Skip to content

SaaS Release — 2026-08-03 to 2026-08-16

Window: 2026-08-03 → 2026-08-16

Kindo’s sign-in foundation is consolidated across email, social login, SSO, sessions, and API keys. Admins get a cleaner SAML setup path with service-provider metadata exposed in the SSO settings experience, while users get polished login screens and more consistent sign-in behavior.

The release also tightens API-key access controls so user-group restrictions are enforced consistently across request paths.

Command Center tabs and AI Spend reporting

Section titled “Command Center tabs and AI Spend reporting”

Command Center is organized into focused tabs for Agent Monitoring, Usage Statistics, Integrations, and AI Spend. Organization-level spend reporting is available from the same admin area as the rest of Command Center, with chart and layout updates that make the page easier to scan.

Kindo expanded the integration catalog and several high-priority connector surfaces:

  • Amazon S3, AWS CloudWatch, and CyberArk are available as new integration targets.
  • Okta includes write and create actions for users, groups, applications, policies, and policy rules.
  • Qualys includes Cloud Agent lifecycle coverage.

Standard integrations also return clearer authorization details when an API denies access, so users see the provider’s specific reason instead of a generic denial.

Resolved connector issues that blocked normal agent work:

  • Swimlane app and record tools handle valid app and record identifiers more reliably.
  • Wiz tool responses are normalized when the upstream server returns schema-incompatible output.

Model-provider errors are easier to triage when a customer-managed provider hits its own rate limits or failures. Error copy distinguishes provider-side failures from Kindo platform failures, helping users route the problem to the right administrator or model owner.

A multimodal Qwen model option is available for organizations that need Qwen-based model coverage for image and file inputs.

Continuing a historical agent run preserves the original integration connection context instead of switching to the viewer’s current connection. This keeps continued runs tied to the same connected account and data scope as the original run.

Resolved an issue where valid one-time sign-in codes and email links could be rejected as invalid or expired. Additional login polish improves button spacing, colors, and production copy across the consolidated sign-in experience.