Skip to main content

Changelog — September 14 – 27, 2026 (in progress)

New Features

  • Endpoints (beta). A new top-level workspace for the hosts you manage through Endpoint Control. Your scope decides which fleets you see — one per Endpoint Control connection — and a fleet switcher moves between All fleets and one fleet. Six tabs: Overview, Endpoints, Collections, Activity, Access and Deploy. See Endpoints overview.
  • Fleet health at a glance. The Overview tab counts Online, Stale and Offline endpoints, charts check-ins, breaks the fleet down by platform and agent version, lists recently enrolled endpoints, and flags what Needs attention — an install link about to expire, endpoints offline for over 7 days, endpoints behind on their version.
  • One table for every endpoint, across fleets: filter by status, platform and tag, search by hostname, IP, UUID or serial, see 24 hours of activity per row, and Tag, Run query on these, Collect file or Remove in bulk. When a selection spans fleets, the action applies to the endpoints you are allowed to act on and says how many are skipped. See Endpoints and endpoint details.
  • A page per endpoint: identity, hardware, activity, tags, Logs, Open in Explorer, and Seen in hunts — the hunts whose results included it. Run query opens a query tab targeted at exactly that endpoint; a Targeting N endpoints banner warns if the targeting is edited away and offers Restore targeting.
  • Collect file. Pull a file from one or more endpoints into a bucket your organization owns. Each run shows per-endpoint status, size, the SHA-256 of the stored archive and Download. See Collect files.
  • Storage destinations in Settings: an S3 or S3-compatible bucket you own, with Test connection, a write-only access key and one Default. File collections need one. See Organization management.
  • Endpoint access. A Responder role lets someone collect files, browse files and run console commands without being a connection admin. Grant it on a whole fleet, or grant Viewer, Operator or Responder on a tag — "responder on everything tagged finance". Only tags in a folder marked Access-bearing can carry access. See Access and activity.
  • An audit trail per fleet. The Activity tab lists every hands-on operation — who, what, on which endpoints, with what outcome — including denied attempts and work done by Scout, a schedule or a watcher on someone's behalf. Command text is recorded; console output and file contents never are.
  • Files and Console (beta, separate rollout). Browse an endpoint's file system and run read-only commands and osquery SELECTs on it, live. Sessions start only when you click start, end when you leave, and everything in them is recorded under your name. File retrieval from the console is refused — use Collect file. See Files and console.

Improvements

  • Endpoint Control speaks one vocabulary. The connection page and the Deploy tab now say Install on endpoints, Uninstall from endpoints, Install link secret and Manage link. Install and uninstall commands, and the secret, are shown only to fleet admins; everyone else sees when the link expires and whom to ask. See Endpoint Control.
  • With Endpoints enabled, an Endpoint Control connection's page shows a compact Fleet card with Open in Endpoints in place of the two-tab panel.
  • Fleets that serve more than one organization are marked Shared and are view-only.