> For the complete documentation index, see [llms.txt](https://www.cakewalk.security/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.cakewalk.security/docs/changelog/2025-product-updates.md).

# 2025

{% updates format="full" %}
{% update date="2025-12-17" tags="new-releases,improvements,fixes" %}

## Auto-deprovisioning

Agent Cake closes the offboarding loop. A remove access request or an offboarding now [removes the account in the app](https://www.cakewalk.security/docs/human-access/how-to-guides/auto-provisioning/how-it-works/control-provisioned-permissions), not just the record in Cakewalk.

Enable it per app from App Governance and choose which permissions it may remove. The complete audit trail an SOC 2 or ISO 27001 auditor asks for comes with it.

## Test the connection first

* Check a configuration works before the first account is created, so a wrong credential surfaces at setup rather than during an offboarding.

## Email verification, in beta

* Some apps only authenticate through a magic link or a code sent by email. Agent Cake can now read a connected Gmail or Outlook inbox, follow the link and finish the job. [Email verification](https://www.cakewalk.security/docs/human-access/how-to-guides/auto-provisioning/how-it-works/email-verification) starts with Slack and Cursor.
* Connect the inbox under Settings, Account, Auto provisioning and link it to the apps that need it.
* Only verification emails are accessed. Use a dedicated account rather than a person's own.

## Clearer task titles

* [Task](https://www.cakewalk.security/docs/human-access/how-to-guides/tasks) titles say what is actually being asked. Approve means one decision and nothing else. Provision, Remove and Update mean somebody has manual work to do.

## Copy link

* A copy link control on apps, users, tasks and [requests](https://www.cakewalk.security/docs/human-access/how-to-guides/requests) hands a teammate the exact thing you are looking at, rather than a description of it.

## Agent Cake coverage

* New apps: [Linear](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/linear), [Clay](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/clay.com), [Vercel](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/vercel) and [Lovable](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/lovable).

## Access Sync coverage

* [Access Sync](https://www.cakewalk.security/docs/human-access/how-to-guides/access-sync) adds ClickUp.

<details>

<summary>Improvements</summary>

* Navigation redesigned across the web app.
* Filter App Governance by app name, and filter on user groups with a new operator built for lists.
* Table sort defaults reviewed so the most useful column leads.
* The sync users button says Sync users rather than New.
* The app connection popup closes itself once the connection is established.
* Slack notifications go through a queue, which keeps them in order under load.

</details>

<details>

<summary>Fixes</summary>

* Duplicate app names with the same alias raised an error on save.

</details>
{% endupdate %}

{% update date="2025-11-19" tags="new-releases,improvements" %}

## Manager Sync

[Reporting lines come from your HRIS or identity provider](https://www.cakewalk.security/docs/human-access/how-to-guides/users-and-groups/joiner-mover-leaver-jml) rather than from an admin maintaining them, so approvals route to the right person on their own.

Where your HRIS has no manager for someone you can set one by hand, and Cakewalk replaces it automatically when the real data arrives.

* Turn it on under Settings, Data Sources, Users, Manage integration settings.
* Onboarding and invite pages suggest the manager when an HRIS is connected.
* Access changes account for permissions that are granted but not yet confirmed by the app.

## Access Sync

* [Access Sync](https://www.cakewalk.security/docs/human-access/how-to-guides/access-sync) reads users and their real access directly from a connected app, so the record reflects the app rather than what Cakewalk was told.
* Launched with Slack, Notion, Asana, GitHub, Linear, Jira, Zendesk, Calendly, Confluence, Intercom, Zoom and Docusign.
* Connect an app from its detail view, then manage the connection from the same place.
* Access carries a confirmation grace period, so a newly granted permission is not read as missing before the app has caught up.

## Access reviews through the public API

* Create access reviews programmatically, for companies that drive their review cycle from another system.

<details>

<summary>Improvements</summary>

* Users found in a connected app but not in your HRIS are linked rather than duplicated, and raise a task to resolve.
* Archiving an app cleans up its connection instead of leaving it behind.
* Multi factor sign in extends to Slack and Calendly, and a configuration that needs a code now says so rather than failing.
* Thin scrollbars in the navigation and in table overflow.
* Front end dependencies updated across every project.

</details>
{% endupdate %}

{% update date="2025-10-31" tags="new-releases,improvements,fixes" %}

## User categories and statuses

[The User Directory](https://www.cakewalk.security/docs/human-access/how-to-guides/users-and-groups/user-management) learns who is who. Employees, contractors and service accounts are distinguished, and a status field makes it clear who to act on and who to leave alone.

Less noise in reviews, and a cleaner record to work from.

* Table filters segment users by category, role or status, including moving a discovered user to ignored.

## Email aliases

* An alias is logged against the right person rather than creating a second record, across onboarding, invitation and editing.
* A primary email can be updated, and an email change coming from your HRIS is applied to someone already being onboarded.

## Merge users

* Two records for the same person can be merged from the user overview.

## Agent Cake coverage

* New apps: [Slack](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/slack) and [Notion](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/notion).

<details>

<summary>Improvements</summary>

* A user discovered in a connected app moves to invited automatically once your HRIS reports them.
* The label reads User category rather than Identity category.
* Request and task events share a request identifier, so the two can be read together.
* Requests and tasks carry the app they belong to in more places.

</details>

<details>

<summary>Fixes</summary>

* Navigating back from a page reached directly landed nowhere useful.
* Duplicate access rows in the user table.
* Deprecation warnings during install that made real problems harder to spot.

</details>
{% endupdate %}

{% update date="2025-09-22" tags="new-releases,improvements,fixes" %}

## Access Reviews

[Access reviews](https://www.cakewalk.security/docs/human-access/how-to-guides/access-reviews) run inside Cakewalk. Create one by Manager or by App Owner, set a due date, choose which apps are in scope, and track completion from a single view.

The point is the evidence. Reviews created and distributed, completion tracked in one place, and a named person accountable for every least privilege decision.

* Reviewers work through a table based flow that takes minutes rather than an afternoon, and get their reminders in Slack and by email.

## Smart Tables

* Create custom views to match how you actually work, then resize, add, remove and reorder columns.
* Share a view with a teammate by link, so a conversation starts from the same screen.
* Live first in User Overview and App Governance.

## Multiple assignees on onboarding tasks

* Onboarding and offboarding [tasks](https://www.cakewalk.security/docs/human-access/how-to-guides/tasks) can go to several admins rather than one. Whoever gets there first resolves it for everyone.
* Offboarding tasks can route to the leaver's line manager or to admins, whichever matches how your company works.
* A task no longer waits for one person to come back from leave.

## Agent Cake coverage

* New apps: [Read.ai](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/read.ai), [Zapier](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/zapier), [Dovetail](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/dovetail), [Apollo](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/apollo), [Intercom](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/intercom), [dbt Cloud](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/dbt-cloud), [Amplitude](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/amplitude) and [Docusign](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/docusign).

<details>

<summary>Improvements</summary>

* Columns can be removed by right clicking the header.
* Column content no longer wraps, and icons align properly in menus and navigation tabs.
* View navigation tabs redrawn to match the designs.
* A webhook that fails is recorded with its result rather than raising an error, so one bad endpoint does not look like an outage.
* Adoption events added to Smart Tables so the next version is shaped by use rather than opinion.

</details>

<details>

<summary>Fixes</summary>

* Creating a review that already existed returned an unhelpful conflict.
* An extra border on the last quick filter.
* Access rows appeared twice in the user table.

</details>
{% endupdate %}

{% update date="2025-08-29" tags="new-releases,improvements" %}

## User statuses

Users gain a lifecycle status, which is the groundwork that later makes discovered, ignored and invited mean something rather than being a guess.

* An endpoint to simulate discovering a user, so the flow can be exercised before real data arrives.

## Offboarding without a decline

* The decline option is gone from offboarding tasks. An offboarding is not a request, and treating it like one left accounts open.

## Choose who owns an integration

* A form to set the integration owner, which is what later lets onboarding and offboarding tasks go to several admins instead of one.

## Self serve setup for Agent Cake

* Each Auto-Provisioning configuration links to its own [integration guide](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides), so an app can be set up without a call.
* Apps still being proven carry a beta marker, so it is clear which coverage is new.
* Configuration credentials move to a new encryption scheme.

## A merge action on users

* Two records for the same person can be merged from the user row actions, and a user carries the source they came from.

## Agent Cake coverage

* New apps: [Datadog](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/datadog), [LaunchDarkly](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/launchdarkly), [Snowflake](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/snowflake), [Pitch](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/pitch), [Confluent](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/confluent), [Aircall](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/aircall), [New Relic](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/newrelic), [Cal.com](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/cal.com), [Coda](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/coda), [TestGorilla](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/testgorilla) and [Fillout](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/fillout.com).

<details>

<summary>Improvements</summary>

* An alias can be set on the edit user page.
* The tasks table carries a Type column, and task titles name the request they belong to in both Slack and the web app.
* Duplicate API credential labels are caught when they are created rather than when they are used.
* App import shows a proper loading state and keeps polling until it finishes.
* Events from your HRIS are ignored for companies that are no longer active.

</details>
{% endupdate %}

{% update date="2025-07-31" tags="new-releases,improvements" %}

## Group changes raise requests

A [User Group](https://www.cakewalk.security/docs/human-access/how-to-guides/users-and-groups/groups-and-role-based-access-control-rbac) and the access it implies stay in step. Removing a user or a default app from a group now creates the requests to match, rather than changing access silently.

* Default apps can be added to and removed from a group directly.
* Where an app owner and a group disagree about who should hold access, the conflict is resolved rather than silently applied.

## Custom fields on requests

* A request can carry custom fields, so the information an approver needs arrives with the request instead of in a follow up message.
* An app request can collect whatever your vendor review process requires before it reaches anyone.

## Webhook delivery at volume

* [Webhooks](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/webhooks) deliver through a parallel queue with several consumers, so a slow endpoint on your side no longer holds up everything behind it.

## Editing an invited user

* Someone who has been invited but has not yet signed in can be edited, rather than being deleted and re invited.

## Agent Cake coverage

* New apps: [Postman](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/postman), [Freshdesk](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/freshdesk), [Cursor](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/cursor.com), [Calendly](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/calendly), Marvin, [ClickUp](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/clickup), [Xero](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/xero), Contentful and [PostHog](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/posthog).

<details>

<summary>Improvements</summary>

* Agent Cake can answer a [multi factor challenge](https://www.cakewalk.security/docs/human-access/how-to-guides/auto-provisioning/how-it-works/multi-factor-authentication) at sign in, so an app with MFA enabled is no longer out of reach. Enabled per app, starting with Miro and ClickUp.
* Only admins can be reassigned to review an onboarding task, which stops a review landing with someone who cannot complete it.
* A duplicate request is caught before it is created rather than returning a conflict.
* Firefox extension 6.5.0, and older browser extension versions keep working.
* The Slack request summary aggregates custom field values rather than listing them.
* Vertical spacing tightened in dropdown and pop out menus.
* Request logs can be sorted by assignee.
* A copy to clipboard control where people had been trying to select text by hand.

</details>
{% endupdate %}

{% update date="2025-06-30" tags="new-releases,improvements" %}

## API keys you can manage

The public API becomes something you can operate. Generate, rename and rotate [API keys](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/authentication) from the product, with a list showing status and metadata rather than a value pasted somewhere and forgotten.

## Webhooks

* Create a [webhook](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/webhooks) endpoint from the interface, add a label, send a test payload and delete it when it is done.
* Action task created and updated events, so an external system can follow a task without polling.

## More of the product through the API

* Endpoints for [work apps](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/api-reference/applications), [tasks](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/api-reference/tasks), [policies](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/api-reference/policies) and [user groups](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/api-reference/user-groups), including adding and removing people from a group.
* The published specification carries enough detail to generate a client from it.
* The users endpoint returns the manager, which is what most integrations reach for first.

## Agent Cake coverage

* New apps: [GitHub](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/github), [Loom](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/loom), [Asana](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/asana) and [Sentry](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/sentry).

<details>

<summary>Improvements</summary>

* Request logs sortable by assignee.
* Cards aligned and tidied across the app.

</details>
{% endupdate %}

{% update date="2025-05-30" tags="new-releases,improvements" %}

## App owners can act

An app owner can perform the admin actions for their own app, so an admin is no longer the bottleneck for apps they do not own.

Delegating that work was one of the more persistent admin frustrations before it shipped.

## Per app analytics

* Each app gets its own view of how it is actually used, which is the number you want before renewing a contract.

## Onboarding and offboarding overview

* A single view of what is coming rather than what has already gone wrong.

## The public API, first release

* The [public API](https://www.cakewalk.security/docs/human-access/open-api-and-mcp/introduction) ships with key and secret authentication using asymmetric keys built to rotate, and the first users endpoint.

## Agent Cake coverage

* New apps: [Figma](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/figma), [Miro](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/miro), [OpenAI Platform](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/openai-platform), [HubSpot](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/hubspot) and [Zendesk](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/zendesk).

<details>

<summary>Improvements</summary>

* Table headers redesigned for higher data density.
* Table search is scoped to the primary column, so searching a name stops matching an unrelated field.
* Managed and unmanaged states are easier to read at a glance in [App Governance](https://www.cakewalk.security/docs/human-access/how-to-guides/apps/app-governance).

</details>
{% endupdate %}

{% update date="2025-04-30" tags="new-releases,improvements,fixes" %}

## Configure Auto-Provisioning yourself

Agent Cake moves out of engineering hands and onto a settings page. Auto-Provisioning has a [configuration page](https://www.cakewalk.security/docs/human-access/how-to-guides/auto-provisioning/how-it-works/configuration-settings), a detail view, a side panel summary and confirmation dialogs before anything is switched on.

Requests and tasks now show whether they will be provisioned automatically, in the web app and in Slack, so nobody does by hand what Agent Cake is about to do.

* A failed configuration cancels its pending work instead of leaving tasks half done.

## AI risk score on every app

* Apps carry a risk level, surfaced in the tables and in app detail, so [App Discovery](https://www.cakewalk.security/docs/human-access/how-to-guides/apps/app-discovery) sorts by exposure rather than alphabetically.

## Microsoft as a source

* Import apps and users from Microsoft as well as Google, with Microsoft SSO shown in the users and apps tables and available as a filter.
* Apps imported from either source arrive as discovered rather than managed, so nothing is governed before somebody decides it should be.

## Managed and unmanaged apps

* An app can move between managed and unmanaged with the side effects handled, and unmanaged apps stay out of the catalogue.
* Employees can request access to an app that is not managed yet, with the request prefilled.

## Change my permissions

* Employees can ask for a different permission level on an app they already have, rather than filing a fresh access request.

## Agent Cake coverage

* New apps: [CloudTalk](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/cloudtalk) and 123erfasst.

<details>

<summary>Improvements</summary>

* Browser extension 5.2.0.
* Search results take admins to the app overview rather than a side panel.
* Long app lists in popovers can be filtered by typing.
* Keyboard navigation works inside menus.
* Restricted work apps on a group are now called hidden work apps, which is what they do.

</details>

<details>

<summary>Fixes</summary>

* Users already deactivated in the identity provider caused onboarding to fail.
* Duplicate emails blocked a company from being set up.

</details>
{% endupdate %}

{% update date="2025-03-31" tags="new-releases,improvements,fixes" %}

## The beginnings of Auto-Provisioning

This is the month [Auto-Provisioning](https://www.cakewalk.security/docs/human-access/how-to-guides/auto-provisioning/introduction/introduction-to-auto-provisioning) stops being a script somebody runs and starts being part of the product. An app gets a provisioning tab, with the endpoints behind it to create a configuration, read the active one and hold credentials safely.

## Certifications and server locations

* Apps carry their certifications and where their data is hosted, shown when a new app is requested, when an admin adds one and when one is updated.
* A security review can be answered from the app record rather than from a spreadsheet.

## Export and import

* Export users to a file.
* Import user access and custom fields from a spreadsheet, including apps by name, for companies moving in from another system.

## Restyled detail views

* User detail, app detail and task and request detail rebuilt around collapsible cards, so a long record is readable.

## Agent Cake coverage

* New app: [ChatGPT](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/chatgpt).

<details>

<summary>Improvements</summary>

* Rejected apps can be reactivated as an admin action rather than recreated.
* Every new company starts with a default admin policy, so approvals work on day one.
* Firefox extension 5.1.0.
* Slack messages and action buttons reworded to match the web app.
* Adding users to a group skips anyone the identity provider has already removed.

</details>

<details>

<summary>Fixes</summary>

* A race between two updates to the same Slack thread lost a message.
* App metadata failed to load for rejected or deactivated apps.
* Requests with potential users but no owner could not be completed.
* Importing a spreadsheet with a repeated key raised an error rather than reporting the row.

</details>
{% endupdate %}

{% update date="2025-02-28" tags="new-releases,improvements,fixes" %}

## Add a new app, as a request

Employees can ask for an app the company does not govern yet. It routes through approval like any other request, with its own task, review step and Slack notifications.

Approving it brings the app in with its certifications and data locations recorded, so a new app arrives governed rather than discovered months later.

* Apps that were requested or rejected stay out of the catalogue until somebody decides otherwise.

## Calculated custom fields

* A custom field can derive its value rather than being typed, and a new field type carries the values it is allowed to take.
* Custom fields can be used to decide who approves a request, so approval routing follows your own data.

## Compliance data on apps

* Certifications and server locations moved onto the app record in [App Governance](https://www.cakewalk.security/docs/human-access/how-to-guides/apps/app-governance).

<details>

<summary>Improvements</summary>

* Request logs and task detail carry the data points that were missing.
* Open request counts include the new request type.
* Policy editing rejects an assignee that cannot approve that request type, at the point of editing rather than at approval.
* App images are served through a validated endpoint.

</details>

<details>

<summary>Fixes</summary>

* Invitations were missing from a response, so people looked un invited when they were not.
* A task already declined returned an error instead of saying so.
* Custom field sorting was wrong.

</details>
{% endupdate %}

{% update date="2025-01-31" tags="new-releases,improvements,fixes" %}

## Custom fields drive approvals

Custom fields stop being decoration. A person custom field can decide who approves a request, so routing follows your own org data rather than a fixed rule.

* Fields can be disabled with a reason, reordered by dragging, and edited on apps that were previously locked.
* A field in use by a policy cannot be quietly edited out from under it.
* Completing an account deletion task clears the person's record and their custom field values with it.

## Offboarding conflicts

* An offboarding checks for conflicts before it starts and surfaces them, rather than failing part way through.
* A user cannot be deleted while they are the subject of an offboarding, or while they are the last person holding something.

## Import from a spreadsheet

* Import work apps and user access from a spreadsheet, with duplicates and mixed case emails handled rather than rejected.

<details>

<summary>Improvements</summary>

* Infinite scroll when adding users, so a long list is usable.
* Apps cannot be assigned to a deactivated user.
* Search and sorting normalize accents and case, so a name matches however it is typed.
* Text fields carry sensible length limits instead of accepting anything.
* Claim access can be turned off separately for the browser extension and the web app.
* Browser extension refinements, and the Slack app moved to a current major version.

</details>

<details>

<summary>Fixes</summary>

* Importing work apps could loop indefinitely.
* Deep links into filtered tables landed without the filter applied.

</details>
{% endupdate %}
{% endupdates %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.cakewalk.security/docs/changelog/2025-product-updates.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
