2025
Releases, improvements and fixes in Cakewalk during 2025.
Auto-deprovisioning
Agent Cake closes the offboarding loop. A remove access request or an offboarding now removes the account in the app, not just the record in Cakewalk.
Enable it per app from App Governance and choose which permissions it may remove. The complete audit trail an SOC 2 or ISO 27001 auditor asks for comes with it.
Test the connection first
Check a configuration works before the first account is created, so a wrong credential surfaces at setup rather than during an offboarding.
Email verification, in beta
Some apps only authenticate through a magic link or a code sent by email. Agent Cake can now read a connected Gmail or Outlook inbox, follow the link and finish the job. Email verification starts with Slack and Cursor.
Connect the inbox under Settings, Account, Auto provisioning and link it to the apps that need it.
Only verification emails are accessed. Use a dedicated account rather than a person's own.
Clearer task titles
Task titles say what is actually being asked. Approve means one decision and nothing else. Provision, Remove and Update mean somebody has manual work to do.
Copy link
A copy link control on apps, users, tasks and requests hands a teammate the exact thing you are looking at, rather than a description of it.
Agent Cake coverage
Access Sync coverage
Access Sync adds ClickUp.
Manager Sync
Reporting lines come from your HRIS or identity provider rather than from an admin maintaining them, so approvals route to the right person on their own.
Where your HRIS has no manager for someone you can set one by hand, and Cakewalk replaces it automatically when the real data arrives.
Turn it on under Settings, Data Sources, Users, Manage integration settings.
Onboarding and invite pages suggest the manager when an HRIS is connected.
Access changes account for permissions that are granted but not yet confirmed by the app.
Access Sync
Access Sync reads users and their real access directly from a connected app, so the record reflects the app rather than what Cakewalk was told.
Launched with Slack, Notion, Asana, GitHub, Linear, Jira, Zendesk, Calendly, Confluence, Intercom, Zoom and Docusign.
Connect an app from its detail view, then manage the connection from the same place.
Access carries a confirmation grace period, so a newly granted permission is not read as missing before the app has caught up.
Access reviews through the public API
Create access reviews programmatically, for companies that drive their review cycle from another system.
User categories and statuses
The User Directory learns who is who. Employees, contractors and service accounts are distinguished, and a status field makes it clear who to act on and who to leave alone.
Less noise in reviews, and a cleaner record to work from.
Table filters segment users by category, role or status, including moving a discovered user to ignored.
Email aliases
An alias is logged against the right person rather than creating a second record, across onboarding, invitation and editing.
A primary email can be updated, and an email change coming from your HRIS is applied to someone already being onboarded.
Merge users
Two records for the same person can be merged from the user overview.
Agent Cake coverage
Access Reviews
Access reviews run inside Cakewalk. Create one by Manager or by App Owner, set a due date, choose which apps are in scope, and track completion from a single view.
The point is the evidence. Reviews created and distributed, completion tracked in one place, and a named person accountable for every least privilege decision.
Reviewers work through a table based flow that takes minutes rather than an afternoon, and get their reminders in Slack and by email.
Smart Tables
Create custom views to match how you actually work, then resize, add, remove and reorder columns.
Share a view with a teammate by link, so a conversation starts from the same screen.
Live first in User Overview and App Governance.
Multiple assignees on onboarding tasks
Onboarding and offboarding tasks can go to several admins rather than one. Whoever gets there first resolves it for everyone.
Offboarding tasks can route to the leaver's line manager or to admins, whichever matches how your company works.
A task no longer waits for one person to come back from leave.
Agent Cake coverage
User statuses
Users gain a lifecycle status, which is the groundwork that later makes discovered, ignored and invited mean something rather than being a guess.
An endpoint to simulate discovering a user, so the flow can be exercised before real data arrives.
Offboarding without a decline
The decline option is gone from offboarding tasks. An offboarding is not a request, and treating it like one left accounts open.
Choose who owns an integration
A form to set the integration owner, which is what later lets onboarding and offboarding tasks go to several admins instead of one.
Self serve setup for Agent Cake
Each Auto-Provisioning configuration links to its own integration guide, so an app can be set up without a call.
Apps still being proven carry a beta marker, so it is clear which coverage is new.
Configuration credentials move to a new encryption scheme.
A merge action on users
Two records for the same person can be merged from the user row actions, and a user carries the source they came from.
Agent Cake coverage
Group changes raise requests
A User Group and the access it implies stay in step. Removing a user or a default app from a group now creates the requests to match, rather than changing access silently.
Default apps can be added to and removed from a group directly.
Where an app owner and a group disagree about who should hold access, the conflict is resolved rather than silently applied.
Custom fields on requests
A request can carry custom fields, so the information an approver needs arrives with the request instead of in a follow up message.
An app request can collect whatever your vendor review process requires before it reaches anyone.
Webhook delivery at volume
Webhooks deliver through a parallel queue with several consumers, so a slow endpoint on your side no longer holds up everything behind it.
Editing an invited user
Someone who has been invited but has not yet signed in can be edited, rather than being deleted and re invited.
Agent Cake coverage
API keys you can manage
The public API becomes something you can operate. Generate, rename and rotate API keys from the product, with a list showing status and metadata rather than a value pasted somewhere and forgotten.
Webhooks
Create a webhook endpoint from the interface, add a label, send a test payload and delete it when it is done.
Action task created and updated events, so an external system can follow a task without polling.
More of the product through the API
Endpoints for work apps, tasks, policies and user groups, including adding and removing people from a group.
The published specification carries enough detail to generate a client from it.
The users endpoint returns the manager, which is what most integrations reach for first.
Agent Cake coverage
App owners can act
An app owner can perform the admin actions for their own app, so an admin is no longer the bottleneck for apps they do not own.
Delegating that work was one of the more persistent admin frustrations before it shipped.
Per app analytics
Each app gets its own view of how it is actually used, which is the number you want before renewing a contract.
Onboarding and offboarding overview
A single view of what is coming rather than what has already gone wrong.
The public API, first release
The public API ships with key and secret authentication using asymmetric keys built to rotate, and the first users endpoint.
Agent Cake coverage
New apps: Figma, Miro, OpenAI Platform, HubSpot and Zendesk.
Configure Auto-Provisioning yourself
Agent Cake moves out of engineering hands and onto a settings page. Auto-Provisioning has a configuration page, a detail view, a side panel summary and confirmation dialogs before anything is switched on.
Requests and tasks now show whether they will be provisioned automatically, in the web app and in Slack, so nobody does by hand what Agent Cake is about to do.
A failed configuration cancels its pending work instead of leaving tasks half done.
AI risk score on every app
Apps carry a risk level, surfaced in the tables and in app detail, so App Discovery sorts by exposure rather than alphabetically.
Microsoft as a source
Import apps and users from Microsoft as well as Google, with Microsoft SSO shown in the users and apps tables and available as a filter.
Apps imported from either source arrive as discovered rather than managed, so nothing is governed before somebody decides it should be.
Managed and unmanaged apps
An app can move between managed and unmanaged with the side effects handled, and unmanaged apps stay out of the catalogue.
Employees can request access to an app that is not managed yet, with the request prefilled.
Change my permissions
Employees can ask for a different permission level on an app they already have, rather than filing a fresh access request.
Agent Cake coverage
New apps: CloudTalk and 123erfasst.
The beginnings of Auto-Provisioning
This is the month Auto-Provisioning stops being a script somebody runs and starts being part of the product. An app gets a provisioning tab, with the endpoints behind it to create a configuration, read the active one and hold credentials safely.
Certifications and server locations
Apps carry their certifications and where their data is hosted, shown when a new app is requested, when an admin adds one and when one is updated.
A security review can be answered from the app record rather than from a spreadsheet.
Export and import
Export users to a file.
Import user access and custom fields from a spreadsheet, including apps by name, for companies moving in from another system.
Restyled detail views
User detail, app detail and task and request detail rebuilt around collapsible cards, so a long record is readable.
Agent Cake coverage
New app: ChatGPT.
Add a new app, as a request
Employees can ask for an app the company does not govern yet. It routes through approval like any other request, with its own task, review step and Slack notifications.
Approving it brings the app in with its certifications and data locations recorded, so a new app arrives governed rather than discovered months later.
Apps that were requested or rejected stay out of the catalogue until somebody decides otherwise.
Calculated custom fields
A custom field can derive its value rather than being typed, and a new field type carries the values it is allowed to take.
Custom fields can be used to decide who approves a request, so approval routing follows your own data.
Compliance data on apps
Certifications and server locations moved onto the app record in App Governance.
Custom fields drive approvals
Custom fields stop being decoration. A person custom field can decide who approves a request, so routing follows your own org data rather than a fixed rule.
Fields can be disabled with a reason, reordered by dragging, and edited on apps that were previously locked.
A field in use by a policy cannot be quietly edited out from under it.
Completing an account deletion task clears the person's record and their custom field values with it.
Offboarding conflicts
An offboarding checks for conflicts before it starts and surfaces them, rather than failing part way through.
A user cannot be deleted while they are the subject of an offboarding, or while they are the last person holding something.
Import from a spreadsheet
Import work apps and user access from a spreadsheet, with duplicates and mixed case emails handled rather than rejected.