WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Quick Start
User Guide
User Guide
Policies - GuardRails
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Anywhere: Remote Device Security
Witness Attack
Witness Attack
Administrator Guide
Administrator Guide
404
404
WitnessAI Release: July 09, 2026
Note: New and updated features may not be immediately available on your dedicated deployment due to participation in limited availability releases, beta programs, or regional configurations.
If you don't see a feature you expect, please reach out to Customer Success. We're happy to help!
New Features
Glean Support
Glean is now supported. Prompts, responses, and tool calls are captured, and displayed in the Conversations console. When tool calls are captured, they will appear on the Discovery console, under the Agents tab.
Kiro IDE Support
Kiro is now supported on browser, CLI, and IDE. Prompts, responses, and tool calls are captured, and displayed in the Conversations console. When tool calls are captured, they will appear on the Discovery console, under the Agents tab. Witness Anywhere does not yet support Kiro CLI.
ChatGPT Desktop Client for macOS
The ChatGPT macOS desktop application is now supported, including policy controls and file attachment visibility.
OpenCode with Claude Model Support
OpenCode is now supported for Claude models. Prompts, responses, and tool calls are captured, and displayed in the Conversations console. When tool calls are captured, they will appear on the Discovery console, under the Agents tab. Witness Anywhere does not yet support Opencode Desktop and CLI.
Codex API Login Session Traffic Capture
Traffic generated from Codex sessions authenticated via API Login is now captured and subject to policy enforcement.
Gemini Enterprise Differentiation
Gemini Enterprise is now tracked and displayed separately from personal Gemini traffic. Gemini Enterprise appears as its own entry in the App Catalog.
Feature Updates
Claude Plugin for Microsoft Office Support
The Claude plugin for Office has been added to the App Catalog, making its traffic distinguishable from personal Claude usage. Admins gain dedicated visibility and the ability to apply separate policy controls to Claude-in-Office activity.
ChatGPT Office Add-In Classification
ChatGPT Microsoft Office personal and enterprise add-ins are now supported, and tracked independently in the console.
Claude Team Support
Claude Team is now supported.
Agentic Sessions: Most-Severe Action Surfaced
The conversation view for agentic sessions now surfaces the most severe policy action recorded for each round-trip, giving admins a clearer picture of policy outcomes without having to inspect each step individually.
MCP Servers Table: RBAC-Gated Controls
The MCP Servers table now provides role-based access control (RBAC) on action buttons and policy copy options, ensuring only authorized users can modify MCP server configuration.
Registration Scripts: Persistent Proxy Enforcement
Witness Anywhere registration scripts now enforce proxy settings for Codex, Claude, and Cursor on each script run, ensuring proxy coverage is maintained even if settings are changed between runs.
Windows Device Registration: ADSI Fallback
Device registration on Windows now falls back to ADSI for email resolution when primary resolution methods are unavailable, improving registration reliability in complex Active Directory environments.
Performance, Reliability, & API Updates
No performance, reliability, & api updates in this release.
Fixed Issues
Policy Enforcement
- Custom block messages and the user's prompt were disappearing after a few seconds in Claude when a DLP guardrail blocked the content. This is now fixed.
- Warnings were incorrectly triggered for managed prompt attachments when the Inspect option was disabled. This is now fixed.
- Gemini Enterprise Route decisions were being downgraded to warnings instead of being applied as routing actions. This is now fixed.
Proxy and Traffic Capture
- Visual Studio Code inline mode was generating duplicate DLP warning and block alerts for the same event. This is now fixed.
- Warning messages were not appearing in Google Docs and Google Sheets responses. This is now fixed.
- OpenAI prompts were being captured but responses were not. This is now fixed.
- Responses in PowerPoint thick client were not displaying or took an unusually long time to appear. This is now fixed.
- SharePoint and Microsoft Graph traffic was being routed through the parser for all endpoints, not just actual upload endpoints. Routing is now correctly scoped.
Console and Alerts
- The Alerts page was failing to load in certain cases. This is now fixed.
- Blocked prompts were not visible in the Alerts view when "enhanced context for agentic" was enabled. This is now fixed.
Identity and Directory
- Group syncs from WorkOS were creating multiple groups with the same name. This is now fixed.
- MCP Servers showed no data in the Discovery view. This is now fixed.
Installation and Deployment
- KACE and WSOne macOS registration scripts were sending malformed emails when staticDomain was not configured. This is now fixed.
Security
- Fixed a vulnerability that allowed unauthorized download of the proxy configuration file, which could expose authentication tokens.
- Fixed a prompt injection vulnerability that could be exploited through GBNF grammar-based injection via intention names.
Known Issues
No known issues in this release.
Breaking Changes
No breaking changes in this release.
Please contact Customer Success if you have questions or need support with this release.