AxonFlow v9.17.0 Release Notes
AxonFlow v9.17.0 adds self-service portal password recovery by email, through Resend or your own SMTP relay, completes the segment-scoped policy rollout begun in v9.14.0 by bringing segment targeting to the orchestrator's dynamic policies and the remaining agent policy planes, and hardens the forgot-password endpoint: no reset token is ever returned over HTTP on a deployed stack, reset tokens are hashed at rest, and the rate limiter no longer keys on an attacker-controlled header.
AxonFlow v9.16.1 Release Notes
AxonFlow v9.16.1 fixes policy attribution in compliance report exports: the Policy column now shows the policy name and version for blocked events, including on previously generated data, and telemetry-sourced events record their policy reference going forward.
AxonFlow v9.16.0 Release Notes
AxonFlow v9.16.0 adds interactive OIDC portal login alongside SAML, hardens all OIDC identity-provider endpoint fetches against SSRF, and fixes an SSO login failure on direct (unproxied) connections. Enterprise-only; no community release.
AxonFlow v9.15.0 Release Notes
AxonFlow v9.15.0 makes interactive SAML SSO login work end-to-end for self-hosted in-vpc deployments, auto-provisions an SSO user's group-mapped role on login, relaxes the governed /api/request empty-email refusal to proceed org-only, and breaks the telemetry digest down by platform version.
AxonFlow v9.14.1 Release Notes
AxonFlow v9.14.1 is a patch release: the RBI compliance audit export accepts PDF and XLSX, and enterprise-only source is removed from the public community distribution with its license header corrected to BUSL-1.1.
AxonFlow v9.14.0 Release Notes
AxonFlow v9.14.0 adds jurisdiction-selectable compliance reports behind one asynchronous API with real PDF, CSV and XLSX renderers, rebuilds the portal compliance page around an honest three-state contract, completes the Indonesia (OJK, BI, UU PDP) export data set, and ships the first segment-scoped policy increment on the agent static plane.
AxonFlow v9.13.0 Release Notes
AxonFlow v9.13.0 is the output of a cross-tenant remediation programme. It binds governed-plane principals and tenancy to the validated credential instead of the request body, scopes pre-authentication lookups so they work on the least-privilege database posture, validates DEPLOYMENT_MODE at boot, adds authentication to the orchestrator API, and unifies nine SSRF egress classifiers onto one range table.
AxonFlow v9.12.2 Release Notes
AxonFlow v9.12.2 is a security patch release: it restores static-policy enforcement at the request and response content gates on deployments running the hardened least-privilege database posture (app-role), makes the policy engine fail closed on an empty system policy set, write-locks the global baseline policies against tenant callers, and isolates the HITL approval queue per organization.
AxonFlow v9.12.1 Release Notes
AxonFlow v9.12.1 is a patch release for deployments running the hardened least-privilege database posture (app-role): it restores tenant dynamic-policy enforcement at workflow gates, portal session persistence, RBAC permission checks, policy read-back, and execution visibility, and adds one small database migration.
AxonFlow v9.12.0 Release Notes
AxonFlow v9.12.0 turns the five-role RBAC model (owner, admin, policy_admin, developer, viewer) into real, enforced authorization: distinct per-role behavior, RBAC-gated policy editing, an owner bootstrap and lifecycle (assign, revoke, last-owner protection), permission-driven response PII, a first-class JumpCloud SSO/OIDC preset, and a tokens column on the audit-export CSV.
AxonFlow v9.11.0 Release Notes
AxonFlow v9.11.0 makes inline prompt-DLP work on streaming LLM chat, closes a class of governance-signal gaps where a matched PII policy could still return a bare allow, lets a headers-only enforcement seam apply an org-chosen posture when it cannot mask a body, and fixes the Path B / SSO org-key and per-org role-seeding gaps that blocked fleet OIDC and SCIM role mapping.
AxonFlow v9.10.0 Release Notes
AxonFlow v9.10.0 delivers per-user identity and role-scoped authorization for fleet deployments: fleets that share one org:license credential now get validated per-user identity and role, cross-user audit/decision/override/cost/execution reads are scoped to the caller's own rows unless they hold an admin role, and a shared-credential caller without a per-user token fails closed to zero rows.
AxonFlow v9.9.0 Release Notes
AxonFlow v9.9.0 unifies per-user audit attribution across all four governance planes behind an opt-in trust gate (AXONFLOW_TRUST_IDENTITY_HEADERS), and closes a forged-identity session-override hijack where one governed user could apply another user's active override to flip a blocked request to allowed.
AxonFlow v9.8.0 Release Notes
AxonFlow v9.8.0 adds Enterprise agentgateway/Envoy PEP adapters (ExtMcp, ext_authz, ext_proc) so a gateway data plane can consult AxonFlow as its Policy Decision Point, retypes every timezone-naive timestamp column to TIMESTAMPTZ, and reconciles the published API reference with the shipped platform.
AxonFlow v9.7.0 Release Notes
AxonFlow v9.7.0 adds Enterprise per-client version-distribution telemetry and hardens the enforcement planes: the response-leg redaction signal on check-output, a fail-closed request plane on policy-load errors, no connector data on blocked gateway pre-checks, and the portal's session drill-down wired end to end.
AxonFlow v9.6.1 Release Notes
AxonFlow v9.6.1 is a patch on v9.6.0 that fixes the audit-search API silently dropping a session_id filter, so the session-summary per-session drill-down now returns exactly the requested session's records.
AxonFlow v9.6.0 Release Notes
AxonFlow v9.6.0 turns the Claude Code and Cowork activity v9.5.0 began ingesting into reporting: a new session-summary API rolls governed activity into per-session buckets enriched with usage metrics, a new operator Grafana dashboard visualizes that usage, and provisioned Grafana datasources now carry stable uids.
AxonFlow v9.5.0 Release Notes
AxonFlow v9.5.0 ingests the native OpenTelemetry stream from Claude Code and Claude Cowork: a new /v1/metrics endpoint lands usage counters as governed records, the log-ingest plane attributes activity to the acting developer, and both ingest planes make rejected exports diagnosable.
AxonFlow v9.4.0 Release Notes
AxonFlow v9.4.0 scopes execution-class detectors to the tools that can execute them, hardens the operation detectors against documentation false positives, makes response-plane redaction fail closed, and fixes decision-chain persistence.
AxonFlow v9.3.1 Release Notes
AxonFlow v9.3.1 is a patch that lets policy action overrides and organization-tier static policies be created on deployments whose organization id is not UUID-shaped.
AxonFlow v9.3.0 Release Notes
AxonFlow v9.3.0 adds per-developer and per-session identity on the audit record, a filterable audit-logs portal with report and export, Cowork/Claude Code OTEL ingest, and a per-integration decision dashboard.
AxonFlow v9.2.2 Release Notes
AxonFlow v9.2.2 adds PII redaction on the check_policy allow path and updates Java example dependencies.
AxonFlow v9.2.1 Release Notes
AxonFlow v9.2.1 is a maintenance patch on v9.2.0 that registers the three audit-verification endpoints in request-path normalization so their telemetry
AxonFlow v9.2.0 Release Notes
AxonFlow v9.2.0 adds read-only MCP posture, tamper-evident audit signing, SIEM export, and cross-border transfer-basis stamping.
AxonFlow v9.1.1 Release Notes
AxonFlow v9.1.1, a security-only maintenance patch, refreshes the container base images to clear an upstream OpenSSL CVE, adds defense-in-depth hardening
AxonFlow v9.1.0 Release Notes
AxonFlow v9.1.0 — a CI gate that keeps every policy enforcement point auditable, the last unaudited denial paths closed, an authoritative built-in policy
AxonFlow v8.7.0 Release Notes
AxonFlow v8.7.0 — audit-trail consolidation onto a canonical decision record (decision_id, plane, correlation chains), per-organization detection posture
AxonFlow v8.6.0 Release Notes
AxonFlow v8.6.0 — Decision Mode PII governance hardening — a PII validator-assignment fix that restored email/phone/IP detection for every tenant, request
AxonFlow v8.5.2 Release Notes
AxonFlow v8.5.2 — the MCP plugin connection now works on self-hosted and Enterprise agents (no more "axonflow failed / OAuth 404"), the audit summary
AxonFlow v8.5.1 Release Notes
AxonFlow v8.5.1 reconciles licensed tier state at boot and adds a fail-closed dev-mode token endpoint for non-production deployments.
AxonFlow v8.5.0 Release Notes
AxonFlow v8.5.0 — Decision Mode request-context propagation and durable audit persistence, UU PDP Pasal 56(b) transfer-basis tag, wired OJK cross-border
AxonFlow v8.4.0 Release Notes
AxonFlow v8.4.0 — OpenAI-compatible gateway, self-hosted deployment alignment with production CFN, axonflow-install bundled OTel + Tempo stack.
AxonFlow v8.3.0 Release Notes
AxonFlow v8.3.0 — Indonesia PII detection, OJK compliance module, OTel observability exporters for Datadog and Grafana.
AxonFlow v8.2.0 Release Notes
AxonFlow v8.2.0 — Decision Mode (PDP/PEP policy decision service), OTel decision tracer, and ecosystem integrations.
AxonFlow v8.1.0 Release Notes
AxonFlow v8.1.0 — HITL outbound webhook (notify_url) + HTTP Idempotency-Key dedup. Two additive features, no breaking changes.
AxonFlow v8.0.1 Release Notes
AxonFlow v8.0.1 patch release — CI green on the v8.0.0 community mirror. No platform behavior change, no migration impact, no SDK or plugin floor change.
AxonFlow v8.0.0 Release Notes
AxonFlow v8.0.0 — Row-Level Security default-on. Agent connects as `axonflow_app_role` (NOBYPASSRLS); SDKs, plugins, and HTTP API consumers unchanged.
AxonFlow v8.0.0 Operator Notes
Enterprise v8.0.0 release notes covering boot guards, portal API changes, auth bootstrap helpers, tenant-delete routing, and upgrade details.
AxonFlow v7.9.0 Release Notes
AxonFlow v7.9.0 adds decision listing, MCP recent-decision lookup, telemetry schema updates, salted IP hashing, and quota attribution fixes.
AxonFlow v7.8.0 Release Notes
AxonFlow v7.8.0 adds Plugin Pro limits, five MCP tools, daily-cap routing, success flags, telemetry stream labels, and a thrift CVE patch.
AxonFlow v7.7.0 Release Notes
AxonFlow v7.7.0 — V1 SaaS Plugin Pro launch ($9.99 / 90 days), free-tier credential recovery, license matrix, GDPR right-to-erasure.
AxonFlow v7.6.1 Release Notes
AxonFlow v7.6.1 rejects critical-policy overrides, fixes empty audit search results, and supports companion plugin read tools.
AxonFlow v7.5.0 Release Notes
Production + security hardening. SDK v7.0.0 and plugin v1.0.0/v2.0.0 majors, 7-day delivered-heartbeat, Community-SaaS lifecycle, /health plugin compat.
AxonFlow v7.4.5 Release Notes
Org-identity propagation fixes on the MAP execution path so /api/v1/executions returns rows and policy evaluation cannot be overridden by request body.
AxonFlow v7.4.4 Release Notes
CreateOverrideResponse schema split — separates create-time TTL clamping fields from the at-rest PolicyOverride entity. Documentation-grade.
AxonFlow v7.4.3 Release Notes
Plugin Batch 1 spec corrections — MCPCheckInputResponse +5 fields, MCPCheckOutputResponse +3 fields, three new explainability schemas added.
AxonFlow v7.4.2 Release Notes
Platform v7.4.2 OpenAPI corrections plus v6 SDK alignment — TS v6.0.0 PolicyInfo rename, Java v6.0.0 entity equality, Python v6.7.0, Go v5.7.0.
AxonFlow v7.4.1 Release Notes
Portal HITL + audit trail visibility patch — approver/rejector identity, Compliance Summary card aggregates, audit_logs emission, sidebar badge refresh.
AxonFlow v7.4.0 Release Notes
Platform v7.4.0 unifies WCP and MAP HITL responses, lowers MAP plan-scoped approve/reject to Evaluation tier, and adds a plan-scoped pending listing.
AxonFlow v7.3.0 Release Notes
Platform v7.3.0 adds retry_context on every gate response, idempotency_key on gate + complete, 409 mismatch, retry-aware tenant policies on Evaluation.
AxonFlow v7.2.1 Release Notes
AxonFlow v7.2.1 surfaces approved_by + approved_at on workflow step responses, exposes approval_id on gate responses, and fixes a Portal /approvals crash.
AxonFlow v7.2.0 Release Notes
Platform v7.2.0 Bug Bash Bonanza — MAP timeout parity, TENANT_REQUIRED fail-closed, login-enumeration fix, Customer Portal sweep, Java SDK 5.5.0.
AxonFlow v7.1.1 Release Notes
AxonFlow v7.1.1 fixes post-release parity gaps so explainability, overrides, audit filters, and richer plugin context work consistently across plugin paths.
AxonFlow v7.1.0 Release Notes
Platform v7.1.0 adds explainability, session overrides, workflow checkpoints, and richer plugin context across frameworks, SDKs, and coding assistants.