September 2026 Release Notes

Arthur Platform

Governance & Access Control

  • Governance Reader role. New role with read-only access to the entire organization policy catalog at any binding level (organization, workspace, or project), replacing the retired Organization Policy Reader role with automatic binding migration.
  • Governance Operator role. New role enabling application operators to re-run compliance checks and sign attestations while inheriting all Governance Reader permissions; bindable at organization, workspace, or project scope.
  • Project Operator role. New project-scoped role for managing alert rules, dashboards, and job scheduling independently from guardrail rule authoring.
  • Organization Governance Admin permissions. Fixed workspace-scoped access so Organization Governance Admins can properly view Discovery, policy compliance Checks, Tools, and LLM Models across all workspaces.
  • Workspace Program Manager access. Fixed global scope accessibility and task state visibility so Workspace Program Managers can access governance scope across applications and evals contexts without unnecessary permission barriers.
  • Workspace binding authorization. Extended workspace binding authorization to the organization level, ensuring proper permission inheritance and validation across the organizational hierarchy.
  • Role-assignment user picker. Now displays two-line rows with display name and email (or client ID for service accounts), with a "Service account" chip to prevent accidental role grants.
  • Discovery catalog access restriction. Removed discovery catalog read permissions from Governance Reader, restricting access to Organization Admin, Super Admin, and Governance Admin roles.
  • Microsoft Entra ID integration guide. Added a comprehensive OIDC customer IdP guide covering app registration, token configuration, claims mapping, and group-based RBAC.

Agent Discovery

  • Discovery Source configuration. New Agent Discovery interface with vendor-grouped sidebar navigation for creating, editing, and managing discovery sources, including inline connection settings and extensible input adapters.
  • Discovery scheduler. Background scheduler that automatically enqueues scan jobs on each engine according to a configurable cadence, with a manual Scan Now trigger for on-demand execution.
  • Credential management. Secure credential storage and retrieval for Discovery sources using AWS Secrets Manager or an encrypted database backend, with gated API access for ML Engine workers.
  • Discovery runs and storage. Platform storage layer and REST APIs for persisting terminal Discovery attempt outcomes, contributions, error codes, denied scopes, and source metadata with permission-gated history endpoints.
  • FETCH_DISCOVERED_AGENTS job. New job kind enabling autonomous 24-hour periodic fetching of discovered agents per source/engine pair on the discovery scheduler.
  • Jamf Pro connector. Real credential schema (base_url, client_id, client_secret) with optional include_groups and exclude_groups fields to scope discovered computers by smart or static group names.
  • Multi-sensor evidence model. Extended Agents API to hold reports from multiple sensors via a new agent_evidence child table with source tracking and a scalar provenance field for agent location data.
  • Agent ingestion resilience. The PUT agents endpoint now validates and stores each agent independently, returning a rejected field for invalid agents instead of rejecting the entire batch.
  • Organization-level data plane listing. New endpoint enabling Global Discovery to select engines across all workspaces within an organization, with paginated results, name and capability filters, and role-based access control.

Policy & Compliance

  • Policy dashboards. Fixed broken policy dashboards caused by improperly configured alert rules erroring during job execution; added alert rule validation and failure tracking so errors surface to users instead of failing silently.
  • Outside count and bulk assignment deletion. Added visibility into apps outside workspace count and introduced bulk assignment deletion with an enhanced delete policy modal.
  • Attestation history. Added a read-only attestation history view within the governance policy detail modal for complete visibility into attestation records.
  • Policy filter visibility. Policy list status and model filters now respect application visibility settings, ensuring users only see filters for applications they have access to.
  • Organization Governance Admin read-only app access. Org Governance Admins can now open and audit applications from a policy's view in a restricted, read-only interface covering configuration, evaluations, guardrails, alerts, and activity logs.
  • Alert rule Test button gating. The Test button on the policy alert-rule page is now gated behind the rule-update permission, preventing read-only viewers from triggering unauthorized model metrics queries.

Alerting & Monitoring

  • 5-minute minimum alert interval. Enforced across all alert configuration surfaces including application and policy alert creation, editing, and testing; existing sub-five-minute rules are migrated automatically.
  • Alert chart preview accuracy. Fixed alert chart previews in Run Test to display only completed historical buckets, excluding unfinished current and future buckets for accurate metrics visualization.
  • Job Queue Depth metrics. Added CloudWatch custom metrics for job queue depth, emitting a QueuedJobs metric every 15 seconds to the Arthur/Scope/Jobs namespace; enabled in production.
  • Monitoring dashboard fixes. Fixed production deploy failures caused by a missing region property in the Job Queue Depth widget and a stale log group SOURCE clause causing ResourceNotFoundException errors.
  • Alerts page performance. The alerts timeline endpoint now uses correlated min() subqueries for O(1) index-only lookups, reducing timeline request latency from 1–8 seconds to under 1 second.

AI SDK & Model Integrations

  • Ultrafast service tier. Upgraded AI SDK to support the ultrafast service tier for OpenAI Responses API image generation.
  • Batch image generation. Added support for image generation requests in batches with improved handling of unsupported batch request types.
  • OpenAI batch management. Added support for batch cancellation and listing capabilities through the AI SDK.
  • New OpenAI models. Added support for gpt-6-astra, gpt-4o-transcribe-diarize, and new GPT Image model IDs.
  • Governance Operator evaluation capabilities. Added experimental evaluation capabilities for Choice, Score, and Boolean evaluations via openai.evaluationModel().
  • OpenAI SDK upgrade. Updated from v6.45.0 to v7.15.0, unlocking the Agents API, Live API, and API key expiration controls.
  • Keycloak mobile fix. Updated keycloak-js to v26.2.4, fixing two Cordova adapter regressions that caused duplicate authentication requests or "Web page not available" errors during mobile login.

Platform Reliability & Infrastructure

  • Ledger write validation. Fixed a critical bug where failed ledger writes could be reported as successful on empty HTTP responses; the system now explicitly validates the presence of an id field.
  • SpiceDB connection stability. Raised SpiceDB gRPC max connection age to one year on AWS ECS, eliminating transient RPC failures from premature connection closure on long-lived clients.
  • PostgreSQL shared memory. Set shared memory to 1 GB on the PostgreSQL service, allowing parallel queries over large tables to run reliably without out-of-shared-memory errors.
  • Nexus registry deprecation. Deprecated the self-hosted docker.arthur.ai Nexus registry; images now publish exclusively to ECR (dev) and Docker Hub (release).
  • Upsolve dashboard export. Bumped Upsolve v1 on-prem image to 0.4.40, enabling the latestVersionsOnly export parameter for slim, re-importable dashboard files.
  • Data fetching completeness. Refactored data fetching to eliminate page size limits, so alert counts, compliance job assignments, and other paginated lists display complete datasets.
  • Renovate-Autofix safeguards. Added a heavy label for excluding complex MRs from auto-fix, branch head SHA deduplication, and a persistent retry budget to eliminate wasteful retry loops.
  • Discovery terminology alignment. Aligned API descriptions and documentation with the new discovery glossary, standardizing terms across the platform with no field or route renames.

Bug Fixes

  • Fixed authorization checks in assignment and analytics query paths so users can only read data for applications within their authorized scope.
  • Fixed broken policy dashboards caused by erroring alert rules preventing compliance checks from completing.
  • Fixed the outside count guard logic to prevent deletion of policies that have external assignments.
  • Fixed frontend TypeErrors when viewing unregistered agents and infrastructure information caused by breaking backend agents infrastructure changes.
  • Fixed discovery source scan jobs to snapshot non-sensitive source fields into job configuration, eliminating 404 errors when engines read sources with insufficient permissions.
  • Removed redundant policies fallback logic from the usePolicies hook following the permissions refactor.

Arthur Engine & Toolkit

Alerting & Compliance

  • ALERT_CHECK null handling. Fixed a critical crash when processing NULL or non-numeric metric values; all-NULL buckets are now classified as NO_DATA so alerts and the compliance chain remain intact.
  • Compliance check ordering. Reordered the alert check job to run compliance checks before alert reporting, allowing validation to proceed for successful rules even when others fail, with errored rule IDs surfaced for downstream processing.

Evaluations & Trace Filtering

  • Continuous eval deep link fix. Fixed the Create button remaining disabled when Evaluator and Version were pre-filled via URL by initializing eval_type as llm_as_a_judge in LLM deep links.
  • Test Prompt dialog layout. Resolved a layout issue where content was cut off without scrolling, giving the form, alerts, and results a shared vertical scroll region.
  • Trace filter session ID. Pasted session IDs are now automatically converted to chips without requiring an explicit "+" click, and filters apply correctly via the Apply Filters button.

ML Engine & Datasets

  • Filesystem instance isolation. Fixed a critical bug where fsspec filesystem instances were shared across jobs, causing stale listing caches for GCS, S3, and Azure Blob connectors; each job now gets a fresh instance.
  • Unified dataset model. Consolidated dual dataset handling into a single dataset model across genai-engine and ml-engine services, simplifying repository and service-layer implementations.

Observability SDK

  • Instrumentor verification. Verified all instrumentors against real published packages and removed 7 broken declarations referencing wrong class names or missing exports; all 33 shipped instrumentors are now confirmed functional.
  • GenAI Engine API key limit. Added genaiEngineMaxApiKeys as a configurable Helm chart value, letting operators set the API key limit directly in values.yaml.

Developer Tooling & CI

  • Renovate observability. Enabled the Renovate auto-fixer to emit Arthur Engine traces, making Claude Code prompts, tool calls, and completions observable and correlated by PR number.
  • Model upload vulnerability scanning. Added build-time vulnerability scanning for model-upload images so security alerts refresh within minutes of a rebuild.
  • models-gcs rebuild gating. Gated the models-gcs image rebuild behind an inputs-changed check, avoiding redundant rebuilds of the 7.25 GB image on version-only bumps.
  • TypeScript upgrade. Updated to v6.0.3, removing deprecated baseUrl from tsconfig and future-proofing for TypeScript 7.
  • ESLint upgrade. Updated ESLint monorepo to v10, swapping eslint-plugin-import for eslint-plugin-import-x.
  • zod upgrade. Updated to v4.5.x, adding pre-compiled schemas via z.compile() for 2–7x faster parsing, new validation utilities, and reduced memory footprint.
  • react-router upgrade. Updated to v8.3.1 with fixes for fetcher abort handling, scroll restoration, route matching performance, and action request origin validation.

Bug Fixes

  • Fixed AttributeError raised by broken instrumentor declarations in arthur-observability-sdk[all].
  • Fixed the Create button remaining disabled in Continuous Eval when form fields were pre-populated via URL deep link.
  • Fixed stale fsspec listing caches persisting across jobs after cloud-backed dataset files were deleted or moved.