Back to all releases

v1.19.3

Platform

// September 2, 2026

One page for every person and agent your organization has seen

The new Identities section gives each person and agent a single page that gathers their access, usage, security findings, cost, devices, and activity from every subsystem, whether or not they have an account on the platform. Every place the dashboard names a person now links there. The same release fixes per-user usage, which showed zero tokens and zero spend for anyone working through Claude Code or Codex while the cost dashboard billed them in full.

Features

  • Identities: a page per person and agent #5949 - Each project gains an Identities index of everyone the organization has seen, replacing Employee Enrollment (its old URL redirects). Each identity page answers one question per tab: Overview flags anyone working through a personal AI account rather than the team one, Usage filters by team or personal account class, Cost shows where the tokens went and what came from cache, Connections groups live MCP connections and the data-flow graph by server, and Activity plots the rhythm a row list cannot. Figures rank against peers for the same window. Names on budgets tables, project home top-user cards, chat transcripts, and killswitch detail are now real links to the identity, so they support cmd+click and copy-link. (Author: @adaam2)

Bug fixes

  • Per-user usage counts Claude Code and Codex #5949 - The per-user metrics summary read only the generic usage attributes, so anyone working through Claude Code or Codex showed zero tokens and zero spend. Both now count. Audit log actors resolve to names in the feed, its actor filter, and the admin activity list instead of reading as columns of email addresses, and resolution goes through the organization's memberships so an actor ID from another tenant never names a stranger. (Author: @adaam2)
  • Identity widgets honor the time range and admit failure #5949 - The audit trail, authorization challenges, and per-person shadow MCP servers now respect the selected time range instead of reading their whole history, with managed devices deliberately left outside it as a current inventory. A panel whose request failed says so and offers a retry instead of reporting "no roles assigned" or "not enrolled" off data that never arrived, and the Cost and Usage tiles show a dash rather than $0 when metrics fail to load. Authorization challenges now key on the identifier the authorization engine records, so the panel no longer reports a clean history for people who may not have one. (Author: @adaam2)
Sagar Batchu
Sagar Batchu
View on GitHub