Back to all releases
// October 7, 2026v1.37.3

Platform

Identity

Assistants get their own agent identity, with dedicated permissions to match

An assistant's tool calls and audit trail used to be attributed to whoever set it up or talked to it. In organizations with agent identity credentials enabled, a new assistant now gets its own dedicated agent, so its activity shows up under its own name, with its own policy, and can be suspended or transferred independently of any person. Existing assistants keep working exactly as before until an admin explicitly upgrades them. Assistant access also moves onto its own assistant:read/assistant:write permissions instead of riding along with project:*, and the Team Access tab can now explain, for any member, exactly why they can or can't reach a given MCP server. More on this in Agent identity and Roles and permissions.

Features

  • Give an assistant its own agent identity — An assistant's Identity tab can set it up with a new agent you name or an existing agent of the project you own or can authorize, starting with access to every MCP server and skill in the assistant's project. The agent can be renamed, transferred, or narrowed like any other agent, and deleting the assistant withdraws its trigger workload identities while leaving the agent in place. The upgrade endpoint and the Platform MCP upgrade tool accept the same choice. (#7107, @danielkov; #7079, @danielkov)
  • Assistant access gets its own permissions — Dedicated assistant:read and assistant:write scopes replace the old reliance on project:*, which no longer opens assistants on its own. Grants can cover every assistant, every assistant in selected projects, or a single assistant, and agent policies can hold them too. Admins keep full access and members keep read access by default. (#4899, @danielkov)
  • See exactly why a member can or can't reach a server — The MCP server Team Access tab gains a Check access section: pick a member to see whether they can connect to, view, and manage the server, and which rule decides it, including the directory role mapping behind a role for organization admins. (#7095, @bflad)
  • A blocked server no longer blocks every server — Fixed a bug where blocking one MCP server for an agent-backed assistant turn removed access to every MCP server on that turn instead of just the blocked one. (#7202, @danielkov)
Sagar Batchu
Sagar Batchu
View on GitHub