• Fix sending Slack notifications for large access requests
  • Fixed links in Events taking you to invalid access review links
  • Added minor UI improvements to requested items in the request detail view
  • Improved date formatting in the event details view
  • Fix back button on Add App page directing to broken route
  • Added filtering by tags to the Risk Center
  • Removed rows that show the global requester role when it is disabled
  • Improved the display order of duration options in access request forms
  • Improved clarity of IDP/HRIS deprovisioning settings
  • Added two new date range presets to the date picker: "Last day" and "Last 7 days"
  • Fixed an issue with redirects on the Requests page
  • Added support for AWS organizational units
  • Updated styling of Access Review Reviewers table
  • Added connection validations for AWS Real time sync
  • Replaced the visibility of a resource with the name of its connection in the table cell
  • Updated Jira create ticket flow to avoid deprecated API
  • Show the higher organization maximum assigned for resources and groups on an empty request form, when both organization maxes are set
  • Added ability to reorder template mapping inline
  • Improved the role selection interface for access requests, making it easier to select multiple roles for a resource.
  • Added links to catalog to requested items on request view

Fixed bug where unused access risk factor wasn't being surfaced for some applicable grants

  • Enabled command K while inputs/textareas/select are focused
  • Added Shift+Select to new tables
  • Fixed bug with bulk selection where deselecting items does not work
  • Fixed inconsistent styling on danger zone page
  • Risk Center suggestion scoring improvements
  • Users can filter for Databricks NHI connections
  • Fixed a bug in UAR bulk reviewer assignment
  • Improved access review experience by making export functionality available for past access reviews while maintaining appropriate restrictions on reminder functionality.
  • When an on-call schedule is deleted in the end system, its assigned group membership access is now immediately revoked. Previously, a 24-hour grace period was given.
  • Added search query to URL for user group, user resources, resource groups, resource roles, and group users tables
  • Updated styling of request duration dropdown
  • Updated styling of the group access tab of a group
  • Fixed access review metrics to correctly count only users specified in filters when generating reports for User Access Reviews.
  • Added an access level column to a user resource and user group tables
  • Updated terminology for inventory apps + bundles to contain "assets" (resources and groups)
  • Added requested by for all requests requested by someone else
  • Added opal_org_name name field to event streaming payload.
  • Added the ability to filter resources by ancestor in the GetResources API. This allows users to retrieve all resources that are descendants of a specified resource, making it easier to navigate hierarchical resource structures.
  • Fixed links from slack, emails, and google chat directing to broken pages
  • Fixed a bug where “Create Access Review Date” input could have the wrong dates
  • Fixed a bug where when adding resources to a group, an apps resources list would not expand.
  • Fixed a bug causing usage data to show as "Not Available" incorrectly for certain groups.
  • Fixed a bug where users resources page wasn't paginated
  • Fixed a bug where propagation tickets may not have displayed correctly

  • Fixed a bug where loading approved requests with a propagation ticket may have failed
  • Added a warning when setting a custom global max resource and group duration if it exceeds a year
  • Fixed broken labels on break glass modal
  • Performance improvements for the risk center.
  • Fixed colors for EC2 usage table in dark mode
  • Added more detail to some GCP connection creation errors.
  • Fixed a bug where the assignment of AWS Identity Center resources were not populated if one of their assignees is missing an email.