Changelog
Every new feature, improvement, and fix in Sim, the open-source AI workspace, with release notes straight from GitHub.
Features
- feat(library): What Is Human-in-the-Loop in AI Agents?
- feat(providers): add Gemini 3.8 Flash
Bug Fixes
- fix(deployments): retire inactive-version side effects by row with bounded outbox continuation
- fix(slack): disclose paid plan requirement
- fix(docs): hide unreleased table expiration
Other Changes
- chore(legal): clarify DPF certification scope
Features
- feat(workflows): expose authenticated run subjects
- feat(credential-groups): add personal MCP OAuth connections
Improvements
- improvement(docs): streamline API reference navigation
Bug Fixes
- fix(billing): coerce COST_MULTIPLIER to a number before sandbox pricing
- fix(desktop): harden update and quit flows
- fix(agent): ignore empty advanced MCP bindings
- fix(agent): move advanced MCP option to bottom
- fix(workflow): preserve canvas and deploy modal behavior
- fix(files): index generated docs without compiling and fix the docx sandbox bundle
- fix(monday): support OAuth 2.1
- fix(execution): keep terminal reconnect off runs a Sim run tool owns
Other Changes
- chore(skills): remove dated patterns and redundancy from skill prompts
Features
- feat(tools): run one integration tool over v2, and fix the ones that could not be run
- feat(resources): remember list preferences
- feat(credential-groups): add event trigger
- feat(models): add Claude Fable 5.1 and align Anthropic prompt-cache minimums
- feat(file): search workspace files by regular expression
- feat(ashby): expand hiring operations and webhooks
- feat(library): Sim: The Open Source Zapier Alternative for AI Agents
- feat(sidebar): live workflow and folder registry updates via workspace-workflows room
- feat(permission-groups): enforce every config key server-side
- feat(slack): list DMs for managed credentials
- feat(streaming): support nested workflow outputs
- feat(copilot): let Run agent cancel workflow runs
- feat(sailpoint): add SailPoint (IGA) integration
- feat(slack): add agent sessions and streaming
- feat(circleback): add API tools, expanded block, and knowledge base connector
- feat(library): Sim vs. Dedicated Chatbot Builders
- feat(workspace): support GIF logos
- feat(sso): add safe member provisioning
- feat(files): add an overwrite option to file write
- feat(library): Best AI Agents for Lead Enrichment in 2026
- feat(files): add workspace content search
- feat(tables): trigger workflows on row deletes
- feat(tables): add automatic row expiration with TTL
- feat(billing): track E2B and Daytona Function sandbox usage
- feat(library): AI Agents for Marketing Automation: Building Agentic Workflows Beyond HubSpot and Zapier
- feat(admin): move a workspace between organizations
- feat(function): mount referenced files into the code sandbox
Improvements
- perf(tests): trim sweep, copilot, and timer-bound suites; run three CI shards
- perf(tests): drop dead upload-context re-exports and unify the CI dummy key
- perf(tests): cut per-file import graphs in apps/sim and shard the suite across CI runners
- improvement(audits): eliminate repeated parsing and scans
- improvement(deps): harden dependency graph
- improvement(integrations): refine Slack AEO content
- improvement(oauth): resolve credential tokens in-process instead of hopping the token route
- improvement(integrations): add Twilio SMS AEO content
- improvement(desktop): harden browser agent
- improvement(settings): accelerate navigation and data loading
- improvement(ui): move secret visibility below description
- improvement(selectors): unify server-side selector execution
- improvement(integrations): refresh Slack integration page SEO copy
- refactor(tables): add column type extension points
Bug Fixes
- fix(selectors): expose incomplete loaded catalogs
- fix(slack): paginate selector resources
- fix(deps): preserve runtime and canvas behavior
- fix(confluence): normalize space identifiers
- fix(selectors): paginate HubSpot owner options
- fix(selectors): close residual cancellation gaps
- fix(cloudwatch): paginate log selectors
- fix(selectors): drain Snowflake result partitions
- fix(tool-input): render every tool param through the canonical sub-block renderer
- fix(canvas): repair React Flow v12 and dependency upgrade regressions
- fix(docker): allow pruned lockfile normalization
- fix(sailpoint): complete integration validation
- fix(slack): restore assistant operation compatibility
- fix(webflow): paginate collection item selectors
- fix(execution): stop treating the workflow owner as a live execution identity
- fix(selectors): paginate BigQuery resources
- fix(selectors): paginate SharePoint sites and lists
- fix(workflows): preserve contrast on gradient tiles
- fix(tables): make the agent tool picker version-aware and enrich the v2 query
- fix(cron): derive async job retention cutoffs from one clock read
- fix(files): bound YAML expansion and buffered reads on the file-serve path
- fix(selectors): paginate HubSpot list options
- fix(notion): resolve custom page title properties
- fix(selectors): normalize Bitbucket workspace UUIDs
- fix(settings): restore SSO recovery and lifecycle test isolation
- fix(executor): stop resolved data from breaking out of generated condition and function code
- fix(auth): revoke stale email share access
- fix(egress): unify SSRF/egress behind one policy with named provenance profiles
- fix(github): make branch protection usable and wire workflow_id to its endpoint
- fix(okta): describe each user param the way its endpoint accepts it
- fix(incidentio): align declared outputs and enum hints with the v2 API
- fix(workflows): authorize paused execution reads
- fix(chat): scope selection clipboard chips to workspace
- fix(connectors): keep rate limits out of failure breaker
- fix(tables): run workflow groups from deployments
- fix(tables): harden timezone and expiration handling
- fix(github): wire the block fields whose ids do not match their tool params
- fix(files): dispatch search indexing from Trigger workers
- fix(admin): report a completed workspace move's true source and its credentials
- fix(sandbox): spend each file ceiling once across every source
- fix(charts): strip ECharts navigation sinks from .chart documents
- fix(helm): bump chart appVersion to the release it ships with
- fix(elasticsearch): resolve Cloud IDs to the real host and correct the integration's output, timeout, and redirect defects
- fix(timezone): consolidate table wall-clock conversion
- fix(provenance): let a run that never started report why it failed
- fix(credential-groups): stop requiring a human subject on workflow ops
Other Changes
- chore(skills): teach babysit about cubic, not just Greptile
- chore(api): remove unused and superseded API routes
- chore(analytics): remove Profound request tracking
- chore(copilot): sync mothership contracts
- chore(security): add proxy rate-limit regression coverage
Bug Fixes
- fix(ci): treat an unreadable cache size as unstable when settling
- fix(browser): harden desktop tool lifecycle
- fix(connectors): stop hydration after rate limits
- fix(ci): stop the layer-cache prune from being able to fail a build
- fix(ci): actually prune the BuildKit layer cache
Other Changes
- test(tools): type the path-safety harnesses instead of erasing with any
- docs(library): update automation-anywhere-alternative
- docs(library): update what-is-an-ai-agent-definition-how-it-works-and-examples
- chore(docs): remove i18n and the five translated locales
Features
- feat(library): Best AI Agents for Slack
- feat(credential-groups): add seventeen OAuth providers
- feat(secrets): reveal visible values to members
- feat(integrations): add Dynamics 365 CRM
- feat(observability): record Redis connection state on failed slot operations
- feat(lambda): add AWS Lambda integration with 50 operations
Improvements
- improvement(ui): soften overflow fade
- improvement(ui): consolidate fade-only overflow
- improvement(usage): add a period-labelled chart to the workspace drill-down
- improvement(tools): retire direct execution
Bug Fixes
- fix(secrets): preserve caret when revealing values
- fix(integrations): validate runtime values the type system only claims to constrain
- fix(lambda): close the remaining contract validation gaps
- fix(dataverse): harden OAuth connection preflight
- fix(execution): release the lease when abort races an undetermined acquisition
- fix(ui): prevent competing sidebar tooltips
- fix(executor): preserve actors for actorless tool calls
- fix(guardrails): route PII validation through app runtime
- fix(execution): treat an undetermined lease as a fallback, not a denial
- fix(knowledge): classify rejected BYOK embedding keys
- fix(logs): prevent dashboard horizontal scrolling
- fix(canvas): show full Agent prompt tooltips
- fix(workflow): stop requiring a human subject on actorless runs
- fix(enterprise): verify invited owner on acceptance
- fix(pricing): correct free-tier credits as one-time, not monthly
Other Changes
- docs(library): update best-ai-agent-builder-2026
- chore(docs): refresh introduction screenshot
- chore(skills): name directExecution as retired in the add-integration checklist
Improvements
- improvement(ci): bound the local Turborepo cache
- improvement(ci): scan CodeQL PRs at the promotion boundary, refresh main daily
- improvement(background): right-size the two knowledge task machines
- improvement(ci): bound docker layer caches and right-size ten runners
- improvement(api): retire route contracts that no route serves
Bug Fixes
- fix(connectors): honor provider retry deadlines
Features
- feat(files): find in an open markdown document with Cmd/Ctrl+F
- feat(usage): add enterprise organization usage monitoring
- feat(mcp): add Codex client configuration
Improvements
- improvement(usage): drop the segmented allowance meter from the usage summary
- improvement(tools): prevent internal request self-hops
- improvement(files): fill the active find match instead of ringing it
- improvement(tables): simplify column dropdown
- improvement(config): gate feature flags by workspace id
- refactor(tools): execute internal operations in process
Bug Fixes
- fix(copilot): say whether a withheld tool call changed anything
- fix: six pre-existing integration defects surfaced by the docs audit
- fix(usage): correct chart clipping, expand truncated rows, add source mix
- fix(docs): stop publishing unsettable params, fix comment blanking
- fix(storage): stop workspace ledger locks from deadlocking on FK key-share
- fix(workflows): authorize automated runs by deployment
Other Changes
- docs(library): update openai-vs-n8n-vs-sim
- docs(usage-tracking): refresh the overview screenshot and correct two stale facts
- docs(library): update ai-agent-vs-chatbot
- docs(library): update what-is-an-mcp-server
- chore(docs): refresh product screenshots
- chore(db): drop orphaned import_* columns from user_table_definitions
Features
- feat(resource-policies): add credential group access policies
- feat(workflows): preserve execution principals
- feat(tinyfish): add TinyFish web agent, search, and fetch integration
- feat(chat): add live voice input waveform
- feat(desktop,cli): support self-hosted desktop installs
- feat(library): Best Dify Alternatives in 2026
Improvements
- improvement(ui): standardize overflow text
- improvement(db): stop declaring retired usage columns ahead of their drop
- improvement(blocks): document child workflow deployment behavior
- improvement(canvas): improve code tooltip readability
- refactor(billing): retire protocol rollout flags
- improvement(cli): automate npm package version bumps
Bug Fixes
- fix(cli): seven defects found by live-testing the CLI against staging
- fix(provenance): derive final-output provenance instead of declaring it unvouchable
- fix(files): fix large file editor performance and selection toolbar placement
- fix(ui): tighten resource header action spacing
- fix(desktop): harden browser and runtime hygiene
- fix(credentials): write an env value and its credential row together
- fix(execution): make function runs rollout-safe
- fix(copilot): scope panel chat drafts per chat
- fix(cli): refuse what the help already says is invalid
- fix(ui): close paste admission edge cases
- fix(chat): guide blocked browser microphone access
- fix(mistral): distinguish response size failures
- fix(landing): reset unmeasurable preview stages
- fix(ui): optimize universal paste handling
- fix(ui): preserve resource view collapse state
- fix(copilot): persist workflow drafts across navigation
- fix(desktop-browser): add recoverable page failure states
- fix(landing): normalize typography weights
- fix(cli): close follow-up gaps
- fix(landing): harden cross-browser compatibility
- fix(knowledge): harden OCR and SharePoint ingestion limits
- fix(landing): stabilize previews across browsers
- fix(v2,cli): second audit pass over the v2 API and CLI
- fix(knowledge): stabilize skipped connector documents
- fix(fireflies): handle nullable transcript metadata
- fix(sandbox): upgrade isolated-vm to 6.2.0
Other Changes
- chore(copilot): sync load_slide_layout into the tool catalog
- docs(self-hosting): correct what a server change clears, and the cert requirement
- docs(blog): update enterprise
Features
- feat(api): publish agent tool input schema
- feat(providers): add GLM-5.3 and GLM-5.3-Flash to Z.ai
- feat(credential-groups): add Atlassian OAuth and invite links
- feat(integrations): add Microsoft Word
- feat(integrations): add Semrush
- feat(slack): launch v2 triggers and backfill custom bots
- feat(api): make the platform operable headless over v2
- feat(library): Best Multi-Agent Frameworks for Production in 2026
Improvements
- improvement(cli): clarify npm package readmes
- improvement(billing): replace daily refresh credits with weekly refresh
- improvement(db): finish workspace file size cutover
- improvement(billing): paginate and parallelize the cycle-close sweep
- improvement(billing): ledger-only usage + period-advance cycle close
- improvement(access-control): wire tool and model permissions into copilot editing
- improvement(tools): tell the model which duplicate tool instance is which
- improvement(privacy): add Data Privacy Framework disclosures
- improvement(workflow): add compact code hover previews
- improvement(tools): support duplicate provider instances
- refactor: remove dead code, orphan modules, and two unused dependencies
- refactor: consolidate three drifted copies, close a gate blind spot, fix stale docs
- refactor: remove dead orchestration entry points and no-op tests
Bug Fixes
- fix(db): harden workspace file size cutover
- fix(tools): extend the transport-deadline disarm to the Node workers
- fix(cli): exit after interactive secret input
- fix(landing): restore section heading weight
- fix(landing): stabilize platform preview motion
- fix(landing): refresh sidebars across landing surface
- fix(landing): refresh workspace sidebar preview
- fix(chat): conceal a missing deployment the way an unreachable one is
- fix(integrations): repair broken endpoints, silent failures, and a path traversal
- fix(v2): stop six responses reporting less than the layer beneath them knew
- fix(docs): validate generated API navigation
- fix(custom-blocks): restore self-host entitlement gate
- fix(microsoft-word): make conditional writes service-enforced and return 400 for bad input
- fix(chat): prioritize workflows across resource menus
- fix(security): require explicit trust for internal tool routes
- fix(cli): correct three descriptions the CLI publishes, and restore --no-recursive
- fix(docs): correct two statements that contradict what they describe
- fix(cli): resolve blockers and majors from a full command-surface audit
- fix(knowledge): harden ingestion pipeline
- fix(workflow): highlight references in code previews
- fix(provenance): classify a latched-but-empty registry's file writes as unrecorded
- fix(copilot): name a count-parallel's branch count
countin the model's read view - fix(tables): prevent truncated sandbox mounts
- fix(sse): rotate workspace streams without gaps
- fix(sse): bound workspace SSE connection lifetime
- fix(ui): unify branded error pages
- fix(memory): close app-service leak paths behind the per-task memory ramp
Other Changes
- chore(tools): correct the bindable-subblock rationale
- chore(flags): remove released feature gates
- chore(skills): drop Cursor Bugbot from the babysit review loop
Features
- feat(setup): add incremental Chat setup
- feat(secrets): let workspace secrets opt out of redaction
- feat(tables): confirm view deletion
Improvements
- refactor: remove five more dead prop chains
- refactor(renderer): drop the isWorkflowRunning prop the views never read
- improvement(provenance): attribute stored-envelope display reads to their execution
- improvement(ui): standardize modal default actions
- refactor: delete code nothing reaches
- refactor(utils): add slugify and adopt it at the eight sites that hand-rolled it
- refactor: replace hand-rolled utilities and dead code with the shared forms
- perf(db): optimize recurring query paths
- improvement(provenance): aggregate and attribute unrecorded durable reads
- improvement(chat): speed up conversation navigation
- improvement(pricing): list Sandboxes as a Max and Enterprise feature
Bug Fixes
- fix(copilot): show custom block names in read tool rows
- fix(consent): enforce consent-aware analytics
- fix(ci): make the utils gate see the wrapped forms of what it bans
- fix(oauth): bind update access to selected credential
- fix(webhooks): requeue deliveries dropped by retryable setup infrastructure failures
- fix(vllm): support LM Studio endpoints
- fix(files): normalize encoded embedded ids
- fix(ci): give push builds a base their audits can actually read
- fix(workflow): hide idle nested subflow end handles
- fix(ci): require a default export before treating a file as a route entry
- fix(ci): stop failing the API audit for adding a compliant route
- fix(ci): walk every route entry the workspace app composes, not just pages and layouts
- fix(react-query): close the lint's blind spots, and the drift they hid
- fix: surface an unbilled run, and clamp the google-docs page cap
- fix(settings): report a failed settings write instead of reporting success
- fix(ci): stop the migration safety audit from passing on a branch it never read
- fix(api): withhold internal failure messages from internal route responses
- fix(files): download a markdown file as a zip only when it really has assets
- fix(files): allowlist the schemes a markdown link may target
- fix(settings): keep billing header stable
Other Changes
- chore(legal): update privacy policy
- chore(lint): turn on the rules that would have caught the dead code