- Added switch auditing to the Instant On specialist, and corrected what its description claims about the hardware
- Added patch confirmation by probe, without paying for a full scan
- Added
instantonas an audit type at the edge - Added Microsoft 365 auditing across the 4 existing integrations: 52 Graph-tier checks plus 44 PowerShell-tier checks for Teams, Purview, Exchange and Defender, with the M365 services categorised instead of falling into “Other”
- Added compliance frameworks and a MITRE ATT&CK map over the Microsoft 365 checks
- Added full Aruba Instant On coverage on the 1920S: inventory (ports, PoE, users, services), telemetry, logging, topology, search and diagnostics, logical backup, writable configuration and maintenance — closing all nine tools across both switch generations
- Added automatic detection of which Instant On switch is on the other side, and a single audit baseline for both generations
- Added the vendor’s verdict to the vulnerability, to the scan finding and to the vulnerabilities view, where a CVE the manufacturer will not fix now reads as a recommendation, crossed with what is actually running on the host
- Added a filter that drops a confirmed fix out of the vulnerabilities list
- Changed
verify_sslto come from the integration instead of being hard-coded totrue - Changed patch claims to be retained rather than contradicted while the host waits for a reboot
- Changed patch grouping to key on the installed version, so the same package at two versions is no longer a single card
- Changed write confirmation to report only what the switch actually applied
- Changed QRadar alerts to read offenses through
siem_ops - Updated Myrmex-Utils from v0.55.2 to v0.64.0, adding context-aware encryption
- Fixed the Argo CD integration’s connection test by pinning
--serverin the test command - Fixed the running kernel being read as something other than the kernel, and added a re-scan when the host changes
- Fixed the agent leaking memory
- Fixed an agent upgrade not triggering a re-scan — the new build now judges the host immediately
- Fixed the source query using the binary version instead of the source version
- Fixed the Node inventory to read
yarn.lockandpnpm-lock.yaml, one package manager per project - Fixed the state of an empty LAG being read-only when it needs to be writable
- Fixed Instant On download and upload ignoring
verify_ssl - Fixed
verify_ssl=falsesent by the caller not reaching the agent - Fixed a group with a confirmed fix still reporting that it was awaiting confirmation
- Fixed the vulnerabilities tab not reloading when the id of the last scan changed
- Fixed the vulnerabilities screen rendering rows it had no data for
- Fixed the findings tab holding on to DOM and polling tabs nobody was looking at
- Fixed a Change Management (GMUD) approval rule overlapping itself and covering the chat
- Fixed deleting the space after a mention locking the chat input
- Fixed the filter bar keeping controls that filtered nothing
- Fixed the dashboard modal covering the chat, and filled in the missing posture translations
- Fixed the subscription reactivation route
- Added control and vulnerability remediation straight from the chat, through Perseus
- Added Office 365 and Entra over the native ops rail, with their own Entra app, a server-side minted Graph token, Graph profiles and preflight accepting an injected token
- Added Intune to the ops rail, plus preflight and online checks for Defender and Sentinel
- Added recognition of
cli_argocdas an Argo CD CLI integration - Added
audit_fix_applystraight from the chat, driven by the same engine as the Change Management (GMUD) window - Added
vuln_fix_apply— from a vulnerability line to the native package, including apk - Added the Intune family and a beta surface to the Graph profiles
- Added the same two integrations through the collector, and fixed the existing ones
- Added an Argo CD custom form and detail view
- Changed Entra, Office 365 and Intune to authenticate through devices and the agent, so no secret lives on the agent
- Changed the Argo CD session timeout from 25s to 90s, with a message pointing at
--async - Changed the integration bases grid layout
- Reverted the macOS store swap — finding F16 turned out to be a false positive
- Fixed
HOMEnot being set when running the Argo CD CLI and its connection test - Fixed a code audit round: hijackable temp files, PowerShell injection in WSUS, and missing ceilings
- Fixed RPM reading epoch and source, apk reading origin, and the inventory running in a single pass
- Fixed the vulnerability cycle: run-now moved out of the loop, deferral and backoff, batched matching, and re-scan by kind
- Fixed the Linux build, broken by an import landing inside a multi-line
use
- Added masking for
service_account_json(GCP) andfingerprint(OCI) on the integration detail route - Removed the Grafana Faro call from bootstrap
- Fixed auditing using the Identifier instead of the credential profile
- Added the ability for Perseus to see the CVEs it fixes
- Added text search, sorting and the missing resource filters to the audit trail
- Added an applied fix clearing the CVE immediately, without paying for a whole scan
- Added live search, a resizable table and CSV/JSON export to the audit view, with NDJSON replacing the array as the wire format
- Added the applied fix showing up immediately, and made the vulnerability scan visible while it runs
- Added a gradient at the top and bottom of a conversation, with breathing room down to the composer
- Added reactivation for an archived user
- Added file attachment in a first conversation
- Added an application error boundary
- Changed context cache pricing to be metered correctly
- Changed a conversation you do not own to return 403
- Changed turning auditing off to close any pending scan
- Changed attack-path and platform-written errors to carry a stable code rather than only English prose
- Improved round-trip cost: batched shell, a receipt in place of the plan, and a pointed per-step get
- Improved delegation caching — a new delegation no longer destroys the previous one’s cache
- Improved the chart axis
- Fixed the open window not following the plan
- Fixed an unlimited contract being charged overage
- Fixed a disabled device audit pretending to still be loading
- Fixed the raw English agent error surfacing on the device inventory screen
- Fixed 9 missing translation keys on the device posture screen
- Fixed a user with no profile picture being treated as a failure
- Fixed role chips not following the row width, and buttons disappearing
- Fixed “Deactivate” being hidden and “Delete” having no confirmation
- Fixed “Disable MFA” appearing for users without MFA
- Fixed the posture chart line being drawn outside its window
- Fixed a tag chip not following the button beside it, and the list needing a reopen to refresh
- Fixed an open conversation needing a click before it loaded
- Fixed a session reset leaving the previous user’s conversation standing
- Fixed a 403 being retried ten times instead of being treated as final
- Added a tool counter that reports the verb, using a closed vocabulary
- Added a second-factor indicator to the organisation’s user listing
- Improved context cache behaviour: the turn note and the capture index moved out of the cacheable prefix, and the cache now grows within a turn
- Improved planning round-trips through batching and a derived note
- Fixed usage measurement to report what was actually consumed
- Fixed completing a plan pruning the specialists and erasing it from the screen
- Fixed a plan step so it is born from the delegation — the gate no longer demands what the runtime now provides
- Fixed a user with no profile picture returning 400 instead of 204
- Fixed the login error message
- Added unified consent, attribution and registration events, with an approved GTM container in the builds
- Added an ITSM coordinator (
hydra_itsm) over sensrit, GLPI and ServiceNow, plus a Jira specialist with the agent’s 39 tools and site auditing - Added an Aruba Instant On specialist (
instanton) over the agent’s web-API tools - Added a posture trail (audit and remediation) to the GLPI specialist
- Added mid-turn questions: the agent stops and asks you, asks everything in a single stop, offers labelled fields, and the turn only resumes once nothing is waiting
- Added a secure credential field, its warning, and a guard that makes an old frontend visible — a secret pasted into the chat can now be used through a labelled door
- Added quota: per-call metering with an accumulator for cached tokens and thoughts, an OpenTurn/SettleTurn gate, a 429
QUOTA_EXCEEDED, an SSEquota_exceededevent, settlement on every terminal state, and a graceful stop - Added automation coverage to the Brontes specialist: a private-credential rail through
my_account, integration registration, folder reorder, tags and subfolders, and the platform contract it now reads and survives without - Added measured packages in the plan, with a promotion counter
- Added a per-agent reasoning depth, set high across the board
- Added first-class 429 handling for quota:
CHAT_008, a persistedquota_exceeded, and the quota reported on done - Added per-route cleanup of a single topology context, and a single cleanup for the lab
- Changed plan selection to a compact layout, and expired sessions are now recovered
- Changed agent arbitration to move out of the tool descriptions into a live block
- Changed the payer and origin to travel on the wire to centurion
- Improved the agent’s instruction budget by 1,470 characters, where the ceiling was misreporting
- Fixed the plan sent by the site silently becoming Personal on registration
- Fixed the currency chosen on the pricing page not reaching checkout, and the price displaying in the wrong currency
- Fixed
$not distinguishing the US dollar from the Chilean peso - Fixed the plans screen ignoring the server’s currency, not grouping plans, and showing “On request”
- Fixed registration being conflated with card-backed trial activation
- Fixed checkout activation confirmation and subscription access alignment
- Fixed the account currency choice not being saved with the subscription
- Fixed registration sending an empty measurement block
- Fixed the billing currency not being preserved, and admitted quota turns not finishing
- Fixed a long-running tool that answers no longer pausing the node
- Fixed the order of answers being hash order
- Fixed a resumed batch belonging to a single invocation, so it resumes only once
- Fixed the coordinator’s answer being discarded on resume
- Fixed
donebeing read as “there is nothing to ask” - Fixed the RBAC preflight missing from the Brontes
devicetool - Fixed the credential guard blocking the very rail that protects the secret
- Fixed the audit trail not being isolated per environment
- Fixed context usage not being read from the latest chat turn
- Fixed identity fusion so every identity counts, and the network gateway is whoever is a hop inside it
- Fixed
/topology/tracenot acceptingdevice_idandintegration_idas a target - Fixed retry tags and unified the quota and plan purchase experience
- Fixed context and plan usage being reported together, and localised advanced mode
- Fixed the context panel not matching the canonical backend measurements
- Fixed the currency selection not persisting, and localised and clarified the extra-capacity checkout
- Fixed plan selection being blocked, and translated contract plans
- Fixed the circular usage indicator in the chat
- Added quota: a versioned price table, a ledger with idempotent usage registration, OpenTurn/SettleTurn/GetQuota, snapshots and reservations, HTTP endpoints for quota, members and purchase, daily reconciliation, and account migration
- Added per-currency pricing on packages, Latin American currencies, and amounts in the currency’s smallest unit
- Added purchased balance that leaves the windows, is debited transactionally, and is bought in multiples
- Added the signing secret to the verified webhook
- Added quota support: a sponsor, blocked and paused execution states, a pre-execution gate on all three trails, and the payer on the wire to centurion
- Added a 429 on a step turning into a paused execution, with automatic and manual resume
- Added playbook generation carrying identity and payer
- Added a support case module over Enredo (ITSM), with comments, attachments, reopen, a service catalogue and a known-issues endpoint
- Added a typed plan in the RBAC envelope, with a fail-closed fallback and filtering by plan
- Added
created_by, user vitality, sponsor validation and the plan on service login - Added a support screen with cases and known issues, category and subcategory on case creation, file attachments, and a link to the status page
- Added quota to the interface: a ring on the composer, a popover, a line in the account popover, and a persistent card when quota runs out
- Added a personal, organisation and free quota view, balance purchase, and per-person usage
- Added extra capacity, automatic recharge in recharges per month, and a per-person share of the pool
- Added the secure credential field and the pasted-secret warning to the chat
- Added agent questions that can carry fields for you to fill in, with a pending-question card in the system’s layout and colours
- Added topology: an unregistered device is a finding rather than noise, a default with several members, and correct handling of duplicate addresses, partner tunnels, dual WAN and registered firewalls
- Added quick hardening fixes by impact as cards, with the controls in view
- Changed currency so it travels through the whole subscription, with the declared country deciding who picks it, falling back to the checkout IP when no country is registered
- Changed the
:subscription_idroutes to authorise correctly - Changed plan resolution to grant access only from the active plan
- Changed the vulnerabilities list to be driven by the fix rather than the CVE, and merged a CVE with no fix into a single card with its detail
- Changed plan prices to display in the currency the subscription is billed in
- Removed the “Installed only” filter from the inventory
- Fixed a plan change being decided by the package document rather than its id
- Fixed trials requiring a card, and reconciled subscription seats
- Fixed overdue invoice recovery and replacement card verification
- Fixed an annual charge being issued at R$ 0.00
- Fixed a currency lookup failure being read as “no previous currency”
- Fixed the dashboard cascading “no data” by decoupling
$environmentfrom the app metric - Fixed service users being counted against seats, and added a seat guard for SSO
- Fixed subscription access enforcement and serialised seat allocation
- Fixed an inactive plan so it raises a flag and preserves the family, restoring the cache
- Fixed an organisation being created without the country of its verified phone number
- Fixed the user phone number being encrypted under
org_0at registration - Fixed tag targeting in ABAC comparing a UUID against a name
- Fixed the risk path leaving the CVE detail
- Fixed scrolling to be the platform’s, and selection to close both ends
- Fixed the program name shrinking in the inventory — the numbers now give way instead
- Fixed the seat calculator showing Brazilian real with a dollar sign, an unknown price reading as zero, and confirmation being allowed anyway
- Fixed the screen offering what the backend refuses, and merged the two rings into one
- Fixed the measurement choice moving out of the screen corner and becoming an account item
- Fixed country becoming an ISO-2 selector in organisation settings, normalising the old free text on load
- Fixed the Entra and Office 365 integrations
- Added a temporary secret stash that keeps the credential off the agent
- Added a declared form contract for integration bases, with four routes so the form no longer has to be guessed
- Added the Aruba Instant On (
instanton) and ServiceNow families to the ops gate - Added a “collect now” topology route, by context or by integration
- Changed the secret-release gate to accept valid access tokens
- Changed secret tags so the handle is resolved at the exact moment of writing
- Changed the update path to resolve the secret handle rather than write it
- Removed an unnecessary RBAC permission on subscription read that was based on the auth token
- Fixed the mask being stored as if it were the credential
- Fixed renaming a device group disarming the modules of every member
- Fixed the Zscaler connection status lying — the connection test now performs a real login
- Fixed a bad default on the base refusing a registration made from the screen
- Fixed an array field’s option list being written as its value
- Fixed
/grc/controlslosing the subselect alias, and/grc/assessmentsrejecting a device target - Fixed the audit gate refusing remediation verbs
- Added full Zabbix 7.0 operational coverage: host lifecycle CRUD, host and template groups, item update/enable/disable, access control, notification delivery log, event correlation rules, cause/symptom ranking and trigger control — 22 new operation tools, then consolidated from 30 tools to 11 through an entity registry, plus a remediation layer of 46 fix blocks
- Added a full Jira operation family (37 tools, Cloud and Data Center) with a 53-control configuration audit
- Added a ServiceNow operation family over its native API
- Added a GLPI remediation layer: 28 fix blocks, six verbs, and
fix_indexon the run - Added typed Shodan and Google Threat Intelligence families, the latter with per-key quota
- Added the Aruba Instant On 1930 family (
instanton) over the web XML API - Changed four Zabbix projectors to keep credentials out of the transcript
- Fixed nine Zabbix defects found by an adversarial review, each reproduced live
- Fixed
management-ip:stealing the address of every FortiGate port - Fixed routes with several next hops (ECMP / SD-WAN) so each continuation line is a member
- Fixed the database audit probing the reference fork and version rather than the deployed one
- Added the full Zabbix catalogue: the 6 missing tools verified live,
zabbix_configand host lifecycle, with 4 dead verbs removed - Added a callable webhook trigger
- Added a Cisco FTD (FDM) specialist: REST-only, 15 tools and 7 skills, with a deployment skill, a FlexConfig tool and topology on the device-audit rail
- Added a 3Com specialist covering the full 4200G CLI in 7 skills
- Added the Check Point specialist back, rebuilt on the current Fortinet pattern, with its 8 skills and Gaia leaving the uncatalogued state
- Added Microsoft Sentinel support, multi-application Microsoft authentication, and a Sentinel skill on the explorer agent
- Added Rapid7 InsightIDR and Prowler sub-agents to the security engineer
- Added the Zabbix specialist the agent’s 11-tool surface and 8 skills, one per moment of the operation
- Added mid-turn questions: the agent stops and asks you, the pending question stays with the agent, the answer is read and persisted, the turn only resumes once nothing is waiting, and answering reopens the conversation status
- Added plan steps with dependency, target and owner, so the agent follows the order
- Added a conversation effort setting that reaches the turn and decides how much the agent takes in
- Added plans that start from enumeration, with the step record as a notebook, the work living on the leaf, and the runtime stamping step evidence
- Added Apolo, so the coordinator knows where things are, and made it explicit that a recalled view is static rather than freshly read
- Added a contribution skill, piloted on Apolo and the Fortinet specialist
- Added Brontes ordering and approving books, seeing the run, and returning the webhook URL
- Added
GET /v1/chat/usage, giving conversation token usage a durable source - Added dependency, target and owner of a plan step through to the panel, plus the record id
- Added the conversation effort key travelling to the agent
- Added quick fixes counted by impact block in the posture summary
- Added the ability to say which integration is broken, without decrypting anything
- Added a completed change re-auditing its target — the posture screen used to sit on a scan up to 24h old
- Added the
ftd,shodanandgtifamilies to the ops and audit gates - Added agent questions appearing on screen and being answerable, with the stream reattaching after you answer and holding when another question is still waiting
- Added the effort key to the composer
- Added drag and drop for files in the chat, plus inline rename and an icon-only action bar
- Added per-program CPU and memory consumption to the inventory
- Added the step attachment opening on its own line, with the coordinator’s note visible, and raw execution output opening on the step line
- Changed the Shodan and Google Threat Intelligence specialists to execute only through the agent
- Changed the “Chat usage” ring to read the real source and show the context window rather than spend
- Changed the interface to hand out a working webhook URL
- Improved context window measurement, removing more code than it added
- Improved registration speed dramatically by removing an N+1 in the role bootstrap — it used to take around 55 seconds
- Improved login speed by resolving the organisation subtree in a single query
- Improved user decryption on login, from around 8 calls down to 2
- Improved agent decryption by batching it, from 18 calls down to 1 per agent
- Fixed the coordinator not knowing it should ask Apolo, and not scoping before delegating
- Fixed 273 resource links across 7 vendors that aborted the turn
- Fixed a turn that pauses to ask arriving as a 500
- Fixed an invalid delegation argument killing the turn
- Fixed a user stop being classified as a failure in all three places that did so
- Fixed the console tape leaking into a neighbouring tool
- Fixed a submitted change being edited silently, and an empty turn not being resumed
- Fixed 25 remaining high-severity dependency findings, and removed pip from the final image
- Fixed preflight dropping
Last-Event-Id, without which a resume never arrives - Fixed a turn the agent had finished being marked as an error instead of recovered
- Fixed the step record disappearing from the coordinator’s note on refresh
- Fixed the confirmation email being sent synchronously and fatally during registration
- Fixed
email_statusnot being set on a normal registration - Fixed the user permission middlewares
- Fixed execution not requiring the correct integration context
- Fixed the review transition to be single with CAS, with a recovering goroutine and bounded fan-out
- Fixed a virtual MAC matching nobody, and the trace requesting a node’s routes by origin
- Fixed a single backslash in the content making the Typst escape produce a live delimiter
- Fixed chat favourites and permanent decisions
- Fixed the posture screen not following scans on its own, and removed the manual scan button
- Fixed the Remediate button sending the raw command without saying the fix engine covers the control
- Fixed the header total not matching the top total in the review
- Fixed a duplicated chip, and changed the context mention to text for legibility
- Added a route with several members keeping each member — hop, interface and tunnel
- Added a single cleanup of the graph across all contexts at boot
- Fixed an identifier being treated as a label, and an edge in the trace being whoever does not route through us
- Fixed an HA virtual MAC minting a phantom device or becoming a cable
- Fixed route weight excluding the route’s origin rather than the owner of the line
- Fixed a Fortinet HA virtual MAC being treated as an identity, anchoring an attachment and stealing an interface
- Fixed a neighbour’s nickname winning over the registered name in an asset’s label
- Fixed a duplicate address between two registered devices being assigned by page order rather than to whoever the others route through
- Fixed two distinct
integration_idvalues ever merging into one asset - Fixed a sighting MAC being treated as an identity, and therefore merging devices
- Fixed two separately registered devices ever merging
- Added the Cisco FTD (FDM) family: session control,
ftd_configas an intent-first smart CRUD with resolve-or-create, a full operation surface, and auditing with remediation - Added NAT, DHCP, logging and administrative access to
ftd_config, with a guard against locking yourself out - Added 16 audit controls to FTD, each verified against real hardware, plus FlexConfig behind a guard
- Added API version negotiation instead of accepting “latest”
- Added a memory bound alongside the existing timeout
- Changed FTD auditing to the NSPM rail, and added topology collection
- Fixed routes, zones and interfaces requiring typed references rather than strings
- Fixed a known error becoming a classified envelope, so troubleshooting no longer swaps the command
- Fixed writes to be idempotent, and a deploy to hand back the job instead of dying
- Fixed interface PAT carrying
patOptions - Fixed Vlan1 being unreachable
- Fixed a filter meant to include rules with no traffic returning none
- Added a macOS password policy fix pack, where the document is the unit of remediation
- Added a forensic host timeline: one capture, one local store, one tool
- Added per-program cost to the host inventory
- Added Trend Micro
correlate_oat, joining an event’s MITRE mapping through OAT, withmitre_grace_minutesholding the ingestion race - Added MITRE tags from threat-intelligence sweeps
- Added context gates on the security configuration checks and runtime guards on the Linux fix, so check and fix answer the same question
- Added a calibrated score and profile, with the frontend receiving what the host actually permits
- Added the layer 3 view back: routes, declared subnets and whole SVIs
- Added unregistered equipment to the map, flagged as such
- Changed the Linux security configuration checks to raise a verdict only on measured evidence
- Improved map cold start, which was waiting on the backbone before opening
- Fixed subscription cancellation and upgrade
- Fixed deleting a pending subscription
- Fixed Alpine matching zero packages because of a suffix, and macOS and Windows having nothing to ask
- Fixed macOS reporting a failed scan over a question with nothing to ask
- Fixed PAM being an inert control, caught by a security review
- Fixed legacy equipment sending an
mpintwith a leading zero being rejected over SSH - Fixed VRP LLDP being read from the wrong format, losing identity
- Fixed an elided FortiGate prompt with a tilde dropping the whole SSH session
- Fixed the prompt being anchored to the hostname before proving it matches
- Fixed the owner of an address being whoever saw it in ARP rather than whoever was registered on it
- Fixed the switch management VLAN not being treated as a network with the core as its gateway
- Fixed LLDP evidence being discarded for arriving after the CAM table
- Fixed the layer 2 tree being buried under the ARP mesh and the subnet boxes
- Fixed a server appearing connected to fourteen switches at once
- Added a single catalogue resolution answering both vulnerability questions, with Match returning both
- Added accumulating context in the chat: sending an item turns it into a context chip and the input gets an index
- Added bulk remediation by impact block on the global posture screen
- Added a segment summary drawing, and stopped the frontend requesting neighbours it hides itself
- Added Portuguese, English and Spanish keys for the new surfaces
- Changed the map default to the estate, with ARP and large segments becoming a question rather than an assumption
- Changed the finding card to open in full, with the control’s actions moving to the overflow menu
- Changed the topology screen to recover from a transient load failure without a page reload
- Improved map latency substantially: a properly sized connection pool, a read that loaded a whole context to discard 99.9% of it, a cache with refresh behind the response, and four analysts opening the same map no longer causing four reads
- Improved correlation writes from 83 statements per record down to 11
- Improved vulnerability matching, which was issuing one query per ecosystem and up to four per installed app
- Fixed the switch MAC table burying the trace route, and the summary collapsing what had nothing to fold
- Fixed the gateway disappearing because the route that proves it is the gateway belongs to it
- Fixed the relay discarding the
appsfield of a vulnerability match request - Fixed the topology screen’s retry doubling the load on the very bottleneck that caused the timeout
- Fixed the map opening cropped, and the zoom buttons rendering as a white block in dark mode
- Fixed the map opening skewed, and a phantom refresh making the camera jump
- Fixed mobile: the input no longer clips, the avatar rotates whole, the root follows the keyboard pan, and the bar became a three-position switch with a Tabs toggle
- Added catalogue waves 2 through 5: 17 new verbs on families that already routed, five SOC families that had zero coverage, perimeter and network (Cloudflare, Azion, Meraki, Locaweb, Sophos), plus config lifecycle, IAM and a REST escape hatch
- Added computed cross-vendor links instead of leaving the agent to guess them
- Added catalogue reconciliation against the devices edge, with a ceiling so a larger catalogue degrades on purpose
- Added
hydra_defenderandhydra_sentinelspecialists over typed tools - Added a Zscaler ZIA sub-agent for the proxy and secure web gateway
- Added the Cloudflare 63-control edge posture audit, and the CrowdStrike Falcon hardening audit
- Added
crowdstrike_rulesandcrowdstrike_modulesto the specialist and the coordinator route - Added QRadar
mode=clone, so the specialist can now create a rule - Added durable user decisions that hold until you change your mind
- Added a plan that is a live object, with one rule, so the agent can see the step
- Added editable execution authorisation recorded on the plan step, visible to the specialist by state rather than by asking
- Added evidence as a requirement for closing a step, stamped by the runtime rather than written by the agent
- Added addressable artefacts by line, letting the agent consult 253 KB without reading 253 KB and without a vendor parser
- Added change preparation without applying it, so only what was inspected gets applied, with the change cut from the source rather than composed by the agent
- Added a progress heartbeat that actually reports rather than only feeding the clock
- Added batch counting out loud, so you stop deciding in the dark
- Added a visible skill catalogue, with each skill publishing its own description and triggers
- Added
audit_run_nowto the Brontes integration, closing the loop after a fix - Added the stop step to the screen
- Added durable decisions: a table, per-turn reinjection, and revocation by click
- Added batch progress from the agent being relayed to WebSocket clients
- Added a waiting notice relayed to the client
- Added plan steps carrying sub-items and an out-of-order mark through to the screen
- Added plan editing from the screen, with the chat proving ownership and the agent holding the rule
- Added expiry for integrations stuck in Waiting Data
- Added the integration id as a label on the agent’s SSH probe session
- Added projection of a registered integration onto the map without collecting anything
- Added audit schedule reconciliation for agents that had drifted, with
run-nowreasserting the schedule before requesting a scan - Added a FortiGate gate pointing at the FortiAnalyzer that holds its logs
- Added a Cloudflare edge and WAF posture audit family with 63 controls
- Added full Oracle Cloud CSPM coverage: 51 of 51 checks across identity, network, events, KMS, compute, block storage and database, with 4 compliance frameworks and integration into the CSPM pipeline
- Added 3 Azure IAM (RBAC) controls and 16 Entra ID controls
- Added Check Point Gaia as an SSH vendor profile with a pluggable escalation verb
- Added CDP/LLDP neighbour discovery plus FortiSwitch, NX-OS and Check Point Gaia topology, Meraki topology through the Dashboard API, and RouterOS wireless association tables
- Added a recorded command tape in
_consolefor composite tools, extended to 8 more transports - Added
set_status, notes and MITRE mapping to the Trend Micro alerts projection - Added SSH integration probing by actually logging in
- Added validation on the audit
session_idused to compose a path - Added per-user saved layouts, including custom edges you draw, hidden and reconnected derived edges, and per-frame size
- Added the raw snapshot to the graph, so LLDP and CDP neighbours finally land
- Added continued polling of Waiting Data even on modern agents
- Added surfacing of integrations that cannot be probed at all
- Added an editable plan panel: add, rename, remove, drag and close, with nested sub-items and an out-of-order mark
- Added user decisions visible above the composer as a collapsible list that survives a refresh
- Added a live terminal that counts the batch and shows the commands composite tools run on the device
- Added a waiting state to the screen instead of a frozen view
- Added a Topology toggle beside Vulnerability and Auditing
- Added installed programs, versions and the processes running from them to the inventory, with each program becoming an expandable card
- Added programs and processes as chat context, and the screen now speaks all four languages
- Added an expanded finding that explains what it is, the risk, and what to do
- Added favourites as a side rail, where a number reveals the name on hover
- Changed the device command tape to be kept separate from the agent’s working context
- Changed SSO to reset when the organisation changes
- Changed to a single integration status vocabulary, and it now says when a probe is impossible
- Changed integration status to report only what is actually measured
- Changed scoring so a target is scored only once it has been evaluated
- Changed SSH so a command ends at the prompt instead of a 500 ms timer
- Changed topology collection to back off rather than give up
- Changed macOS to report running programs
- Changed the macOS audit to report compliance only where it was verified
- Changed
integration_idto a hard correlation anchor - Changed the plan panel to report the real status and follow updates
- Changed a failed scan to report its failure instead of loading indefinitely
- Improved the Docker image by 1 GB, where a recursive
chownwas duplicating the whole tree - Improved the heartbeat so it no longer rewrites every column of the device
- Removed
centurion_plannerand its entire tree - Fixed a generated playbook being born unrunnable, with no
service_user_id - Fixed a
{{item.*}}reference being accepted on a step with nofor_each - Fixed the catalogue listing not being scoped to the tenant
- Fixed a verb aimed at the wrong devices edge being accepted
- Fixed free-form parameters reaching a device CLI and a URL path without constraint
- Fixed “not rejected by the device” being reported as “accepted” in the batch log
- Fixed Stop interrupting only the narrative rather than the batch
- Fixed the specialist not seeing what it had captured itself
- Fixed the index announcing 145 KB as “16 lines”, and two identical lines reading as two different firewalls
- Fixed an artefact id collision silently erasing data
- Fixed the SSH sanitiser erasing device configuration
- Fixed a rule that wrote
q\nto a FortiGate, and “waiting” being read as “rejected” - Fixed the panel counting events instead of commands, and erasing the explanation
- Fixed state that was shared becoming per-user
- Fixed 36 high-severity dependency findings
- Fixed a client disconnect killing the execution
- Fixed the decision listing not reporting how many rows came back
- Fixed audit trail read routes not authorising
organization_id - Fixed posture not reflecting audit and vulnerability fixes immediately
- Fixed per-target posture being non-deterministic
- Fixed a 404 masking a real error on single-record reads
- Fixed the finding category reporting “Other” for 95 codes the engines emit
- Fixed a partial update encrypting the name and recalculating its hash
- Fixed bind values appearing in the database logs
- Fixed Meraki registration merging two devices into one, and added it to the topology schedule
- Fixed SSH cross-talk by allowing one writer at a time on the channel
- Fixed
MRX-SUDO-006failing every Mac over a module macOS does not have - Fixed a failed scan reporting its reason instead of becoming an orphan line
- Fixed connectivity reconciling against the cloud’s status, and no longer losing reports
- Fixed stale agent-reported IPs not expiring when a device changed networks, and pruning only ARP-discovered addresses
- Fixed two facets of the same device becoming two boxes
- Fixed page ordering being discarded, and assets not being promoted once known
- Fixed the tunnel wait ignoring the caller’s
timeout_seconds - Fixed
integration_idnot being passed into the GCP projection - Fixed the stored status not being shipped, so the collector could not reconcile
- Fixed a hardening fix result arriving at devices as “unknown message type”
- Fixed the posture screen to a single call with 30-second polling and backend numbers
- Fixed topology labelling an agent-backed asset by MAC rather than its registered name
- Fixed topology drawing: a route becomes an edge, each network a box, and interfaces move to hover
- Fixed each terminal command starting on its own line
- Fixed the multi-chat tab not matching the size and background of the workspace tabs
- Added Microsoft token minting, releasing Defender and Microsoft Sentinel
- Added the Zscaler family to the ops edge, and the
crowdstrikeandcloudflareaudit types - Fixed zombie runs not being released, so a dead worker stopped disabling a playbook
- Fixed a Microsoft provisioning error surfacing as an opaque AADSTS code
- Fixed the on-demand guard blocking runs it could not collide with
- Fixed the HTTP client margin sitting below the tunnel wait
- Added Microsoft Defender XDR and Sentinel families on the collector rail
- Added the Zscaler ZIA family — the proxy and secure web gateway — on the standard rail
- Added
crowdstrike_rulesfor Custom IOA rule management, andcrowdstrike_modulesfor licensed modules and seat usage - Added a CrowdStrike audit family mapping Falcon hardening to CIS, ISO and PCI
- Added QRadar rule creation by cloning an existing rule
- Added drag-to-place topology nodes, saved per user and context, with a view/edit mode and custom connections you can draw, reconnect and resize
- Added a requirement for Defender and Sentinel to declare a collector
- Fixed the IOC probe pointing at the legacy API, where a 404 was being reported as “not licensed”
- Fixed QRadar rule logic dying on Accept, whose absence invited the agent to invent
- Fixed the agent ignoring the negotiated
timeout_seconds - Fixed five review findings in the CrowdStrike audit, all of them empty approvals
- Fixed a long list of topology layout defects: node pools now sit in their own VPC, the subnet gateway centres over its hosts, on-prem hosts pack into a compact grid, GKE node pools nest inside their subnet, a multi-homed firewall stays on the border, a device’s WAN interface stays beside the equipment, and orphan child nodes no longer crash the graph
- Fixed connection dots not being grabbable, and drawn connections not rendering
- Fixed card hover tooltips disappearing in view mode
- Fixed Microsoft consent returning to an empty screen instead of the form, and Connect being allowed without consent
- Fixed resuming an in-flight execution after logout
- Fixed a blank screen when opening a patch change with no applied plan
- Fixed switch and router commands not appearing in the terminal, and Cisco commands not being coloured like the rest
- Fixed “My Accounts” requiring an environment flag
- Added a Box content-cloud specialist
- Added
fortinet_flow_lookup, answering which rule serves a flow, withpolicy_idmode and named categories - Added
flow_lookupat the ops edge - Added
flow_lookup: which rule governs a flow, resolved in a single call, with named categories, lookup bypolicy_id, and SD-WAN, policy routes and VPN in the verdict - Changed VPN troubleshooting to diagnose the cause rather than only reporting “tunnel down”
- Changed the agent log to exclude the enrollment token
- Changed the Windows audit to report an unset policy value as unset
- Fixed toolset loading on import, an empty secret, and a tool that raised
- Fixed
integration_idnot being passed into the GCP projection - Fixed
verify_sslbeing ignored by the REST executor - Fixed the Linux service inventory and a disk-usage underflow
- Fixed large command output being silently truncated
- Fixed ephemeral UDP client sockets appearing in the listening-ports inventory
- Fixed GKE node-pool members not being collected from instance group manager URLs
- Fixed the FortiOS post-login banner not being auto-accepted
- Added RBAC to the global template administration API
- Added encryption for stored webhook tokens
- Added typed input and output schemas between the coordinator and its sub-agents, with deterministic hand-off of the specialist’s analysis
- Added the ability for a specialist to say “this is not my domain”
- Added a Kaspersky Security Center specialist and a GoCache CDN/WAF specialist
- Added the Kubernetes cluster hardening audit as a tool, and made it the canonical audit path
- Added Change Management (GMUD) and plan tools to every specialist
- Added ABAC policy creation
- Added a new topology layout engine: subnet-first on-prem with real subnet frames, nested cloud layout, aggregated GKE node pools, VPC peering lines, load-balancer backend edges, and empty cloud subnets collapsed into one summary card per VPC
- Added a personalization menu grouping language, theme and scale
- Added agent install OS tabs, the plan as a context chip, and a data-driven audit type
- Added gated audit tabs and findings filters on the security posture screen
- Changed Scribe so its creation graph emits a step per chapter, section and block, and stopped it misreporting what it produced
- Changed device logging to exclude the device token
- Improved startup reliability
- Improved the left sidebar
- Updated vulnerable dependencies
- Removed 23 unreachable functions and guarded the int64 to uint casts
- Removed the coordinator flow, converting the prompts to tool-based delegation
- Fixed the webhook trigger
- Fixed the Postgres TLS mode falling back to
preferinstead of being explicit - Fixed pagination errors being swallowed
- Fixed a level 3 raw payload leaking into the root coordinator, and one delegation’s report leaking into another’s envelope
- Fixed the user’s message disappearing when the session had an active task
- Fixed report failure being silent
- Fixed tool counters summing across different agents and delegations
- Fixed unparameterised queries in the agent package, including the process callstack, and corrected
LIKEescaping - Fixed an audited integration opening on Settings instead of Overview
- Added a collector-owned topology schedule, with the integration topology toggle reflected to the collector on update
- Added GCP topology collection handed to the agent, with a shared projection
- Added the
kubernetesaudit type and the Kaspersky, Box and GoCache families at the edge - Added
update_failedon the device list and detail - Added suppression of updates for agents too far behind to self-update
- Added a Kubernetes cluster hardening audit with 126 controls, plus remediation
- Added GCP cloud topology collection, including GKE node pools and their member instances, Cloud Run services and load-balancer backends
- Added a Box content-cloud operation family with 33 verbs
- Added an F5 BIG-IP operation family over iControl REST
- Added a GoCache CDN/WAF operation family with a posture audit
- Added Kaspersky Security Center operation and incident-response tools
- Added QRadar rule logic to
qradar_rules get, returning the rule’s real logic - Added LAN devices grouped into their network, with gateways labelled as routers
- Added GKE node-pool members embedded inside their group node, and recognition of the load-balancer forwarding relation
- Added ingestion of exposed listening ports from the host snapshot
- Added topology command pass-through and snapshot projection
- Added projection of agent-collected GCP inventory
- Changed listening-port topology to keep only service ports, dropping RPC and ephemeral noise, and to attribute macOS listeners to their launchd service and package
- Changed listening ports to render as host services rather than as nodes
- Fixed error responses exposing internal stack details
- Fixed the installer rejecting the 32-bit Windows target
- Fixed six defects in the QRadar rule-logic reader, and corrected its cost estimate
- Fixed the family registry broken by a conflict resolution
- Fixed reused addresses chaining devices into a single asset
- Fixed stale cloud assets and deleted instances lingering on the map
- Fixed stale IPs remaining in a node’s address list
- Added zoom to the left sidebar menu and improved the theme
- Changed the quick action menu
- Fixed left sidebar search
- Added Italian
- Added invitations for members of other organisations, with an improved invite design
- Added a structured filter specification, rolled out across 11 more verbs
- Added tool workflow composition by default, with data-flow validation
- Added the GLPI family to the catalogue, and synced the devices allowlist
- Added the observed network topology as something every agent can see, and told Brontes plainly when to reach for it
- Added a TrueNAS storage sub-agent, a CyberArk PAM sub-agent and a Google Workspace specialist
- Added the QRadar rule surface with its volume gate wired in
- Added audit-fix remediation tools to Perseus
- Added integration allocation into folders
- Added hardening as a change kind, dispatched to the host on approval
- Added connectivity status for ops families, starting with Google Workspace
- Added the CyberArk PAM and Google Workspace families at the ops and audit edges, plus the Splunk audit type and four others the agent already shipped
- Added Cloud Router and NAT split, with the VPN tunnel wired to its peer and the auto-allocated egress IP resolved from router status
- Added a soft memory ceiling to the agent, handing back what Windows Update had cached
- Added host audit remediation by impact block on Windows, Linux and macOS, gated by change management, with fixability carried on the control itself
- Added device audit remediation, starting with FortiGate, validated on live hardware and covering 6.x and 7.x
- Added a TrueNAS SCALE storage operation family with full API coverage, plus a TrueNAS configuration hardening audit
- Added a Google Workspace operation family and its configuration hardening audit
- Added a CyberArk PAM Self-Hosted (PVWA) operation family
- Added audit families for Zabbix, GLPI and Grafana — 103 controls, validated live — and a Splunk hardening audit with 79 controls
- Added
qradar_rule_author, measuring a rule’s cost before enabling it - Added a persisted collector-owned topology schedule with enable, disable, run-now and remove commands, pushing snapshots to the topology service
- Added network-exposed listening ports reported with their owning service, on Windows and macOS as well
- Added per-interface groupings with name, MAC and addresses, carrying interface prefix, VLAN and tunnels through the graph
- Added cloud roles, vendors, container kinds and containment relations on a node
- Added recording of which host observed each ARP neighbour, the interface name carried into the graph, and the default route promoted to a gateway edge
- Added a strict opt-in topology gate per device
- Added the organisation topology map: cloud resources drawn with their provider’s mark and role, nested account, VPC and subnet frames, exposed-port panels, orthogonal edges, and Cloud Router, NAT and VPN rendering
- Added per-integration toggles for the audit and topology modules
- Added hardening remediation on the device screen: select controls and generate a change, with the fix checkbox gated by the control’s fixability
- Added a guided setup screen for Google Workspace, with every field reachable or derived, and the operator able to name the integration
- Added mentions as inline highlights, with a character limit, copy and paste, selection and mobile support
- Added an aligned grid of eight quick actions shared by every surface
- Added role duplication into an unsaved draft
- Changed the logo icon
- Changed browser console output to exclude session tokens
- Changed the Elastic Security audit to collect across all 17 endpoints
- Changed scoring so only completed checks produce findings, and gated dependent controls
- Fixed error responses exposing internal stack details, across every service
- Fixed cancelled subscriptions not being reactivatable
- Fixed session cookies not being scoped host-only to the apex, and orphaned copies being left behind
- Fixed catalogue item fields not matching the agent’s real projected keys, and added a drift detector
- Fixed a CORS wildcard, replacing it with the platform allowlist
- Fixed 8 invented base ids hiding 6 specialists in production
- Fixed framework and severity filters on the FortiGate audit, and a control id typo
- Fixed a panic on profile photos smaller than the detection window
- Fixed a deleted integration base returning a 500 for the whole tenant
- Fixed the updater reporting the stored size rather than what the agent receives
- Fixed the device data block only refreshing at registration
- Fixed an inventory retry that spiked the agent to around 1 GB
- Fixed a duplicate full download on every release
- Fixed registered devices reporting stale OS, CPU and RAM
- Fixed a node reading interfaces that were not its own
- Fixed one physical interface reported by two producers appearing twice
- Fixed branding logos being validated by filename rather than by content
- Fixed multicast groups becoming assets in the graph
- Fixed host inventory relay to devices
- Fixed an unclearable session cookie, a redirect storm, and made the chat 401-proof
- Fixed Mermaid colours not following a theme change
- Added GCP network topology collected from the provider API: cloud accounts, VPCs, subnets, peering and managed services, with gateways, external peers and PSA-hosted services nested
- Added agent fleet and version telemetry with failure panels, and an egress bandwidth dashboard
- Fixed a managed service being placed by its type rather than by where its address lives
- Fixed GCP subnets being keyed by bare name instead of by region
- Fixed a VPN fallback that claimed the internet through the peer
- Added a declared and enforced token type on every JWT
- Added interface, ARP and MAC table collection from network integrations, on by default, with per-device and per-integration toggles exposed to the interface
- Added the TrueNAS family at the ops edge
- Added an environment-driven agent version with a startup gate and egress metrics
- Removed dead routing that exposed 81 unauthenticated routes
- Fixed the WAF rejecting legitimate email addresses through its SQL injection and XSS rules
- Fixed the network vendor being resolved by brand rather than by base id
- Fixed the installation token lifetime being uncapped, and bad values being accepted
- Fixed error responses exposing internal stack details
- Fixed the QRadar audit, rebuilt against live console data, including per-endpoint paging quirks
- Added a host vulnerability scanner on the agent, on by default and gated by the platform, with manual on-demand scans, installed-app inventory, and OS-level coverage for Windows (MSRC), Alpine and Ubuntu
- Added third-party application patching on Windows through a catalogue-driven native installer
- Added a run-as primitive so patching can run as the analyst’s own account rather than the system account, on Windows, Linux and macOS, including non-admin accounts
- Added
patch_apply_nowfor direct interactive application - Added an embedded host asset graph with an Attack Path query, exposure state, and a
host_inventoryquery driving the Inventory tab - Added detection rule authoring for Wazuh and Elastic, plus
wazuh_exceptionsfor rule-scoped alert suppression - Added QRadar and Azion configuration hardening audit families
- Added a generic REST tool that can drive any integration
- Added user account management across QRadar, Elastic, Wazuh, Bitdefender and Zabbix
- Added MITRE ATT&CK tagging on security configuration controls across all operating systems, and filled the gaps on the FortiGate and Huawei baselines
- Added a canonical topology schema, Windows ARP collection, and routing table reporting where the default route identifies the gateway
- Added a whole-context topology read
- Changed the Meraki audit to a firewall-first design with a product and feature not-applicable gate, growing from 39 to 68 controls
- Changed cloud posture checks to emit SKIPPED when no resource is found
- Fixed the QRadar, Azion and GCP audit types being rejected by an out-of-sync allowlist, and QRadar and Azion being classified as network rather than platform
- Fixed distro CVEs being queried by the installed binary rather than the source package
- Fixed a failed scan leaving an orphan running row
- Fixed vulnerability and audit schedules colliding, so both can coexist
- Fixed asset and reputation reads always failing the context scope check
- Fixed a white screen on the integration detail page
- Fixed the audit type not being forwarded on enable, sending QRadar to the cloud engine
- Added acceptance of the graph’s false-positive exposure verdict
- Added the threat intelligence service: MISP and market feeds, multi-source IOC corroboration, on-demand IOC enrichment with a durable store, free-key providers, and budget-safe proactive enrichment with daily budgets
- Added per-context reputation models with a scoring engine, a context-scoped store and unified lookup
- Added an NVD CVE mirror with on-demand enrichment, feed membership, RDAP routing and pivots
- Added a user-facing IOC lookup endpoint with synchronous enrichment
- Added the vulnerability matching core: an OSV-normalised advisory model with a per-ecosystem matcher, OSV sync, a match store and a match endpoint
- Added an MSRC ingester for Windows, a Windows application update catalogue built from winget, and NVD CPE matching for third-party applications
- Added RBAC gating on the investigation read routes
- Added a device Inventory tab with live application, service and port topology, in list and graph views, identifying unattributed services
- Added the false-positive exposure verdict to the device vulnerability tab
- Changed the device Configuration tab to be fluid, moving the run-as credential card into it and naming it “Private credential”
- Removed “Last seen” from the overview card
- Fixed OSV dumps being held in memory, unblocking non-Debian ecosystems, RPM distros and language ecosystems
- Fixed OSV advisories not being self-sufficient for CVSS score and severity
- Fixed accent buttons being illegible in dark mode, and completed the device detail translations
- Fixed the MITRE coverage scrollbar not following the platform style
- Added a subscription reactivation route, including subscriptions pending cancellation
- Added a Locaweb platform specialist with 12 network operation tools, a CyberArk Identity IAM/PAM sub-agent, and Orion with threat intelligence tools and dedicated sub-agents
- Added Brontes under the coordinator with a platform-management toolset, an
install_agenttool for endpoint onboarding, folder management, and RBAC and ABAC access-control tools - Added environment-aware sub-agent visibility, so a specialist without an active integration stops being offered
- Added headless per-integration Athena analysis triggered by a change, plus an on-demand audit-report skill carrying full findings and remediation
- Added rule create and edit modes to the Wazuh and Elastic sub-agents, and the
wazuh_exceptionstool - Added per-message timestamps and a “now” anchor for the agent
- Added context caching for the agent’s instructions and tools
- Added one device tool with folders, an audit module and safe bulk operations
- Added the conversation id to every streaming frame
- Added stream resume so a client link switch no longer kills the run
- Added conversation ownership enforcement on the agent read route
- Added a first-class vulnerabilities table with a patch view and manual runs, plus a per-device vulnerability module gate that is on by default
- Added independent audit and vulnerability scores composed into one navigable posture
- Added a MITRE ATT&CK coverage matrix, scoped to the integration’s asset class, with a dedicated host asset class for host audits
- Added on-demand device Attack Path pull with a snapshot
- Added per-finding exposure state from the host graph, and a per-target vulnerability rollup covering known exploited vulnerabilities and active exposure
- Added a tunnel hop for the pre-scan vulnerability gate, a dedicated verb for on-demand host graph queries, and routing of exposure verdicts from the agent to devices
- Added multi-chat with tabs in the header: per-conversation drafts, mentions and thinking steps, a green dot for a finished background tab, and mention chips rendered in the tab label
- Added a redesigned global security posture page with per-integration security tabs, a category filter, a posture trend bar and a MITRE ATT&CK breakdown
- Added a solution-first vulnerability view driven by the patch rather than the CVE, with a manual scan, a per-vulnerability risk path graph, and exposure shown as in use or not in use
- Added a composite device posture card with score by area, and vulnerability and audit module toggles on the device detail
- Added the run-as credential interface on the device detail, with neutral per-user wording and Spanish and Italian translations
- Added
@playbookand@runbookinline tags that open the editor in the right sidebar - Added a richer device header, a System card and a Configuration tab
- Changed the platform agent into domain agents, adding observability and moving Sentinel and Intune
- Changed a manual vulnerability run to proceed when a previous scan was abandoned
- Changed vulnerabilities to be unified into the Findings tab on devices
- Improved the error messages for user invitations
- Removed the WSUS sub-agent
- Fixed tag management requiring no authentication, and webhook tokens not being redacted in runs
- Fixed tool, action and script configurations missing from the runbook listing
- Fixed a vendor leak in the specialist descriptions
- Fixed the agent starting a run on a resume-only request
- Fixed vulnerability scans overwriting the host audit’s findings, by scoping scan reads by class
- Fixed host, device and database findings being categorised as “Other”
- Fixed partial updates wiping module flags
- Fixed the inventory payload wire key not matching devices
- Fixed CVEs linking to NVD by the distro-prefixed advisory instead of the canonical id
- Fixed the audit toggle reflecting the module flag rather than the real audit configuration
- Fixed double-feeding the stream on resume
- Fixed the consolidated agent answer not appearing in a playbook run’s detail
- Added change-triggered per-integration Athena analysis, merged into a global priority queue
- Added organisation-exclusive visibility for integration bases, public or restricted
- Added a per-device run-as credential, choosing between the system account and the analyst’s own, injected into interactive agent dispatch
- Added native audit auto-provisioning when an integration is authorised
- Added a per-scan severity snapshot at ingest and a deterministic per-integration overview
- Added relaying of host vulnerability match requests and application update matches to the intelligence service
- Changed the posture score to count skipped checks as success
- Fixed more than one open scan per integration, and stale scans not being reaped
- Fixed Azure not being recognised as auditable, and its findings being categorised as “Other”
- Added cross-tenant authorisation enforcement on the RBAC administration and user routes
- Added the Locaweb and CyberArk Identity families to the ops allowlist
- Added a CyberArk Identity IAM operation family, extended with policies, applications and analytics
- Added a Locaweb server API family with 12 tools covering its full 52-endpoint surface
- Added REST observability integrations for Datadog, Dynatrace, Grafana and Elastic
- Added an Argo CD CLI tool manager for Linux, macOS and Windows
- Changed patch status to be reported only from conclusive scans
- Changed Windows pending-update reporting to distinguish auto-serviced updates
- Improved decryption by only decrypting the fields each endpoint renders
- Fixed email address case sensitivity
- Fixed integration credential masking missing secret, passphrase and similar fields
- Fixed apt applying without updating first, and made apt discovery fail closed
- Fixed the DNS server role being matched as a substring rather than exactly
- Added the FortiGate per-policy interface convention to the agent’s recorded facts
- Added a full Sophos netsec sub-agent covering API operations, audit, troubleshooting and skills, with intent-first configuration and policy tools and content search
- Added a Docker operations skill for host Docker work
- Added the Sophos, Tenable and Cisco Meraki families at the ops and audit edges
- Added a campaign rollup endpoint for a patch change
- Added a full Sophos SFOS family: operation tools across objects, firewall, web, network, routing, VPN, authentication, security and system; a 136-control CIS hardening audit; firewall-rule policy analysis; SSH diagnostics; logical configuration backup; an intent-first rule tool; a smart-CRUD engine covering every entity; and content search by address, port or partial name
- Added Azure cloud posture: 149 checks across storage, data stores, network, containers, Defender, monitoring, virtual machines, app services, API management and AI search, with a baseline, score-only framework maps and Azure-aware remediation
- Added
qradar_rulesto operate correlation rules over the API - Added Tenable Vulnerability Management: a specialist agent backed by a family of 7 tools
- Added a Cisco Meraki family with intent-first smart CRUD that reuses or creates objects
- Added Cloudflare Logpush and R2 log reading
- Added structured filter clauses across 11 more verbs
- Added guided Cloudflare registration with zone and account discovery, including R2 Logpush per zone
- Added a structured filter builder in the tool parameters editor
- Added a structured change draft on “Request change”, with a campaign rollup card on the change detail and automatic polling of pending updates
- Changed “Request change” to populate the chat as a hidden chip rather than sending automatically, opening the change in the sidebar on the first reply
- Improved retry backoff, cutting roughly 30-second stalls
- Improved the Sophos audit from around 220s to 87s by collecting through multi-entity reads, and backup from around 4 minutes to 84s
- Improved agent hardening: secrets kept out of the log, command construction tightened, and path and permission handling reviewed
- Removed autofill from the left sidebar and a duplicated tooltip in Safari
- Fixed patch changes not opening the approval page from the frontend
- Fixed Cloudflare and Azion WAF specialists being routed to the wrong coordinator
- Fixed audit enable and disable being allowed while the target agent is offline
- Fixed the real Azure subscription id not being sent on audit enable
- Fixed Postgres connection pools being unbounded, which could exhaust slots
- Fixed scheduled patch items whose window had expired not being aborted and reported
- Fixed the ingest identity not being bound to the authenticated session
- Fixed an infinite loading state on the security policies tab
- Fixed chat title rename and display, scroll focus, and the cursor resetting after deleting a space
- Fixed 118 pre-existing TypeScript errors
- Changed the security posture screen to be gated to the Enterprise plan
- Fixed mobile navigation
- Added a Splunk sub-agent for Enterprise and Cloud
- Added PAN-OS tools and skills to the netsec sub-agent
- Added an
is_service_userclaim on service user tokens - Added pending risk-acceptance letters surfaced on findings, with the signed letter rendered as an HTML view and a PDF export
- Added PAN-OS audit and configuration verbs at the edge
- Added a Splunk family with SPL search, Enterprise Security notables, saved searches and enrichment
- Added an SSH-only Palo Alto PAN-OS family with audit, enrichment and configuration
- Added rendering of the risk-acceptance letter to PDF, with a visual signature block built from the signer’s name
- Added GLPI as a service management provider, with a shared ITSM detail kit
- Added security posture on network integrations
- Added host and patch selection with “Request change” from the chat
- Added a mobile menu
- Changed Windows change execution to handle a host awaiting reboot
- Changed the risk-acceptance letter flow
- Fixed the audit type not always being emitted
- Fixed vulnerable operating system packages in the web server image
- Fixed Mermaid zoom and pan being lost when switching the right-side tab
- Fixed workspace and integration cards
- Added a
toolrunbook type with per-step iteration, a generation envelope that composes workflows from tool nodes, per-step parameter overrides, and projection references for bulk list parameters - Added per-tool parameter schemas for the runbook editor
- Added an Azion WAF and edge firewall sub-agent, and a GLPI service-desk sub-agent
- Added
fortigate_config_diffby backup id or date, plus asset-memory tools for the FortiGate sub-agent and host memory tools on the remediation agent - Added workflow composition to the playbook generator, with a repair loop and projection references
- Added routing of network and database integration audits to the device engine, with the audit type auto-filled from the integration base on enable
- Added the Splunk family to the ops allowlist
- Added reconciliation of pending-signature mutes as a safety net for missed callbacks
- Added a unified patch status schema with an item lifecycle and inventory merge, where change approval writes the plan into the device and the agent pulls it
- Added a read-only fleet pending-patches endpoint with a device patch status snapshot, and the console that reads it
- Added daily FortiGate configuration backup at a fixed time
- Added an on-demand rebuild route for a single asset’s memory note, an agent-managed memory block, and device-scoped memory routes for hosts
- Added bulk correlation graph calls to the intelligence service
- Added FortiGate configuration diff by backup id or date, with an encrypted store and age-based retention
- Added the agent pulling its patch plan over the tunnel and applying from it, retiring the local store
- Added recurrent pending-inventory push to the device record
- Added host purpose and role signals on Windows and Linux
- Added a periodic intelligence graph snapshot sender
- Added relaying of patch results, patch inventory and patch plan requests, audit enable, disable, run-now and remove commands, scan lifecycle events, and host graph snapshots to the intelligence service
- Added a redesigned automation experience: a new workflow canvas with tool-node cards, generated drafts opening in the editor, editable node parameters, loops and conditions in the step drawer, a code surface for script runbooks, and a redesigned creation screen, directory and execution monitor
- Added the signed risk-letter mute flow with running-scan polling
- Added a folder management overhaul with safe operations and batch move
- Added the threat intelligence service as the default provider
- Added a schema-driven tool parameter editor and a searchable integration picker
- Added full Italian translations for automations
- Changed the chat to stop auto-injecting asset memory, surfacing it as a read-only panel instead
- Fixed playbook generation being blocked by a network egress problem, and failing slowly against a dead endpoint
- Fixed reasoning steps pausing for authorization when they should run unattended
- Fixed rich mention tags not being collapsed in generated playbook names
- Fixed the asset-memory builder using a hardcoded configuration instead of the fleet’s
- Fixed pending patches being scoped to the full organisation tree rather than the selected context
- Fixed service users being blocked by the private-credential requirement
- Fixed Windows patch application by skipping superseded updates and excluding Defender signatures
- Fixed workspace tabs resetting on refresh
- Added a database engineering coordinator with five engine sub-agents, senior-DBA skills per engine, and a sensitive-data scan tool
- Added Cloudflare and four NoSQL database sub-agents
- Added Athena as a sub-agent with enforced risk validation, an explicit noise-versus-real-risk verdict for critical and high findings, batched validation per integration, and coverage of host and operating system targets rather than cloud alone
- Added FortiAnalyzer log-analysis tools, and FortiGate configuration backup and restore over SSH
- Added deeper agent reasoning behind a switch, with a capped budget
- Added an isolated builder endpoint for the asset memory note
- Added a preview endpoint that renders the risk letter as a PDF with no side effects
- Added activation of a pending-signature mute once the risk letter is signed
- Added assisted mute with a posture verdict and a risk-acceptance gate, plus a risk-acceptance letter template, HTML renderer, PDF render and signing envelope
- Added device and host audit enable with its own configuration table, a latest-scan endpoint, a running-scan endpoint for polling, and audit target listing with display labels
- Added a deterministic tenant posture score composed from findings and adjustments
- Added the FortiAnalyzer, FortiGate, Cloudflare, Azion and database families to the ops and audit allowlists
- Added attribution of operation mutations to the authenticated user
- Added encryption for sensitive fields on an agent partial update
- Added a database audit family covering PostgreSQL, MySQL, SQL Server, Firebird, Oracle, MongoDB, Redis, Cassandra and Elasticsearch, each live-validated, growing the control baseline from 91 to 286 with CIS and NIST coverage, a field-level encryption scan, and a generic execution tool across all engines
- Added a FortiAnalyzer integration for logs, devices, system and enrichment
- Added a network operations crate with Cloudflare WAF and Azion WAF and edge firewall families
- Added a GLPI ticket-handling family, allowed at the ops edge
- Added per-asset memory facts collection with a local change log
- Added per-finding framework and compliance mapping for host and device findings, with a primary baseline and compatible frameworks
- Added a generalised audit scheduler covering host and device audits, with on-demand runs that do not touch the schedule
- Changed the signing envelope to be sent on creation, so signer emails fire
- Fixed FortiGate CLI templates not matching FortiOS 7.4 and 7.6
- Fixed sub-organisation creation
- Fixed the risk-letter verdict being sourced from the client rather than the assessment
- Fixed the FortiGate and FortiAnalyzer ops allowlist lost in a merge
- Fixed scan totals and score not being recomputed from all persisted findings
- Fixed failed-probe controls being marked as passing
- Fixed sensitive-data scanning flagging shaped but unconfirmed plaintext, with name masking and confidence
- Fixed large binary downloads being cut by a 30-second timeout
- Fixed context selection in sub-organisation rules and policies
- Added an
intel.readpermission for threat intelligence lookups - Added a public document signing page with a PDF viewer
- Added muting findings with a risk-acceptance gate
- Added integration memory surfaced to the agent through the attachment
- Added sub-organisation menus
- Added pagination to root-level artefacts
- Fixed updating a role
- Fixed the default asset group being recreated instead of relinked
- Fixed the context cache
- Fixed the SendGrid form’s URL options, verify-SSL default and dropdown
- Fixed a background 401 forcing a login on a public page
- Fixed deleting a card also opening the item
- Fixed hand-authored script runbooks reverting to draft on save
- Added a native cloud posture engine in Rust with an AWS provider covering 602 checks, and a complete GCP provider reaching parity at 103 checks across Cloud DNS, Storage, SQL, Compute, Logging, IAM, BigQuery, KMS, GKE and more, each with a baseline framework and cross-framework mapping
- Added a SentinelOne Singularity operations family with threat enrichment
- Added audit families for Juniper (CIS), Huawei VRP, FortiSwitchOS and Dell N-series, each with a troubleshooting profile
- Added a warm SSH session pool with vendor-aware login
- Added an agent-side cloud audit flow with a persisted scheduler and on-demand runs
- Added a SendGrid email operations tool and an intrusion sweep with a journald fallback
- Added a compliance heatmap, a pass-rate honeycomb by service, and open-findings cards by severity
- Fixed legacy SSH algorithms for older Cisco equipment, and switch-aware IOS troubleshooting
- Fixed AWS collection hanging by bounding SDK operation timeouts, and restored multi-region enumeration
- Added an operations verb catalogue spanning all 10 families, with read and enrichment capabilities in the script sandbox, read-only network and SSH troubleshooting, and an audit surface
- Added runbook draft and active status with an approval gate, compile-time validation on create and update, and a dry-run harness with golden fixtures
- Added playbook generation mixing script and reasoning steps, with tool listing, approval, and asynchronous generation with polling and a fallback
- Added multi-context queries, enabling parent to child access
- Added deterministic rendering in Scribe: raw tool data captured on a side channel, an exhaustive planner, a deterministic FortiGate audit adapter replacing a 31-second fallback, and mask inference where the agent infers the shape and the renderer produces the output
- Added a playbook generator agent with its own endpoint
- Added Athena, the posture analytics agent, with GRC analytics tools and a standalone deployment mode
- Added a SendGrid email sub-agent, and EDR-backed Juniper hardening audit and troubleshooting tools
- Added an auto-connect path for FortiGate and then all remaining SSH vendors, removing explicit connect and disconnect
- Added localised chat error messages, including Italian
- Added private integrations: accounts with per-user individual credentials, with MFA guarding and an audit trail
- Added Italian to RBAC and validation
- Added subscription management permissions for the signing module, granted to the administrator and analyst roles
- Added the findings store, mute engine and audit API, with a latest-scan endpoint, universal cross-provider finding categories, a multi-severity filter and a deterministic scan score
- Added posture analytics triggered after scan ingestion, and an on-demand audit scan with a 10-minute guard
- Added the Juniper and Huawei audit types, and the SendGrid family, to the allowlists
- Added a self-describing SSH command with vendor and enable injection
- Added recording of terminal scan failures, surfaced on the latest scan
- Added Italian for report types and tags
- Added a code block creation endpoint
- Added the automation composer: a “Create an automation” screen rendering generated playbooks, a modern trigger selector, drag-to-reorder, a segmented tool picker with keyboard navigation, and a revamped execution monitor
- Added a public document signing page with a PDF viewer gated on reading to the end, served at the root for signers without an account
- Added a global security posture screen
- Added sub-organisation role configuration, user pagination and a saved row count
- Changed the agent hierarchy so netsec and security mount directly under the coordinator, retiring the orchestrator layer
- Changed the transfer menu to list every sub-agent
- Changed tool call start and completion into a single persisted line
- Changed context validation to fail closed
- Improved the runs list by returning a per-run summary, removing a query per run
- Improved the Fortinet agent’s instructions by 52% and its tool descriptions by roughly 58%
- Improved the executions list from one call per run to a single call
- Removed the 50-row table cap and raised the cell and header length limits
- Fixed playbook deletion returning an error by removing the whole subtree
- Fixed captured tool data being corrupted by the sanitiser, turning tables into text
- Fixed Dell command syntax, verified on live hardware
- Fixed just-in-time provisioning not being idempotent for a colliding username, and an inverted blocked check
- Fixed cross-organisation role validation for sub-organisations
- Fixed intermittent 503s from a destructive user cache
- Fixed the agent audit schedule not being dropped when an integration is deleted
- Fixed translations in chat, investigation and updates
- Added a SentinelOne Singularity sub-agent
- Added report editing in Scribe, with deterministic rendering of tool data into blocks and the planner marking which blocks are data-backed
- Added the SentinelOne family at the ops edge
- Added a Change Management (GMUD) interface: an RBAC-aware catalogue, chat mentions, a history timeline, an execute button, PDF export and leaner detail cards
- Added Zabbix and SentinelOne as alert providers
- Added multi-tenant GitHub connection through your own OAuth, discovering an existing installation
- Added Italian
- Changed planning so Centurion owns the plan and sub-agents update its steps
- Changed the agent to raise a change request only when you explicitly ask for one
- Changed the GitHub skill to cover organisation management
- Changed plans to appear in the workspace tabs instead of a card above the input
- Fixed duplicated actions collapsing when expanding the reasoning history
- Fixed translations in reports, chat and home
- Added a Zabbix monitoring sub-agent
- Added read-only troubleshooting on network devices for Fortinet, Cisco and MikroTik
- Added
audit_fleetwith scope by device, by folder or across the fleet, including recursive folder targeting and macOS support - Added the FortiGate policy-audit option to the audit tool
- Added terminal handling for a tool that requires a private credential
- Added a git-workflow skill in place of the previous publish tool
- Added private integrations: linking, resolution and testing of individual credentials, closed fail-closed after review
- Added change history and agent-driven execution, with the requester as owner and the executor recorded separately
- Added the Zabbix family and the network-device enrichment verb at the ops edge
- Added multi-tenant GitHub connection through your own OAuth
- Added “My Accounts”: individual credentials for private integrations, reachable from the workspace settings menu, with a redesigned modal and the type locked by the integration
- Added an alert scope filter, EDR alert enrichment, folder mentions and a redesigned change screen
- Fixed MikroTik output not being cleaned through the RouterOS terminal modifiers
- Fixed patch dispatch failures not being surfaced, and the change not updating on execution
- Fixed editing an account losing its secret, errors not being visible, and inactive tiles not being dimmed
- Fixed translations in reports, investigation and organisation
- Added a Zabbix operations module: collection, interaction, enrichment, alert management and dashboards
- Added SSH troubleshooting on network devices, with profiles for Cisco IOS, FortiOS and MikroTik RouterOS
- Added FortiOS directed collection, routing by target address and auto-directing interface and health logs
- Added richer, vendor-agnostic QRadar offense enrichment with destination address and port, payload and action
- Added enrichment projections for CrowdStrike, Rapid7 and Apura list rows
- Added 14 MikroTik audit controls covering VPN, IPv6, wifiwave2 and SMB, and corrected the parser
- Changed the patch scheduler to accept reference-only schedule items from the platform
- Added
audit_fleet, a fleet-wide CIS hardening audit across many devices at once - Added three consolidated host tools — investigate, diagnose and triage — replacing the granular tooling
- Added a macOS audit backend built on the CIS Apple macOS and mSCP baselines
- Added macOS host enrichment with operating system inventory, investigation trace and asset-graph parsing
- Added a redesigned host investigation — diagnose, investigate and triage — with eBPF and ETW tracing
- Added user token usage logs
- Changed every patch schedule to become a change request, including a single host, with immediate apply available
- Changed the Wazuh and Elastic sub-agents to operate only through the agent
- Fixed a QRadar search re-polling itself, and added a hostname filter
- Fixed a sub-agent result not converging on a terminal state
- Fixed transient stream disconnects being treated as a stop
- Fixed Rapid7 credentials not resolving from a multi-access configuration
- Fixed FortiGate multi-VDOM configuration normalisation and pager advance
- Fixed error, report, documentation, folder, configuration and chat translations
- Added patch management to Perseus: reading, proposing and scheduling, a patch report, and fleet and campaign tools across many devices
- Added Change Management (GMUD) tools, with a change kind, sub-agent step contribution owned by the inserting agent, and drafting that never submits on its own
- Added a Bitdefender sub-agent with incident enrichment and a CIS audit
- Added a Change Management (GMUD) governance layer over patch management, dispatching and reconciling patches directly, with a patch kind discriminator, campaign auto-wrap and result ingestion
- Added named-approver rules with self-approval by default, and editing allowed in any pre-execution state with cancel and revert
- Added a global batch executor and a patch campaign layer
- Added cross-organisation support across reads, handlers and audit events, with by-identifier resolution over the whole envelope
- Added an operations route for SIEM and EDR tools, with the Axur, Apura, Bitdefender and SensrIT verbs allowed at the edge
- Added Apura BTTng team discovery
- Added patch management: discovery, a local schedule store, an apply engine and a scheduler, with reboot-policy enforcement, dnf and yum support, a Windows update facade and an approval gate
- Added cross-operating-system patch history, reboot hints inferred on Linux, and robust Windows reboot detection
- Added self-contained HTML dashboards for both audit and patch results
- Added framework scoping, a severity floor and failures-only filters to the device and host audits, with all 7 device catalogues tagged by framework
- Added a host telemetry graph collector, uploading through the tunnel
- Added SIEM and EDR operation and enrichment tools across 6 platforms, plus Axur, Apura BTTng and Bitdefender families
- Added a Bitdefender GravityZone CIS hardening audit, validated against a live tenant
- Added an ITSM block with Elastic Cases and SensrIT tools, including verbatim ticket and customer reads
- Added Updates: a right-side report panel, a management screen, a campaign-first view with device multi-select, and a native dashboard that opens on schedule
- Added a directory of changes in the chat sidebar, with a detail tab, rendering from structured data with inline editing and an approval-rules screen gated by permission
- Added cross-organisation MSSP governance, with the real organisation flag exposed and the cross-organisation gates honouring it
- Added Bitdefender to the alert sources and migrated CrowdStrike, Apura BTTng and Elastic onto the shared transport
- Changed six SIEM sub-agents to operate through the agent as a single tier, and migrated the Axur, Apura BTTng and SensrIT agents to agent-side operation tools
- Changed ticket providers into a registry covering SensrIT and Elastic Cases
- Changed the investigation alert picker to be driven by a date range instead of a manual identifier search
- Changed the report context to be mandatory on every call, failing closed
- Fixed SensrIT operating by the wrong ticket identifier — the integration identifier is now resolved transparently
- Fixed an integration action not being bound to the integration’s own context
- Fixed a FortiGate full configuration being truncated, by anchoring prompt detection on the hostname
- Added cross-organisation ABAC: policy columns, a backfill, two-pass environmental policy evaluation, top-down cache invalidation and an MSSP gate
- Added inherited-policy and parent-role read endpoints, and an organisation-scope on roles mirroring the context scope
- Added an audit events read endpoint carrying the acting organisation and a cross-organisation marker, plus cross-organisation governance events
- Added permissions for ABAC policy management, audit logs and change management
- Added a dedicated MSSP toggle endpoint
- Fixed a password reset being blocked by a global domain rule instead of respecting the user’s own organisation
- Fixed social login being allowed for a domain or user managed through SSO
- Added a deterministic creation workflow to Scribe: table and chart blocks projected without guesswork, blocks generated in parallel, and editing of an existing report
- Added a durable audit trail, enriched with the organisation name, the user’s email and the command that was executed
- Added audit read endpoints and auditing of the chat routes, including the source address
- Added a user email filter on audit events
- Added a dedicated permission for reading audit logs
- Added auditing of the authentication, user, organisation, context and RBAC routes
- Added auditing of every read route through a global middleware
- Added an audit screen
- Added a multi-step automation flow editor: per-step integration and inputs, chained references, a field picker with value mapping, a “stop if” guard, conditional branching, flow-level input configuration and a one-minute schedule option
- Added tool-backed runbook templates and an action flow, plus a script runbook editor with its translations
- Added an alert provider registry covering Axur, CrowdStrike and Apura BTTng
- Added tabs and a filter to the automation screens, with a flatter edit design
- Updated a vulnerable dependency
- Fixed each step’s output not appearing in the execution monitor
- Fixed sub-organisation user settings
- Added text analysis to the script sandbox
- Fixed script runbook results not rendering in the execution monitor
- Added a sandboxed Go script runbook that can execute integration actions
- Added deterministic vendor action playbooks driven through the devices service
- Added SensrIT action templates for creating, updating and closing an incident, with corrected impact and urgency mapping
- Added deterministic value mapping between an action’s fields, explicit input chaining, per-step conditional execution and a per-step “stop if” guard
- Added a runbook type to the context API and to the context listing
- Fixed an action step’s references not resolving, and per-step output not reaching the run monitor
- Fixed an empty reply being returned instead of the completed result
- Fixed global templates missing from the runbook read
- Added an autonomous coordinator mode for book generation
- Added CrowdStrike Falcon and Apura BTTng specialist sub-agents
- Fixed the injection detector running against the password field on a confirmed password reset
- Added hardening audit tools with a Myrmex baseline for FortiGate (127 controls), Cisco (83) and Wazuh (44), each self-contained from connect through disconnect
- Added device inventory and focused-category detail to the FortiGate audit, with every offending entry identified in the finding
- Added a read-only host triage tool to Perseus
- Added routes for managing integration bases, and an audit execution route at the edge
- Added the MikroTik, Meraki, Elastic Security and GCP audit types
- Added a cross-platform device audit engine covering FortiGate, Cisco and Wazuh, then four more families, with a shared session layer and session paths that work on Linux, macOS and Windows
- Added multi-access support to the Wazuh audit, covering the manager and indexer surfaces
- Added a status breakdown to the audit run response and its summary
- Added standardised theme and typography across the product
- Added GitHub repository listing and association for cloud integrations
- Changed the audit tools to run through the agent, wiring 7 families
- Changed Wazuh from 10 direct tools to 3 operation-based tools
- Changed the chat so the scroll wheel works from the side gutters but not over the input
- Fixed the FortiGate audit recovering when the device returns no prompt, omits core sections, or sends a pre-login banner
- Fixed management-plane controls to detect more than one exposed interface and a wide-open trusted host
- Fixed Cisco snapshots missing the start of a command’s output
- Fixed Wazuh responses being discarded when the envelope came back mis-escaped
- Fixed host investigation improvising when a result came back empty
- Fixed an integration base rejecting a complete document on creation
- Fixed the Windows inventory not reporting the real product identity from the registry
- Fixed duplicate reasoning entries caused by a polling fallback, and isolated history from the live view
- Fixed the seats and token limit control being offered on Enterprise plans
- Added direct alert and incident triage tools for QRadar, Rapid7, Microsoft Sentinel and SensrIT
- Added direct tools for Google Threat Intelligence, Shodan, Prowler and Axur
- Added a hardening audit tool and playbook to Perseus, plus artefact reading so it stops repeating calls
- Added shared filesystem and command-line primitives, with a stated reason required on every call
- Added an infrastructure-as-code workflow to the GCP agent, split into plan and execute with backend detection and a persistent repository knowledge cache
- Added SensrIT to the security orchestrator, accepting either the ticket number or its identifier
- Changed QRadar, Rapid7 and SensrIT to read from a single source of truth, dropping 194 bundled asset files
- Fixed SensrIT being confused with Microsoft Sentinel in routing
- Fixed Elastic listing building blocks as alerts by default
- Added SAML single sign-on: configuration and activation, a Microsoft Entra adapter, assertion replay protection, just-in-time provisioning with role replacement, and administrative endpoints behind dedicated permissions
- Added protection for SSO-managed accounts: local authentication and credential changes are refused, and account creation, pre-registration and password reset are blocked for a claimed domain
- Added SSO identity fields on the user profile, and surfaced the authentication method in the members list
- Added bulk password reset on SSO deactivation, with custom user selection and an activation preview
- Added deletion of an SSO configuration, purging the domain claim so it can be claimed again
- Added multi-factor reset for a locked-out account
- Added the SAML single sign-on login flow, with a retry action and collapsible technical detail when sign-in is blocked
- Added SSH skill catalogues for five vendors — 116 procedures in total — wiring thematic suites for Fortinet, Cisco, Dell, Huawei, MikroTik and Palo Alto covering switching, routing, security, VPN, deployment and diagnostics
- Added a Juniper Junos specialist and an Axur digital risk sub-agent
- Added skill-driven single-tier agents for Elastic Security and Wazuh, with direct tools for alert triage, exception binding and lookup fallbacks
- Added web search to Iris
- Added a per-invocation loop guard for repeated tool calls, plus a tool-call budget and a verdict cross-check in triage
- Added persistent planning shared across the multi-task agents
- Added GitHub to the periodic connectivity probe, with token refresh
- Added device resources and alerts read from the analytics store
- Added GitHub command-line support, and Oracle Cloud command-line installation on Linux
- Added a token refresh protocol so a credential is pulled rather than pushed
- Added the token refresh handler
- Added an SSO administration tab in organisation settings: a provider wizard, read-only service-provider fields, a saved-metadata status card, an activation mode chooser with custom user selection, a deactivation confirmation with reset summary, and a delete action
- Added a redesigned Security tab for SSO users, and the authentication method in the members table
- Added a live SSH terminal side panel, with SSH tool responses rendered as terminal-style cards
- Added integration identifier, auto-suggestion and toggles to alerts and investigation
- Added plan management
- Changed the FortiGate and MikroTik audit skills into benchmark-style baselines with table-only output
- Changed SSH sessions to be keyed by conversation rather than by message, with dead sessions detected and idle ones closed
- Changed the command-line probe timeout from 15s to 30s
- Changed the connectivity probe to a 10-minute interval with a two-failure threshold, reducing flapping
- Improved the multi-factor disable flow for administrators and users
- Updated dependencies to address published vulnerabilities
- Fixed the password reset email carrying an incomplete address, and added a dedicated notice for SSO deactivation
- Fixed transient SSO state surviving back navigation, and a redirect loop after the callback
- Fixed free plan verification
- Fixed Dell skills being split by dialect, and privileged mode being entered automatically before a write
- Fixed Junos sessions landing in the shell instead of the CLI
- Fixed truncation being applied to SSH output
- Fixed a shared correlation identifier causing responses to collide
- Fixed per-integration alert fetches running concurrently again
- Added the GitHub integration, with environment configuration and token management
- Fixed the connection test not falling back to the first multi-access configuration
- Added organisation and context validation on the user listing
- Added reCAPTCHA on phone registration
- Added a Microsoft Sentinel integration form with its own application registration, skipping the collector on creation
- Added Wazuh and Rapid7 InsightIDR alerts to case management
- Added a customer filter to the ITSM ticket list
- Added inline editing for multi-access integration fields
- Added a sub-organisation billing notice
- Changed tool start and completion into a single entry, with HTTP failures detected in the reasoning console
- Fixed the chat auto-resuming after a stop, and the reasoning card not showing reliably
- Fixed profile saving and the name not updating reactively
- Fixed context creation and adding a context to a sub-organisation
- Fixed the multi-factor name and preferred-method selection
- Fixed the free plan bypass
- Fixed the chat logo flickering
- Added resumable streams, so a dropped connection resumes where it left off, forwarding the last received event
- Added end-to-end request correlation, propagated to the agent service, with a catalogue of stable error codes and incident reporting
- Added a self-correction loop when an agent calls a tool that does not exist
- Changed an overload response to report an incident instead of a verbose error
- Fixed stream disconnects being handled abruptly, and aligned the processing timeout
- Fixed the conversation status not being cleaned up when a stream disconnects
- Added organisation and founder creation through the Google Marketplace integration
- Added structured error codes
- Improved user management
- Fixed simple-field encryption on update
- Fixed unescaped ampersands in an SVG breaking the render
- Added a theme configuration with a matching loading screen
- Added new languages
- Added an overdue payment screen
- Added the Google Marketplace integration
- Added a route that returns the overdue payment link
- Improved the password strength indicator and its rules
- Removed the option to skip plan selection
- Fixed an upgrade failing when the payment is incomplete
- Added theme synchronisation across sessions
- Changed alert fetches to run one at a time per integration, with the error state shown on the chip
- Fixed Elastic building blocks being listed as alerts
- Fixed the security agent not persisting per conversation
- Fixed mobile layout and dark-mode sidebar bleed, and polished the reasoning console and markdown table headers
- Added a Kubernetes specialist agent
- Added a stated reason on every tool call, shown to you in place of the raw tool name
- Added sending email from a shared mailbox
- Added a stop request event on the stream
- Added Kubernetes management with a periodic connectivity test
- Added UniFi API endpoints, extended with hardware information
- Added error reporting when creating or editing an integration, so the failure reaches you instead of being swallowed
- Added an explicit status while an integration waits for data
- Added Kubernetes cluster scanning and hardening, with
kubectlsupport on Linux, macOS and Windows - Added database actions and periodic database connectivity testing, starting with PostgreSQL
- Added a diff mode to SSH snapshots for incremental reads
- Added error propagation while an integration is configured on the collector
- Added feedback when creating and updating an integration
- Added a filter that shows only online collectors in integration fields
- Changed the platform coordinator to own cloud, SRE and DevOps work, simplifying routing
- Changed integration actions to carry a dynamic timeout and their action identifier
- Changed integration connectivity testing to run on the agent instead of the tunnel
- Fixed a target timeout being reported as a request failure
- Fixed agent activation on macOS
- Fixed per-integration loading feedback, and made the QRadar fetch parallel
- Added artefact search directly from the chat input
- Added parameter discovery for a discovered action
- Added logging for a failed webhook
- Fixed ITSM polling, a reasoning console entry, icon mapping and the tab interface
- Fixed the payment callback URL
- Added routing to the security agent when you mention a SensrIT-based integration
- Fixed default values missing from a multi-access integration’s creation payload
- Added multi-type integration support, so one integration can carry several access configurations
- Added orchestration of database actions and connection tests, with the integration status updated afterwards
- Added an authentication type for APIs that expect the key as a query parameter, and allowed those injected parameters to satisfy a required one
- Added passthrough when an action body is a single placeholder
- Added ITSM ticket enrichment with an Investigation Wizard tab, alert detail expansion and indicator extraction
- Added alert search by identifier for Elastic and QRadar
- Added multi-access support in the interface
- Added parameter discovery for a discovered action
- Added the SensrIT description to the security coordinator
- Improved integration discovery speed and unified the selector
- Improved case management and the ITSM ticket filters
- Fixed the cross-organisation invitation details
- Fixed the subscription upgrade session not being returned
- Added smart truncation of SSH output, awareness of device errors, and a Sophos menu protocol
- Added connectivity testing local to the agent, with status change notifications
- Added routing for database actions and tests
- Added an ITSM tickets view in Service Management
- Changed REST actions to carry a dynamic timeout chain and their action identifier
- Improved Service Management
- Fixed the SensrIT form fields not appearing before the OAuth redirect
- Fixed ITSM integration discovery and alerts loading indefinitely
- Fixed dark mode in the chat background, case management buttons, the connectors dialog and sub-organisation tabs
- Fixed a QRadar action and a user update
- Added QRadar alert details and indicator extraction in the enrichment and investigation screens
- Added QRadar support for personal integrations
- Fixed email sanitisation on user update, which was affecting reads, updates and password change
- Added support for several connectors at once, managed through a single modal
- Added rendering of documents attached to a case
- Changed the menu system inside tabs to a single standard
- Fixed the alert screen loading and the modal background colour
- Added reading files from Google Drive
- Added five API sub-agents: NetBox, Barracuda, Shodan, Google Threat Intelligence and QRadar
- Added a global platform context, moving documentation retrieval to Iris
- Added analysis of files stored in SharePoint, and consolidated the productivity tools into one integration each with cached authentication
- Added tool call events on the stream for retrieval tools, with completion republished
- Added persistence of tool output and response from the stream
- Added Case Management with unified alerts, threat intelligence and full detail, plus an Investigation module and an investigation wizard
- Added organisation-scoped integration bases
- Added an activity bar for reaching menus while the sidebar is collapsed
- Added alert grouping by title and host, and deduplication across personal and contextual cases
- Added OAuth2 exchange support for integrations such as SensrIT
- Added a file filter for SharePoint
- Added permissions on the administrative pages, with a redesigned administration screen
- Added an asset limit and an unlimited seats option on a subscription
- Changed the security coordinator to work with personal and contextual integrations transparently
- Changed Perseus to fail fast on an offline device, with a circuit breaker
- Changed “Investigation” to “Enrichment” on the case screen
- Improved user management
- Fixed SSH terminal and device tool output not being sanitised before reaching the agent
- Fixed a summarisation step producing an invented result in the security coordinator
- Fixed first-message latency and stability under pod degradation
- Fixed the Perseus scope, and added RouterOS to the network security coordinator
- Fixed Portuguese accents on the Threat Intelligence screen, cut-off buttons in the integration deletion modal, and UniFi fields being sent as arrays
- Fixed personal Google Threat Intelligence mapping for threat intelligence searches
- Fixed translations and mobile responsiveness
- Fixed the cancellation return
- Added organisation-scoped integration bases, with a two-hop OAuth exchange for organisation integrations and a dedicated table for user integrations built on an organisation base
- Added Outlook Mail, SharePoint, Google Drive and Gmail
- Added an authentication type for Google Threat Intelligence
- Added default values on the integration base form, and a category filter
- Added permission-scoped alert listing
- Changed personal integrations to run either on a collector or locally
- Added a UniFi integration form and detail view
- Added Google Threat Intelligence enrichment
- Improved interface animations and the stability of the integration detail cards
- Removed the playbook and runbook screens temporarily
- Fixed stream error handling with automatic retry, an error response view and a diagram fallback
- Added the integration base creation and registration flows, with a filter by name and route-level permissions
- Added permissions for personal integrations, granted automatically
- Added the ability for personal connectors to call the core service
- Changed the email update policy to be less restrictive
- Fixed adding seats on an unlimited-seat subscription
- Added integration cards for FortiGate over SSH, Huawei, MikroTik, UniFi, Cisco Switch, Intelbras, Meraki and n8n
- Added indicator detection inside tables and an intelligence context type
- Improved new chat creation speed, reasoning console timing and the integration request timeout
- Fixed a crash in Elastic alert details when a field was not a list
- Added direct streaming from the agent, so a response arrives as it is produced, with reasoning steps recorded and persisted as they arrive
- Added a dynamic timeout on integration action execution
- Added the response identifier on the stream
- Added integration-specific detail cards, starting with a Wazuh agents card that polls on its own, an Elastic Security detection alerts card, and a Trend Micro Vision One Workbench alerts card with date range filters
- Added an expandable rules card to free space on the integration screen
- Added live reporting across the remaining artefact types
- Added automatic indicator context in the chat
- Added newer Fedora and Ubuntu releases
- Added non-sensitive access configuration fields to integration mentions in the chat
- Added long-lived tokens
- Added ARM builds for Oracle Linux and Fedora
- Fixed mobile login
- Changed the platform specialist to the cloud coordinator
- Improved the wait time for an agent response, and raised the processing allowance for complex tasks
- Improved the GCP specialist’s guidance
- Fixed the Myrmex agent installation script and tool
- Added the ability for the cloud agents to install the Myrmex agent on their own
- Added Oracle Cloud support, including its command line
- Added structured output on requests, and stricter planning guidance for cloud command-line calls
- Added ARM support across the Linux distributions
- Added device filtering by token
- Added builds for ARM and AMD architectures
- Added command markers for cloud command-line calls on Linux and macOS
- Added a cloud coordinator with skills for AWS and GCP
- Added an artefact service for large tool outputs, read line by line rather than all at once
- Added charts and flowcharts to Scribe, produced as vector graphics
- Added conversation-scoped session isolation, so concurrent sessions no longer collide
- Added attribute-based access control: a rules engine with AND, OR and NOT condition trees, environmental policies, conditional asset rules, and targeting by role, device, integration, folder, tag and user tag
- Added context restriction on roles
- Added folder tags with umbrella inheritance
- Added enforcement of entity-targeted access policies on every device and integration route, including folder move and tag assignment
- Added ARM64 to the download and update flows
- Added ARM64 cross-compilation for Ubuntu, Debian and Amazon Linux
- Added an HTML-to-PDF generation pipeline with dynamic branding, a report preview, and an editor for sections and charts
- Added chart and flowchart rendering, with multiple colours, editable types and cached results cleared on change
- Added report formatting to the ABNT standard, with headers, footers, chapter numbering and logo placement on export
- Added a split-panel report editor with live PDF preview, advanced customisation and chart management
- Added a Security Policies tab in organisation settings, with a wizard-style policy editor, progressive disclosure, and folder, tag and user tag targeting
- Added tag management and assignment in organisation settings
- Added macOS to the device list with its own download section
- Added a resizable sortable table and responsive chat width
- Improved the permission cache with atomic overwrite, debouncing and batched queries
- Improved resilience under concurrent command-line and SSH sessions
- Improved chat auto-scroll, pre-reasoning animations and severity labels in mentions
- Fixed corrupted terminal output not being sanitised before evaluation
- Fixed skill loading being visible as a tool call
- Fixed a role being created without its default asset group, and the cache not being invalidated on assignment or on a policy change
- Fixed asset-level filtering on folder and tag listings, and hardened context validation across the handlers
- Fixed concurrent command-line and SSH sessions sharing state
- Fixed several formatting breaks: bold and list markers, backticks, hash characters in subtitles, unicode characters, and chart caption duplication
- Fixed a semaphore stall that could drop the agent connection
- Fixed scrollbar layout shifts and diagram rendering
- Removed the reCAPTCHA check from social login
- Fixed login with Google
- Fixed duplicated reasoning entries and the answer text colour
- Fixed workspace background colours, overscroll and the chat input being clipped
- Fixed redundant requests and mobile scrolling in the device detail
- Added an n8n workflow automation sub-agent
- Added a Tenable Vulnerability Management sub-agent
- Added license awareness and error handling to the Bitdefender specialist
- Added a unified URL field for integrations
- Added context chips for file attachments, shown in sent messages
- Added a government flow and a country selector for sub-organisations
- Changed the connectivity check to treat any HTTP response as a service being online
- Fixed duplicate reasoning steps and transfer events
- Fixed a connection being aborted without a proper close
- Fixed update flags remaining set permanently
- Fixed chat pagination, scroll layout and integration sorting in custom folders
- Added a Bitdefender specialist
- Added last activity on the agent messages endpoint
- Fixed a false “worker is dead” detection and a heartbeat gap
- Fixed a cache deadlock that could hang a conversation
- Fixed a false inactivity timeout by following the agent heartbeat
- Improved folder management, drag-and-drop stability and move feedback
- Fixed the Microsoft authentication tools
- Added a tool for sending email to the user
- Changed the Microsoft agents into separate specialists
- Changed the Microsoft integrations into separate entries
- Added native Debian support
- Added investigation and report prompts
- Changed Wazuh to the network security coordinator, with the sub-agents named in the routing descriptions
- Fixed the macOS installer and its error handling
- Fixed connections to legacy Cisco 3650 and 3750 switches closing early
- Fixed polling dropping on conversation switch, refresh and network loss, and the reasoning console being hidden by auto-scroll
- Fixed light mode contrast
- Added social login with redirect, linking an account that already exists, and multi-factor support in the sign-in link
- Added redirection to a license upgrade
- Added multi-factor support when linking an account through single sign-on
- Added a recovery system that prevents a conversation from locking up
- Added an asset limit for integrations and devices, plus a route reporting the organisation’s usage
- Added device deletion
- Added native Debian support and a macOS installation token
- Added predefined prompts and an agent installation hint
- Changed transactional email to Amazon SES
- Changed the integration listing to include or exclude disabled entries
- Improved the password reset screen and flow
- Improved the plan upgrade process and payment refresh
- Fixed duplicate messages on retry, message repaint, sliding and rendering errors when loading history
- Fixed three critical issues in the mobile interface
- Added a new login and registration flow with phone verification, a profile step and license upgrade
- Added the Myrmex platform agent with its own knowledge retrieval, plus specialist retrieval
- Added a Grafana agent
- Added asynchronous processing with a full status channel and a lightweight status endpoint
- Added an asynchronous architecture with a worker pool
- Added the interviewer agent, with the message identifier returned immediately
- Added persistence of reasoning steps
- Added profile fields and a biography
- Added SMS verification of a mobile number during registration, across every registration type
- Added a route that checks whether an email is already registered
- Added the organisation and context creation flow
- Added Debian support
- Added support for legacy 3650 switches
- Added document management for XML, DOCX and text files, with a viewer and editor in the content view
- Added a new chat button, history and sidebar controls, and conversation management
- Added intelligent polling with a dual timeout and reliable resume
- Changed the coordinator to ask for the devices in the conversation’s context
- Changed retrieval tools to be internal and hidden from view
- Improved the reasoning display and chat styling
- Fixed the screen going blank when the browser’s page translator altered it
- Fixed the Debian version check
- Added the Oracle Cloud command line and interactive commands on GCP
- Added SSH keys for legacy switches
- Added the supervisor as a service
- Added marketing tags
- Fixed error handling when creating additional GCP command-line profiles
- Fixed the mobile upgrade flow and the Office 365 collector logic
- Fixed the screen breaking when the browser’s page translator ran
- Added reCAPTCHA on the application sign-in
- Fixed reCAPTCHA on mobile
- Added a Cisco Umbrella specialist
- Improved the SSH and API guidance
- Fixed the session service not handling errors
- Added OAuth
- Added command-line setup during integration registration
- Fixed the additional fields returned by Microsoft social login
- Added secret editing on an integration
- Added the last seen time to the device tooltip, and restricted the offline warning
- Changed the resend confirmation endpoint to work from pre-registration
- Removed an internal field from the integration detail
- Added an Oracle Cloud specialist, with the GCP guidance rewritten
- Added spreadsheet analysis
- Added the world’s most spoken languages, with reasoning shown in the chosen one
- Added spreadsheet file support
- Added the user’s language on the request
- Added multi-language support and XML file handling
- Added articles to the Learning screen, opening as a workspace tab with read tracking and a completed badge
- Fixed mobile scrolling on the Learning tab
- Fixed a collector not being set when an integration was created
- Added AWS authentication through the EC2 instance profile, with several AWS profiles supported side by side
- Added GCP authentication through a service account and through a virtual machine identity, also with several profiles
- Added multi-step integration forms with recommended methods, several form options alongside the plain form, and token generation from within the form
- Added integration deletion
- Added AWS and GCP support, including the EC2 instance profile and several profiles on one collector
- Added the instance metadata service version 2
- Added a new Windows installer that asks for the token during installation
- Added validation of several accounts on AWS and GCP integrations
- Added AWS and GCP integration forms with collector selection, and a redesigned integrations screen
- Added a new download page
- Added translations for the dynamic integration fields
- Changed form fields to be optional, requiring at least one
- Improved the device and integration screens
- Fixed the integration health flow
- Fixed the configuration file URLs and removed the host field from the Windows installation
- Fixed the page zooming on mobile when an input takes focus
- Improved mobile navigation
- Added a video to the Learning section with view tracking
- Fixed the onboarding tour for both free and paid users
- Added upgrade through a checkout session
- Changed free subscription creation to skip the payment provider entirely
- Improved the social login message and the free plan screen
- Removed the manage billing button on the free plan
- Fixed the redirect after registering on the free package
- Added a new subscription flow
- Added a payment route and redirect validation
- Added an AWS specialist
- Added an exit instruction to the WatchGuard specialist
- Added a delay notice on the usage logs
- Improved translations
- Fixed social login error handling and its feedback
- Added recursive folder counts, hiding empty defaults
- Fixed the order of password validation on login, which was blocking social login
- Fixed the upgrade not working
- Changed the tokens used in the password definition flow
- Changed the registration checkboxes into a single consolidated set
- Added a fail-closed policy for role-based access control
- Added a validation and sanitisation system across the routes, including authentication
- Added five network device specialist agents
- Added detailed token limit information from the billing service
- Added tax identification to checkout, and a free checkout session
- Added an invoice payment link
- Added the subscription flow, packages and registration steps
- Added a detailed token limit card with a free plan upgrade path
- Added dynamic column resizing in the clipboard
- Changed seat reduction to apply no proration
- Changed promotion codes to be accepted only on a paid checkout
- Improved the upgrade flow, opening payment links in a new tab
- Fixed sanitisation destroying an email or phone number
- Fixed the token limit check on a free subscription
- Fixed the reCAPTCHA token missing from the automatic login after registration
- Fixed plan propagation
- Added new SSH cryptographic algorithms
- Added a token package fee and decimal spend limits
- Added fiscal validation and a usage check on free subscriptions
- Added reorder buttons to the clipboard
- Improved chat mentions, folder rules and the workspace layout
- Improved the subscription and billing screens, with usage logs sorted
- Fixed a crash on enterprise subscriptions and during fiscal data validation
- Added file upload support
- Added a detailed token usage route
- Fixed handling of a deleted or cancelled subscription
- Added file upload
- Added a Fortinet specialist
- Added automatic authorisation of device registration
- Added Amazon Linux and Fedora 41, alongside further Linux distributions
- Added a simplified route for generating an installation token, with the download route requiring and validating it
- Added the architecture parameter to the download
- Added a single download script for macOS and Linux, with a notice showing how long until the device registers
- Added folder management with drag and drop
- Added a connected integrations card to the device detail
- Improved the operating system selection and the organisation overview, with search
- Added the organisation identifier to the organisation route
- Added a subscription read permission so the user can sign in
- Added feature flags on the organisation screen and in the chat, with token limit management
- Improved the upgrade confirmation dialog
- Fixed the reasoning display, its aggregation, and the spacing of pinned messages
- Fixed reCAPTCHA on manual registration
- Added sign-in and registration through Google and Microsoft, with a simplified flow
- Added a route for disabling social login and returning to a password
- Added the enabled social providers to the user profile
- Added a system of stable error codes
- Added error handling when you cancel the provider’s screen
- Added a device folder system
- Added tool output to the conversation, with agent formatting and avatars
- Added a stop button to the chat
- Added pinning of sent messages to the top of the conversation
- Added redirection to package selection when there is no subscription
- Changed multi-factor options to be unavailable with social login
- Fixed the refresh token being written through a path that re-encrypted it
- Fixed permission population on registration
- Fixed the automatic sign-in after registration
- Fixed being signed out when sending a message
- Added a 429 response when the usage limit is reached
- Fixed the token usage count
- Added a routing matrix to the coordinator, with separated domains and a distinct persona per agent
- Added a silent mode to the coordinator, and removed its bias toward one specialist
- Added rules that keep an agent to the data it actually has
- Added recording of tool output, with sensitive output redacted
- Added guidance for losing connectivity while a device reboots
- Added tool output to the conversation
- Added a function that stops an interaction mid-run
- Added token metering
- Added a route that returns the subscription for an organisation
- Fixed sub-organisation creation
- Added a Windows update specialist built on WSUS, with PowerShell tooling
- Added update tools to Perseus
- Added a summarisation agent
- Added a Google Workspace CIS audit tool, with email listing and the permissions it needs
- Added knowledge of PDF documents
- Added folders
- Added the macOS update flow
- Added the Windows Update API and a WSUS-driven update flow, with agent tools for updates
- Added the recipient’s name to an organisation invitation
- Improved the SSH, command-line and HTTP timeouts, and fixed a lock during upgrade
- Improved the buffer size and compression
- Fixed the download URL rejecting an unknown version
- Fixed the macOS supervisor not restarting, and the Linux update process
- Fixed the keepalive handler
- Added a Palo Alto specialist with its own memory
- Added a context memory system
- Added a tool for time calculation
- Added reasoning and external tool output shown as they happen, replacing the generic opening message
- Added a token limit on a tool response
- Added context topology memory with its own routes
- Added an enable-password system, falling back to the SSH password
- Added the macOS update flow and download
- Added macOS and Google Workspace support, with a Google Workspace specialist
- Added automatic detection of authorisation after manual approval on Linux
- Changed the coordinator to answer as a coordinator and format the result, without adding technical analysis
- Changed the final answer to be returned in Portuguese
- Changed the PowerShell timeout to 90 seconds
- Changed the email token lifetime from 5 minutes to 1 day
- Improved the Linux update process, and fixed a duplicated configuration and a macOS update loop
- Fixed the Oracle Linux 10 build
- Added the password registration flow
- Fixed the reCAPTCHA token not being sent
- Fixed seat typing when creating a sub-organisation
- Added SSH specialists for Huawei, Cisco, Fortinet, Dell and MikroTik, wired as sub-agents
- Added web search to the SSH specialists, with improved search
- Added an enable-password system
- Added a final response agent, with diagram support in its output
- Added native pie charts, with plotting and legend rendering corrected
- Fixed chart normalisation and the report preview
- Added marking an integration offline when its collector goes down
- Changed SSH to an interactive session, with the handling improved
- Fixed the agent crashing on Windows, and service execution on Windows
- Fixed the Linux service manager, the update process and the configuration flow
- Fixed a full agent restart
- Fixed access to the GCP console
- Fixed the audit report and the memory agent
- Added sub-organisation creation on an enterprise plan
- Added street number and complement to the organisation update
- Added a subscription package check before permissions are cached
- Added pagination to the threats route, with slice search and ordering
- Fixed permission validation
- Fixed the integrations collection name
- Changed the report submenu and structure
- Added persistent agent memory
- Fixed the collector and authentication toggles
- Added Office 365 and GCP through their command-line tools
- Added the Office 365 command line
- Added cloud command-line tooling, including GCP on Windows and Office 365
- Added a new SSH subsystem
- Changed the SSH specialists to operate through the command line
- Changed the device authorisation payload to a boolean, matching what the read route returns
- Changed integrations to the command-line authentication types
- Fixed the Oracle Linux installation process and the Linux build
- Added a new subscription validation flow
- Added management of additional seats
- Fixed the alert detail loading repeatedly
- Added payment validation before a subscription is modified, cancelling the operation instead of leaving it inconsistent
- Fixed tokens not being updated when seats are added — they are now proportional to the number of users
- Added a learning path with an initial guided tour
- Added a coming-soon card for video content
- Changed the right sidebar to open by default
- Fixed the mobile chat, chat history, photo saving and general layout
- Added an artefact service for large outputs
- Added a cloud command-line system, with the coordinator wired to it
- Added a monitoring specialist over Elastic, with a new SSH service
- Added a command-line action type
- Added command-line actions, with credential handling and chunked output
- Changed the SSH tools to operate through the command line
- Improved the coordinator’s guidance and reduced its tool surface
- Fixed token pricing and the package token structure
- Added a notification when a new version is available
- Added passkeys and passwordless sign-in
- Added a preferred multi-factor method, falling back to a password when the preferred one is removed
- Added backup codes, with their management and use
- Added the date of the last password change
- Added a password change route
- Added reCAPTCHA
- Added storage of an invitation for a user who already belongs to another organisation, with expiry handling and a resend route
- Added multi-factor authentication with a method chooser
- Added passwordless sign-in with a dedicated management tab
- Added the preferred method, backup code management and the last password change
- Added a password change flow for existing users
- Changed font sizes and translations to a single standard
- Improved multi-factor management
- Fixed passkey handling
- Added promotional codes
- Added multi-factor authentication, on secured routes
- Added resending an invitation to a user who has not confirmed their email
- Added soft delete and reactivation of a user
- Added the email status to the response
- Added service user creation
- Added agent, device, Linux and SSH actions, with long-running sessions that keep their context
- Added SSH and HTTP connectivity tests for integrations
- Added CentOS and Oracle Linux, with RPM versioning and signed packages
- Fixed the password reset and its translation
- Fixed Cisco and MikroTik SSH connections
- Fixed the Windows event log and the Linux update process
- Added the automation module: playbook, runbook and template cards, a redesigned single-page runbook editor with side navigation, scheduling with a calendar, execution monitoring, a folder system with pagination and real-time status, and tag filtering
- Added webhook token security, with a warning before the token is revealed and a preview when editing
- Added role management with its own screen
- Added a sub-organisations list, its members and a redesigned screen
- Added service user management
- Added a simple user listing with a new detail layout
- Added an allowed-permission list for creating roles, and removed the root permissions
- Added a field identifying service users
- Added permissions for the automation module
- Added the Meraki API integration
- Added handling for an upgrade or downgrade left incomplete
- Changed the asset group field to be optional
- Fixed key rotation to be version agnostic
- Fixed integration authorisation
- Added a timeline with checkpoints and restore
- Added a folder system with filtering and its own routes
- Added audit and access policies
- Improved charts, captions and flowchart generation
- Fixed the table block
- Added a new registration screen with dynamic plans and public sector validation
- Added the portal’s translations
- Added completing payment for a subscription that was created but never paid, through a dedicated refresh route
- Improved tags and the chat cards
- Removed the license selector screen
- Added a rebuilt Scribe
- Added planner agents with their own endpoint
- Added REST, device and SSH actions
- Added a tunnel status check and integration status reporting
- Added the subscription management route back
- Fixed the payment redirect URLs
- Added a content delivery network for static assets
- Added a folder system and a timeline to reports, with a smart preview and the author in the header
- Added a favourite button for a conversation
- Added a message queue on the input, with autocomplete
- Changed the portal to a single domain, with the sign-in screen restyled
- Improved the password reset screen
- Fixed chart blocks, the report viewer and a loop when saving
- Added favourite conversations
- Fixed the host used by integration actions
- Added the report editor: a hierarchy of sections, a table editor, chart and flowchart generation, an HTML preview and a PDF build
- Added tags, types and subtypes, with ordering and moving a block between sections
- Added version tracking on a report
- Added role-based access control across the report routes
- Added the agent system: a coordinator that routes to specialists, with a planner, a notes module and a session and cache layer
- Added Scribe for report authoring, Orion for threat intelligence, and Athena, each able to hand work between them
- Added specialists for SSH devices, GCP, pfSense, Meraki, Elastic, UniFi and Wazuh
- Added document reading with retrieval, so a file you upload can be consulted rather than re-read in full
- Added an artefact service, with images and long outputs stored outside the conversation
- Added token counting and a rating control on an answer
- Added horizontal scaling and structured logging
- Added conversations with the agent system, including image input and follow-up handling
- Added a document system with artefact storage, and report download from the conversation
- Added conversation status synchronised with the agent, with per-conversation state
- Added renaming a conversation
- Added usage reporting to the billing service, with monthly totals per organisation and optional context filtering
- Added organisations, contexts and users, with seats added and removed on invitation
- Added sign-in through Google and Microsoft
- Added role-based access control with automatic bootstrap on startup, roles, asset groups, permissions and policies
- Added invitations by email, with the link and session expiry handled
- Added encryption for confidential fields
- Added user listing filtered by organisation, with sensitive fields excluded
- Added device and integration management, with status monitoring
- Added agent download for Linux, with the installation URL per architecture
- Added SSH action routes and custom headers on an integration
- Added editing an integration, listing by type, and access fields on read
- Added encrypted credential storage
- Added subscription management with a payment provider, covering the payment method, invoices, yearly payment and the customer portal
- Added seats, including unlimited and enterprise contracts
- Added automatic token purchase and usage registration
- Added synchronisation of overdue subscriptions
- Added the registration flow with reCAPTCHA
- Added a demo request
- Added the chat interface, with reasoning shown as it happens and a conversation history
- Added device and integration detail screens, and the installer download section
- Added role management following access control
- Added the reports page and its editor
- Added an alert layout with severity
- Added a package upgrade dialog
- Changed authentication to use cookies
- Fixed the invitation flow
- Added the foundation of the platform: organisations, contexts, users and authentication
- Added the first version of the licence screen
- Added a global apply button in the chat
- Fixed the password reset card layout and an error in the conversation history
- Added the site identifier to a site notification
- Added scan status and automatic refresh on the site detail
- Improved responsiveness on the endpoint detail
- Fixed deleting, reading and updating a site
- Removed the reports menu
- Fixed context loading, the reasoning window and polling error handling
- Removed the licence requirement for downloading the agent, and the licence check on authentication
- Fixed site handling
- Added device groups with their own routes
- Added a route reporting used licences, the licence identifier in the agent download, and authorising or deauthorising a device, including partial deauthorisation of assets
- Added site registration with a favicon and a data field, with the URL normalised and checked for duplicates before a scan job is created
- Added agent authorisation, with an agent registering unauthorised by default
- Added a route returning the contexts owned directly by an organisation
- Added a window manager for the chat, with draggable cards and a global popup
- Added a Sites tab with an add-site dialog, site details and their translations
- Added regions based on licensing
- Added a user listing
- Added an alert detail window, with summarise and compare actions
- Added a country list
- Added investigations: their structure, blocks, execution and results
- Added CVE collection and search
- Added device synchronisation
- Added compression of tunnel payloads
- Added last-seen reporting and batched log processing
- Improved the supervisor update process, including the signature database download
- Added file event collection and a YARA scanning pipeline
- Added Linux process and log parsers
- Added automatic syslog startup on Windows
- Added new form types, including an automation field and array parameters
- Added continued reporting when an integration base returns an error
- Added a handler for malware hash updates
- Improved the program inventory
- Fixed the agent reconnecting and a registration problem
- Added integration search with its documentation
- Added fields for local integrations, and a selection list in integration parameters
- Added the icon and vendor of an integration to the response
- Added a default status for a new integration, and an assignee
- Added the user’s language, with a route for reading it
- Added a new logs screen
- Added a map dashboard with a globe view of connections
- Added reasoning steps shown while an answer is produced
- Added integration search with documentation, and a standard screen for new integrations
- Improved memory usage
- Improved the integration form and the message queue status
- Added control fields on an integration
- Added the integrations tab with the start of its detail view
- Changed the input to refuse a new message while one is being processed
- Removed the last-seen calculation for integrations
- Fixed the device detail, and a blank screen when there were no devices
- Changed network data collection from every 5 minutes to every minute
- Added scoring for devices and integrations, with network data per device
- Added geographic location for an address
- Added alerts from network data
- Added reasoning steps to the conversation
- Added the reports page
- Added alert cards and a table on the home screen, with a side panel and an alert detail
- Added the device detail view with a process list and a visual process flow
- Added the device score
- Added full screen to the dashboard
- Added retrying a failed answer
- Added a keep-alive on the connection, with the agent pool reporting its status
- Improved the process call stack route
- Added installed program collection, with the inventory available through the API
- Added merging two accounts
- Added threat intelligence from MISP, covering addresses and hashes
- Fixed a bug when merging integrations
- Fixed the registration process and the supervisor update
- Added the endpoint agent for Windows, Linux and macOS: event collection, a syslog collector, software inventory, and CPU, memory, disk and installed program reporting
- Added a scripting system with parsers, database access and SSH, so an integration can be read without a dedicated build
- Added a supervisor that keeps the agent running and updates it
- Added a log enricher that resolves users
- Added the installer for each platform, including RPM
- Added a version check
- Added serving the agent to older Windows versions
- Fixed empty agent messages being returned for a conversation
- Added the report routes
- Added responsiveness to the detail screens
- Added agent messages, with routes for managing them and parallel retrieval
- Improved the device list loading
- Added a new counting mechanism for alerts
- Removed a deprecated user creation route
- Fixed the threat detail and how the alert box is read
- Fixed the forgotten password flow
- Fixed the agent data route ordering by timestamp
- Fixed the agent update process
- Fixed the download parameters on GCP