Shipping notes from the emisar team. Subscribe via
RSS
or watch the
GitHub repo
.
Sandboxed agents and clearer account pages
v0.48.0
Connect AI agents through co:op, Docker Sandboxes, nono, or Dev Containers from one Console flow. The generated setup stays with the account-specific key, while one guide compares supported agents and explains what each sandbox can still access. Billing now uses clearer invoice states and a more responsive layout, and update notices make required action stand out without turning optional upgrades into warnings.
Console
Connect an agent now includes complete, account-specific setup for co:op, Docker Sandboxes, nono, and Dev Containers, followed by one connection test and an Audit check.
Billing management is easier to find, invoice states are clearer, and paid workspaces without invoices now show an explicit empty state.
Runner and MCP version indicators keep optional updates quiet, distinguish required updates, and provide the relevant update command where you need it.
Security
The agent-sandbox guide compares what each option can still reach, including shared project files, credentials, host tools, and network destinations. co:op is recommended for most local setups.
Website
Four separate sandbox pages are now one task-first guide with a shared connection path, supported-agent comparison, and provider-specific recommendations and risks.
Shared visibility and clearer reviews
v0.47.0
Operational roles can now inspect workspace-wide runners, packs, approvals, runbooks, and run history. Actions still require current runner and pack access. Console runbook starts stay bound to the release and plan you reviewed; a changed plan requires another review. Console pages also have simpler guidance, consistent filters, and clearer recovery when something goes wrong.
Console
SSO groups now show role, runner, and pack access together. Edit roles in place, add access beyond locked connection defaults, and filter members by group without leaving the provider page.
Profile separates simple name edits from verified email changes, clarifies sign-in methods and MFA, and shows more useful session details with ten sessions per page.
Approvals distinguish a failed catalog load from an unavailable action or changed contract. Runner and pack access changes keep entered notes, inputs, and unsaved runbook edits while refreshing the controls.
Security
Shared operational reads do not grant permission to execute, cancel, approve, or change access. Use separate workspaces for teams that must not see each other's operational records.
Owners always have workspace-wide action access. Existing Owner scopes are updated with an audit record; use the Admin role for scoped administration.
Credential and access changes enforce current membership and resource authority, with clearer audit records. Approval emails for the same request stay in one thread.
Runner
Runner credential rotation uses the authenticated connection. Dispatch journal updates append durable transitions and compact periodically instead of rewriting the whole journal for each change.
MCP
Agent discovery follows the same shared-read and scoped-action rules as the console. Run requests give clearer guidance for recording a reason, evidence, and expected result.
Automatic Hermes and Goose setup uses their native Windows configuration paths. Setup guidance now includes co:op.
Packs
New Stripe and Braintree packs cover billing investigation, refunds, disputes, and related corrections.
The Airflow pack supports Airflow 2 (API v1) and Airflow 3 (API v2); jobs, assets, and backfills require Airflow 3.
GCP can list projects visible to the current credentials, Cloudflare analytics reports GraphQL errors, and pack limits follow backend and per-run constraints.
Billing
Checkout returns to its original workspace even if another tab switches workspaces. Monthly reports go to every Owner, and unsubscribe text explains that it turns reports off for the whole workspace.
Platform
SIEM tokens are paginated, large console reads and catalog refreshes do less repeated work, and retained runbook output remains readable without an associated action attempt.
Reliable recovery and leaner internals
v0.46.0
Runbook cancellation now survives a control-plane restart, and retried MCP draft changes recover their original result even after the draft changes again. Checkout reservations prevent repeated requests from creating another payable checkout; ambiguous provider responses remain pending until reconciliation can establish what happened. This release also removes unused code and duplicated helpers across the control plane, runner, bridge, and contributor tools.
Security
SSO provider trust changes and session revocation commit together. OAuth client-metadata fetching now has one deadline covering the entire request.
Runner redaction now masks long private-key blocks and sensitive argument values cut by output limits. Default rules preserve public AWS access-key IDs while masking recognized secret-key and session-token fields.
MCP uninstall probes run as the invoking user instead of executing user-owned binaries with elevated privileges. The HTTP client dependency includes fixes for two HTTP/1 parsing advisories.
Runner
Every encoded progress frame stays within the transport limit, and output caps preserve valid UTF-8 across streamed results and journal previews.
Installers accept IPv6 loopback portal addresses, assess each installed MCP copy independently during upgrades, and report the configuration they retained.
When GitHub CLI is unavailable for provenance verification, interactive installers ask whether to continue; noninteractive installs print a warning.
Billing
Subscription conflicts have durable cleanup records, and cancellation is confirmed against the provider before local closure. Cancellation stops recurrence; the initial charge remains unchanged.
Self-hosters using live billing must stop old checkout producers and finish their in-flight requests before enabling checkout traffic on this version. Existing unresolved payment links block a fresh checkout.
MCP
Older draft operations without a saved result return operation_incomplete. Inspect the current draft before making another change.
Console
Manual agent setup shows the correct commands and configuration paths for Linux, macOS, and Windows.
Copy buttons preserve literal command content and whitespace, omit presentation prompts, and restore their contents after repeated clicks.
Removing an unadvertised retired pack version works again, and audit CSV exports stream instead of loading the complete export into memory.
Platform
Release migrations recover interrupted concurrent index builds and verify the expected index definition before continuing.
The database availability alert now selects the monitored database's actual metric identity.
The v1 failure-path pass
v0.45.0
This release takes the v1 audit through recovery, revocation, and publication paths. A runner with corrupt replay state now refuses to start instead of risking a duplicate infrastructure change, while membership removal and credential revocation commit together and an unaccepted invitation grants no account access. Sentry reports strip active MFA setup material. Installers authenticate signed checksum metadata before trusting release archives, runner updates validate the staged binary against fielded configuration before stopping the service, and registry publication refuses stale catalogs or changed immutable schema objects. MCP paging and output now match the published tool contract, and the 99-pack catalog received another pass over risk, redaction, bounded output, shell wrappers, and false all-clear results.
Security
Corrupt legacy dispatch state stops runner startup, so lost replay evidence cannot turn a retried dispatch into a second infrastructure change.
Removing a member now revokes their API keys and device grants in the same transaction. Pending and expired invitations remain unauthorized until acceptance completes.
Sentry strips active TOTP seeds and recovery codes from LiveView state. Run audit events now include the dispatch justification and the policy decision, reason, version, and matched rules without retaining hostile request text.
Runner
The dispatch journal uses bounded atomic snapshots, and startup fails closed when an older journal cannot be recovered.
Managed updates validate the staged binary against configurations written by fielded installers before stopping the service, then replace the executable with one rename.
Wrapper arguments, action descriptors, and structured results receive stricter validation. Secret-shaped values stay masked across output types without flattening valid JSON.
MCP
list_packs can return every action in the largest supported pack, tool errors stay within their published contract, and changing a page size no longer invalidates a continuation.
Client configuration writes compare the file they actually read before replacing it, preserve formats the client accepts, and keep Emisar credentials out of browser child processes.
Installers reject unpinned downgrades and incomplete checksum metadata. A Windows reinstall now repairs stored credentials even when the parent shell carries direct-command credentials.
Packs
The full catalog was reviewed for real-world risk, source redaction, output caps, host access, HTTP failures, and shell argument boundaries.
Raw configuration readers that can expose secrets now carry the matching risk, while status actions stop with the underlying command instead of returning a false healthy result.
Versions that skipped their required approval gate were retired, and the changed action authoring schema now publishes under a new immutable version.
Platform
Runner and MCP installers authenticate signed checksum metadata before using archive hashes. Release verification is pinned to the trusted workflow and exact tag.
CI now exercises the privileged runner boundary as root, selects the full signing seam, and fails when required formatters or infrastructure tools are missing.
Registry publication rejects stale catalog generations, and release policy checks cover the environment, workflow pins, and registry writers used by delivery.
Console
Large SSO group sets page through synchronization and display, failed runs are directly filterable in Audit, and runner disconnect messages remain valid UTF-8.
Admin actions use server-resolved operator labels, the agent picker is easier to read, and Gmail dark mode no longer rewrites transactional email into an unintended palette.
The v1 hardening pass
v0.44.0
This release closes a full pre-1.0 security audit. Runners now reject a malformed or wrong-version dispatch at the wire, before it can reach a host, keep each pack's execution inside its own tree, and refuse credential state they do not own. Most of the pack catalog was republished: three actions were corrected to describe the change they actually make, more secret-bearing reads are redacted at the source, and versions that could print credentials were retired across the fleet. Signed dispatch, the MCP bridge, and both installers each close edge cases the audit found, and every runner and bridge binary now ships from a trusted publisher with signed checksums and provenance you can verify before you install.
Security
Patched the OIDC library for a HIGH-severity SSO authentication-bypass advisory, and now reject control and bidirectional characters at ingest so they cannot reach an approval or audit surface.
The raw session cookie no longer reaches LiveView assigns, and a spoofable staff operator id no longer reaches a customer's audit trail.
Both installers fail closed on a tampered download: a checksum that does not match stops the install.
Runner
A dispatch that fails to decode, or carries the wrong wire-protocol version, is rejected at the wire and journaled; a protocol mismatch is now permanent, not a retry.
Each pack runs contained to its own tree, the runner's journal is protected from path-argument actions, and the runner refuses a credential file it does not own or that is reached through a symlink.
status is a single-shot report, an interrupted action has its whole process group killed, and SIGHUP reloads the full config.
MCP
find_actions pages on rank, so promoting a concept can no longer loop or skip results.
Several OAuth and MCP responses that reported the wrong thing to a client were corrected, and the device poll buckets per authorization so concurrent installs behind one address do not exhaust each other.
Packs
Most of the catalog was republished. Three actions were corrected to describe the change they make, and several reads that could answer with a false all-clear now report honestly.
Secret-bearing reads redact more at the source, including Redis ACLs, pm2 environments, and secret-named variants, and versions that printed credentials, including old minio releases, were retired across the fleet.
Privileged packs ship an exact host-access recipe, and every pack's curl runs with the user curlrc disabled.
Platform
Portal pages load faster and their cost is measurable, a paid plan's entitlements follow the subscription lifecycle, and Paddle runner quantities stay in sync.
A requester can withdraw a run that is still waiting for approval.
Every runner and bridge release is built by a trusted publisher workflow with signed checksum attestations, and every Docker image CI builds or ships is pinned.
Website
Disclosed X as an analytics processor, stopped the Free plan advertising a support channel it does not include, and corrected homepage and audit-capability claims.
Verified the GitHub org behind emisar.dev and stated the standing security-support policy.
SSO and directory access, end to end
v0.43.0
Directory groups now grant access through the exact group resource emisar received, even when the provider sends no external ID. Renaming a group keeps its role and runner grants; deleting it removes them, and recreating a group with the same name does not bring old access back. The Okta, Microsoft Entra ID, JumpCloud, Google Workspace, and Keycloak guides now match current provider screens and say exactly which OIDC and SCIM paths were live-tested. Team, SSO, approval, and transactional email flows are also cleaner across desktop and mobile.
Security
Role and runner-access mappings bind to emisar's immutable SCIM group ID. Optional provider external IDs remain correlation data, and two groups with the same name stay distinct.
Okta groups without an external ID can be mapped directly. OIDC convergence for Okta and Entra accepts only an exact active SCIM identity under the provider's configured identifier claim; an explicit unverified email claim is still denied.
Directory group changes serialize with mapping writes, so rename keeps the selected grants while membership removal and deletion revoke them before another authorization decision can use stale state.
Console
Pending access requests stay compact until a decision needs runner choices or an existing-account warning, then open a focused dialog. Team controls stack cleanly on smaller screens, and SSO connection details read as one stable record.
Directory role and runner-access selectors use the actual synced group resource instead of a free-form external ID. Approval override asks for the audited reason once, then states the skipped approval count and the checks that still apply.
Website
Provider guides were walked through against fresh Okta, Entra, JumpCloud, Google Workspace, and Keycloak setups. Screenshots were recaptured from current provider screens, de-identified, and reviewed at the width customers see.
Each guide now distinguishes live-tested OIDC and SCIM lanes from capabilities the provider's standard application does not offer, instead of implying every provider uses the same directory-sync path.
Also
Transactional emails put the next action first, link the account context when it exists, express approval state in words as well as color, and keep the HTML and plain-text versions aligned.
Signed dispatch uses your own PKI
v0.42.0
Signed dispatch now uses ordinary X.509 certificates, so the certificate that authorizes a run can come from the PKI you already have instead of a format only emisar reads. The certificate names the runners it may target, and each runner checks the chain against the anchors you configured. The MCP bridge also exposes every tool as a shell command, and Windows support spans the bridge, its clients, and ARM64. Identity and session flows now carry current authority through their final transaction, including MFA, email, SSO, SCIM, device grants, OAuth refresh, and per-session revocation.
Signed dispatch
A dispatch certificate is a standard X.509 certificate you issue from Vault, AD CS, step-ca, or any CA you already run. It carries the runners it may target in a subject alternative name, and the runner verifies the chain against the anchors in its own config. Adding an anchor takes effect on reload, without restarting the runner.
Ed25519 and ECDSA P-256 keys sign; RSA does not. Only the leaf needs an elliptic-curve key, so the CA above it can stay on RSA. The audit record keeps the fingerprint of the exact certificate that authorized each run.
Security
A policy edit is limited to the scope the editor holds, standing grants can be revoked in bulk, an expired agent key is revoked in one step, and a membership suspension records who did it.
MFA and SSO decisions are rechecked at their final write: enforced accounts require current proof, administrator resets require a fresh factor tied to the acting session, TOTP replay state uses the locked verification time, and SSO callbacks revalidate provider policy, claims, and account bindings before minting a session.
Magic links, confirmation codes, and invitations are bound to the current email address. Signup keeps existing-address attempts neutral without creating a public workspace, and exact session revocation removes only the selected credential before disconnecting its socket after commit.
SCIM writes serialize with provider changes, DELETE retires the directory resource and its independent OIDC authority, and a later POST revives only the SCIM resource. Device-grant claims recheck the approver, and replaying a spent OAuth refresh token revokes that connection and its active successors.
OIDC work has bounded request, tunnel, and tenant budgets; every outbound destination uses the same public-address policy. Private identity-provider exemptions remain confined to development builds, the privileged installer transport is constrained, and current Bandit advisories are patched.
Bridge and CLI
Every MCP tool is now also a bridge command, so a shell script or an LLM without MCP support can call emisar directly. Validation errors say what to send instead, runbook output drains on its own, and typed JSON output is formatted.
The bridge owns client connect and disconnect, so a client installed later is connected without reinstalling. Windows support covers the installer, its clients, and ARM64, and client-config backups refuse symlink destinations instead of following them.
Packs
emisar pack diff shows what an upgrade changes, and emisar pack verify proves a pack is configured before you rely on it. Each pack's setup requirements appear on its page and in the CLI, pack suggest can read a registry catalog URL, and Nomad namespaces are supported.
Credential-bearing remote reads stay on configured destinations, low-risk metrics and log queries have explicit cost bounds, process diagnostics avoid secret-bearing files, and the Redis Sentinel down-state probe is structurally read-only.
Console and docs
Approval decision history is consolidated, every signer appears in the verdict, and a loaded choice stays visible while the form is edited.
Owners and administrators can approve a request using an override when the configured approval quorum cannot be reached. The override is audited. Pricing cards, comparison cells, FAQs, and structured offers now read the same Billing plan contract.
The console now uses one semantic icon system, keeps destructive MFA actions visually and verbally distinct, and makes session inventory and revocation state truthful.
The docs shell switches examples by operating system, the AI agent pages are split per client, and the quickstart, runner, and client-connection pages were rewritten in plain language.
Pack CI runs only what changed
v0.41.1
A pack change now runs behavior tests only for the affected pack instead of replaying the entire matrix. Changes to the shared harness, loader, catalog, or runner execution path still run every behavior plan, and a test-only edit no longer queues an unchanged registry publication. The release path keeps the full checks wherever runtime behavior can move while shortening the routine feedback loop.
Role and scope changes take effect immediately
v0.41.0
Changing a member's role, runner access, or pack access now reconnects their open web session before it can keep acting on stale authority. Billing managers get a finance-only console; operators can own agents, approvals, and runbooks without team or policy administration; and scoped admins cannot delegate more reach than they hold or arm account-wide pack cleanup. Runner and pack scopes govern current discovery, targeting, and new work, while account run and audit history stays available to roles allowed to read it — including the names needed to investigate what happened.
Security
Role and scope changes disconnect the member's live session and force a fresh authorization check. Account-wide pack cleanup requires full pack access, and helper reads that expose pack versions or exact run commands now require the caller's checked subject.
The read-only staff console is available only after MFA, and its proof is tied to the current enrollment rather than surviving a disable-and-reenroll cycle.
Console
Each role now sees the navigation, actions, filters, and empty states it can actually use. Billing managers land on Billing without a dead Dashboard link; no runner access is explained as a permission state rather than mistaken for a new account; and restricted pack and action views say why their results are limited.
SSO group mappings paginate in both directions. Filters keep their compact grouped treatment, timestamp and source tooltips flip away from viewport edges, and action menus close on Escape or an outside click across both app and marketing pages.
Packs
The 100-pack catalog now carries 1,689 actions. New diagnostics cover Consul registration churn, bounded process context and connections, GCP Cloud Logging names and entries, and Terraform replacement paths.
Platform
The Runner and MCP Bridge are rebuilt with Go 1.26.6 for the current standard-library advisory batch.
Large runbooks finish, and every result stays readable
v0.40.0
A runbook no longer fails publication because its expanded plan crossed an arbitrary total-step ceiling. The limits that protect the service remain — 16 stages, 256 resolved items, bounded targets, waits, arguments, and output — but a useful procedure can now be as long as those real bounds allow. When a terminal result is too large for one MCP response, the first call keeps the summary and returns an opaque continuation for ordered, 64 KiB output pages with explicit progress counts; small executions still finish in one call. Action discovery now also follows the member's current runner and pack scope in the console and MCP, including open pages after access or a runner group changes.
Security
Runner, pack, action, approval, and audit discovery now intersects the member's current runner and pack scope. Catalog rows require a deployment on a runner the member can see, malformed cross-account associations fail closed, and mounted console pages refresh when runner facts or the member's scope changes.
Phoenix LiveView is patched past the open-redirect advisory that affected navigation targets.
Runbooks
The arbitrary 32-step ceiling is gone. Definition size, stage count, target fan-out, frozen-plan size, and the 256-item execution ceiling remain the bounds that stop real resource growth.
Large terminal output is paged as complete records through wait_for_run. Each page names the total, returned, and remaining record counts and carries an opaque 15-minute continuation bound to the execution and credential lineage.
Runner
An official installer-managed runner can now update itself with emisar update. It verifies the release checksum and GitHub build attestation before handing the bundle to the same stop, swap, restart, and rollback transaction used by the installer; image and infrastructure-managed runners stay with their deployment owner.
pack update --json now emits its partial report before returning a post-update validation error, so automation keeps machine-readable results on every failure path.
Packs
The catalog now carries 100 packs and 1,682 actions, adding JFrog Artifactory, Databricks, Sentry, Symbolicator, and NTPsec while substantially expanding Cassandra and Cloudflare operations.
The admin runner's declared packs and executable checks now match what the production host actually carries.
Console
Approval forms now live-validate an empty restricted pack selection alongside runner scope, and an MFA enrollment completed in another tab returns to the app instead of sending the user through a misleading email-verification loop.
Runbook lists show a loading state on the disconnected first render, approval evidence links directly to its audit record, and invitation completion leaves one clear receipt instead of a finished form.
One runbook, one unpublished change, and a diff before you publish
v0.39.0
Every save of a runbook used to mint a version, so the number counted saves rather than decisions: fifteen authoring passes were fifteen versions, and v7 could be the second thing that ever ran. Which version was live, which was a draft sitting on top of it, and which had been superseded were three facts smeared across those rows, and the editor opened whichever row you clicked — so an old version was one click from what looked like a live editor. Publishing from there made old content the newest published version and silently changed what a plain Run dispatches. A runbook is now one thing carrying one unpublished change. Publishing shows the lines that differ from what runs today, mints the next release, and clears the change; only the live release runs, an agent's edit replaces that one change under the hash it read, and every execution keeps the exact definition it started with.
Security
The runner redacts more of what a config actually calls a secret: connection strings and database URLs, key-derivation inputs like salt and pepper, cookie and session signing keys, and the passphrase spellings. This is a safety net under actions that forget to declare their own redactions, never a reason to lower an action's risk tier — a key name nobody thought of still leaks.
Reading a pfSense certificate no longer emits its private key, and the fleet installer keeps a reusable enrollment key off the process command line.
Runbooks
Publishing is a confirmation that shows the change: the lines replacing what runs today, against the exact text whose hash is the definition's identity. A first release says so instead of showing an empty diff.
Only the live release runs. Naming an older one answers not_live rather than quietly running current content, and a draft runs only with explicit consent plus the hash of exactly what you read.
History is inspectable and no longer editable. The runbook list names the live release on the Run button itself and marks waiting changes with a quiet dot.
Packs
The behavior harness now proves the shapes it used to skip: a real service manager booted as PID 1, a Docker daemon each case owns, iptables inside the namespace it writes, and a real dpkg database for install, remove, and autoremove.
pfSense gains resolver, NTP, and WireGuard peer reads that never return their secrets, plus a DHCP reservation staged for the operator to apply.
Billing
A new subscription adopts the Paddle customer an owner's email already has instead of failing, and a repeating conflict now says which one it is.
A vanished runbook, a deny that matched nothing, and a session that would not end
v0.38.0
A runbook too large to project answered as if it did not exist. That answer is reserved for an untrusted pack or a runner outside your scope, which have to stay indistinguishable from absence — but size is not that kind of fact, and folding it in meant list_runbooks quietly dropped the runbook while get_runbook denied one sitting in the operator's own console. It was reachable rather than theoretical. The budget is counted in bytes while the title and description limits counted characters, and a description at the documented 4,096-character limit encodes to 12,288 bytes in Japanese: writing your description in your own language was enough to make your runbook vanish. A size failure now reports its size, and those character limits carry byte bounds derived from the budget instead of assumed against it.
Security
Ending a member's sessions now disconnects the session they are looking at, not just the cookie behind it. The disconnect asked for the addresses of sessions the same transaction had already deleted, found none, and left an open console working until the next navigation.
Console
A policy override that cannot match anything is flagged while you write it. The glob grammar treats every character except * as a literal, so an override written out of regex habit — cassandra\.drop_* — validates, saves, and matches no action id that can exist. For a deny rule, that reads as protection the fleet does not have. The warning is advisory and never blocks: an override may legitimately name a pack you have not installed yet.
Website
Eight documentation and marketing links no longer render a stray space before the punctuation that follows them.
Self-rotating runner credentials and a harder execution boundary
v0.37.0
A runner token now carries a 90-day life and refreshes itself two thirds of the way through, over the connection it already holds, so rotating a fleet credential no longer means going back to the host — and a token presented after its expiry is refused. The execution boundary tightened to match. Action children start with no_new_privs, so nothing a pack runs can pick up setuid or file-capability privileges the runner does not already hold, and an argument that resolves into the runner's own credential or state directory is refused before it reaches a shell. Reads that can hand back credentials wait for an approval now instead of being classified low risk, and signed dispatch signs the exact narrative a human approver reads.
Security
Every runner token has a bounded life, including the ones minted before rotation existed. A token past its expiry is refused at connect, and the refresh happens over the existing connection with no host access.
Reads that can return credentials are approval-gated rather than low risk, and the runner masks a run's sensitive values in a single pass, so one match cannot rewrite another's marker.
MFA enrollment and recovery-code regeneration both require proof of the current inbox, and credential step-up codes are rate limited across the cluster rather than per node.
Runner
Action children start with no_new_privs, one symlink-containment walk covers every path the runner opens, and an action argument naming the runner's own state is refused before it reaches a shell.
Upgrade note: because no_new_privs applies to the whole process tree, a setuid or setgid helper no longer elevates. If a non-root runner reached a resource through one — postqueue is setgid postdrop, which is how mailq reads the Postfix queue — give that runner user direct access instead, such as membership in the postdrop group.
Every pack's curl is confined to an explicit protocol with globbing off, so a URL that arrives in an API response cannot expand into extra transfers or carry a credential to a host that response chose.
An official multi-architecture container image is published at ghcr.io/andrewdryga/emisar-runner, with build provenance and an SBOM.
MCP
Signed dispatch signs the narrative a human approver actually reads (attestation v5), and the bridge verifies that narrative rather than a reconstruction of it. The signing key comes from a pinned credential directory instead of the environment.
Runbook targets can name a runner group in the model contract, and an agent can revise and test a draft before a human publishes it.
Packs
The catalog now carries 95 packs and 1,498 actions, adding Apache Airflow, Spark, Google Cloud billing, and BunnyCDN.
Every risky action in a modeled pack is now either proven by a behavior case against a real service or carries a declared reason it cannot be, and each pack's structured output is bounded to fit the runner's cap at its own advertised worst case.
Console
Runbook target selection scales to a real fleet: one stable trigger that names the chosen targets, a searchable roster of dense one-line rows, and scope icons that encode cardinality instead of infrastructure nouns.
Platform
The reads behind agent and console traffic got measurably cheaper. An action resolves from its own pack instead of the whole catalog, a catalog listing compares a stored descriptor digest instead of every descriptor column, and the keyset pages have the indexes their cursors need.
Staged runbooks and hardened enterprise identity
v0.36.0
A runbook can now carry a production operation from declared inputs to a staged result: typed inputs are bound once, stages run sequentially or in parallel against selected runner groups, steps extract named outputs, test success conditions, and wait within explicit bounds. An approval freezes the whole execution plan before any step begins, canonical JSON imports the same definition shape the console and MCP use, and the execution page shows each attempt and extracted value in order. Enterprise identity now gets the same fail-closed treatment: OIDC discovery and JWKS fetches stay behind a connect-time address policy, SCIM changes lock and reconcile the authority they act on, and names shown in runs and approvals are resolved only inside the account where the action happened.
Security
OIDC discovery, JWKS refresh, and redirects are fetched through one bounded address policy that rechecks the document actually received; changing an issuer also clears credentials that belonged to the old one.
SCIM bodies are bounded before authentication, group PATCH operations apply atomically in wire order, directory-owned suspensions can be reversed only by their owner, and disabling a connection retires the sessions and pending links it vouched for.
Run and approval attribution now resolves a person's name through the membership in the action's account, so a profile from another workspace cannot leak into the audit surface.
MCP
The bridge and portal adopt the 2026-07-28 MCP routing headers and dual-era endpoint, including OAuth Client ID Metadata Documents for clients that use them.
Release qualification names both required client models explicitly and requires Claude and Codex to pass the same held-out contract at the exact release commit; Gemini and Grok remain optional local evaluators.
Packs
The catalog now carries 91 packs and 1,386 actions, including bounded reads for GCP IAM, Monitoring, and Compute; Pure protection and performance history; Terraform state safety; Nomad job health; OIDC and JWKS; nftables; TCP; and Docker Compose.
A missing source command or an HTTP 4xx or 5xx now fails the action instead of letting a downstream pipe or successful transport report an empty success, and registry installation preserves a pack script's executable bit.
Console
Runbook authoring uses type-aware inputs, compact target selection, explicit sensitive-output controls, one whole-run approval plan, and canonical JSON import instead of a parallel definition format.
Execution pages follow the run detail's answer-first structure, with stages, attempts, output rows, waits, and terminal causes presented in execution order.
Website
Authentication and directory documentation now has one operator path across SSO, SCIM, account access, and the Okta, Entra, JumpCloud, Google Workspace, Keycloak, and generic OIDC guides, with one numbered step per provider screen.
Runner identity by hostname and pack behavior proven on real services
v0.35.0
A runner now identifies itself by its hostname: a reboot reconnects the same runner, a replaced ephemeral host enrolls as a new one, and no generated identity has to survive on disk for either to work — an explicit runner.id still overrides the default. Pack retention leaves a live fleet alone the same way: a version a connected runner still advertises is never swept, so a stable fleet keeps its pins and trust decisions through quiet weeks instead of losing them until the next reconnect. Behind the catalog, every behavior case now runs against its own disposable instance of the real service it targets, readiness is proven on the network path the case dials, and each high-risk action changed by the argument-boundary sweep carries a successful behavior case or a declared machine-readable risk exception.
Packs
Behavior fixtures assume nothing they did not arrange: cases run as a non-root identity in a disposable service, the state a case asserts on is created by that case, and the snmp OSPF adjacency builds its network namespace on AppArmor-confined hosts, where the default container profile denies the mount.
Readiness means the service a case will actually reach: ZooKeeper answers every four-letter word the suite uses before the first case starts, and databases that seed through a temporary boot-time daemon are probed on the routable address rather than loopback.
The behavior matrix finishes in less than half the wall-clock time: a plan's images are pulled before its first case, slow suites shard across CI rows, and a plan whose service is heavy caps how many of its cases run at once.
Platform
The hosted admin runner bootstraps from a version-pinned release download with retries instead of asking the GitHub API which release is current, so an anonymous rate limit cannot keep a control-plane VM from starting.
A production deploy re-plans when a manual apply has superseded its saved plan instead of failing the release.
Website
A clarity pass from founder review: the security page shows the signed-dispatch boundary at the point it acts, the home comparison states signed dispatch and the no-inbound-port posture in their own rows, case studies and comparisons read at the docs rhythm, and connect pages name the agent in the attribution line.
Also
Checks that used to run only in CI moved into the canonical gates — staticcheck into the Go gates, the Portal-only checks into the portal gate — so a green local gate and a green CI run mean the same thing.
Live run output for agents and a tighter pack-argument boundary
v0.34.0
An agent waiting on a run now sees the output as it arrives: wait_for_run streams the run's event log through a scope-bound cursor, bounded by encoded bytes with oversized events fragmented, so a long action reports progress instead of going quiet until it finishes. Pack arguments gained a matching boundary — only finite choices and two-sided bounded numbers may render into a fixed shell program, while open-ended strings, paths, and arrays now travel as environment values or whole argv elements, and an authoring-time lint rejects a pack that breaks the rule. The documentation was rebuilt alongside both: terminal casts recorded from real CLI runs, a navigation split by the job you came to do, and pages corrected against the implementation.
Security
The runner installers keep credentials off process argv. A GitHub token, an API key, and a device code used to ride the curl command line, where any local process could read them; they now travel as headers on standard input.
Five pack arguments could pass a leading dash through to the target binary as an option. Their patterns now anchor the first character to a non-dash class, and pip_show terminates option parsing explicitly.
Runbook creation never casts status, so a client-supplied "published" cannot mint published content; publishing at birth is its own transition gated on manage permission.
Authorizer row-scoping fallbacks fail closed with an empty query rather than an unscoped one, and a Credo check keeps them that way. The runner's trust gate now refuses a run whose registered action has lost its pack.
Bandit is patched for the WebSocket denial-of-service advisory, and OAuth registration rejects redirect URIs with no host or a fragment.
MCP
wait_for_run takes an output cursor and returns the next one, reading the event log forward within the caller's scope. The tail wakes on new progress rather than a row timestamp, and a finished run's trimmed output can still be paged back in.
Pre-run dispatch rejections — contract changes, refusals, rate limits — log bounded, allowlisted fields, so a rejected call is visible in operations without putting model input in the log.
Packs
The loader rejects open-ended substitutions in fixed shell programs at authoring time, which turns a per-pack review habit into a check that runs in the gate.
Curl-backed API actions fail on 4xx and 5xx responses instead of reporting transport success, and catalog metadata is validated against the same bounds the runner enforces.
Risk tiers are consistent across the catalog: reload is high everywhere, scale is high everywhere. Behavior plans replaced generated cases, and pack compatibility matrices run in CI.
Console
Operator input survives a re-render. A half-written approval note, a chosen grant scope, a cleared runner-scope draft, and a partially typed policy override are no longer lost to a co-approver's broadcast or a refused submit.
A pack-trust conflict names the runners that disagree about an action instead of failing generically, and run detail titles the terminal-cause panel by what actually happened.
Subscription reconciliation pages through its work and isolates a failing row, and inactive runners are cleaned up on a schedule.
Website
The security page shows the approval loop as a console recording driven by a real run, not a mockup, and the docs carry terminal casts captured the same way.
Documentation is reorganized by task: single sign-on and directory sync split apart, cloud and CLI agent connection split apart, containers separated into Kubernetes and Nomad with a host-install page, and operational limits and autoscaling fleets given their own pages.
Body text reads at 16px on a capped measure, screenshots are cropped to the feature and open fullscreen, and an llms.txt index plus a Keycloak setup guide were added.
Also
Repository development tooling is consolidated behind one contributor command, and durable engineering knowledge moved into a single reviewed knowledge base.
Trust-aware action discovery and clean runner re-enrollment
v0.33.0
Action discovery now follows the runner's current pack trust: MCP catalog, search, exact lookup, and runbook recovery expose only complete manifests for exact versions an operator still trusts, while the console keeps an untrusted advertised action visible for diagnosis but locks Run with the reason. Dispatch rechecks the same contract, so revoking trust closes stale pages and tool calls too. Runner uninstall now removes the cached token while preserving local evidence, and a changed enrollment key re-registers the configured id or hostname automatically.
Security
Pending, rejected, revoked, retired, hash-mismatched, and incomplete pack versions no longer enter model-visible discovery; trust failures stay on operator surfaces and in the audit trail.
An advertised runner action whose exact pack version cannot dispatch remains visible for diagnosis, but Run is locked with the reason. Transaction-level dispatch revalidates trust so stale console state cannot execute.
OAuth return targets survive SSO and registration, including the original query string, without accepting an external redirect.
Runner
Default uninstall removes the cached token and legacy token file while preserving configuration, local evidence, and logs; --purge still removes everything.
A changed enrollment key re-registers the configured runner id or current hostname and replaces the cached token without an identity-reset prompt.
MCP
Catalog tools and runbook recovery fail closed when trust changes between inspection and execution without introducing the hidden pack version into model-visible results.
ChatGPT tool annotations distinguish read-only calls from mutations, and domain verification accepts OpenAI's text challenge.
Claude evals select MCP authentication by mode and skip interactive permission prompts during headless runs.
Also
A public incident-response skill gives customer agents a bounded observe, diagnose, act, and verify workflow.
The Packs page follows the live catalog and gives unadvertised versions one day to disappear before cleanup.
Real-agent MCP evals and symptom-language action search
v0.32.0
Real agents now certify the MCP surface before it ships: a scheduled eval drives Claude and Codex through a fail-closed relay against a live stack and hard-fails on policy violations, invalid mutation arguments, dispatches without prior inspection, and placeholder run reasons — an API change that confuses a model now fails a build, not a customer. And search learned how operators actually talk: packs carry 562 phrases of operator vocabulary, ranking weighs rare words over common ones, and page-one recall on a symptom-language benchmark against the production catalog went from 46% to 100% — "the db is slow" finds the right postgres action on the first call.
MCP
run_action takes an optional justification chain — evidence for what the agent observed, expected for the outcome it predicts — beside a reason that can now run to 2000 characters. Approvals and run details render the chain, so a reviewer sees the basis and the hypothesis, not just the request.
Paginated reads hand back a copy-ready next call instead of a bare cursor; an agent continues a search by echoing one object.
list_runners names each runner's dispatchable packs inline, answering what a named host can do in one call.
Actions can opt into typed JSON results, dispatched against the pinned trusted descriptor.
Packs
A curated synonym map expands operator shorthand like db, mem, and k8s during search.
The registry serves the catalog compact and gzip-encoded behind a CDN — about a tenth of the previous transfer.
The Nomad Autopilot health action is fixed.
Runner
Runner access is explicit: a member is scoped to the runners and groups they may use, chosen in a clearer scope picker.
A missing client binary travels as separate host readiness evidence: the action stays advertised for manifest verification and is simply not offered for dispatch.
Also
Empty runner onboarding points at installing a pack catalog instead of a run that cannot succeed.
The ChatGPT connector's OAuth consent page renders correctly under its sandboxed CSP.
Enterprise plans name their dedicated Slack support channel.
The MCP installer preserves a commented Zed config
v0.31.1
Connecting Zed through the installer no longer drops to a manual step. Zed ships a settings.json with comments and trailing commas that the installer's strict JSON parser refused; it now adds the emisar server while keeping those comments, the trailing commas, and any servers already configured. The same comment-safe merge covers any editor that keeps a commented JSON config.
Browser-approved agent connect and pack lifecycle control
v0.31.0
Connecting a local agent no longer moves an API key by hand: the installer opens a browser approval, you approve the connection on a consent page, and per-client keys are written straight into the agent's config — the secret never touches the clipboard, shell history, or a process argument. And the pack catalog becomes something operators run, not just watch: delete a pack or a single version, revoke trust on a version, or let versions no runner advertises anymore age out on their own.
Security
Five pack actions that could read a leading-dash value as a command flag are fixed, and their old versions retired.
Three actions that dump container or process environment now require approval.
Runner
The runner CLI reloads the daemon on its own after a pack change.
One upgrade step for self-hosted runners: rename the config key auth_key_env to enrollment_key_env and re-mint any keys that were never enrolled — connected runners keep working.
MCP
The same installer now sets up thirteen MCP clients.
Packs
A runner still lagging on a version a security fix retired now reads as retired and points at the upgrade, instead of posing as an unknown pack asking to be trusted — approving it would have re-authorized the vulnerable bytes.
Outdated packs show a quiet update-available hint.
Nomad reaches 0.2.0 with deployment control and metadata-filtered discovery.
Console
Essential text on every marketing and console page is raised to WCAG AA contrast, kept there by a new check.
Under-permissioned roles get a clean denial instead of a server error.
Database-enforced tenant isolation and steadier dispatch
v0.30.0
Tenant isolation now lives in the database itself: every runner-owned child row carries a composite foreign key to its account, and CHECK constraints backstop the security-relevant enums — so a cross-tenant or out-of-range write is refused at the row, not just in application code.
Security
Public pages and error responses carry the same Content-Security-Policy as the rest of the site.
Sentry is disclosed as a subprocessor, with its events scrubbed of personal data before they leave.
A runner that requires signed dispatch announces it over MCP.
Runner
A runner at capacity redelivers the dispatches it refused.
The stale-dispatch sweep drains the oldest queued first, and stuck pending runs advance instead of stranding.
Console
Active sessions each render as their own row with their own address, sign-in time, and revoke.
A retired pack's re-trust control no longer crashes the packs page.
Faster run search on large accounts.
Platform
Direct paging for severe database and load-balancer alarms.
Leaner MCP results and a hardened pack catalog
v0.29.0
MCP results now meet LLM clients where they are: canonical string forms of integers and booleans coerce instead of failing the call, every rejected argument names its field and the JSON type it was sent as, and run summaries omit what carries no signal — streams that produced no bytes, completeness flags that are simply true, and per-stream digests — so a typical summary shrinks by a third.
Security
Disabling multi-factor authentication now demands a fresh step-up challenge.
Production session cookies always carry the Secure flag.
Packs
Secret-dense config and environment dumps now require approval.
Redis ACL password hashes are redacted from low-risk reads.
Exec-style arguments reject a leading dash so a hostile value cannot be read as a flag.
Upgrade-safe runners and honest fleet alarms
v0.28.0
Runner upgrades now migrate the durable dispatch log across format and location changes instead of silently refusing every dispatch afterwards, and one broken installed pack degrades just that pack — named on the runner page and in MCP diagnostics with its load error — rather than crash-looping the whole runner.
Security
Sign-in enforcement for SSO and MFA requirements covers every controller route.
SCIM and other machine endpoints are rate-limited.
Runner connections assert a TLS 1.2 floor.
Runner
An offline runner shows its real connection status instead of tamper-flavored trust alarms about a stale advertisement.
The installer verifies dispatch state with the staged binary before touching a running service.
emisar doctor explains a corrupt dispatch log, a degraded pack, and the last cloud rejection offline.
Platform
Direct alerts for database-down and no-healthy-backend conditions.
Reliable runner startup and clearer MCP failures
v0.27.0
Runner upgrades now use one final durable dispatch journal and refuse to connect when that state is corrupt, so a bad upgrade can't quietly half-run.
Runner
Unsigned installations stay independent from signing state.
Sensitive values are redacted from failure causes before they're reported.
MCP
Run summaries expose a bounded terminal failure message.
Connector setup keeps key-bearing commands out of shell history.
OAuth consent lets a person choose the account they intend to connect.
Platform
Newer non-destructive production plans supersede stale ones without adding a second approval gate.
Reconnect-safe runs and a clearer agents list
v0.26.0
When a runner drops its connection and comes back, the control plane recovers the runs that were in flight instead of stranding them, and the runner repairs any packs it kept across an upgrade before resuming work.
Runner
Skips processes that were already cancelled.
Reports a failed local audit honestly instead of masking it.
Bounds the action catalog it advertises.
Console
The LLM agents list groups by the person behind each key and shows each connection's emisar-mcp bridge version inline, so an outdated bridge is obvious and one step from the upgrade command.
Stricter runner results and cleaner settings
v0.25.4
The runner now rejects broken action contracts, invalid execution options, unchecked path targets, and out-of-range result metadata before those values cross the host boundary. Pack releases rebuild from the live registry history, and account settings drop redundant state labels.
Versioned registry schemas for append-only publishing
v0.25.3
Pack Registry schema publishing now versions immutable JSON schema filenames and identifiers, so a changed catalog or action schema appends new objects instead of colliding with a prior release. The publisher still creates every immutable object before moving catalog pointers, and tests tie each schema identifier to its public object path.
Exact action validation and stronger UI proof
v0.25.2
Action arguments now keep numeric membership checks exact across the portal and runner, reject invalid allowed values before a pack or run proceeds, and validate the runner execution envelope instead of silently dropping malformed options. Contributor workflows also gain a frontier review preset, durable loop knowledge, a backlog drawer, and required before-and-after screenshot evidence for UI fixes.
Cleaner setup and reliable release publication
v0.25.1
Runner and connector setup now keeps one-line commands compact, uses shorter Claude.ai instructions, and leaves transport diagnostics out of customer screens. Fleet examples distinguish supported from unsupported runners, account settings use quieter status labels, and release publication waits for the tagged commit's required CI result instead of losing a race. Runner argument parsing also accepts numeric strings only when they use valid JSON number syntax.
Durable execution and a tighter MCP boundary
v0.25.0
Runner execution now begins only after durable audit evidence and remains bound to the trusted pack, dispatch record, output digest, and terminal result.
Runner
Cancelled process trees are contained, ambiguous paths and inexact numeric limits are rejected, and pattern-matched values stay redacted across log rotation.
MCP
The native MCP endpoint exposes twelve server-owned tools with bounded waits, crash-durable mutation recovery, and safer key promotion.
Platform
Coordinated installers, rollback-aware releases, multi-zone delivery, and clearer connector setup make the operating path easier to inspect.
Stronger delivery controls and clearer trust evidence
v0.24.1
Delivery now rejects stale or incomplete plans, authenticates installer release metadata, narrows production credentials, and keeps published images and packs tied to tested bytes.
Website
The Trust Center leads with current controls and a live DNSSEC chain.
The official MCP Registry description explains emisar in plain language for people who discover it outside the website.
Hardened hosting, safer releases, and a public status page
v0.24.0
The hosted platform moved to hardened cloud infrastructure with zero-downtime rollouts, a private-network database, and independent external monitoring behind a public status page at status.emisar.dev.
Packs
The pack registry serves from its own hostname, registry.emisar.dev, with anonymous access narrowed to exact object reads, generation-specific verification, and end-to-end tarball checks.
Platform
Portal releases publish the exact image exercised by CI.
Binary releases are immutable and reproducible.
Production plans queue in order without replacing an operator's pending review.
More reliable background work and a cleaner runner setup
v0.23.0
Routine product work is now more predictable: approval expiry, audit retention, billing sync, sign-in cleanup, and timed-out runs are handled by the control plane itself.
Also
Billing contact sync keeps customer records tied to active account owners.
Runner setup puts the install script details where operators need them.
Annual billing, Team-owned SSO, and safer input handling
v0.22.0
Billing now supports monthly or annual checkout, shows recent invoices, and lets operators download invoice PDFs from the console. SSO moved into Team, where pending access requests, connection status, sign-in links, MFA enforcement, and Require SSO live next to the roster.
Security
Tightened handling of oversized directory-sync data, runner output, signup recovery, email changes, and account-scoped billing or runner actions.
A calmer, clearer console
v0.21.0
The console now uses one page language across fleet, agents, policies, packs, runbooks, billing, approvals, and audit — empty states explain the next useful action, dangerous actions share one confirmation dialog, machine identifiers are easy to copy, and navigation looks like navigation rather than a row of buttons.
Console
Policies show what a rule allows, approves, or denies against the account's actual catalog.
Pack search can narrow by risk tier or matching action.
Audit and approvals read like records
v0.20.0
The audit trail is easier to scan during an incident: each row makes the actor, target, action, and outcome clearer, and approval detail pages open with the decision state, then the command, arguments, reason, policy evidence, reviewer note, and timestamps in one record instead of scattered panels.
Audit
SIEM export configuration moved to its own managers-only page, off the browse view.
Checkout, MFA sign-in, and cleaner account forms
v0.19.0
Checkout now follows the selected plan, and billing-manager seats can manage billing without receiving broader admin powers. Accounts that require MFA can challenge after a magic-link sign-in with TOTP or a recovery code.
Console
Code entry, secret reveal, enrollment steps, switches, cards, and mobile list rows share the same console patterns, so repeated workflows feel familiar instead of rebuilt per page.
Directory sync owns directory-managed access
v0.18.0
Directory-managed members now behave consistently: synced roles stay owned by the IdP, deactivated users arrive suspended, manual suspensions are not undone by later syncs, and IdP-deactivated members cannot be reinstated from emisar.
MCP
MCP keys can be limited by action and runner scope before a dispatch reaches a runner.
Console
Runner scope selection is clearer and reused across invitations and MCP keys.
SSO setup and audit retention become inspectable
v0.17.0
SSO setup now has dedicated connection pages with pending access requests, a test-connection step, synced users, sync health, and read-only provider fields after creation.
Audit
Plan changes affect retention going forward rather than silently erasing existing rows.
Exports record that they happened.
Important identity, plan, retention, and action-run events carry the details an operator needs later.
Passwordless sign-in, signed dispatch, and verified packs
v0.16.0
emisar now signs users in with magic links or SSO only. Email changes require a fresh verification step, and invite and confirmation emails carry sign-in links instead of asking for a password.
Security
Signed dispatch gives runners a way to reject requests that were not made by a configured client.
MCP
MCP keys gained action scopes, expiry, kind labels, and rotation.
Packs
The pack test harness expanded across the database, Kubernetes, routing, Nomad, and firewall packs.
Product analytics and the console craft pass
v0.15.0
Server-side product analytics that set no tracking cookie: a weekly-rotating salted visitor id, scoped to marketing and growth, with no client SDK and the processor disclosed on /privacy, /trust, and /dpa.
Security
Self-approval becomes a named policy mode: single-operator or four-eyes.
Console
A console craft pass unifies the design system into one surface recipe, a dense-table width tier, shared empty states, and a single product term — the LLM agent; MCP is the protocol.
Approvals gain a live expiry countdown and a per-card risk tier.
The audit log goes on a logging diet, and mobile gets real operator cards.
The marketing site, rebuilt
v0.14.0
A ground-up rebuild of emisar.dev: a how-it-works walkthrough traces one real action through every gate with the actual payload, and an MCP reference, a procurement-ready Trust page, a Data Processing Addendum, and a Guides surface fill out the funnel.
Website
The pack registry is searchable, and the changelog is data-driven with an RSS feed.
Platform
A roughly 1,590-test QA suite across portal, runner, and mcp.
A marketing-honesty pass that cut every claim we could not back.
Domain metrics for run outcomes, approvals, and billing.
"The Gate": a new identity and design system
v0.13.0
emisar gets a face: a gate logo and custom wordmark, a single emerald brand token in place of the old indigo-and-emerald mix, a signature display typeface, and material depth from film grain, emerald glow, and glass elevation — with the gate device drawn into the hero from the logo.
Console
The control plane moves onto the same brand token and type signature.
Website
The marketing site is overhauled with a use-cases hub, a packs registry, a Trust page, ROI-tied pricing, and a WCAG AA contrast pass.
Security-review hardening and the datastore pack wave
v0.12.0
A full security-review pass closes the sharp edges, and the datastore pack wave lands with it: CockroachDB, MongoDB replica-set lag, ClickHouse, Kubernetes and RKE2, Redis Sentinel, and SNMP.
Security
A durable runbook-execution record ends a continuation ACL bypass.
Pack trust fails closed, and the trusted pack hash is snapshotted at authorization.
A cancelled approval-gated run can no longer be approved and delivered, and approval grants are consumed in the same transaction as the run.
A privilege reduction disconnects the member's live sockets, and MFA verifies against the current secret under a row lock.
Runner
Live signing-key rotation over SIGHUP.
Bridge-attested signed dispatch
v0.11.0
End-to-end Ed25519 attestation on every dispatch: the MCP bridge signs each run_action frame, the portal relays the signature untouched, and an enforcing runner verifies it before executing — so a compromised control plane can relay a request but never forge one.
Runner
The emisar keygen command mints the keypair; runners advertise enforcement, their trusted key IDs, and a maximum attestation age.
Console
The runners index shows a Signed-only chip, and a refused run is its own terminal state.
Multi-tenant URLs and the console redesign
v0.10.0
Slug-based tenant URLs nest the app under a per-account path with a cross-slug tenant guard, SSO sign-in lands on the team's branded page, and a per-account require-SSO switch forces members through the account's IdP.
MCP
Bridge hardening: response caps, oversized-frame resilience, and redirect refusal.
Console
The console is rebuilt across five workstreams: nav regrouped into Operate, Fleet, and Settings; a single content-width scaffold; load errors that no longer read as empty; dead-end flashes that name the next move; and audit deep-links from every run, runner, and approval.
Platform
New Credo layer-boundary checks guard the architecture.
SSO, SCIM, and four-eyes approvals
v0.9.0
A configurable approval gate you set per policy: forbid self-approval and require a number of distinct approvers. OIDC single sign-on (Google Workspace, Okta, Keycloak) and SCIM 2.0 directory sync provision and deprovision from your IdP.
Security
IdP groups map to emisar roles, and offboarding revokes a member's access and sessions automatically — with real-world interop for Okta header tokens and linking an IdP identity to an existing member.
Console
The shared component system fills out with typed-confirm dialogs, selects, checkboxes, and an accessibility pass.
Fleet operability and the operator-experience overhaul
v0.8.0
Multi-machine clustering so dispatch and Presence span control-plane nodes, stale runs that re-dispatch to an online runner instead of stranding, and runbooks that honor a per-step runner target.
Packs
The pack catalog reaches 73 packs and 1,096 actions.
Console
A deep operator-experience sweep through runs, runbooks, approvals, the dashboard, team, and audit: streaming output, offline affordances, blast radius shown before dispatch, a live execution that rehydrates on refresh, recovery-code download, role-change confirms, and an escape hatch for an MFA lockout.
The audit log gains actor, date-range, outcome, and free-text filters, and the first shared component system lands.
The runbook engine, scoped policy, and a reliability pass
v0.7.0
The runbook execution engine arrives with grouped targets, parallel waves, and a live results page, and policy gains per-runner and per-group overrides.
Security
Approval expiry is enforced at decision time, pack trust is re-gated at approval, and the policy and grant audit commits in the same transaction as the run.
Rate limits on the unauthenticated and MCP endpoints.
Runner
Runs stuck running on a dead runner now time out instead of hanging forever.
Packs
An opt-in shell break-glass pack ships for staging.
Platform
A top-to-bottom correctness, authorization-shape, and test-coverage pass.
Pack catalog expansion, runbooks over MCP, and security hardening
v0.6.0
The catalog grows by fourteen packs (iscsi, multipath, bonding, frr, nic, victoriametrics, victorialogs, pfsense, traefik, tailscale, pure-flasharray, vector, typesense, zot), and emisar pack suggest recommends the ones a host actually runs.
Security
An OAuth-consent privilege escalation closed, streaming output redacted across line boundaries, the script hash re-verified at exec time, and credentials streamed over stdin instead of argv.
MCP
Runbooks become readable over MCP through list_runbooks and get_runbook, so an agent can fetch a saved runbook and run it step by step.
Public beta control plane
v0.5.0
The hosted control plane opens: connect an MCP client, scope it to selected runners, and run a declared catalog behind policy — now on Elixir 1.20 and OTP 29.
Website
The first marketing surface: comparison pages against SSH and a custom MCP server, the CSI data-loss use case, an animated home demo, and a zero-trust page mapping emisar to Anthropic's agent-safety framework.
Remote MCP over OAuth 2.1
v0.4.0
An OAuth 2.1 authorization server lets a remote MCP connector authenticate and scope itself to your runners.
Runner
Runner identity becomes stable through a durable external id so re-registration is idempotent, and connection state moves to Phoenix Presence.
Packs
The emisar pack uninstall command and pack setup blocks.
Console
A live badge surfaces packs waiting for a trust review.
Platform
Sobelow and mix_audit scans in CI.
The pack registry and install CLI
v0.3.0
The emisar pack install command pulls one hash-verified pack at a time instead of dumping the whole catalog, with a no-service flag for binary-only installs and install-time config baking so a runner boots without hand-editing. MCP tool calls now return the real result, including failures, rather than a bare status of sent.
Approvals, audit, and the control set
v0.2.0
The pieces that make it safe to act: human approvals with revocable standing grants, a SHA-256 hash-chained host journal alongside a searchable cloud audit and NDJSON SIEM export, account-wide MFA with recovery codes, request idempotency, versioned runbooks, and per-runner billing through Paddle. The first action-pack library ships with it.
The foundation
v0.1.0
Where it began: an outbound-only on-host runner that advertises and executes a typed catalog, YAML action packs with typed argument validation, a risk-tiered default-deny policy engine, and an append-only audit trail. A JSON-RPC MCP server with tools/list and tools/call exposes the catalog to any agent, and a docker-compose dev stack plus single-use enrollment keys make it runnable in minutes.