built-in messages.
- #7262: Docs call
run_after_setting_<entry>tools memory validation tools.
Deprecations and Removals
- #7260: The unused default response
utter_ask_how_to_helpis removed. Completed still asks withutter_ask_wants_to_continue.
Improvements
- ENG-3360: When
modify_model_requestormodify_tool_callcrashes or times out, or the main model call fails, the user hearsutter_model_request_hook_error,utter_tool_call_hook_error, orutter_model_call_errorinstead of silence. Override those names inresponses.yml. The exception text is not spoken, andrephraseon those responses is ignored.
2026-09-29
Breaking Changes
-
#7185: Mantle model
credentials must use
api_key: ${ENV_VAR_NAME}(and the same${…}form for other sensitive model keys). Literal secrets are rejected. See Secrets. -
#7104: Skill-level
requiresis rejected at train. Usepreconditionplusagent.ymlorchestrator.preconditionsto run a resolver first, orhidden: trueto omit a skill from routing. Tool-levelrequiresundertool_constraintsis unchanged. Seeprecondition,preconditions, andhidden. -
#7056: Mantle tracker
persistence and the event broker now use nested ProtoJSON for conversation
events instead of flat
"event"JSON. Classic (non-Mantle) projects are unchanged. See Conversation events. -
#7170: The default voice
silence timeout is now 30 seconds (was 7). Set
silence_timeouton the voice channel inintegrations.ymlif you need a different wait.
Features
-
#7104: Skills can declare a semantic
precondition, and projects bind it inagent.ymlorchestrator.preconditionsso the engine parks the consumer, runs a resolver skill, then continues or abandons the request without hiding the skill from routing. If the resolver is already the active skill, the consumer is parked under that run instead of interrupting it. Skills can also sethidden: trueto stay off the routing catalogue while remaining startable viacall,linkorresolve_with; prose@skillmentions of a hidden skill fail validation. Inspector labels a parked consumer as pending while the resolver is the active skill. -
#7035:
on_incoming_message/modify_incoming_messagenow run on final user text before it is stored. Modified text is what gets stored and what the turn runs on. Rejected text and fail-closed hook errors stay on the tracker as discarded, are omitted from model and completion-judge history, skip the user-message orchestrator turn, and are answered with response templates:HookRejection.response_messagemay select a bot-defined response, while failures useutter_incoming_message_rejected. When that first payload also opens a session,default_session_startstill runs so session-start memory writes apply, and named reject replies are resolved after that turn. See Hooks. -
#7107:
on_outgoing_text/modify_outgoing_textnow run once on each completed agent utterance, including fillers. Modified text is stored and sent; rejected text is dropped without being stored and replaced with a response template (HookRejection.response_messageorutter_outgoing_text_rejected), so the tracker only ever records what the user actually received.modify_outgoing_textbuffers streamed output until the whole utterance passes the hook; observe-only hooks do not. Incoming-message rejection replies also pass these outgoing hooks. See Hooks. -
#7187: Train and validate fail when
skill.mdprose references@tool.<name>for a tool that does not exist or is not visible to that skill. -
#7170: After three silence-timeout check-ins,
the next consecutive silence ends the call with a goodbye. A skill can do the same with an ordered-block
action: hangupafter an authored goodbye response.
Improvements
- #7105: Mantle conversation
events now include stable
event_idandsequencefields so consumers can order and deduplicate reliably. - #7130: Mantle ProtoJSON now covers the remaining conversation event types (session, voice, skills, ordered blocks, and related engine events).
- #7159: Voice Conversations
now distinguish backchannels from barge-ins, ignoring backchannels while
recording them as
user_input_suppressedevents. Voice channels download an approximately 90 MB NLI cross-encoder model from Hugging Face for this classification; by default, it applies to transcripts shorter than three words with a 0.5 confidence threshold, configurable throughmin_wordsandthreshold.
Bugfixes
- #7162: Paged collects can now clear a button choice and return to the same collect to show refreshed dynamic buttons without an explicit listen step or an LLM turn.
- #7202: Memory saved during a conversation stays available when the assistant uses Postgres, Redis, or another tracker store, so collect steps continue and tools see the values they require.
- #7191: Agents no longer receive
set_fieldsprompt guidance when the tool is unavailable for the current turn.
Documentation
- #7130: Documented Mantle conversation event ProtoJSON under Conversation events, including the dual-write skip list and golden fixtures for consumers.
- #7188: Mantle documentation now uses Rasa’s rebrand colors and typography for a consistent visual experience.
Breaking Changes
- #7123: The bundled
default_session_startskill no longer greets. Override that skill and send/session_startwhen the agent should speak first. See Start a conversation.
Features
-
#7025:
on_turn_started/on_turn_finishednow run around each Mantle turn. Builders can observe turn start and the finalcompleted/cancelled/errorstatus without blocking the turn. See Hooks. -
#7024:
on_knowledge_query/modify_knowledge_queryandon_knowledge_results/modify_knowledge_resultsnow run aroundsearch_knowledge. Builders can rewrite the query or filter/reorder retrieved passages; neither point acceptsHookRejectionorRetryModel. Query-hook crashes are fail-closed (search skipped); results-hook crashes are fail-open (original passages kept). See Hooks. -
#6972: Dynamic button source
tools are engine-only and validated by
rasa train; missing, MCP, and confirmation-gated sources are rejected, while invalid runtime button references are omitted without dropping valid siblings. -
#6969: A response variant can
name a tool with
buttons: {source: <tool_name>}, and that tool supplies the buttons for the message withcontext.set_buttons([...]). Buttons built with arefwrite the chosen value to memory on tap, exactly like a staticset:session.<skill>.<entry>=<value>button; the message is sent without buttons when the tool returns none or fails. -
#6707: The model can now wait for the next user message without sending a reply,
by calling the reserved
listentool after a question already asked this turn. Guided collect steps, post-search answer calls, and pending tool confirmation do not offer this tool. Mixedlistenplus text or other tools ignoreslisten. -
#6760:
on_model_request/modify_model_requestnow run on each main LLM loop iteration. Builders can rewrite provider-bound messages and allowlisted per-callmodel_settings(temperature,top_p,max_tokens,presence_penalty,frequency_penalty,stop,seed). Empty-completion retries reuse that hooked request without re-running hooks. Credentials, provider/model, and tools stay engine-owned; this point has no intentional veto (HookRejectionis not accepted). See Hooks. -
#6771:
on_model_response/modify_model_responsenow run after each main LLM completion and before any user-visible emit or tool dispatch. Builders can rewrite response text and tool calls, or raiseRetryModel(feedback=...)to discard the response and steer the next iteration with an engine-only system note.HookRejectionis not accepted at this point; unexpected crashes, timeouts, or invalid returns are fail-open. A registered response modifier buffers the main completion (no live token stream) so rewrites and retries match what the user hears. See Hooks. -
#7023:
on_tool_call/modify_tool_callandon_tool_result/modify_tool_resultnow run on the LLM tool-call batch path. The engine prefights every proposed call before any tool runs;RetryModeldiscards the whole batch (including accompanying text) and steers the next iteration. A registered tool-call modifier buffers the main completion (no live token stream) so retries and fail-closed crashes cannot leak speech. Modified arguments reach dispatch; modified results are whatMcpToolExecuted/ToolExecutedstore and the next prompt replays.HookRejectionis not accepted on tool calls; tool results have no control signals. Confirmation resume, settable writes, and correction replay do not invoke these hooks. See Hooks.
Improvements
-
#6987: Session-start
channel metadata on Mantle conversations is now recorded as a
memory_setevent (with write provenance), so Studio and other consumers can read it without relying on a legacyslotevent for that value. -
#6895:
context.memory.getaccepts an optional default. Unset,None, or unreadable fields return that fallback (get("card_list", [])is[]) instead ofNoneor aTypeError. Local tool failures logerror_typeat ERROR and the exception message at DEBUG. - #6831: Inspector bot-turn latency details now include time spent in earlier LLM calls, making multi-step and tool-driven responses easier to diagnose.
-
#6824:
complete_skillis offered when the active skill has prose instructions, including while a hybrid skill is in an ordered block. Ordered-block-only skills omit the tool and finish when the block ends;cancel_skillis still available. -
#6773: Voice conversations now
process overlapping transcripts normally and preserve rejected barge-ins or audio
blocked during DTMF collection in the new
user_input_suppressedtracker event. -
#7144: Evaluation scenarios can
now assert skill and ordered-block lifecycles, memory writes and clears, and tool runs,
including several tools in one user turn, and can check those facts in order.
Inspector downloads include these assertions. A Mantle run rejects
slot_was_set,slot_was_not_set,generative_response_is_relevant, andgenerative_response_is_grounded. Use the memory assertions for written state.
Bugfixes
-
#7161: Hybrid skills no
longer offer
complete_skillwhile an ordered block is active, preventing repeated refused completion calls before the block finishes. - #7123: When a new or expired session starts on a real user message, that message is now handled in the same request instead of being answered only after the next turn.
-
#7060:
complete_skillno longer intermittently refuses to complete a skill whose exit criteria were actually met, which could otherwise re-engage the caller with an unnecessary step after the conversation had already wrapped up. - #7057: Copilot documentation search now finds pages on the current docs site and omits unpublished drafts.
- #7052: Mantle voice calls now keep processing spans in a single call trace, making individual calls easier to debug.
- #6968: Voice agents now release LLM requests as soon as response generation completes while speech continues in order and remains interruptible.
-
#6863:
context.memory.set("project.<entry>", …)andcontext.memory.set("<active_skill>.<entry>", …)now write the named field instead of failing as undeclared, matching howgetalready resolves those names. An own-skill qualified name does not fall through to project memory. Cross-skill writes stay rejected. -
#6906: Skills with
complete_whencriteria no longer refuse exit when an early path detail that exempts a requirement (for example a damaged-card reason) was pushed out of the completion check by multi-message bot replies. - #6826: After a canned ordered-block reply, leftover hybrid prose can continue on the same turn instead of waiting for the next user message.
- #6847: Custom default skills now start from their configured entry and are discarded cleanly when the customer moves to another task.
-
#6846: After a customer
answers a tool confirmation, repeated same-turn LLM calls no longer ask for
confirmation again; unanswered confirmations are still re-asked after a
digression. A later ordered
execute_toolstep of the same tool can still ask again in that turn.
Documentation
- #7080: New
Writing prose page covers how to word a skill’s
descriptionand body. Name the subject before the action in a description, and separate them with a dash, so routing matches on the thing being asked about. - #6850: Skills that use
requires_confirmationmust not also ask for confirmation in prose — pick one mechanism so the customer is not prompted twice. - #6762: Clarified hook
control-flow semantics, including
RetryModelfeedback as a non-persisted system note, sequential multi-toolmodify_tool_callpreflight, discarded text handling, and unavailable audio hooks.
Deprecations and Removals
- #6912: Skill
deny_read/deny_writelists are removed. Memory visibility and writes follow public, private, and project scopes only. Leftoveraccess:/deny_read/deny_writekeys in skillmemory.ymlare ignored and are not enforced.
Breaking Changes
- #6729: Skill-level
complete_whenmust be a mapping withconditionand/orcriteria(bare strings are rejected). Use it on skills that have prose instructions; ordered-block-only skills cannot declare it (they finish via block end without this gate). When authored,complete_skillis hard-gated on those requirements and is refused while an ordered block is active. See skill.md.
Features
- #6783: The live conversation
stack now distinguishes skills from ordered blocks. Guided skills show the
skill together with a
mainblock. Inspector and Copilot display this stack shape. Pre-existing Mantle conversations that still use the previous flow-based live stack still load and replay, but are not upgraded in place — restart the conversation (including any in-flight Inspector session) before continuing under the new stack shape. Block-levelflow_*events are still written as well. - #6732: Mantle voice agents can now
respond when a user remains silent for the configured timeout through the customizable
default_silence_timeoutskill. Silence timeouts and their configured duration are recorded in the conversation tracker and included in the agent’s conversation context. - #6729: Optional
complete_when.criteria(sentences in natural language) are checked oncomplete_skill. The check fails closed: timeouts, errors, or malformed judge answers refuse completion (skill stays active) instead of treating the skill as done. With criteria present, condition-only auto-complete is disabled.
Improvements
- #6800: Large FAQ files under
references/now train without a manual split, andsearch_knowledgereturns the matching section. Builders can set character chunk size and overlap underreferences.chunking.
Bugfixes
- #6729:
complete_skillis refused while a tool confirmation is pending for the active skill. Resolve or decline the confirmation first;cancel_skillstill abandons the skill. - #6787: When a user revises a
value the agent already captured, a refused memory write is now reported as an
error and the agent is told to use
correctinstead of silently keeping the old value. - #6759: Invalid LLM-issued
local and MCP tool calls now return a retryable result to the model instead of
running the tool or sending its
on_failureresponse. Orderedexecute_toolsteps with invalid arguments stay on the step without running the tool oron_failure.
Features
- #6765: Conversations now record ordered-block lifecycle
(
ordered_block_entered/completed/cancelled/interrupted/resumed). Block-levelflow_*events are still written as well. Inspector and Copilot map these types. See Tracker events. - #6699: Tapping a button whose
payloadis aset:memory reference now writes the declared memory field directly, without an LLMset_fieldscall (llm_settableis not required). Post-write hooks run on these taps the same way as on LLM writes. The payload must match a button on the latest agent message — typing a schema-validset:string that was not offered there is rejected. If the tap targets a field the active skill cannot write (for example a memory entry from an earlier skill), or the payload is stale/invalid, the agent replies with a fixed notice that the selection is no longer available or an invalid value — naming it when the inbound message metadata includesbutton_title— and asks the user to choose an available option or type their message. A second tap on a write-once project field is rejected the same way and leaves the first value. Override the packaged notice by declaringutter_set_memory_button_skippedin your ownresponses.yml. - #6699: Response variant
metadatafromresponses.ymlis now stored on bot messages in the conversation tracker, not only the internalrephraseflag.
Improvements
- #6789: Conversation-scoped
structured logs now include
conversation_idacross engine and voice processing. Voice TTS debug events no longer also emit a duplicaterecipient_id.
Bugfixes
Features
- #6669: You can now add static
buttonsto named responses inresponses.yml; the engine delivers them on collect and action asks in chat and web channels, including after streamed rephrase, with memory placeholders resolved in button titles and payloads. Taps with a free-textpayload(or an omitted payload that defaults to the title) are handled like typed input — see Plain-text payloads. - Mantle hooks authoring surface (preview): import
on_*andmodify_*decorators, typed payloads, andHookRejection/RetryModelfromrasa.mantle.hooks. Place modules inhooks.pyorhooks/**/*.py; train-time validation runs before packaging. The runtime does not invoke hooks yet — turn-path wiring lands in a follow-up release.
Improvements
- #6587:
rasa init --engine mantlenow bundles the Mantle documentation into your project at.rasa/docs/mantle/, and the installed agent skills tell your coding agent to read it rather than guess. Add it to an existing project withrasa tools init docs mantle. See Getting started.
Bugfixes
- #6695: Rasa CLI commands now work on Python 3.14.
Previously every command, including
rasa initandrasa --version, failed immediately on startup.
Breaking Changes
-
#6610: The orchestrator LLM now
uses
llm.model_groupand a matchingmodel_groupsentry. Move inline provider, model, and credential settings fromllm:into that group:Seeintegrations.yml. -
#6733:
rasa data validatenow requires every conditionalnextto include anelsefallback:See Conditional branching.
Bugfixes
- #6733: Called skills no longer
restart when no conditional
nextbranch matches.
Breaking Changes
- #6670:
rasa data validatenow fails when a tool reaches the internal memory manager or clears memory entries. Clear fields this skill owns withcontext.memory.set. Fields another skill owns must be cleared from that skill. See Tools.
Features
- #6654: You can now declare static
buttonson response variants inresponses.yml(each with atitleand optionalpayload). This PR adds parsing and train-time validation only —rasa trainchecks button shape andset:memory payloads against the readable and button-writable memory rules the engine will use when those buttons write memory on tap; button delivery at runtime is not included yet. - #6650: Conversations now record
skill lifecycle (
skill_activated/completed/cancelled/interrupted/resumed), tool runs (tool_executed, local or MCP), and memory writes (memory_set/memory_cleared). Skill-levelflow_*,mcp_tool_executed, andslot_setevents are still written as well. Inspector and Copilot map these types. See Tracker events.
Improvements
- #6670: When a collect step is skipped because the value is already known, the agent is told not to ask for that value again in the same turn. See Prompt templates.
Bugfixes
- #6715: Voice responses no longer play stale audio from an interrupted response after a barge-in.
Breaking Changes
- #6678: Starting the same
skill again in a session now resets that skill’s public and private memory
to each field’s
initial_value(nullwhen unset). Values still stay after complete, cancel, and interrupt until that next run. Put session-long facts in project memory. See Lifetime. - #6637: Project memory is no longer writable by the LLM (
set_fields,collect, orcorrect). Train rejectsllm_settable: trueandcollect:on a project field. Collect user-facing values in skill memory, then writeproject.*from a tool or post-write hook. After the first successful write, further writes fail for the rest of the session. See Skill vs project memory. - #6637: Memory fields no longer support
immutable. Skill public and private memory stays writable. Project fields remain write-once after the first successful write. See memory.yml. - #6608: Tool calls now
time out after
10seconds by default. Set the top-leveltool_timeoutinagent.ymlfor slow local@toolfunctions. Imported MCP tools use the same default unless their server sets its owntool_timeoutinintegrations.yml.
Features
- #6608: You can connect
agents to MCP servers. Declare servers under
mcp_serversinintegrations.yml. Skills can import remote MCP tools withimport_tools: [mcp/<server>:<tool>]. See Import MCP tools.
Improvements
- #6718: OpenTelemetry metrics now show the time between consecutive agent responses in a Mantle turn, including waits after fillers and before final responses.
- #6637: Set project memory now stays visible in a dedicated
### Project Memoryprompt section, including while routing. That section tells the model those facts are already set for the session and will remain so. See System Prompt and Prompt templates. - #6637: Session-start metadata can populate project memory for fields marked
seed: true. A metadata value that does not match the declared field type is skipped (the field stays unset). Train rejectsseed: trueon skill public or private fields. See Seeding from session start. - #6608: Langfuse tool-call traces now record the tool name and argument keys as the span input, not argument values, so account identifiers and other inputs stay out of the trace.
- #6693: When call recording is enabled, voice traces now include a span for storing the recording, with its storage location and whether it was saved, skipped, or failed.
Features
- #6645: You can now declare conditional
response variants in
responses.yml: each variant may include a memorycondition, the engine delivers the first match in YAML order or a required default, andrasa trainrejects empty text, invalid conditions, and malformed default rules with a located error.
Improvements
- #6685: Voice traces now show whether a barge-in happened while audio was playing or still queued, and they include dropped agent responses when content capture is enabled.
Features
-
#6697: Added Deepgram Flux
TTS. Voice agents can now use Deepgram Flux for streaming text-to-speech by
setting the TTS provider name to
deepgram_flux. - #6343: Voice interruption events in Inspector now show how far the agent response played before the user interrupted, including confirmed playback progress and the full response duration when available. The engine also tells the model that the interrupted response may not have been heard in full.
Bugfixes
- #6679: Installing Rasa Pro on macOS no longer fails while building LiteLLM. Previously LiteLLM had no prebuilt macOS wheel, so it was compiled from source and the install failed unless a recent Rust toolchain (rustc 1.94.1 or newer) was already available.
-
#6674: Voice agents can now
connect to speech providers on systems that require custom CA certificates configured
through
SSL_CERT_FILE.
Breaking Changes
- #6603: The engine internals are now
named Mantle throughout (the
calm_v2package becamemantle, and the persistedengine_versionvalue changed fromcalm_v2tomantle). Custom tool modules must update their imports fromrasa.calm_v2.tools.*torasa.mantle.tools.*— e.g.from rasa.mantle.tools.decorator import tool, ToolContextandfrom rasa.mantle.tools.result import ToolResult. Agents whosetools.pyfiles import the oldrasa.calm_v2.*path fail to load until updated. Models trained on earlier.devbuilds will not load and must be retrained. - #6652: Python 3.10 is no longer supported. Use Python 3.11 through 3.14.
Improvements
- #6652: Mantle now includes the
latest Rasa Pro
mainline after 3.19.0 (Sanic 25, Python 3.14, and optional voice call recording), and pinsrasa-sdkto3.20.0.dev1.
Bugfixes
- #6595: Setting
rephrase: trueon a response now also rewords confirmation questions, messages when the user says no, and success or failure messages.
Breaking Changes
- #6576: The CLI engine value is now
mantleinstead ofmaestro. Userasa init --engine mantleandrasa tools skills install mantle. The old value is rejected rather than deprecated, so update any scripts that passmaestro. See Getting started.
Bugfixes
- #6600: Users can now correct a previously collected skill-scoped memory value.
Improvements
- #6531: Tool-call acknowledgement fillers (
prompts.ack_enabled) are off by default on text channels and on by default on voice. Setack_enabled: trueorfalseinagent.ymlto force either way for both modalities. Removed redundant inline-text guidance fromcancel_skilllifecycle and tool schema; generic acknowledgement guidance still applies when ack is enabled. - #6512: The default system prompt now places deploy-stable and episode-stable sections before the current date and time so provider prompt-prefix caches stay warmer across turns. The System Prompt and Prompt templates reference pages match the new order and wording.
Features
- #6360: Voice agents now expose OpenTelemetry traces for calls, provider connections, transcription, input decisions, speech synthesis, and audio playback. See Observability.
- #6504: Skill instruction prose can
reference live memory with
@memory.project.<field>and@memory.<skill_id>.<field>(prompt substitution and train validation). Unreadable@memoryrefs, incomplete@memorylookalikes, and baresession.*in free prose fail train. See skill.md — Memory.
Bugfixes
- #6552: Voice-ready and custom channels can now mark incoming turns as voice so the engine applies voice-specific prompt guidance.
- #6546: Voice calls now reject spoken input while a DTMF collect step disables audio input, with the rejection recorded in tracing.
- #6558: The tool-call acknowledgement section (and its examples) is no longer repeated in the system prompt on every agent-loop iteration. The agent acknowledges once per turn, so the guidance is now included only on the first LLM iteration and dropped on later iterations, trimming prompt tokens. See the System Prompt reference.
Breaking Changes
- #6401: Ordered-block steps now
reject unknown YAML properties. The removed collect-step keys
force_collectionandtool:are no longer accepted — useask_before_filling: trueinstead. The agent also fails to start when a skill directory cannot be parsed or when two skill directories in the sameskills/tree declare the same skill id.
Improvements
- #6428: Mantle projects without an
endpoints.ymlno longer log errors about the missing file when running CLI commands such asrasa train. Endpoint-backed tracing, metrics, and secrets configuration is skipped instead. CALM projects are unaffected. - #6423: Tools can read
another skill’s
publicmemory (andproject.*) via fully-qualified names oncontext.memory.get, with the same visibility as conditions /read_all(private fields anddeny_readstill blocked). Writes stay scoped to the active skill and project. - #6401: Step and skill load
validation now surfaces clearer, actionable error messages (including migration
hints for the removed collect-step keys), and
rasa data validatereports unloadable skill directories instead of relying on silent skips at runtime. - #6405: Langfuse tracing is configured under optional
tracing:inintegrations.yml(type: langfuse,${VAR}keys, optional knobs such asenvironmentandtimeout). Example agents no longer rely onendpoints.ymlfor tracing; Langfuse declared only inendpoints.ymlstill works with a deprecation warning until you migrate the block.
Documentation
- #6423: The
tools and memory.yml references
document fully-qualified
context.memory.getreads for sibling public fields. - #6401: The
skill.md reference documents ordered-block step
validation, the removed-key migration table, and collect-step authoring without
per-step
tool:overrides.