Back to all releases
// October 2, 2026v1.35.0

Platform

Identity

Platform

The Access Hub is an organization-wide page, and trusted platforms and allowed machines are editable

Workload trust belongs to the organization, so the Access Hub now lives at the organization level, in the organization sidebar under Secure, for anyone holding workload:read or workload:write. Old project URLs redirect there. A trusted platform and each machine allowed under it can also be edited in place instead of being removed and re-registered, with every edit recorded in the audit log alongside the state before and after. Note the breaking change below if you call the saved-query API. More on how roles map to scopes in Roles and permissions.

Breaking changes

  • The explore saved-query service is removed — explore.listQueries, createQuery, updateQuery, and deleteQuery are gone; Explore saves through the new widgets service instead. The query:* audit actions and the audit_log.query_event_v1 webhook event are retired rather than removed: nothing emits them any more, but audit entries already written keep their labels and existing webhook subscriptions stay valid. (#7060, @subomi)

Features

  • The Access Hub is one organization-wide page — The Hub is at /<org>/access-hub, listed in the organization sidebar under Secure for anyone holding workload:read or workload:write, and old project URLs, including a trusted platform's page, redirect there keeping the issuer, query, and hash. The workloadIdentities API no longer needs a project when called from a dashboard session, which reads and writes the organization tier; API-key callers still name a project. (#7010, @aa-wong)
  • Edit a machine's allowed access in place — Each machine on a platform's page has an Edit action that opens the access form prefilled, so its label, tags, and assigned agent can be changed without removing and re-allowing it. The subject and its match kind stay fixed once access is allowed, reassigning the agent also applies to the same subject's access at the other tier, and each edit is recorded in the audit log with the machine's state before and after. (#7007, @aa-wong)
  • Edit a trusted platform in place — A platform's page has an Edit action that opens the registration form prefilled, where its name, description, tags, and JWKS URI can be changed. The issuer URL and the wildcard admission setting stay fixed once a platform is registered, and each edit is audited with the platform's state before and after. (#7005, @aa-wong)
  • The Access Hub reads more plainly — The page opens with a one-line summary of what it is for, each platform card shows only its name, description or issuer URL, and tags, and on a platform's page the issuer and keys URLs sit on labeled lines of their own. (#7004, @aa-wong)
  • Tailscale private access works on any plan once enabled — An organization enabled for Tailscale private access keeps it on any plan, instead of the dashboard warning that private access is no longer available after a move off Enterprise. (#7014, @TristanSpeakEasy)
  • List a project's chats from Platform MCP — A metadata-only list_chats tool lists one project's chats over a bounded window with masked participants, whether risk was present, timestamps, message counts, and opaque cursors. It never returns titles, message content, or raw identities, so an agent can find the conversation worth investigating without reading it. (#6857, @simplesagar)
  • Explore's saved questions become widgets — A widget keeps a question together with the chart that draws it, and the chart is checked against the question on save and again on read, so an impossible pairing fails visibly instead of rendering an empty frame. Any member can list, get, save, update, and duplicate a widget, and duplicating is how a widget is shared, giving the caller their own copy. Deleting someone else's widget needs project write access, and every change is audited. (#7058, @subomi)
  • Role plugins are prepared automatically for new organizations — A new organization gets a plugin created or reused for each application role, ready to configure for distribution rather than assembled by hand. An auto-created plugin is empty and non-default, exposes its origin, and never replaces an existing plugin's name, contents, or audiences. (#7041, @alx-xo)

Bug fixes

  • Plugin assignments follow a deleted role out — Deleting an organization or global role, including a directory-synced one, removes its plugin assignments, while assignments for other roles and organizations are left alone. (#7043, @alx-xo)
  • The catalog install's Guardrails step loses a redundant button — Switching the recommended policy off and adding the server already installs it without a guardrail, so the Skip for now button is gone. (#7012, @dennnis-ez)
  • Long toolset slugs resolve again — A stored slug longer than 40 characters is now accepted on lookup instead of being rejected as invalid. (#7066, @simplesagar)
Speakeasy Team
Speakeasy Team
View on GitHub