Skip to main content
September 4, 2026

What’s new

Feature details live in the Product Changelog:
  • Choose the HTTP method for Test Connection
  • Faster Ontology version history and folder listings

Bug fixes

  • Chat: A model’s content refusal now shows a plain message and ends the turn, instead of leaking the provider’s refusal wording or, on Google models, ending silently.
  • Ontology: A .tql file’s default_connector is now a default, not a requirement — Ana runs the query against a connector the chat has, instead of reporting the data as unreachable.
  • Dashboards: A dashboard whose data source was deleted or misconfigured now stops with one clear error naming the source, instead of retrying forever.
  • Dashboards: A dashboard left open or idle for more than a day no longer loses the ability to read data.
  • Connectors: A header, query parameter, or body field saved empty now displays as empty, instead of appearing to hold a secret.
  • Playbooks: A playbook now opens for roles without Ontology read permission, which previously left the editor without its prompt.
  • Ontology: Restoring a previous version no longer leaves behind empty folders.

Upgrade guide

No changes required.
September 4, 2026

Bug fixes

  • Ontology: Member-level access control entries now generate correctly again. A stricter internal ID range check had rejected some valid member and role assignments, silently leaving the accounts it touched without the access granted by their OWNERS file.
  • Self-hosted: Ontology library git operations now recover automatically after an interrupted commit or a pod crash, instead of leaving the library locked or in a partially written state. A stale lock left behind by a crashed process is cleared only while the current process holds the org lock, and an hourly background audit repairs any leftover inconsistency.

Upgrade guide

No changes required. A new optional value sandbox.capacityReservation.resources sets CPU and memory requests and limits for the capacity-reservation placeholder pods. Unset fields keep the existing defaults (100m CPU / 500Mi memory).
September 4, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Kimi K2.6, GLM 5.2, and DeepSeek V4 Flash now keep their reasoning context across tool calls, so a multi-step turn no longer discards the model’s earlier reasoning.
  • Self-hosted: Fixed request routing when authentication is enforced. Some routes matched two rules and returned a server error, and others matched none and returned Not Found. A CI check now renders the rules in every authentication mode and fails on an overlap or a gap.
  • Self-hosted: An upgrade no longer errors part way through a rolling deployment when replicas on the previous version still query columns dropped in 1.3.16. Those columns are restored as unused placeholders.
  • Security: Updated fflate to patch an infinite loop triggered by a malformed ZIP64 archive.
  • Chat: Slack and Teams chats now start from a member’s personal defaults for connectors, tools, model, and methodology, falling back to the organization’s defaults only where the member has set none. Both surfaces previously used organization defaults only, even though the web app already honored personal ones. A channel’s playbook context still overrides both.

Upgrade guide

No changes required.
September 3, 2026

What’s new

Feature details live in the Product Changelog:
  • Claude Fable 5.1 model
  • Duplicate roles and create roles in bulk
  • Dropbox connector
  • Design system permission for designers (Beta)
  • Ontology files in data app compute functions (Beta)
  • Higher data limits for data apps
  • Published apps and dashboards serve a fixed Ontology version
  • Ontology sync retries after remote changes
  • Auto-attached Ontology files in Thread Insights
  • The CLI is now called refinery
  • Verify a data app from the CLI before sharing it
  • Data app library home and sorting (Beta)

Bug fixes

  • Data apps: Apps with large documents are now served in their organization’s design system. Previously an app whose document grew past an internal size threshold silently fell back to the stock look.
  • Data apps: A HEAD request for an app document styled by a design system now reports the correct Content-Length instead of omitting the header.
  • Data apps: Version History shows saves again for every organization, and existing apps with no history receive an initial version so the panel is never empty.
  • Connectors: Power BI dataset previews now work for Import, DirectQuery, and Live Connection models, not just push datasets, and failures explain what went wrong instead of showing a generic error.
  • Chat: Pasting text copied from Word or Excel now pastes the text instead of attaching a screenshot of it.
  • Chat: Duplicate tool names are removed before a request reaches the model provider, so providers that reject duplicates no longer fail the turn.
  • App: Tabs left open when a new version ships keep working instead of failing to load a page.
  • Playbooks: Header status chips no longer flash the wrong state while a playbook loads.
  • Observability: The People table’s date range now applies to threads, playbooks, and dashboards, not only to ACUs.
  • Security: A failed update to a sandbox’s API key scope now keeps the previous scope in place instead of leaving the sandbox unscoped.
  • Settings: Members granted delegated API key permission can mint API keys again.
  • API: Marking a chat read that does not exist returns Not Found instead of an internal error.
  • Self-hosted: Deployments that route LLM traffic through a proxy no longer poll the providers’ public status pages.

Upgrade guide

No changes required. A new optional value compute.dataApps.snapshotMaxBytes adjusts the data app snapshot limit for deployments that need a ceiling other than the 128 MB default.
August 27, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Playbooks: The card header no longer squeezes the playbook title down to a few characters when the status and other chips are shown next to it.
  • Playbooks: After creating a playbook on Azure-hosted deployments, the editor opens ready to edit instead of staying inert until the page is refreshed.
  • Chat: Returning to a chat from Settings no longer leaves the layout frozen at its load-time width, so the drawer and split pane resize normally again.
  • Dashboards: The refresh source list now scrolls when it is long instead of running off the dialog.
  • Connectors: The share dialog now names the connector, or secret, being shared instead of showing a generic title.
  • Skills: Icons no longer overlap on rows that list more than one skill.
  • Desktop: The controls in the window’s top bar are clickable again.
  • Self-hosted (FSx ONTAP): Access controls are reliably reinstalled when a sandbox is re-materialized, so a reused sandbox keeps the correct file permissions.
  • Self-hosted (NFS): Files written when an Ontology library worktree is merged keep writable permissions on owner-squashed NFS volumes, so later edits and syncs succeed.

Upgrade guide

No changes required.
August 25, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: A long conversation could stop responding permanently after Ana compacted its history. Affected conversations recover as soon as this ships — no need to start a new one.
  • Chat: Kimi and GLM models no longer loop on empty query results, which could run a conversation into hundreds of successful but empty queries.
  • Connectors: Ana now sees the correct table structure on Postgres, Redshift, SQL Server, Synapse, Trino, Firebolt, and usage-analytics connections. Every table previously appeared to hold every column in the database, which could send queries to the wrong table.
  • Usage: Cached token support on models served through Fireworks, including Kimi and GLM.
  • Self-hosted: An installation configured with a single AI provider starts up reliably instead of crash-looping.

Upgrade guide

No changes required.
August 20, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Settings: Searching members by name now finds everyone in the organization, not only the members on the page you are looking at, and the list sorts by name instead of quietly falling back to email address.
  • Chat: Opening a data app, skill panel, or artifact drawer resizes the chat pane again, instead of leaving the split frozen at the width it had when the page loaded.
  • Playbooks: The Delivery Settings dialog shows the playbook’s real active or inactive status instead of always reading “Inactive”.

Upgrade guide

No chart or values changes are required to upgrade.One network prerequisite applies, and only to the new usage and billing connector, which is provisioned into every organization automatically. It reads from TextQL’s hosted usage service, so the deployment needs outbound access to https://console.textql.com — or to whatever compute.consoleApiEndpoint points at. Without that connectivity the connector still appears in the connector list but returns an error when queried; nothing else in this release depends on it.
August 19, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: A dropped response stream is now detected instead of being held open by heartbeats, so a stalled turn surfaces rather than hanging indefinitely.
  • Chat: Transient model and compute failures are retried automatically instead of ending the turn.
  • Chat: Ana no longer invents a name for members who have not set one.
  • Chat: Files truncated on upload are now marked as truncated, so Ana knows the content is incomplete and can act on the provided scripts instead.
  • Chat: Fixing a query used by several data apps no longer pulls every affected app into the conversation.
  • Chat: The API connector checkbox now updates as soon as it is toggled.
  • Data apps: The drawer no longer opens at zero width.
  • Data apps: An app whose entry document is not HTML is now rejected at save time with a clear error instead of failing later.
  • Data apps: Ana can read an app’s existing files before editing them in organizations that do not have the Ontology library enabled.
  • Data apps: “View in Ontology” appears only when the app actually has library files.
  • Ontology: Stale HEAD and reference locks now heal automatically instead of blocking further changes.
  • Connectors: Redshift connectors are no longer relabelled as Postgres.
  • Connectors: Dismissing the Tableau collections dialog returns to the Connectors page.
  • Connectors: The Jira API provider can now reach api.atlassian.com.
  • Models: Corrected the Vertex AI model identifier for Claude Haiku 4.5, which previously failed to resolve.
  • Billing: Forcing a refresh now clears a cached organization suspension.
  • Security: EXPLAIN ANALYZE can no longer be used to bypass the application database’s write gate.
  • Interface: Dark mode now covers tint families the dark layer previously skipped, and dialogs no longer leave the page scroll locked when they close.
  • Sign-in: Refreshed the sign-in surfaces, including a full-color Google button.

Upgrade guide

No configuration changes are required.
August 14, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Sign-in: Fixed a sign-in loop caused by session-token handling; inbound session tokens are now revoked and refreshed correctly.
  • Chat: The model picker stays fully on screen, and the Gemini model shows its correct logo.
  • Chat: A chat whose sandbox was reclaimed mid-turn now resumes automatically instead of halting.
  • Chat: Excel sheets with mixed-type columns now load instead of failing the upload.
  • Chat: Switching threads no longer carries over another thread’s artifact-drawer state.
  • Slack: Long responses that exceeded Slack’s block-size limit now post; oversized sections are split so the response is delivered.
  • Teams: The Report content button responds again.
  • Dashboards: Data-source query timeouts are handled more gracefully instead of failing the dashboard.
  • Data apps: Deleting a data app now removes it from the library, and the code tab shows the app’s real file layout.
  • Data apps: A data app attached to a chat stays attached even after it scrolls out of the history window.
  • Connectors: The sidebar no longer blocks navigation to Connectors while the connector list is slow to load.
  • Connectors: Adding custom API access no longer fails with a cryptic “No revision ref” error.
  • Ontology: Restoring a previous version now restores every file in that version, not just one.
  • Playbooks: A playbook deleted while a run is in progress no longer attempts to deliver its report.
  • Models: Kimi K3 and GLM 5.2 now route through reasoning-mode caching, fixing sharply higher cost and repeated re-thinking on each message.
  • MCP: Renaming an MCP server no longer signs members out of it. Only changing the server’s URL revokes the OAuth tokens issued for it.
  • MCP: Saving an MCP server that the server rejects now reports the failure in the form instead of showing a success message.

Upgrade guide

No changes required.
August 12, 2026

What’s new

Feature details live in the Product Changelog:
  • Run analyses from the command line
  • Automatic deletion of inactive threads
  • Fork a chat with new connectors, model, and methodology
  • GPT-5.6 xhigh thinking effort
  • Report objectionable content in Microsoft Teams
  • Email tool no longer capped per run or per day
  • FSx ONTAP scratch failover for sandbox workers
  • Chat stays pinned to the newest message
  • Higher sandbox egress rate limit

Bug fixes

  • Chat: Attaching a very large data app or dashboard to a chat no longer overflows the model’s context window and breaks the conversation; oversized attachments are now budgeted, and any chat previously broken this way recovers on its own.
  • Data apps: Data apps now report accurate data freshness — the “refreshed” time only advances when a rebuild actually re-fetched its sources — and deleting an app now cleans up its cached data.
  • MCP: OAuth sign-in now succeeds against authorization servers that append parameters to a redirect URI that already contains a query string.
  • Skills: Disabled TQL and Malloy skills no longer appear in the chat skill menu.
  • Sidebar: The organization switcher submenu no longer closes while you are typing in its search box.
  • Self-hosted: The Tableau connector now garbage-collects its Hyper extract volume instead of letting it grow unbounded.

Upgrade guide

No changes required.
August 10, 2026

What’s new

Feature details live in the Product Changelog:
  • Per-member OAuth for BigQuery
  • Member-level Ontology permissions
  • Command-line API key authorization
  • Governance controls for raw SQL
  • Reset system roles to default permissions
  • Upload BI workbooks into the sandbox
  • Word and PowerPoint files in Slack and Teams
  • Custom node affinity for deployments
  • Service replicas spread across dedicated nodes
  • Keep models available in VPC deployments
  • Developer toolchains in the sandbox bash tool (Beta)
  • Comment on data apps for Ana to revise (Beta)

Bug fixes

  • Chat: The chat pane no longer collapses when the window is resized on mobile, and automatic thread titling no longer overwrites a title you set by hand.
  • Connectors: BigQuery connectors no longer show no tables when no dataset is pinned, and turning off per-member OAuth for a connector now resets its authentication strategy instead of leaving the previous one in place.
  • Power BI: Reports that use row-level security and cannot be previewed with the connector’s shared service account now show a clear “No preview available, RLS enabled” message instead of a generic error.
  • Data apps: The artifact drawer now opens reliably.
  • Desktop: Screenshot capture in the in-app feedback modal works again.
  • Self-hosted: Sandbox state cleanup now works on Azure Blob storage instead of failing to list objects.
  • Security: Patched dependency vulnerabilities in js-yaml, SvelteKit, DOMPurify, nanoid, and go-git.

Upgrade guide

No changes required.The new scheduling values are optional and default to unset: global.nodeAffinity and per-service nodeAffinity apply a raw Kubernetes node affinity to service and sandbox worker pods.
August 6, 2026

What’s new

Feature details live in the Product Changelog:
  • Per-member SSO for SAP HANA
  • Steer the live turn with Cmd/Ctrl+Enter
  • View Ontology source in the app
  • Ontology entity count in the tree
  • Faster Ontology file browser
  • Version history shows who published
  • Automatic default connector for new chats
  • Sidebar quick actions on hover
  • Separate compute class for dashboard workers
  • Compute class and machine family for every deployment
  • Spread service replicas across nodes
  • Restrict ingress to sandbox pods
  • Override the system default model
  • Larger uploads on Azure Blob storage

Bug fixes

  • Ontology: A stale git index.lock left behind by an interrupted write no longer blocks later Ontology library writes; the lock is now cleared only after it is proven orphaned.
  • Ontology: Fixed several configuration-sync issues that could keep Ontology changes from applying cleanly.
  • Models: Setting an organization’s default model no longer leaves the organization’s other models turned off.
  • Chat: Thinking cells no longer sort below the answer.
  • Slack: Replies no longer request HTML formatting that Slack cannot render.
  • Reliability: Deleting an organization no longer fails intermittently with a database deadlock.
  • Data apps: Duplicating a data app now keeps its SQL and TQL functions.
  • Self-hosted: Deployments using FSx for NetApp ONTAP now bring library volumes that are offline back online automatically instead of failing.
  • Desktop: Updated the desktop app’s Electron runtime to pick up upstream security fixes.

Upgrade guide

No changes required.The new GKE scheduling values are all optional and default to unset, so upgrading changes nothing until you set them: sandbox.computeClassDashboards, per-deployment computeClass / machineFamily (now also available on valkey, oathkeeper, in-cluster Postgres, and the other services), and global.serviceMaxReplicasPerNode.Sandbox worker pods are now created with a NetworkPolicy that restricts inbound traffic to the compute engine. On clusters without a NetworkPolicy controller it is inert, and no configuration is required where one is enforced.
August 3, 2026

What’s new

Feature details live in the Product Changelog:
  • DeepSeek V4 Flash 0731 model
  • Attach a HAR file to feedback reports
  • Build dashboards from any chat
  • Compact data app view switcher
  • Sidebar bookmarks no longer bleed across organizations or members
  • More accurate BigQuery dataset scope checks
  • More reliable MCP credential updates
  • Report delivery no longer forced on app follow-ups

Bug fixes

  • Sidebar: Bookmarked threads no longer bleed across organizations or between members sharing a browser profile; bookmark membership and ordering are now persisted server-side per member.
  • Connectors: A BigQuery connector scoped to a dataset no longer rejects a query against an in-scope view solely because the view reads a table outside that dataset.
  • MCP: Updating an MCP server’s credentials, completing OAuth re-authentication, or disabling a server now drops its cached connection immediately instead of reusing the old one until it expires.
  • Chat: A follow-up message in an app-mode chat that began from Slack, Teams, or a playbook run is no longer forced into producing a report.

Upgrade guide

No changes required.
July 30, 2026

What’s new

Feature details live in the Product Changelog:
  • Data apps (Beta)
  • Use an existing SecretStore for external secrets
  • Per-pod credentials for sandbox egress
  • Skill panel and improved code rendering
  • Custom Anthropic gateway per-model overrides
  • Dashboard and data app heartbeats pause when hidden
  • Fewer false stream stalls in chat
  • More reliable Fireworks tool calls
  • Schema tab fix for MySQL and ClickHouse
  • Clearer disabled MCP server status
  • More reliable MCP OAuth sign-in
  • Sidebar collapse fixes
  • Data app thread dropdown fix
  • Cleaner Ontology file browser
  • Tableau datasource targeting for TQL queries
  • Identify the calling credential via the public API

Bug fixes

  • Connectors: The connector CA certificate is now delivered to the sandbox correctly in every secrets mode, completing the External Secrets fix from 1.3.5.
  • Sandbox: Python code that reassigns interpreter built-ins such as sys no longer breaks file transfers and every later cell in the chat.
  • Notifications: Ontology config sync failure alerts are now delivered in-app only, instead of also sending an email for every failed sync.
  • Sandbox: Self-hosted deployments using FSx for NetApp ONTAP now retry sandbox storage slot bind verification instead of failing sandbox startup on a single unverified attempt.
  • Sandbox: Self-hosted deployments on GKE Autopilot with spot nodes enabled no longer fail to schedule sandbox worker pods.

Upgrade guide

No changes required.Sandbox worker pods now run a small sandbox-proxy-sidecar container that authenticates the pod’s egress traffic with a per-pod credential. It needs no configuration and its footprint is minimal, but expect to see the extra container on every sandbox pod. A new Kubernetes Secret, sandbox-proxy-worker-tokens, is also created by Compute engine.In externalSecrets mode: to reuse a SecretStore that already exists in the cluster instead of having the chart create one, set global.externalSecrets.createSecretStore: false and point global.externalSecrets.secretStoreName at the existing resource.
July 29, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • API keys: The “Never” expiry option in the Create API Key dialog now applies instead of falling back to a default expiry.
  • Sandbox: Active sandbox workers are no longer voluntarily evicted during cluster scale-down on any cloud, so long-running chats and dashboards are no longer interrupted by node consolidation.
  • Connectors: Self-hosted deployments using native external secrets now fetch the connector CA certificate correctly.
  • Settings: OAuth application dialogs are now scrollable, so their full contents are reachable on smaller screens.
  • Security: Patched a desktop dependency vulnerability (brace-expansion).

Upgrade guide

No changes required.
July 28, 2026

What’s new

Feature details live in the Product Changelog:
  • Dark mode
  • TQL queries against Tableau
  • Kimi K3 model
  • Increased permission granularity for Observability access
  • Folder deep links for dashboards
  • Zoom controls in the image viewer
  • Settings management in the SDK

Bug fixes

  • Settings: Role model-access change hardening.
  • UI: UI improvements across the skills popout and data tab graph.
  • RBAC: Hardening of permissions checks for role model-access and connectors attached to playbooks.

Upgrade guide

No changes required.
July 27, 2026

What’s new

Feature details live in the Product Changelog:
  • Claude Opus 5 model
  • Bash tool (Beta)
  • Sidebar bookmarks
  • Admin-only Ontology folders
  • Organization-wide sharing controls
  • Failover on stalled model responses
  • Table previews for all SQL connectors
  • Usage heatmap in Observability
  • Sandbox egress rate limiting
  • Faster Tableau introspection
  • Custom API connector connection testing
  • UI refinements
  • Values file generator for self-hosted installs
  • Cluster-scoped resource opt-outs
  • Sandbox storage improvements for FSx ONTAP deployments

Bug fixes

  • Chat: Deprecated models are handled correctly by the scheduled deprecation pass, and chats on a removed model fall back to the organization’s default model.
  • Chat: Fixed chart rendering and screenshot failures for visualizations that use JavaScript callbacks.
  • Dashboards: Failed sandbox spawns now release their workers and orphaned dashboard workers are cleaned up, so dashboards no longer get stuck on dead workers.
  • Uploads: Files without an extension can be added via drag and drop, and PowerPoint and Word uploads are stored correctly.
  • API keys: Stale API key references now recover automatically instead of failing until the key is re-created.
  • Playbooks: References to deleted connectors are pruned, and items created by removed members show the creator’s email instead of an internal id.
  • Ontology: Reviews containing overlapping edits to the same file now apply cleanly.
  • Slack: Workspace sync is scoped correctly on Slack Enterprise Grid workspaces.
  • Security: Patched dependency vulnerabilities (postcss, SvelteKit, electron-builder, GitPython).

Upgrade guide

No changes required.New optional values are available for clusters that restrict cluster-scoped resources: sandbox.createPlaceholderPriorityClass: false (or set sandbox.placeholderPriorityClassName to use an existing class), sandbox.createGlobalDefaultPriorityClass: false, and global.manageVpcCniConfig: false now correctly skips the VPC CNI ConfigMap.The Helm chart now ships a gen-values.sh helper that generates a starter values file for a new deployment.
July 21, 2026

Bug fixes

  • Connectors: Self-hosted deployments that supply the connector credential encryption key through a secret store (External Secrets, Sealed Secrets, or native external secrets) start more reliably.
  • Connectors: The connector encryption primary key ID is now handled consistently as a non-sensitive value across every secret mode.

Upgrade guide

No changes required.
July 20, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Fixed hanging conversations by improving block streaming.
  • Chat: Long conversations compact their context earlier, reducing mid-turn failures on long threads.
  • Chat: Optimized sidebar chat list loads faster for members with a large number of chats.

Upgrade guide

No changes required for most deployments.If you call the v2 REST API Ontology endpoints on a sandbox, the library path segment has been renamed to ontology with no alias kept: POST /v2/sandcastles/:id/library/changes becomes .../ontology/changes and GET /v2/sandcastles/:id/library/diff becomes .../ontology/diff. Update any integrations that reference the old paths.If you relied on OIDC group-to-role synchronization, note that it has been removed. Assign roles in the app or link SCIM groups to system roles instead.To route sandbox DNS egress through the in-cluster DNS service — for clusters where a fixed DNS service IP does not work, such as some AKS and GKE setups — set sandbox.dnsViaKubeDnsService: true in your values file. It defaults to false; when enabled, sandbox.clusterDnsIp is ignored.
July 20, 2026

What’s new

Feature details live in the Product Changelog:

Upgrade guide

Mandatory for every deployment — no opt-out. This release requires a connector credential encryption key. If it is not set, helm upgrade/helm install fails a pre-install check with an error, and the compute engine refuses to start. Complete the steps below before upgrading.
  1. Generate a 32-byte key, base64-encoded:
  2. Set the key ring and the primary key ID under global.auth in your values file:
    If you use externalSecrets, nativeExternalSecrets or none, do not put the key material in your values file. Instead provision the <remoteKeyPrefix>-connector-encryption-keys secret in your external store (default prefix textql), and still set global.auth.connectorEncryptionPrimaryKey to the key ID (for example k1).
  3. Upgrade the chart. On first start, any connector credentials still stored in plaintext are automatically encrypted in the background using the primary key.
Do not lose or remove a key that has encrypted data. connectorEncryptionKeys must retain every key ID that was ever used as the primary key, because decryption needs it. To rotate, add a new entry (for example k2=<new base64 key>), point connectorEncryptionPrimaryKey at the new ID, and keep the old entry so existing credentials stay decryptable.
July 17, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Ontology: Non-admin members no longer lose access to the ontology query tool.

Upgrade guide

No changes required.To annotate the service accounts the chart creates, set global.serviceAccountAnnotations (applied to every service account) and/or a per-service <service>.serviceAccount.annotations map (later wins on key conflicts). Each service also accepts <service>.serviceAccount.name to override the account name and <service>.serviceAccount.create to skip creating it. Leaving these unset keeps the previous names and creates each account.To attach custom sidecar or init containers, set <service>.extraContainers and <service>.extraInitContainers (arbitrary Kubernetes container specs; can be supplied from a separate values file via -f) on web, compute, tableau, mountie, ontology, valkey, or oathkeeper. Sandbox worker pods accept the same keys under the sandbox values; changes there apply to every worker pod and take effect after a compute-engine roll, so keep them lightweight.
July 16, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: A transient permission-check failure no longer shows a false “Request Access” screen; the underlying error is surfaced and access is re-checked once the check succeeds.
  • Chat: Improved handling of deleted datasources/connectors.
  • Chat: Unsupported or mislabeled image formats are now skipped and reported to the model as unavailable.
  • Connectors: Further hardened Tableau connector authentication and HTTP handling to eliminate remaining intermittent 401 errors on data source queries and metadata lookups.
  • Embeds: Tableau embed URLs now accept optional parameters to preselect which connectors a chat uses and to enable SQL and Ontology features for that chat, so an embed can be scoped directly from its URL.
  • Charts: ECharts visualizations no longer render blank under strict cross-origin resource policy headers, and the chart Grid Style popover no longer renders behind the chat input and cards.
  • Dashboards: When a dashboard’s service is still starting or recovering, opening it now shows an auto-reconnecting retry page instead of a proxy error.
  • Observability: Fixed total calculations and idle-time handling in the thread timeline view.

Upgrade guide

No changes required.To override the Tableau connector’s Kubernetes resources, set tableau.resources.requests and tableau.resources.limits (CPU and memory) in your values file; unset values keep the defaults (3Gi memory / 1 CPU requested, 8Gi memory limit).Google Cloud NetApp Volumes can now back the Ontology library. Set compute.libraryStorageBackend to fsx, point compute.fsx.ontapEndpoint at the ONTAP REST proxy URL, and set compute.fsx.authMode to gcp (OAuth via GKE Workload Identity — grant the compute service account NetApp admin on the pool’s project). Existing FSx deployments (authMode: basic) are unaffected.
July 15, 2026

What’s new

Feature details live in the Product Changelog:
  • Chargeback for usage costs (Beta)
  • Revert approved Ontology changes
  • Progressive results in batch chat cells
  • Streamed cell events in the chat API
  • Built-in skills
  • Configurable Python execution timeout
  • Helm chart version in settings

Bug fixes

  • Playbooks: Sharing a template-based playbook now accounts for access to the underlying template data — extending access when the sharer is able to, or warning when the data cannot be shared — instead of sharing a playbook the recipient cannot fully use.
  • Chat: Deep links to a chart or other artifact are no longer dropped on slow connections; the linked item now opens once the chat finishes loading.
  • Connectors: Per-user OAuth sign-in now completes reliably under strict Cross-Origin-Opener-Policy across the API, Azure SQL, Databricks, Power BI, and Snowflake connectors.
  • Connectors: Dataset-based Tableau chats now use the connectors configured for the dataset.
  • Sandbox: Out-of-range date and time values are now nulled at dataframe boundaries instead of failing the conversion.
  • Sandbox: Wedged Python executions are now stopped by a compute-side deadline, with clearer timeout errors and correct handling of cancellations.
  • Dashboards: Fixed a write-access check that could drop valid grants, and improved error reporting and retry pacing for external data requests.
  • Self-hosted diagnostics: The Network Check no longer reports false failures for the sandbox-to-engine probe or for browser file uploads, and audit logs, rate limiting, and per-IP OAuth limits now record the real client IP instead of the ingress address.

Upgrade guide

To cap how long a single sandbox Python execution may run, set compute.constraints.python.execTimeoutSeconds in your values file. Leaving it unset keeps the default; the minimum enforced value is 60 seconds. Executions that exceed the limit are stopped with a clear timeout error.
July 14, 2026

What’s new

Feature details live in the Product Changelog:
  • Lower storage use for chat working files

Bug fixes

No user-facing fixes in this release.

Upgrade guide

No changes required.
July 14, 2026

Bug fixes

  • Connectors: Fixed Tableau Personal Access Token session churn — the connector no longer signs out and re-authenticates around every operation, which invalidated its own active sessions and caused intermittent 401 errors on data source queries. Concurrent sign-ins are now serialized and back off when Tableau rate-limits.
  • Connectors: Tableau dataset creation and refresh now stop with a clear error when data sources cannot be resolved from the selected views, instead of continuing with incomplete data.
  • Sandbox: Active sandbox workers are no longer disrupted by node consolidation on EKS Auto deployments during cluster scale-down.
  • Slack: Reports containing tables with blank cells now deliver to Slack reliably, instead of failing with a formatting error.

Upgrade guide

No changes required.
July 13, 2026

What’s new

Feature details live in the Product Changelog:
  • Merge conflict resolution for Ontology changes
  • Role management in the v2 REST API
  • Ontology library files in the v2 files API
  • AWS CodeCommit git sync for Ontology
  • Research reports honor the requested document format
  • Configurable sandbox worker directory retention

Bug fixes

  • LLM: Fixed a 400 error from Fable on consecutive steering messages.
  • Dashboards: Hardened generated-code handling and fixed a data-source access join that could hide accessible sources.
  • Chat: The app now auto-recovers when a page fails to load one of its code chunks, instead of leaving a blank or broken view.
  • Connectors: Large queries no longer stall sandbox SQL parsing, and requests to an org’s own Azure storage account host are no longer blocked by the SSRF guard.
  • Sandbox: File preview hints are now scoped to user-visible output files, and a compute request timeout was raised so longer query dispatches are no longer cut off prematurely.
  • Members: Fixed the member reinstatement email.

Upgrade guide

No changes required.To change how long idle sandbox worker directories are kept before the daily cleanup job deletes them, set compute.worker.directoryRetentionDays in your values file. Leaving it unset (or 0) keeps the default of 30 days. Lower it when sandbox storage is tight — note that sandboxes older than the retention period can no longer be respawned.
July 10, 2026

What’s new

Feature details live in the Product Changelog:
  • GPT-5.6 model family
  • Connector access management in the v2 REST API
  • Postgres password from AWS Secrets Manager
  • Playbook output gated on connector access
  • Persistent Power BI and Tableau selections

Bug fixes

  • UI: Various minor fixes to the chat page.

Upgrade guide

No changes required.To source a PostgreSQL connector password from AWS Secrets Manager, provide the secret reference when configuring the connector; the deployment must have read access to the referenced secret.
July 10, 2026

What’s new

Feature details live in the Product Changelog:
  • Concurrent multi-organization sessions
  • Encrypted OIDC and OAuth secrets at rest
  • Chat drafts
  • People analytics in observability
  • Dashboard list-view actions

Bug fixes

  • Slack: Channel and user syncing now completes reliably on very large workspaces under rate limits, and a failed refresh no longer wipes the cached channel and user tables.
  • Chat: Canceled or expired requests (such as navigating away mid-stream) no longer surface a spurious error.
  • Connectors: Editing an API connector no longer drops previously saved authentication headers.
  • Artifacts: Images and PDFs upload and convert more reliably, and unavailable assets now show a clear placeholder instead of a broken link.
  • Sandbox: Fixed a connection leak to sandbox workers that degraded performance over long uptime.

Upgrade guide

No changes required.
July 9, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Switching threads no longer leaves the message “expand” control dead; threads containing cell types this build doesn’t recognize now load instead of breaking; runaway line-break floods in markdown are collapsed; and the composer keeps focus when an artifact URL updates.
  • Chat: Removed a false “sandbox restarted” error on send, and fixed dropped sends and lossy sandbox restores when reconnecting.
  • Charts: Fixed blank liquid-fill and extension charts.
  • Ontology: Fixed the “create new file” button.
  • Sandbox: Fixed cross-replica worker allocation races, and multi-GB sandbox states now persist with memory escalation after out-of-memory kills.
  • LLM: Fixed an assistant-prefill 400 error on failover retry, and backup failover is now gated on whether the backup model supports the request.
  • Azure: Fixed copy/paste, theme-editor logo upload to Azure file storage, and propagation of email attachments through Azure Email Communication Service.
  • Playbooks: A replay of the last run is no longer presented as a live run.

Upgrade guide

No changes required.
July 1, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: The “thinking” indicator now appears immediately when you send a message — including on brand-new threads — instead of showing up late or not at all.
  • Chat: Pasting multiple images into the composer no longer collides them under a single filename; each pasted image now uploads and reaches the sandbox correctly.
  • White-label: Additional hardcoded “TextQL”, “Ana”, and textql.com references — across the frontend, chat prompts, emails, and Slack — now resolve to the deployment’s configured brand.
  • API: The v2 chat API now honors the documented top-level connector_ids field even when tools is set, so programmatic chats start with the connectors you requested instead of none.
  • Ontology: Config edits now save optimistically for a snappier editing experience, and roll back cleanly if a save fails.

Upgrade guide

No changes required.To route Anthropic model traffic through the TextQL console proxy over Bedrock, set global.providers.anthropicProvider: "console_proxy_bedrock". To use it as an automatic fallback for your primary Anthropic endpoint, set global.providers.anthropicBackupProvider: "console_proxy_bedrock".
June 30, 2026

What’s new

Feature details live in the Product Changelog:
  • Opus 4.7 and Kimi K2.5 deprecation
  • Sandbox scratch volume failover

Bug fixes

  • Connectors: Fixed Ramp OAuth by keying the flow off the authorization URL rather than the configured provider, so Ramp connects reliably.
  • Ontology: Fixed auto-attach rule settings.
  • Sandboxes: Self-hosted sandbox storage now fails loudly when the configured NAS path is empty instead of starting in a bad state, and junction-resolution errors surface through the scratch-volume backend.

Upgrade guide

No other changes required.
June 26, 2026

What’s new

Feature details live in the Product Changelog:
  • Support of custom gateway when using Anthropic models
  • Self-managed Kubernetes secrets mode
  • New chart flags to disable k8s CRDs and use Ingress in GKE
  • Configurable asset URL expiry
  • Ontology change review in the v2 REST API
  • Importable library subdirectory modules
  • Hide the desktop app page for branded deployments

Bug fixes

  • Models: Fixed interleaved tool-call streaming on Snowflake Cortex that could corrupt tool-call IDs and create duplicate cells.
  • Chat: Runs interrupted mid-tool-call now resume across pod drains and deploy handoffs — backed by a durable send queue and pending-turn recovery — so conversations no longer get stuck.
  • Chat: Fixed a citation delivery bug that could drop citations from an answer.
  • MCP: Fixed sandbox output and state handling, plus several connection issues for dynamic MCP — bare-origin OAuth resource indicators, query-tolerant audiences, and pre-session SSE probes are now handled correctly.
  • Connectors: Fixed Ramp OAuth by no longer sending access_type=offline.
  • Connectors: The OAuth callback URL now stays visible after an authentication failure, so you can finish connecting.
  • SCIM: Re-provisioning a previously deactivated member now restores the existing member instead of failing.
  • Playbooks: Editing a playbook as a non-owner no longer unexpectedly forks it.
  • Ontology: Config run_as now accepts an email address instead of requiring a member ID.
  • Desktop: Auth cookies are now flushed to disk, fixing periodic logouts.
  • Charts: Fixed the minimap Y axis.

Upgrade guide

To use the Values.global.secretsMode: none, contact the TextQL team. To use a custom Anthropic gateway or another LLM gateway endpoint, contact the TextQL team.If you call the v2 REST API Ontology review endpoints, the patches resource has been renamed to changes — update any integrations that reference it.No other changes required.
June 22, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Dashboards: Chatting with a dashboard now automatically attaches its .tql query connectors, so Ana can query the same sources the dashboard uses instead of starting with none.
  • Dashboards: Live-dashboard queries are now attributed to the viewer rather than the dashboard creator, so warehouse session identity and audit logs reflect who is actually viewing.
  • Charts: ECharts visualizations no longer render blank in scheduled reports and emails.
  • Chat: Stalled runs now recover and resume across compute restarts and deploy handoffs, instead of leaving a conversation stuck mid-run.
  • Chat: Your model selection is now preserved when starting a new thread.
  • Chat: Live chat updates fall back to SSE streaming when the primary connection is unavailable, keeping streams reliable.
  • Connectors: Fixed SQL Server and Synapse connections over Microsoft Entra by correcting TLS server name and protocol negotiation.
  • Steering: Fixed steering on GPT models, and the Steer button on a queued message now appears only for steering-capable models.
  • Models: Gemini’s output cap was raised and stream retries hardened, reducing truncated or dropped responses.
  • Ontology: A durable migration marker fixes a “migrate” banner that could linger after migration had already completed.
  • Ontology: Config-managed objects now catch up when the Library repository drifts without a sync trigger.

Upgrade guide

No changes required.
June 18, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: A conversation no longer breaks when Ana encounters an unrecognized tool call; the turn now degrades gracefully instead of erroring out.
  • Chat: The report tool stays available across every turn of a conversation, instead of dropping out after the first turn.
  • Chat: An expired connector token no longer wedges a chat — the connector prompts for re-authentication instead of stalling the conversation.
  • Chat: Long option labels and answer text in question cells no longer overflow the card.
  • MCP: ana_poll is now history-backed, so a long-running answer can no longer be lost between polls.
  • MCP: The OAuth authorize flow now accepts OIDC scopes.
  • MCP: Internal framework _summary fields are no longer leaked into outbound MCP tool calls.
  • Ontology: The scheduled-sync failure banner no longer appears when git is disconnected, and the “Sync now” spinner now rotates in the correct direction.
  • Ontology: Transient ONTAP job 404s are now retried instead of failing the operation on FSx ONTAP deployments.
  • Sandbox: Query result dataframes can now be used with Streamlit’s cache decorators.

Upgrade guide

No changes required. Source citations are enabled for all organizations automatically on upgrade.
June 16, 2026

What’s new

Feature details live in the Product Changelog:
  • MCP server management
  • Connector discovery over MCP
  • Save playbooks as configuration files

Bug fixes

  • Dashboards: Fixed a stale-state bug that could leave a dashboard stuck instead of refreshing.
  • Ontology: Patch review links now deep-link to the specific review instead of the review list.
  • MCP: Tool input schemas now preserve anyOf / $ref, fixing tools whose parameters use them (such as DataHub’s get_entities).
  • MCP: The assistant and company names surfaced over MCP now follow the deployment’s configured brand.
  • Compute: Fixed a cross-replica disagreement about the sandbox storage backend that could cause sandbox file errors on multi-replica deployments.

Upgrade guide

No changes required.
June 16, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Sandbox: Fixed checksum handling for sandbox file uploads, so uploading files into the Python sandbox no longer fails on non-AWS S3-compatible object storage.

Upgrade guide

No changes required.
June 16, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Compute: A request cancellation (a turn ending or timing out) no longer cascades into a failed sandbox cleanup. Previously it could leave a chat stuck in a “no worker assigned” state and surface a misleading “persisting chat generation fence … context canceled” error; failed and respawned workers are now always cleaned up so the next turn assigns a fresh sandbox.
  • Connectors: API connectors using the client-credentials OAuth grant now automatically refresh their access token when it expires, instead of failing once the token lapses and requiring manual re-authentication.
  • Connectors: Deleted or inaccessible connectors no longer appear in default connector lists or in new chats.
  • Google Cloud Storage and other non-AWS S3-compatible endpoints no longer fail with SignatureDoesNotMatch; default request checksums are disabled for non-AWS endpoints.
  • Chat: The sandbox is kept alive during active turns, reducing intermittent “recovering files” errors on long-running chats.
  • Dashboards: An attached dashboard now renders in the artifact drawer before the first message is sent.
  • Ontology: Fixed auto-attach for context file paths.
  • Microsoft Teams: Fixed manifest validation errors and the outline icon.
  • Settings: The role dialog now displays model access correctly.

Upgrade guide

No changes required.
June 11, 2026

Bug fixes

  • White-label: Settings → Personal and the Authorized Apps list now display the deployment’s configured assistant and brand names instead of hardcoded “Ana” and “TextQL”, so white-labeled deployments read correctly throughout these screens.
  • MCP: The MCP server now normalizes request headers on POST, accepting clients that send a parameterized application/json content type (such as Microsoft Copilot) instead of rejecting the handshake.

Upgrade guide

No changes required.
June 10, 2026

What’s new

Feature details live in the Product Changelog:
  • FSx snapshot storage routing

Bug fixes

  • SCIM: Updating a user’s externalId via PUT or PATCH is now accepted instead of being rejected as immutable, so identity providers that re-issue external IDs (for example after an attribute-mapping change) sync successfully. A value already assigned to another user returns a 409 uniqueness error.
  • MCP: Ana’s MCP server now returns JSON responses during the connection handshake, fixing connections from Microsoft Copilot.
  • Ontology: Patch cells no longer fire duplicate concurrent requests for the same patch, and approval lookups wait until the patch has finished being created.
  • Compute: Per-worker library volume mounts now use NFS soft mounts, so a storage outage surfaces as errors instead of leaving processes blocked indefinitely.

Upgrade guide

No changes required.
June 10, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Auth: SCIM-provisioned users are no longer denied login when their username domain differs from their email domain — OIDC logins now reconcile to the SCIM-provisioned identity, preserving organization memberships.
  • Ontology: Patch diffs are now computed from a snapshot taken at diff time, fixing spurious “no changes” failures and files that could not be added to a patch.
  • Dashboards: Recently viewed dashboards now stay warm for a configurable period before release, and failed dashboard startups no longer leave orphaned workers or phantom billing.
  • Chat: Long mentions now wrap correctly on narrow screens, and CSV preview filter dropdowns position correctly.
  • Playbooks: The empty-state status now reads “Awaiting run” instead of “Awaiting input”.
  • Compute: Wedged sandbox storage mounts are now detected and unmounted automatically, independent of live sandbox pods.

Upgrade guide

No changes required.Istio resources (such as authorization policies) can now be disabled by setting global.istio.enabled: false for clusters that do not run Istio. The flag defaults to true, preserving existing behavior.
June 10, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Run-completion delivery is more reliable with a long-poll fallback, and streaming no longer re-processes the entire conversation on every token.
  • Slack: Response delivery is now idempotent, preventing duplicate messages; image attachments render correctly in Slack and email.
  • Auth: Allowed email domains are normalized when read, so case differences no longer cause false mismatches; fixed login on mobile WebKit browsers; expanded the disposable-email blocklist.
  • Dashboards: Fixed slow loads and stuck updates, and idle dashboard sandboxes are now released based on viewer presence.
  • Ontology: Fixed Git sync pushes to empty repositories, folder renames, and file-tree truncation; config reconciliation now resolves the repository HEAD instead of assuming main.
  • Compute: The screenshot browser recovers from panics instead of failing runs, the LLM proxy now matches Anthropic’s 32 MB request size limit, and the FSx backup tagging algorithm is fixed.
  • Sandbox: Runaway outbound request loops are now capped.

Upgrade guide

No changes required.Individual SQL queries now time out after 5 minutes by default, raised from the previous shorter limit. To change the default, set compute.constraints.sql.execTimeoutSeconds in your values file.
June 8, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Completed cells no longer re-arm streaming, and stuck streams now reconcile through a run-state poll — including on newly created chats — so conversations stop showing a spurious “still running” state.
  • Chat: Hardened run-completion events in the v2 chat handlers so runs reliably report when they finish.
  • Tableau: Fixed fsGroup permissions that broke Hyper extract queries, and hardened the connector’s container security context and finalizer handling.
  • Ontology: Patch diffs are now computed against the merge-base for accurate change sets, and draft patches correctly show approve and deny buttons.
  • Connectors: Connector logos now render without distortion in connector pills.
  • Compute: Outbound AWS S3 uploads no longer stall.
  • Sandbox: Idle sandboxes are now reclaimed correctly; fixed a last-access tracking bug that could defeat TTL expiry.
  • Security: Upgraded pyarrow to 23.0.1 to address a dependency vulnerability.

Upgrade guide

No changes required.
June 4, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Switching conversations during a network error no longer leaks report mode, dashboard mode, fast mode, or methodology settings between chats.
  • Dashboards: Suspended organizations now stop dashboard retry storms — dashboards are marked failed with a clear suspension message instead of repeatedly respawning.
  • Chat: Requests like “give me”, “create”, or “write X” now deliver the file directly in chat instead of saving it to the Ontology library.
  • Tableau: Upgraded the connector’s web framework to address a Starlette host-header vulnerability.
  • Connectors: The AWS Partner Central connector now uses a tightly scoped endpoint allowlist instead of a broad *.amazonaws.com pattern.

Upgrade guide

No changes required.
June 3, 2026

What’s new

Feature details live in the Product Changelog:
  • Distributed compute engine
  • Ana Claude Code plugin
  • Library skills via slash command
  • Word document uploads
  • PowerPoint uploads
  • Snowflake optional database
  • Ontology patch revision history
  • Bedrock per-user audit attribution
  • Email tool access control

Bug fixes

  • PowerBI: Embed now works correctly inside sandboxed iframes (Power BI custom visuals) where allow-same-origin is absent.
  • Connectors: OAuth config rows are de-duplicated and access-checked so non-admins can no longer view private connector keys.
  • Databricks: Fixed a nil-pointer crash when converting decimal array columns.
  • Dashboards: SQL Server and Azure Synapse queries are now correctly routed for dialect transpilation.
  • Chat: Fixed a stream iterator panic and a nil dereference during message streaming.
  • White-label: The browser notification icon is now brand-aware; white-labeled deployments show their own logo instead of the TextQL default.
  • Compute: Sandbox allocation now falls back to Filestore/EFS automatically when FSx capacity is exhausted.

Upgrade guide

No changes required.
May 29, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Billing — service account seat exclusion: Service accounts are automatically excluded from active seat-limit calculations.
  • Sidebar: Recent Threads no longer appears nearly empty for members with many automated background chats; these are now excluded server-side before the 50-thread limit is applied.
  • Ontology: Orphaned patches are now denied on submission.
  • Chat: Empty attachment wrapper no longer reserves vertical space in the input card when no files are attached.

Upgrade guide

No changes required.If you want to restrict all users from whitelisting domains (other than your own) in your OIDC authentication, you can use the flag global.auth.allowCrossDomainEmailAllowlist: "false" in your values file. Otherwise, the value will be set to "true" so you can whitelist domains in your deployment.
May 28, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • PowerBI: Connector no longer incorrectly shows as “connected but not available in this chat.”
  • OAuth: MCP consent state is correctly resumed after a login redirect.
  • Ontology: Auto-approve spinner sizing corrected.
  • Chat: Search filters reset on hard refresh instead of persisting stale state across sessions.
  • Reports: Markdown tables now render correctly in email delivery.
  • RBAC: Playbook template endpoints now correctly enforce playbook:read permission.

Upgrade guide

No changes required.
May 25, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Tool cells (SQL, Python, DAX, and others) now stay expanded across remounts and navigation.
  • Chat: Cross-origin artifact downloads now force a blob fetch, fixing silent failures in some browser configurations.
  • PowerBI: Missing member OAuth no longer triggers a full logout; reauth is surfaced inline instead.
  • MCP Servers: Settings modal no longer hangs on “Loading servers…” due to a reactive loop.
  • Settings: Notification preferences can now be updated without prior email-based access.
  • Share links: Org branding is now respected in share link unfurl cards.
  • Model restrictions: Role and org model allowlists are enforced across all chat APIs.

Upgrade guide

No changes required.
May 15, 2026

Bug fixes

  • Fixed network policy that was blocking internal sandbox health checks for specific environments.

Upgrade guide

No changes required.
May 15, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Chat: Unsent draft text no longer leaks between chats when navigating; each chat retains its own draft independently.
  • PowerBI: Connector auto-enable no longer gets forcibly cleared during connector updates.
  • Ontology: Fixed parameter placeholder for MSSQL/Azure Synapse schema DDL queries.
  • Chat: Safari caret mispaint after inserting an @-mention chip via Backspace is resolved.
  • Platform API: Code execution failures now return a consistent response payload with an explicit error field and empty outputs.

Upgrade guide

global.internalKey and global.sandboxAuthKey must be secret from now.Check your global.secretsMode:
  • If you are using sealedSecrets, make sure to seal those values using kubeseal and then add the value to the values.yaml file.
  • If you are using externalSecrets or nativeExternalSecrets, make sure the secrets are created in Secrets Manager.
To restrict serving assets from specific domains, as well as use CSP policies, set the compute.previewDomainUrl, compute.previewDomainCertificateArn and previewCsp attributes. You can also set web.allowedOrigins to restrict the extra origins allowed for CORS. Setting these attributes will redeploy your Load Balancer and you will require to point the DNS to the new one (set a maintenance window to perform this operation - it will cause downtime).
May 13, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • RBAC: API key create/rotate/revoke operations now follow the correct permission flow. Fixed the assume roles issue.
  • Sandbox: Org-installed packages no longer override base dependency versions.
  • Chat: Connector chip correctly attached when inserted after a multi-line paste in Chrome.
  • Shared chat link no longer stuck on a loading skeleton until refresh.
  • Snowflake: Ontology table discovery using native object listing, surfacing objects beyond INFORMATION_SCHEMA.

Upgrade guide

No changes required.
May 11, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Model picker now populates all org-enabled models (was showing only “System Default”).
  • SCIM, desktop download, and Git API routes excluded from the frontend auth catch-all and handled by their own access control rules, allowing these in functionality when enforceAuth: True.

Upgrade guide

No changes required.If you use VPC endpoints with private IPs, you may configure the new compute.ssrfTrustedHosts allowlist in Helm values to permit those hosts in outbound request validation.If you use Bedrock with cross-account access, the new bedrock.customRoleArn and bedrock.customRoleExternalId values are available for STS role assumption.
May 7, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Oracle: Fixed missing synonym resolution for connect_string/wallet auth.
  • Sandbox: Fixed RBAC admin permission enforcement.
  • Share modal no longer fails to re-open after being closed.
  • Numbered list rendering fixed in chat.
  • UX improvements for expired and timed-out threads.
  • Sidebar navigation pinning and back-navigation across panels.
  • Packages settings tab no longer stuck in loading state when empty.

Upgrade guide

No changes required.Recommended update: if you use global.bedrockGlobalInference, the attribute will be deprecated in the future. We suggest moving it to global.bedrock.globalInference.
May 1, 2026

What’s new

Feature details live in the Product Changelog:

Bug fixes

  • Tableau: Retry on expired sessions; fix multi-connector modal selection.
  • PowerBI: Fix stale dataset name resolution; run upfront discovery queries at thread start.
  • Databricks: Fix client credentials auth in SQL execution.
  • SAP HANA: Fix sqlglot transpilation.
  • Auth: Survive backend restarts without forcing re-login; fix logout redirect for enforceAuth mode; clear stale cookies on OIDC reauth.
  • Chat: Fix parallel SQL/Python race condition; fix blank parallel tool cells from SDK delta misrouting; disable attach button while streaming.
  • Connectors: Fix domain whitelist save button; fix New API Access button skipping picker; default auth type to token for API providers.
  • Slack: Auto-sync channels; gate admin actions for non-admins.
  • Security: Harden sandbox (CVE-2026-31431); harden console TLS cipher suites; fix xmldom/postcss vulnerabilities.
  • Bedrock: Strip eager_input_streaming for Haiku 4.5.

Upgrade guide

No changes required.
April 23, 2026

What’s new

Feature details live in the Product Changelog:
  • Dashboards engine rebuild
  • Ontology library redesign
  • Redesigned assume-roles experience
  • Mark threads as unread
  • Markdown previews in the artifact drawer
  • Connector UI gated on connector write permission
  • Observability billing granularity
  • TLS 1.2 and 1.3 enforcement
  • Automated Helm chart releases

Bug fixes

  • Dashboards: Fix Dash callbacks; fix prefill errors on LLM-created dashboards; fix parameterized queries; fix hot refresh on dedicated workers.
  • Tableau: Retry on expired sessions.
  • Slack: Fix mentions and WhoAmI; chunk blocks to respect 50-block limit.
  • Chat: Fix tool_result image interleaving in parallel batches; improved chat navigation performance.
  • Sandbox: Reduce lock contention causing deadline exceeded errors.
  • Databricks: Fix client credentials auth in SQL execution.
  • Console: Fix invoice due date timezone and off-by-one.
  • Hourly playbook frequency detection restricted to exclude minute-level schedules.

Upgrade guide

1.1.0 deprecates several Helm values attributes.
  • global.aws.useBedrock deprecated. Remove from the code.
  • compute.sealedSecrets deprecated. Use compute.secretsMode = "sealedSecrets" instead.
  • compute.worker deprecated. Attributes go to another section, called sandbox (at the root level like global, compute, web, etc).
    • compute.worker.computeClasssandbox.computeClass
    • compute.worker.machineFamilysandbox.machineFamily
    • compute.worker.imageTagsandbox.imageTag
    • compute.worker.useInternalSandbox → remove from the code
  • compute.constraints.sandbox deprecated — move sandbox constraints to the sandbox.constraints block instead.
  • global.loopsApiKey - move to global.loops.apiKey.
Running helm validate or helm install will validate whether your file is correct, and provide you instructions / deprecation messages where needed.If you use API Connectors with private IP ranges, please whitelist the corresponding IPs using Values.compute.ssrfAllowedCIDRs (CIDR format, comma-separated). Equivalently, you can also enable Values.compute.ssrfTrustedHosts with comma-separated URLs.
April 21, 2026

What’s new

Feature details live in the Product Changelog:
  • Slack sender names and View in App
  • Granular per-thread sharing controls
  • Tool restriction controls and admin override
  • Per-user MCP OAuth tokens
  • Pause playbooks from the editor
  • Copy artifact filenames
  • Ontology file API
  • Usage and billing sidebar permission gating
  • Org logo removal and theme editor polish

Bug fixes

  • Sandbox: Timeout guardrails and proxy error reduction.
  • Connectors: Fix Snowflake role not applied; fix BigQuery regional dataset routing.
  • Chat: Fix connector dropdown direction flip and flicker; fix OAuth prompts hidden by collapsible tool call UI.
  • Settings: Fix dropdowns crashing on click.
  • Dashboards: Fix unpublished changes status mismatch; increase spawn and script timeouts.
  • Auth: Fix cross-org shared link switching.
  • SCIM: Add Retry-After header to 429 responses.
  • ACU billing calculation fix.
  • Mobile UI improvements.
  • Security: Critical dependency vulnerability patches.

Upgrade guide

No changes required.