crewAI and legacy LangChain framework support — FireTail now detects AI usage in repositories built with the crewAI framework and legacy LangChain versions. If your teams use either of these frameworks, their AI footprint is now automatically discovered during repository analysis.
Expanded repository analysis query support — Repository analysis now supports additional query types, improving the breadth of AI usage patterns that can be detected in your code.
AI Discovery (Cloud)
New AI platform added to supported catalogue — An additional AI platform is now recognized by FireTail, expanding the range of cloud AI services that can be automatically discovered and monitored.
AI Discovery (Workforce)
Workforce identity discovery on endpoint devices — The endpoint agent now discovers AI provider account identities on devices and links them to workforce users, giving you more accurate attribution of who is using which AI services across your organization.
Enhanced ChatGPT detection for signed-in and anonymous users — ChatGPT usage is now consistently detected and logged regardless of whether the user is signed in or browsing anonymously, ensuring complete visibility into ChatGPT activity across your workforce.
Device agent version tracking — You can now see which version of the FireTail agent software is running on each device, making it easier to manage your fleet and ensure agents are up to date.
AI Logging (Workforce)
Blocked domain action logging in browser extension — The browser extension now logs blocked domain actions specifically, giving you more granular visibility into when domain-blocking policies are enforced.
Website log deduplication — A new debouncing mechanism reduces duplicate log entries for repeated requests to the same website, resulting in cleaner and more accurate workforce activity logs.
Improved header redaction — The endpoint agent now redacts additional sensitive tokens from request headers in workforce logs, strengthening data privacy.
AI Governance
Adaptive topic guardrails that learn from real usage — Topic guardrails now learn from real user prompts. When a prompt matches a topic guardrail, it is stored as a new example so the guardrail improves over time.
Custom topics for Prompt Intelligence — You can now define and manage custom topics for Prompt Intelligence, including automatic sub-topic generation and example embedding.
Topic risk scores for guardrails — Topic guardrails now support a risk score field, allowing you to assign and view risk levels for individual topics to better prioritize your governance response.
Allowed email domain restrictions for workforce policies — You can now configure allowed email domains per platform when creating or editing an AI Workforce Policy, restricting AI access to users with specific corporate email domains.
System topic policies automatically enforced — System topic policies are now automatically scheduled and enforced alongside AI workforce log policies.
Block guardrails now always take priority over inform guardrails — Guardrail evaluation now processes blocking guardrails before informational ones, ensuring enforcement actions are never skipped due to an earlier informational match.
Fixed policy merging bug that could cause incorrect enforcement — Fixed a bug where lower-priority policy capabilities could override higher-priority ones during policy merging.
Fixed device guardrails missing group and project assignments — Fixed an issue where devices did not receive guardrails assigned through the owning user's groups or projects.
Real-time topic updates on endpoint devices — Endpoint devices are now notified in real time when topic data changes, ensuring devices enforce policies using the latest topic definitions.
Sensitive content automatically masked in learned prompts — When user prompts are stored as topic examples for adaptive learning, sensitive content such as email addresses is now automatically masked before processing.
Improved long prompt handling for guardrail evaluation — The local embedding engine now splits long prompts into overlapping windows, so content beyond the model's input limit is no longer silently dropped.
Proxy, domain, and guardrail annotation support in browser extension — The browser extension now supports proxies, domains, and guardrail annotations, expanding enforcement support across more complex network environments.
Fixed clearing optional policy fields causing validation errors — Fixed an issue where clearing an optional text field (such as a user-facing message) in a policy caused a validation error instead of properly removing the value.
Posture Management
Google SecOps integration (preview) — You can now set up Google SecOps notification integrations from the integrations page. This feature is available as a preview.
General Improvements
Stacked navigation panels with breadcrumb trails — Panels now stack on top of each other when you explore related resources, with a breadcrumb trail and full browser back/forward support.
Clickable resource names throughout the platform — Resource names across audit logs, projects, devices, employees, topics, guardrails, and dashboards are now clickable and open the relevant detail panel in place.
Custom date range picker for dashboards — You can now select custom date ranges in dashboard time selectors with 10-minute granularity.
Filter findings and guardrails by name — You can now filter findings by specific finding names and search guardrails by name in filter dropdowns.
Filter suggestions for all resource types — Filter suggestions are now available across all resource types, making it easier to find and apply filters throughout the platform.
Visual quota progress bars — The Quotas page now displays color-coded progress bars showing your usage relative to your quota limits, with an improved responsive layout on large screens.
Distributor access management — You can now manage distributor access settings through a dedicated interface, with deployment support for both EU and US regions.
Domain allow-list validation improvements — Domain allow-lists for authentication providers are now more consistently validated and normalized, ensuring reliable enforcement across services.
Endpoint agent crash recovery on Windows and macOS — The endpoint agent now automatically recovers proxy settings after a crash on Windows, and the Windows installer also automatically restarts the agent service on crash for faster recovery.
Transparent (TUN-based) traffic interception on Windows — You can now choose between proxy-based and transparent (TUN-based) traffic interception modes during Windows installation.
Seamless Windows agent upgrades — The Windows installer now supports in-place upgrades, automatically preserving configuration, certificates, device identity, and tokens. A token is only required for fresh installs.
WSL2 CA certificate trust management — The endpoint agent can now install and remove its root CA in WSL2 distributions on Windows, ensuring TLS interception works correctly for clients running inside WSL2.
Improved macOS installer for managed deployments — The macOS installer now supports pre-generated CAs for MDM/RMM fleet deployments with improved trust verification, flexible configuration, and better error reporting for certificate-related issues.
macOS proxy compatibility improvement — The system proxy bypass list on macOS has been optimized to fit within platform size limits, improving compatibility with system proxy configurations.
Fixed agent starting with untrusted CA certificate — Fixed an issue where the agent could start intercepting HTTPS traffic without a properly trusted CA certificate.
Fixed agent crash loop without configured token — Fixed a crash loop that occurred when the agent started without a configured API key. The agent now waits for configuration and starts automatically once configured.
Improved skeleton loading and empty state guidance — Panels now show skeleton loading placeholders instead of blank content, and empty listings display helpful guidance messages.
Fixed model names truncated in PDF reports — Fixed an issue where model names were truncated in PDF reports. Full model names are now displayed.
Fixed audit log drawer navigation — Fixed an issue where the audit log drawer could not be opened from within other drawers.
Fixed devices not clickable in employee view — Fixed an issue where devices listed under an employee's Devices tab were not clickable. Clicking a device now opens its detail panel.
Stricter SCIM email uniqueness enforcement — SCIM user email uniqueness is now more strictly enforced, reducing the risk of duplicate user accounts.
Improved application startup performance — Several platform services now start faster by deferring loading of internal resources until they are needed.
Fixed several minor bugs and stability improvements — Addressed various minor issues across the platform to improve overall reliability and stability.
Discontinued features removed from API responses — Retrieving an organization's features now excludes discontinued features. If your integration relied on seeing discontinued features in the response, update your code accordingly.