September 15, 2026
**A consolidation release: assistants and integrations see of flows only what their role allows, WIP limits are no longer silently rounded, and configuration errors speak plainly:** Webhook task credentials never appear in answers to agents, a badly written WIP limit is flagged while editing and publishing, a script trying to read the Library where it is not supported stops with a message instead of writing empty values; literal Library search, assistant chat usable from the keyboard.
- Security: Flow detail for agents and integrations without credentials
September 13, 2026
**Activity log, protection of historical data, legal hold, account defence and sessions under control:** administrators see and export who did what, case history and the log can no longer be altered through ordinary means, a case or a process can be put on legal hold with a reason, repeated sign-in attempts lock the account and every web session can be listed and revoked. The same version brings thirty fixes from September testing, a reorganised sidebar and a profile photo.
- Security: Tracked, verifiable history and log
- Security: Protected accounts and sessions under control
September 10, 2026
**Full close-out of September's verification round:** sessions with a ceiling that truly applies everywhere, shareable exports with no secrets and addresses preserved, document search that reveals nothing about protected files, scheduled items that no longer skip their initial checks, Event configuration errors that are finally clear, and text extraction diagnostics.
- Security: The session ceiling applies everywhere
- Security: Shareable export: no secrets, addresses preserved
- Security: Document search with no leaks
September 10, 2026
**Security polish after 0.87.0:** webhook JSON bodies no longer have template forms that escape protection and every configuration error shows up right away, the browser extension can no longer mix up two connections, and automatic alerts never go out without their configured credentials.
- Security: Webhook JSON bodies: every template form protected
- Security: Extension: never a stale response on a new connection
- Security: Automatic alerts only with the right credentials
September 10, 2026
**Stronger sign-in security, a browser extension that renews itself, a safer and more comfortable Designer:** sessions now have a maximum duration and logging out closes every web session, the browser extension link no longer expires silently, Webhook tasks are validated before you can even save them, and the app loads faster.
- Security: Stronger sign-in security
- Security: Stronger security for automations and alerts
- Security: Safer extension linking
- Security: Confidential document text stays protected everywhere
September 8, 2026
**Stronger security, simpler everyday work:** a hidden risk in automated scripts is closed, confidential data stays protected across events and flow fields, and documents, the Library, the Designer, Kanban and the extension all gain concrete refinements.
- Security: Safer automated scripts
- Security: Confidential data protected everywhere
- Security: Safer extension relinking
September 7, 2026
**Diagnostics and usability:** document uploads that reveal nothing to those who shouldn't know, a keyboard-navigable Library, and a "Preview" that appears only where a preview truly exists.
- Security: Uploads without clues
September 7, 2026
**Operations without surprises:** interruption-proof extension linking, Event tasks that always tell the truth, an event log that respects visibility, and a task detail identical from every door.
- Security: Extension linking with confirmed delivery
- Security: The event log respects visibility
September 6, 2026
**Integrity and protections:** confidentiality no longer gets lost on save, credentials survive edits, events never copy restricted data, and every invalid configuration gets a clear no instead of a silent fallback.
- Security: Confidentiality survives the save
- Security: Events never copy restricted data
- Security: Credentials survive header edits
September 5, 2026
**Full portability and data that never gets lost:** exports and duplications carry everything, nested data never vanishes silently, numeric inputs are no longer silently "fixed", and legacy AI configuration meets a clear gate with the migration path written in the error.
- Security: Nested data is never silently lost
- Security: Gate on legacy AI configuration
September 5, 2026
**Monitoring sees the whole family:** unambiguous multi-version views, confidentiality that follows each item in its own version, diagnostics that never lie, and scope-proof agent tools.
- Security: Confidentiality follows the version
- Security: Scope-proof agent tools
September 5, 2026
**Clear contracts, nothing lost:** free drafts with strict publishing, a Document trash with guided restore, errors that speak plainly, and a complete audit of automatic rules.
- Security: Free drafts, strict publishing
- Security: Document errors that speak plainly
- Security: Every rule leaves a trail
September 4, 2026
**Provable trust:** deletions with verifiable proof, crash-proof extraction delivery, a hardened AI boundary and credential-free exports — a release entirely dedicated to security and reliability.
- Security: Deleting means proving
- Security: A hardened AI boundary
- Security: Exports without secrets
September 2, 2026
**Document library and text for AI:** your organization's reference materials become stable, named assets you can call from flows and let agents read — and FlowSharp now extracts text from PDF and Word files, safely.
- Security: Hardened extraction and a tougher document channel
September 1, 2026
**Documents meet automations:** n8n and AI agents can now upload, update and download documents with the API key — all it takes is a URL.
- Security: Full defenses on URL downloads
September 1, 2026
**Certified erasure:** deleting a tenant now truly deletes its files from storage too, with a grace window and proof of erasure.
- Security: Storage erasure for deleted tenants
August 31, 2026
**Document storage hardened:** an independent security review of the new document subsystem, with every relevant issue closed before production activation.
- Security: Concurrency under control
- Security: Personal upload sessions
- Security: Remote operations faithful to their provider
August 31, 2026
**Documents join your processes:** contracts, reports and attachments are uploaded straight from forms, with versions, preview, quotas and a grace period — on S3-compatible cloud storage governed by FlowSharp.
- Security: Grace period and controlled deletion
August 28, 2026
**Your installed base gets itself in order:** the new Diagnostics finds work stuck on never-configured automations and unblocks it, privacy protections survive copies and versions, and item creation speaks the language of your process instead of JSON.
- Security: Privacy protections survive copies and versions
August 28, 2026
**Items get a real title and AI plays by your rules:** the title is visible everywhere, searchable and composable from a template — even AI-generated once data is complete; empty automations no longer claim success; and what reaches AI models is decided per flow, protected by default.
- Security: AI receives only what the flow allows
August 26, 2026
**Sensitive data stays sensitive and the numbers tell the truth.** An indicator that would reveal one person's data now stays hidden for everyone, impossible durations no longer distort time and cost — and you can see how many were excluded — and processes that wait for several tasks to finish now publish without workarounds.
- Security: Indicators on sensitive data protected from every role
- Security: Tighter control over outbound connections
August 24, 2026
**The flow list scales and diagnostics tell the truth.** /flows loads families in pages with server-side search; Data diagnostics flag unresolvable references, default rules carrying conditions and Sub-flows without a destination (with no more false alarms); a rejected save shows a clear banner with phase and rule; procedures and guides get real Markdown typography.
- Security: Stricter import and forms
August 23, 2026
**From the flowchart to the Procedure.** One click and the AI drafts a chaptered procedure — one per phase, with the activities, who performs them and the expected result, automatic phases included — which you review and save in ActiveSOP, already linked to phases and activities. Phases now carry their own guide, visible to whoever works on the item.
- Security: References always within the tenant boundary
August 23, 2026
**The security wave.** Three doors closed in a single pass: webhook responses can no longer drag sensitive data into internal records, AI client registration gets real boundaries — size, quota and lifecycle — and a hostile PDF can no longer slow the platform down.
- Security: Watertight webhooks
- Security: Boundaries for AI client registration
- Security: Hostile PDFs take no hostages
August 22, 2026
**Errors that tell you what to fix.** The Designer fork rejects reusing a request with different content, import errors list duplicate keys and the phases involved, export refuses documents with broken references, and OAuth errors speak the OAuth contract.
- Security: Fork idempotency without surprises
August 22, 2026
**Metrics that declare what they measure and an audit trail that says who acted.** Every dashboard number explains its basis, unit and population; alongside structural automation comes the period's observed automation; the trend shows since when data exists. The audit trail records who acted and through which channel, and alert telemetry reflects real deliveries — with one less personal data item in payloads.
- Security: Honest alert telemetry and less personal data
August 22, 2026
**Lists that don't lie and AI assistants with two more tools.** Changing page really skips a whole page, totals stay stable while you scroll, search reaches the task calendar, and counts respect your visibility. MCP assistants gain task listing and data updates with the same rules as the APIs, and read-only users are no longer offered impossible actions.
- Security: Counts within your perimeter
August 22, 2026
**Truly immutable versions and data protection that follows the family.** Reactivating a version used by items creates a new draft instead of reopening it; an archived process can't be republished or shared by mistake; duplicate copies exactly the chosen version; and a new sensitive classification on the parent process also protects child elements already generated in other processes.
- Security: Sensitive data protection reaches children
August 21, 2026
**What you save is what runs.** Designer rules, events and forms are verified at the source: a default rule can no longer hide a condition that would be ignored, an "on event received" rule must point to an actually subscribed event, an import no longer creates nameless event definitions, and form schemas are checked against what the runtime can interpret. Plus, Human phases gain the Rules tab for event-driven waiting.
- Security: No more internal errors from empty event references
August 21, 2026
**Events delivered all the way through and clear answers even in edge cases.** The event engine always executes every action of an event, in the right order and without duplicate effects; an overly wide calendar range is rejected with an explicit message, deleting an initiative from the Plan never leaves orphaned elements, and integrations see more while revealing less.
- Security: More discreet authorization errors
August 21, 2026
**No more pieces lost along the way.** An imported or saved process arrives whole or is rejected with the exact list of what to fix, and retries on element creation can no longer return the wrong result.
- Security: Safe retries on element creation
August 21, 2026
Sensitive data protected across all versions, transparent AI Summary. Sensitive-field classification applies to a process's entire version family, history shows what was actually protected, the AI Summary communicates clear states, and integrations get new tools with explicit risk labels.
- Security: Sensitive fields protected across the whole version family
August 20, 2026
MCP profiles with tailored permissions, duplicate-free events. Each integration can have its own profile with a dedicated address and explicit permissions, OAuth authorization respects the profile's boundaries, and event delivery is protected from duplicates even when things go wrong.
- Security: OAuth authorization within the profile's boundary
- Security: Explicit permissions for MCP keys
- Security: Public links revoked with the process
August 19, 2026
OAuth-ready MCP connectors, more transparent events. Remote connectors can authorize without keys in URLs, versioning preserves event actions, and telemetry now distinguishes receiving an event from actually applying an effect.
- Security: Consistent Process Map scope and idempotent requests
August 17, 2026
A security-focused update. Two-step verification for administrators, secure one-time alert confirmations, stronger and rotatable at-rest encryption, sign-in links and keys kept out of logged URLs, and less sensitive data retained in history.
- Security: Two-step verification for administrators
- Security: Secure one-time alert confirmation
- Security: Stronger, rotatable encryption of sensitive data
- Security: Sign-in links and keys kept out of logged URLs
- Security: Less sensitive data kept in history
August 15, 2026
Clearer rules, alerts that actually arrive. One draft per version family, events and timeouts applied in the order they really happened, SLA warnings delivered to owners through alert policies, and an export that flags plain-text credentials.
- Security: Export flags plain-text credentials
August 14, 2026
The 0.83 release is now more robust in real-world cases. Retries, versions, timeouts, and SLAs produce reliable outcomes; export and duplication preserve the design; Events gains recovery tools; compare and Analytics costs reflect the same runtime reality.
- Security: Retries and completions without duplicates
August 13, 2026
Flows without hidden dead ends, operational recovery under control. The designer blocks processes that cannot reach a final state, automation stalls become visible alerts, cross-install invitations survive retries and crashes, Admins can recover an item through MCP, and the extension downloads preconfigured from Settings.
- Security: Federation invites resilient to replay and forwarded links
August 12, 2026
Edit a published flow without losing anything, and an engine that always tells the truth. "Save" on a published flow now creates a new version with all your changes, in one step. Sensitive data follows the data wherever it is copied, engine failures become visible and recoverable, the Events page is complete, and the operational views show what is really happening.
- Security: Sensitive data follows the data
August 9, 2026
Your flows travel, your work stays safe. Duplicate a flow with one click, import it from file, paste or URL, share it across installations with an expiring link. And every change made from tabs, guides or services is now visible to the designer save: no more silent overwrites.
- Security: URL import with network guards
August 7, 2026
Time tells the truth. A scheduled item no longer looks "already started": the start date appears only when the process actually begins, and metrics, SLAs and sorting follow suit. This release also brings real per-visit analytics, a rule validator with no code execution in the browser, and more predictable API contracts.
- Security: Validation without execution, diagnostics without data
August 7, 2026
Four targeted closures. Activity sequences now resume reliably from every channel — including AI agents via MCP —, completed items no longer accept changes even under concurrency, the scheduler no longer produces false conflicts, and the activities' technical configuration stays on the server. No migrations: a simple upgrade.
- Security: Activity configuration stays on the server
August 7, 2026
Honest responses, sequences that never stall. Second stabilization wave: concurrent saves have a single winner, activity sequences always resume — even after a crash —, scheduled items start when you actually move them, event rules now work on human phases too, and the n8n contract says the same thing everywhere: UI, snippets and guides. No migrations: a simple upgrade.
- Security: Historical outcomes redacted in rules too
August 6, 2026
The crash-safety guarantees become complete. An independent audit combed the previous release for remaining gaps — and this release closes them all: deliveries that can no longer be lost, durable resumes, no superseded executor able to overwrite fresh work, and dangerous configurations blocked before they reach production. No migrations: a simple upgrade.
- Security: Protected identities and per-tenant boundaries
August 5, 2026
The engine becomes crash-proof. Seventeen coordinated changes close critical races and crash windows: events that can no longer be lost, outcomes with a single winner, always-recoverable creations, atomic escalations. With one declared breaking change for n8n integrations.
- Security: Hardened event provenance and alerts that really arrive
August 4, 2026
Security hardening. Five fixes from an independent security review, all on the boundary between different workspaces and on what ends up in technical logs. No change to everyday use: these are barriers tightening.
- Security: Boundaries between workspaces
- Security: Logs and permissions
August 3, 2026
The work-item lifecycle, with no blind spots. Events raised by activities and scripts now genuinely fire and start the listening flows, an unreachable child flow is stopped at publish instead of remaining a promise, every outcome — succeeded, failed, skipped — appears in the item's history, and a failed activity can be retried, skipped or resolved with a tracked note. Plus three security hardenings from an independent external audit.
- Security: Hardenings from the external audit
August 1, 2026
Confidential data stays confidential everywhere, and everyone sees only what is theirs. A safeguard is worth as much as its least guarded exit: a field could be hidden on the item's page and appear in the clear in the indicator computed from that very field, and a read-only role could see no flow in its own list yet still learn names and volumes from another screen. Confidentiality now follows the data wherever it is recomputed, visibility is the same from whichever direction you arrive, and connections with external assistants work the way the standard expects.
- Security: Confidential data stays confidential everywhere
- Security: Everyone sees only what is theirs
July 31, 2026
The rules you write are the rules that hold. Some conditions the designer offered — "greater than or equal", JavaScript rules written the way the assistant suggested, fields in the very form the AI recommended — were accepted on save and then silently ignored by the engine. Now the places where you write and the places where your process runs speak the same language: deadlines have a single grammar, a badly written value is rejected right away instead of vanishing, and if a rule errors at runtime you find it written in the item's history.
- Security: Reference integrity, inside your organisation
July 30, 2026
What you configure shows up, and what the product promises holds. Your brand colours now actually colour the interface, instead of saving with no effect. Deadlines no longer spin silently. The designer tells you the truth about what happens when you mark a phase as final, instead of hiding the controls and letting the diagram tell a different story. And the key for connecting an AI assistant no longer travels inside the address.
- Security: The assistant key leaves the address
July 29, 2026
Uploaded logos are visible again, and the rules hold outside the interface too. Uploading a logo really did work — the file was saved — but nobody could see it back: that is why the defect stayed invisible for so long. Alongside come six security fixes, work that no longer sits stuck in a queue, and a long list of rules the product promised without enforcing them outside its own screens.
- Security: A personal key no longer widens what you can see
- Security: Credentials and sessions close when they should
- Security: The mail server can no longer point inwards
July 29, 2026
Outbound communications work again, and your data stays inside your organisation. Since 25 July every call to an external system was failing before it even started: notifications, alerts, links between installations and email sent through web services. This version repairs them. Alongside come an important privacy fix on the AI assistant connection, protection for the configurable AI engine, and a long list of refinements from tester feedback.
- Security: Outbound calls work again
- Security: History stays inside your organisation
- Security: The AI engine stays out of the internal network
July 28, 2026
The interface only promises what you can actually do. Commands the server would reject no longer appear: those who don't design processes see them read-only, and the two near-identical "force" buttons for changing status — with very different effects — have become a single, clear command about what it respects and what it overrides. On top of that, email forms fill in without surprises and several server responses now tell the truth.
- Security: Fewer clues for outside observers
July 28, 2026
An item closes when the work is done, and reconciled names stay reconciled. The last phase of a process can have work to do, and until it's done the item is not complete: before, it was considered closed the moment it got there, and the counts said "done" with the checks still open. On top of that, a hand-written name linked to a real person no longer comes back on its own.
- Security: Internal errors no longer describe how the system is built
- Security: The reconciliation panel stays inside your organisation
July 26, 2026
Updating FlowSharp no longer signs you out, and no update starts without a verified backup. Anyone with the page open during a release was often disconnected and saw a row of red errors appear. Underneath there was a real defect: a momentarily unreachable database was reported as "session expired". Now the page waits and recovers on its own.
- Security: No update starts without a verified backup
- Security: Sample users on older installations
- Security: Stricter checks on automations and attachments
July 26, 2026
Protection against connection hijacking now covers calls to AI providers too. The previous version bound outbound connections to already-verified addresses for webhooks, n8n and email; the path to AI providers was still on the old transport. It now follows the same rule.
- Security: Calls to AI providers now use the protected transport
July 25, 2026
Email now goes out from your own channels, and whoever forgets a password no longer has to call the administrator. Until yesterday all mail left through a single channel, configured once for the whole installation: every organisation received notifications from a sender that wasn't theirs. Now each one configures its own sending channels, with a fallback order if the first doesn't answer.
- Security: Identity emails stay on the system channel
- Security: Procedure documents are no longer public
- Security: Safer installations from the first boot
- Security: Outbound connections are harder to hijack
July 25, 2026
Work assigned to a name that doesn't exist yet no longer disappears in silence. You can still type a person's name as the assignee before you've even created their user — that's normal while you sketch a process — but now the system tells you, instead of leaving that work with no alerts and no reminders.
- Security: Checks extended to entity links and role names
July 23, 2026
Data that's harder to corrupt, configurations that don't fail silently. Entity references no longer duplicate over a stray space or a capital letter, a non-existent assignee no longer leaves work hanging on nobody, and views that promised an option now actually give it to you.
- Security: Verified entity type and assignee
July 22, 2026
Security update to the image-processing library. Same contents as 0.63.0, plus an update to the component that processes uploaded logos.
- Security: Image library updated
July 22, 2026
What you see in the list is what you filter, search and export. The status filter no longer hides items from other flow versions, search behaves predictably with special characters, and the CSV file contains exactly the rows in front of you.
- Security: Search no longer exposes restricted fields
July 22, 2026
Process maps no longer lose work and protect published versions. Edits made during a save are no longer overwritten, back-to-back saves no longer trigger false conflicts, and a published map is now truly immutable.
- Security: Published versions protected and concurrency enforced
July 22, 2026
Safer external links and more reliable incoming data. The entity link can no longer run code on click, and a flow's start data is now checked by type too.
- Security: The entity link can no longer run code
July 22, 2026
Governance of external domains is now truly enforced, everywhere. When you deny a provider the block is respected — even YouTube or Google Drive — and the check covers every content type, not just embedded frames.
- Security: "Deny" now really blocks, even well-known providers
- Security: No external content escapes the check
- Security: Validated manual add, and a denied domain stays denied
July 21, 2026
Assigning a manual task is now one clear gesture, with no surprises. A single assignment field in the designer, the notification reaches the right person, and dynamic assignees really work.
- Security: Dependencies updated against the latest vulnerabilities
July 21, 2026
Search and filters that scale, with no rows silently disappearing: on items, tasks and events, search now works across the whole archive — no more hidden caps hiding older records. And embed-domain governance now recognizes content that already exists.
- Security: Existing embed domains recognized
July 20, 2026
More security control, more reliable data, no lost work: decide which external domains are allowed in embeds, maps no longer overwrite each other across tabs, flow names and codes become unique, and the Automation Plan stops counting phantom savings.
- Security: Organization-governed embed domains
July 19, 2026
Stronger foundations: organization isolation in the busiest areas is now guaranteed "by construction" by the system itself, with an automatic guard preventing regressions; every sensitive page's permissions are under continuous test. Same app, much more robust underpinnings.
- Security: Organization isolation by construction
- Security: Page permissions under continuous test
July 19, 2026
Fast, high-impact polish: navigation without double loading, list filters kept separate per organization, uniform error messages, better accessibility — plus two automatic guards that watch over server errors and translations before they ever reach production.
- Security: Automatic guards on errors and translations
July 18, 2026
Safer and faster: a last loophole toward the internal network closed in integrations, cache cleared on user switch, responsive login even under load and quicker transitions. Plus, the n8n snippets generated by the app now work on the first try.
- Security: Internal network protected with no loopholes
- Security: User switch with no leftovers
July 18, 2026
Data security and a more reliable engine: items are readable only when their flow is visible to your role, sensitive fields are masked in exports and AI channels too, non-blocking AI tasks no longer lose their verdict, and published Process Maps become immutable. Plus a round of polish on the Automation Plan and AI Assistants.
- Security: Item visibility with no shortcuts
- Security: Sensitive fields masked wherever they leave the app
July 17, 2026
Stricter permissions and a more accessible app: integration credentials and the automation backlog are now restricted to the right roles, the Copilot truly applies final-state outcomes, What-if no longer creates duplicate initiatives, and the sidebar, filters and dialogs are fully usable with keyboard and screen readers.
- Security: Credentials and backlog restricted to the right roles
July 17, 2026
Reliability and isolation: external systems connected to your flows no longer receive duplicate deliveries when an internal job is retried, and data isolation between organizations is now guaranteed "by construction" at the database access layer.
- Security: Stronger isolation between organizations
July 15, 2026
Quality and polish: the Copilot can set flow-level SLA and expected path and its edits are always applicable; Saving Challenges gain a clearer export, readable amendments and localized notifications; plus accessibility and security fixes.
- Security: Security and robustness polish
July 13, 2026
Dependency security: a known vulnerability in a third-party library shipped in the production image is closed, plus a new automated check that keeps similar issues from silently coming back.
- Security: Dependency hardening
July 12, 2026
Federated identity (Phase 1): you can now invite someone who already works on another FlowSharp tenant — same installation — to operate on yours too, without creating a second account with a separate password. They always remain the owner of their identity: you invite, they accept, and they can move between companies with one click, always keeping it clear "where they are".
- Security: Deterministic login
July 12, 2026
A wave of fixes from tester reports: more reliable designer saves, status duplication without "ghost routing", tighter control over admin overrides of automatic tasks (with protection against late n8n responses), and documents/PDFs finally rendered properly in task guides — including PDFs on Google Drive.
- Security: Automatic tasks — admin override and late responses
July 12, 2026
A security hardening pass from the latest audit: closed a few isolation gaps between customer tenants on task opening, manual status change and automation initiatives, and made the real-time channel more resilient against a potential overload.
- Security: Tenant isolation
- Security: A more resilient real-time channel
July 11, 2026
The Saving Challenge becomes contract-proof: the frozen baseline now carries a SHA-256 fingerprint that makes the integrity of the numbers provable, a simulator lets you try fees and parameters before proposing the contract, and every monthly consolidation arrives as a notification. List and detail tell the accrued story at a glance: cumulatives, chart, measured vs estimated savings. Contains a database migration.
- Security: Verifiable contract
July 11, 2026
A security release, the outcome of a targeted audit of authentication, tenant isolation, integrations and file upload. Three areas were already solid, three points hardened: API keys now always have an expiry, automation scripts can be limited in the actions they perform, and MCP keys automatically align with the current role of whoever created them. No impact on day-to-day use — the changes are backward-compatible.
- Security: API keys always expire
- Security: More controllable automation scripts
- Security: MCP keys aligned to the real role
July 10, 2026
A fixes-only release: a round of API and UI *hardening*. It closes situations where you could silently lose work (a repeated request with different data, two operations racing on the same item) and some mismatches between what the interface shows and what it then acts on (flow list, map printing, event roles). No database migration.
- Security: Printing and event integrity
July 7, 2026
Second security pass: all remaining audit findings closed — tenant-validated event references on maps and strict limits on design and AI functions.
- Security: Tenant-validated event references on maps
- Security: More robust map saving
- Security: Limits on AI design functions
- Security: Event integration snippet fixed
July 7, 2026
New: Export PDF — maps and flows become meeting-ready documentation, with graphs, phases, tasks and period numbers.
- Security: Sensitive data never in the document
July 7, 2026
Security pass: per-tenant isolation of the event log and hardened dependency configuration.
- Security: Event log isolated per tenant
- Security: Update-proof dependency policy
July 7, 2026
Tidier Process Map: compact toolbar, map import, the Flow Agent lands on the designers — plus an MCP security fix.
- Security: Flow-scoped MCP keys and the agent
July 6, 2026
Real-time flow diagnostics in the designer, n8n payload halved and safer, AI generation that always produces publishable flows.
- Security: Service keys never enter item data + single payload contract
July 6, 2026
Guide images restored, deploys safe against unmigrated schemas, internal errors never exposed.
- Security: Deploys can no longer start on an old schema
- Security: Internal errors never exposed
July 5, 2026
QA fix batch for n8n and the designer: clearer import, idempotent snippets, connector test aligned with the real contract, a more honest designer on errors.
- Security: Sturdier secret variables + role-consistent menu
July 4, 2026
Quality and security hardening: more tenant-isolation tests, agent Data Shield refinements, updated in-app guide.
- Security: Tenant isolation verified by tests
- Security: Sturdier agent Data Shield
July 4, 2026
Data Shield comes to the Flow Agent: the chat AI provider only receives pseudonymized data.
- Security: The model only sees pseudonyms
- Security: No extra configuration, MCP included
July 4, 2026
"Secret" variables for credentials and tokens, plus Process Maps list refinements.
- Security: Controlled reveal, always audited
- Security: Works everywhere, redacted in logs
July 4, 2026
QA fix batch: more robust filters and parameters, more consistent designer, more reliable dashboard, clearer Chrome extension.
- Security: Safer production connector test
- Security: More robust list filters and parameters
- Security: Boolean variables validated
- Security: Numeric thresholds validated
- Security: Webhook URL masked
- Security: More precise permissions banner
July 4, 2026
Consolidation release: anti-duplicate reliability, consistent access control, and clearer WIP.
- Security: Consistent role-based visibility
- Security: Safer MCP keys and WIP fail-closed
July 2, 2026
A Flow Template Library and a smoother n8n integration — open the workflow in one click and test webhooks with a guided popup.
- Security: Local n8n no longer blocked
June 30, 2026
Variables get much easier to use — the `{x}` picker respects your selection, fields show the resolved variable value, and the variables editor is cleaner. Plus a round of quality and security fixes.
- Security: Stricter API validation and safer publish
June 24, 2026
Three security-audit findings mitigated: async callbacks, logo upload, design-time AI
- Security: Hardened async task callbacks
- Security: Logo upload restricted to Admins
- Security: Design-time AI respects sensitive fields
June 24, 2026
Data-contract diagnostics in the designer + data governance extended to the Flow Agent
- Security: Data governance on the Flow Agent
June 23, 2026
Consistent start requirements across every channel + shared "when to use a flow" between the built-in Flow Agent and external MCP agents
- Security: Start requirements on every channel
June 22, 2026
8 security audit findings fixed, dependencies at zero vulnerabilities
- Security: Security audit addendum
- Security: Dependencies: 24 → 0 vulnerabilities
June 22, 2026
AI never runs on empty data, per-phase force transition, entity naming
- Security: AI no longer runs on empty data
June 21, 2026
Data Shield on nested fields, richer rule builder, readability fixes
- Security: Data Shield on nested fields
June 20, 2026
Read-only access for non-editors, stricter API validation, cleaner designer edges and dark-mode fixes
- Security: Permissions & UI consistency
June 19, 2026
Faithful flow import (routing rules + extension/agent fields), extension reliability, and read-only design action
- Security: Read-only design action for non-editors
June 19, 2026
Consistent required-data validation across all create channels, enforced entity reference, and persistent list filters
- Security: Required-data validation on every create channel
June 19, 2026
Scheduled item start, working state timeouts, MCP start-events, stronger API-key security and import/export fidelity
- Security: API-key security & import/export fidelity
June 19, 2026
Reliable task open/reassignment tracking, observable events, more accurate metrics, and security hardening
- Security: Security & robustness
June 18, 2026
Items no longer get stuck on automatic steps, stronger API/MCP security & privacy, paginated lists, fuller audit trail, and admin unblock for AI tasks
- Security: API/MCP: privacy and clean errors
June 18, 2026
No more blank dashboard, safer n8n form, admin unblock for stuck AI tasks, and flow publishing via MCP
- Security: n8n form: no wrong autofill
June 18, 2026
Security hardening (extension token scope, CORS, HSTS) and extension robustness fixes
- Security: Extension token confined to its endpoints
- Security: Robust CORS and HSTS
June 6, 2026
Work on items from a popup that reuses the real web UI (SSO) + optional item title
- Security: Secure single sign-on between extension and popup
June 6, 2026
Operational side panel for the Chrome extension (mini-cockpit) + per-tenant disconnect
- Security: Extension actions enforce the same rules as the web app
June 2, 2026
Security hardening, flow-scoped API keys and Flow Agent polish
- Security: Full security hardening (codebase audit)
- Security: Flow-scoped API keys
- Security: Events: who can raise them
May 19, 2026
Chrome extension (MVP), entity prefix, contextual flow start from external systems
- Security: Extension Auth & RBAC
May 10, 2026
Visual flow progress, related items, activation mode
- Security: Input Validation Hardening
May 9-10, 2026
n8n Native Bridge, task views, deploy with SSL
- Security: n8n Security Audit
May 9, 2026
AI copilot, analytics dashboard, calendar view
- Security: Critical Security Remediation
Apr 28 - May 1, 2026
Version management, Kanban board, flow deletion
- Security: Security Hardening