2026
A full rundown of our latest releases, improvements and fixes in Cakewalk.
Choose which Connections each group can use
Agent Access is open by default: every Member sees the whole catalog and can connect any app in it to their agents. That is the right starting point for most companies and the wrong one when Cakewalk is the gate in front of sensitive business data.
Connection access now has a second setting. Switch it to Curated and you decide which Agent Connections each User Group may use. A Member only sees the Connections allowed for the groups they belong to, and the groups come from the HRIS or identity provider you already sync, so access follows your own org structure.
Turning it on does not cut anyone off. Cakewalk starts you from what people already have and shows you who is affected before any change applies. Nothing is deleted either: a Connection someone loses keeps its credential, is marked Restricted to explain why it stopped working and resumes on its own the moment you allow it again.
Open stays the default. Nothing changes for your company unless an Admin switches.
Google sign in for six more apps
Six more apps can be provisioned with a Google login instead of a stored password. Sentry, Figma, Dovetail, Zoom, Loom and Slack join ChatGPT, Miro and Mixpanel.
Sign in with Google is enabled per app, so coverage grows as each one is proven. Existing configurations keep working untouched.
Group membership with a choice of action
Adding users to a User Group now offers three paths: raise access requests for each person, apply the access directly as an Admin, or record the membership and change no access at all.
The same choice applies when removing members, so a group change no longer forces one behaviour on everyone in it.
Where an option is unavailable the dialog says why, for example while the group is still onboarding or when the group has no access to the app in your identity provider.
Broken integration warning in App Governance
A warning icon in App Governance marks any app whose integration has broken, so a silent sync failure is visible from the overview rather than discovered later.
Filter the table by Yes, No or No Integration to see only the apps that need attention.
App detail carries the same warning, plus a separate notice when the last sync ran too long ago.
Access Sync coverage
Access Sync reads users and their access from Vercel, incident.io, Sanity and PagerDuty.
Agent Cake coverage
New apps: Sanity, ClickHouse, Heap and PagerDuty.
A better Slack app
Agent Cake answers in Slack on an upgraded model.
Permission descriptions render properly in request threads, and app owners appear by name rather than as a raw email address.
Sign in with Google
Some apps only let people in through Google. Agent Cake can now sign in with a Google account instead of an app username and password, which brings those apps into Auto-Provisioning for the first time.
Connect a Google account once in Settings and reuse it everywhere it applies, or enter Google credentials on an individual app's own configuration screen. Live for ChatGPT, Miro and Mixpanel.
A configuration can offer a username and password login and a Google login at the same time, rather than forcing a choice between them.
This drives Google's own sign in page rather than an OAuth consent screen. The account has to allow password sign in, and where 2 Step Verification is on it has to use an authenticator app.
The Set up Service Accounts guidance still applies. Use a dedicated account, not a person's own login.
Company SSO login for every customer
Logging in to Cakewalk through your company's own SAML identity provider is available to all customers. It was previously limited to some.
Signed authentication requests are supported for companies that require them.
Public API additions
Read only API credentials, for integrations that should never write.
Webhook signatures version 2, which adds replay protection.
ChatGPT
Agents running in ChatGPT can use Cakewalk. Three tools stand in for your whole catalog, which is how a client without native MCP support reaches your company's apps.
Human Access and Agent Access together
Users and User Groups stay in sync across both modules, so a person added in one appears in the other.
Navigation moves straight between the two, and a module's entry appears only if your company uses it.
When an app has no seats left
Provisioning that fails because the target app has run out of seats now says exactly that, rather than reporting a generic failure, and the requester is notified.
Add your own Connections
The catalog is no longer the limit. Admins can add custom MCP servers that Cakewalk does not ship, and they behave like everything else: same Policies, same approvals, same Audit Log.
Each custom Connection carries a name, a category and an image, so it sits in the catalog rather than beside it.
Connections that need setup are labelled
A Connection that cannot register itself automatically is marked as awaiting setup, with a warning icon in All Connections and an alert card explaining what is missing.
My Connections disables Connect on anything not yet configured, so an employee does not walk into a dead end.
Mark as configured moves the Connection to Active once the credentials are in place.
Search excludes Connections that are still awaiting setup.
Correct a tool's action type
Admins can reclassify what a tool does, as Read, Write, Destructive or External, one at a time or in bulk from the Connection's Tools tab.
Policies are keyed to action type, so this is the fix when the wrong Policy fires because a tool arrived classified incorrectly.
The correction survives the next catalog sync.
Personal access tokens
A Connection can authenticate with a personal access token. That completes three ways to connect, alongside automatic client registration and credentials an Admin supplies.
Public API for access requests and the audit log
Create access requests through the API, to grant, change or remove access, routed through Policy and approval exactly as they are in the product.
Read requests and audit events through a filterable endpoint, which gives a SIEM something to pull from on its own schedule.
Denials that explain themselves
When a Policy denies a tool call, the response names the Policy that fired.
An agent client that cannot show an approval prompt gets a message saying so, rather than an unexplained denial.
Connect once, inherit your access
Agent Access is live. Employees authorize an app once, and every Agent they run reaches it through Cakewalk with exactly their own access, governed on every call.
The Agent never holds the credential. Cakewalk injects it at call time and never returns it to the Agent or the model, so a compromised context has nothing to steal.
Agent permissions match that person's permissions in each app, so a teammate's Agents stay scoped to the teammate.
Inline approvals
A sensitive action pauses inside the Agent client. Approve or deny in place and the Agent resumes with full context.
The Agent experiences a slow tool call, nothing more, so a decision does not end the task.
Policies
Create custom Policies and review the defaults, each evaluated per company.
Conditions read the person's department, job title, team and location, and the app's own attributes.
Test a Policy against past agent activity before it goes live, and see which calls it would have decided differently.
Sessions and the Audit Log
Every tool call through the gateway is recorded: who ran it, what it did, against which Connection, and which Policies fired.
Sessions are viewable across Agents, users and Connections. Admins see everything, employees see their own.
Collapsible rows show the tool calls inside a session, and a side panel opens one call in full.
Agents and Connections
Agents overview and detail, in grid and table views. My Agents for employees, All Agents for Admins.
Connection detail lists the tools that Connection exposes, with disconnect and bulk actions.
Agent status derives from real activity: Active, Inactive or Not Connected.
Add an Agent before it ever connects, so the catalog reflects what your company sanctions rather than only what has been used.
Empty states redesigned
Every table now explains what is missing and what to do about it, instead of showing an empty rectangle. A quieter month on Human Access while Agent Access was being built.
The redesign covers users, apps, requests, tasks, reviews and group imports.
Clearer ownership on onboarding and offboarding
The onboarding and offboarding tables label the column Assignee(s) rather than Manager, which matches who actually does the work. A manager is often not the person completing the task.
A rebuilt Slack app
The Slack app is rebuilt around conversation. Cakewalk runs as an assistant in your Slack sidebar, understands plain language, and keeps everything about a request in one thread.
Most access work no longer needs the web app at all.
Ask for what you need. Request access for yourself or for someone else, change a permission level, remove access, or ask for several apps at once.
Check the status of a request, have a reminder sent to your approver, and find out who owns an app.
When the app you asked for is not tracked, the assistant suggests alternatives rather than stopping at a dead end.
Approvers complete tasks in Slack. Every follow up stays in the same thread, and live status shows what the assistant is doing while it works.
Mention Cakewalk in a channel and it moves the conversation to a direct message.
Notification preferences
Choose which notifications you receive, by category and by channel, from your profile. This was a top customer request.
Notifications that require immediate action cannot be switched off.
No-Touch Onboarding
Point an integration at one synced group from your identity provider and new joiners in that group receive their default apps with no review step.
It combines with Auto-Provisioning, so a joiner can be fully set up without anyone opening Cakewalk.
Table views persist
Filters, columns and sorting are stored on your account, so a view is the same on every device and in every tab.
Non-human identities
Agents and service identities found in connected apps appear in their own table, with a compact detail popover.
App Governance leaves beta.
Access Sync coverage
User sync for Linear rebuilt.
Agent Cake coverage
New apps: Atlassian and Tableau Cloud.
Bulk access in Slack
Access requests stop being one app at a time. Agent Cake handles several people and several apps in a single message, and validates a removal list before anything is applied, so a bad list fails before it changes access.
Cancel a request and search active requests without leaving Slack.
Non-human identity discovery
Agents and service identities discovered in connected apps are collected in one table for security and compliance review.
Visibility is read only. Requests, Policies and provisioning do not apply to them.
Access Sync coverage
Access Sync reads users and their access from Sentry.
Agent Cake coverage
Loom rebuilt on browser automation.
Tables rebuilt
Every table in Cakewalk gets the same filtering, grouping and scrolling behaviour, so what you learn on one works on the rest.
New filters across users, user accesses, work app users, Access Reviews, request logs and group imports.
Infinite scroll with an x of y count, so a long list no longer needs paging.
Group by moved into a gear menu, with a new interface and a visibility panel beside it.
Custom fields are available in table queries, including calculated ones.
Access conflicts
Conflicting access is recorded and flagged with a warning icon and a tooltip, so an Admin sees the conflict in the table rather than after granting.
Public API
New endpoints for work apps, and API credentials to call them.
Access Sync coverage
Agent Cake coverage
Linear provisioning rebuilt, with an optional workspace choice.