Changelog

Product release history and version updates

Changelog

This page tracks Deslicer AI product releases. You see what's new, improved, and fixed in each version.


Release Format

Each release includes:

  • Date — Release date
  • Version — Semantic version (e.g., 1.2.0)
  • Summary — High-level overview
  • Features added — New capabilities
  • Improvements — Enhancements to existing features
  • Fixes — Bug fixes and stability improvements

Most Recent Release

Date: 2026-07-01 Version: 1.18.0 Summary: Splunk Observability Cloud MCP integration with three purpose-built Observability agents, DAP Platform product planes for Splunk Enterprise, worker uninstall and enterprise host decommission, and live async subagent streaming in chat.

Features added:

  • Splunk Observability Cloud integration — Connect agents to Splunk Observability through the hosted MCP Gateway. Query metrics, run SignalFlow, inspect APM services and traces, and search alerts. Configure realm and org access token from SettingsIntegrations. See Splunk Observability Cloud.
  • Observability purpose-built agents — Three new public agents: Observability SRE Copilot (on-call triage), Observability Platform Builder (dashboards, SLOs, synthetics), and Observability Cost & Cardinality Steward (MPM and FinOps). See Purpose-Built Agents.
  • Splunk Observability skills — Six new runtime skills for native ops, deep UI workflows, dashboard building, SLO setup, synthetics setup, and Metrics Pipeline Management. See Agent Skills.
  • DAP Platform planesPlatform now separates shared DAP Status and API Keys from the Splunk Enterprise worker plane with dedicated sub-tabs for install, credentials, enrollment, pending approvals, nodes, and inventory groups. See Platform Planes.
  • Worker bootstrap uninstall — Worker-enrolled node detail pages include Uninstall worker with script and manual command tabs for on-host cleanup. See Insights Nodes — Worker Uninstall.
  • Enterprise Host lifecycleEnterpriseHost lifecycle lets administrators decommission worker bootstrap enrollments per product plane, with optional purge of observed inventory. See Enterprise Administration — Host Lifecycle.

Improvements:

  • Live async subagent streaming — When the Orchestrator delegates to an async subagent task, tool calls and intermediate results stream into the subagent card and activity timeline while the task runs. See Chatting with Agents — Tool Activity Display.
  • Product-scoped DAP access — Enterprise roles can grant view or manage access per worker product plane without exposing enrollment and node management to members who only need shared DAP status.
  • Decommission deep links — Node detail pages link directly to Host lifecycle with the host pre-selected for enrollment removal.

Fixes:

  • Fixed async subagent tasks showing no live progress until the delegated agent completed
  • Fixed DAP platform pages not reflecting the shared-vs-product plane navigation model

Date: 2026-06-24 Version: 1.17.0 Summary: GitHub publish path rules per integration, richer DAP execution and plan lifecycle UX, compliance finding context, worker enrollment install options, and stronger tenant isolation for DAP and integrations.

Features added:

  • GitHub publish path rules — Each GitHub integration can define Allowed paths and Blocked paths so agents only publish to approved repository locations. Blocked patterns always win over allow rules. Configure from the GitHub integration editor or tool sheet. See GitHub Integration — Publish Path Rules.
  • Execution results drill-down — The execution detail page shows config files written to disk, per-key INI mutations inside each file, and Splunk actions (restart, bundle apply, rolling restart) with expandable success and failure output. See Executions — Execution Details.
  • Plan approval prerequisites — When Splunk credentials or worker enrollment prerequisites are missing, the Approve Plan dialog and in-chat confirmation cards show guided warnings with links to Splunk Credentials or Enrollment. See Change Plans — Approval Prerequisites.
  • Worker install options — After creating a Worker enrollment token, the install dialog offers Shell, Ansible, and Manual tabs with copy-ready snippets for each method.

Improvements:

  • Plans list accuracy — Plan status reflects the latest execution outcome when the stored plan status is stale (for example, showing Completed after a late success). Failed or partial plans expose a Retry action that re-queues only failed jobs.
  • Plans list execution column — Each plan row links to its latest execution with live progress hints (waiting for worker, jobs running, job counts).
  • Compliance current values — Security compliance findings show the live value, not set, redacted for sensitive settings, or inherited from the Splunk config layer that supplied the value.
  • Pending Approvals host facts — Expanded rows separate self-reported host facts (architecture, Splunk version, network) from server-captured metadata (source IP, token purpose, key TTL).
  • Enrollment tenant slug guard — Worker install snippets are blocked with a clear message until an enterprise administrator sets the tenant slug.
  • Chat send recovery — If a message fails to send before the chat session hands off to the streaming transport, your typed input is restored so you can retry without retyping.

Fixes:

  • Fixed DAP UI and integration tool configs leaking across tenants — each tenant now sees only its own DAP data and scoped integrations
  • Fixed plan approval from chat surfacing opaque errors when Splunk session prerequisites were incomplete
  • Fixed execution event logs showing stale output after a job retry on the same host

Date: 2026-06-17 Version: 1.16.0 Summary: Deslicer Automation Copilot Observe→Automate skills, Splunk execution credentials for plan rollout, and execute-readiness checks that verify credential coverage before deployment.

Features added:

  • Splunk execution credentials — A new Splunk Credentials page under DAP Platform lets you store Splunk management credentials for plan execution. Scope credentials as tenant default, host group, or specific host. Test connections, edit labels and secrets, and view last validation time. See Splunk Execution Credentials.
  • Plan execute readiness — The Execute dialog on approved plans checks that credentials cover every targeted host before rollout begins. Missing coverage shows an amber warning with a link to configure credentials. See Change Plans — Splunk Credential Readiness.
  • Deslicer Automation Copilot Observe→Automate skills — Four new runtime skills codify the fleet co-pilot workflow: Observe Fleet Audit (read-only posture review), Investigate Config Drift (peer comparison with evidence), Resolve Plan Target Group (blast-radius confirmation before plan creation), and Plan Lifecycle (HITL) (approve, execute, monitor, and retry existing plans). Pre-attached to the Deslicer Automation Copilot. See Deslicer Automation Copilot and Agent Skills.

Improvements:

  • Credential scope hierarchy — Host-scoped credentials override group credentials, which override tenant defaults. Plan execution evaluates the most specific match available for each targeted host.
  • Per-host plan targeting — Compliance and remediation plans that attach changes to individual hosts are checked against those hosts specifically, with fallback to the plan's host-group credential or tenant default when per-host credentials are absent.
  • Deslicer Automation Copilot — Public agent seed updated with fleet audit, drift investigation, target-group resolution, and plan lifecycle skills plus matching insight and plan-diff tools.

Fixes:

  • Fixed plan execute blocking when only a tenant default credential exists but individual hosts lack host-scoped entries
  • Fixed plan execute readiness not falling back to host-group credentials for uncovered per-host targets
  • Fixed plan execute proceeding without Splunk management credentials configured for all plan target hosts

Date: 2026-06-15 Version: 1.15.0 Summary: Policy-controlled enrollment approvals, DAP inventory group assignment with configuration-driven role suggestions, GDI v7 post-onboarding orchestration, unified Splunk Data Input Monitoring agent, Splunk Environment Documenter, app inventory host comparison, and compliance evaluation improvements for large fleets.

Features added:

  • Pending Approvals — A new Pending Approvals page under DAP Platform lets you review and approve enrollment requests before hosts receive credentials. Insights and Worker enrollments flow through a shared pipeline; tenant policy decides auto-approve vs. manual review. Approve or reject individually or in bulk, then assign approved hosts on Inventory Groups. See Pending Approvals.
  • Inventory Groups — A new Inventory Groups page maps enrolled hosts to Splunk inventory roles and availability groups. Configuration-driven role suggestions appear for unassigned hosts with bulk-apply support. See Inventory Groups.
  • GDI Agent v7 — Evolved onboarding agent with post-onboarding handoffs to Deslicer Automation Copilot (governed DAP deploy), Splunk Value Architect (use-case and compliance reports), and Splunk Data Input Monitoring (scheduled ingestion checks). Includes Splunk Cloud ACS setup and inline compliance/MITRE coverage before deploy. See GDI Agent v7 and Data Onboarding.
  • Splunk Data Input Monitoring — Unified agent for ingestion presence (freshness, volume, staleness) and data quality / CIM conformance. Builds input-health dashboards, creates per-dataset scheduled monitors, and opens HITL-gated remediation drafts. See Splunk Data Input Monitoring.
  • Splunk Environment Documenter — Living documentation agent that collects fleet topology, inputs, indexes, and drift, then publishes chapterized markdown with Mermaid diagrams to GitHub via pull request. See Splunk Environment Documenter.
  • App inventory host comparison — The Apps insights page now has a Compare hosts tab. Select two or more hosts to see shared apps and per-host deltas. See Insights Dashboard — App Inventory.
  • Worker and Insights enrollment tokens — The Enrollment page lets you create separate tokens for Insights (Splunk add-on) and Worker Node purposes, with purpose-specific install instructions.

Improvements:

  • Enrollment page redesign — Token table supports search, sort, pagination, and displays token type, enrolled hostnames, and purpose-specific install snippets.
  • Compliance evaluation performance — Large-fleet compliance audits run server-side with cached results and explicit refresh, avoiding timeouts on fleets with 100+ hosts.
  • Worker host handling — Worker-bootstrap hosts show a Worker badge on the Nodes page and are excluded from compliance scoring and inputs coverage denominators (expected zero-state, not errors).
  • Compliance host filter — Host filter on the Security insights page resets when you switch tenants.
  • Inputs Coverage refresh — Inputs insights page adds host filtering, grouped input-type view, and manual refresh.
  • New agent skills — Splunk Data Input Tracking, Splunk Environment Documentation, Deploy GDI App via Git, Deploy GDI Config as Draft, and Remediate Compliance Finding. See Agent Skills.

Fixes:

  • Fixed compliance host filter persisting stale selections after tenant switch
  • Fixed worker-origin hosts incorrectly included in compliance evaluation
  • Fixed MCP tool config tenant access validation in scheduled monitor creation

Date: 2026-05-29 Version: 1.14.0 Summary: Splunk data sizing tools for estimating ingest volume, storage, and license tiers. @-mentions for routing prompts to specific subagents and workflows. Integration approval cards for on-demand tool enablement during chat. Splunk 10.x compliance baseline support. Launch discount removal with standard pricing.

Features added:

  • Splunk Data Sizing Tools — The Splunk Monitoring Use Cases integration now includes data sizing tools that estimate Splunk ingest volume (GB/day), events per second (EPS), raw and compressed storage, and recommended license tiers. The embedded catalog covers 206 source profiles across nine categories (Security, IT, OT, Network, Protocols, Business, Cisco Products, OT Vendor Systems, OT Hardware), with support for both endpoint-typed sources (firewalls, hosts, IDS) and protocol-typed sources (Modbus, OPC UA, MQTT, SNMP). The Splunk UC Catalog agent can now answer questions like "How much data will 10 Palo Alto firewalls generate?" and "What license tier do I need for 200 GB/day?" See Data Sizing.
  • @-mentions for subagents and workflows — Type @ in the Orchestrator chat input to open a palette of available subagents and workflows. Select a target to route your prompt directly to it instead of relying on automatic routing. Mention multiple targets in a single prompt. In single-agent chat, @-mentions let you reference other agents. See Chatting with Agents — @-Mentions.
  • Integration approval cards — When an agent needs a tool from an integration not currently enabled, an approval card appears in the chat. You choose which configuration to use, whether to enable it for the current session only or permanently save it to the agent, and approve or deny the request. See Chatting with Agents — Integration Approval Cards.

Improvements:

  • Splunk 10.x compliance support — Compliance evaluation now works for hosts running Splunk 10.x. When a dedicated 10.x baseline profile is available, it is used automatically. Otherwise, the system falls back to the 9.x hardening baseline with a log entry noting the fallback, so compliance audits no longer fail with "No compliance baseline available." See Security Compliance.
  • Orchestrator loading experience — The Orchestrator chat start page now shows a centered logo animation while loading, with suggestion groups revealing in stages for a smoother visual experience.
  • Standard pricing — Standard plan pricing is €70/month and Enterprise plan pricing is €150/month. Launch discounts have been retired.
  • Subagent integration enablement — Subagent agents spawned by the Orchestrator can now inherit integration tools from the parent, with approval cards propagated to the user when a subagent requests access to an unapproved integration.

Fixes:

  • Fixed compliance tab returning 403 for owner and admin users due to missing platform permissions in the database
  • Fixed mobile chat input scrolling not anchoring correctly when the keyboard appears
  • Hardened Supabase security advisor findings — enabled RLS on exposed public tables and restricted direct Data API access

Date: 2026-05-25 Version: 1.13.0 Summary: Enterprise Inventory Management for organizing Splunk fleet topology via groups, roles, and catalog templates. Multi-tenant orchestrator chat for sending prompts across multiple tenants in parallel. Landing page redesign with interactive marketing video and use case showcase. Workspace admin quick links for enterprise users.

Features added:

  • Enterprise Inventory Management — A new Inventory page under the Enterprise section lets you organize your Splunk fleet into logical groups mapped to DAP roles (cluster peers, search heads, forwarders, deployment servers, and more). Create groups, assign enrolled hosts, apply topology templates from the platform catalog, and manage fleet structure per tenant and environment. Templates define complete topologies by indexing tier (Single, Distributed, Clustered, Multi-cluster) with configurable role selection, cluster counts, and availability groups. See Enterprise Inventory.
  • Multi-tenant Orchestrator — The Orchestrator chat now supports multi-lane mode for enterprise users with multiple tenants. Select up to three tenants from the Tenant Switcher, type a single prompt, and it fans out to all selected tenants simultaneously. Each tenant runs in its own parallel lane with independent status indicators, and results appear side by side. See Multi-Tenant Orchestration.
  • Landing page redesign — The homepage now features an interactive marketing video with play/pause controls, a scrubber timeline, timestamp display, hover-revealed sound toggle, and fullscreen mode. A new Use Cases section showcases DAP Insights alongside existing capabilities. The previous chat demo has been replaced by the video player.
  • Workspace admin quick links — Enterprise users with administrative capabilities now see a Workspace administration card on the General dashboard page with shortcuts to Tenants, Teams, Members, Roles, and Settings. Links are capability-gated — you only see sections you can manage. See Enterprise Administration.

Improvements:

  • Landing page video controls — The hero video includes a scrubber bar, play/pause toggle, elapsed/total timestamps, a hover-revealed sound button, and fullscreen support for a polished viewing experience.
  • DAP Insights use case tab — The landing page Use Cases section now includes a DAP Insights tab demonstrating fleet observability alongside the existing Splunk automation showcases.
  • Inventory template tier selection — Catalog templates are organized by indexing tier with role dependencies, conflicts, and required roles clearly displayed before application.
  • MCP flow diagram theming — The landing page MCP architecture diagram now respects the active color scheme for consistent brand presentation.

Fixes:

  • Fixed hero video play() AbortErrors that could appear in the console when switching tabs during playback
  • Fixed R2 video host not being passed into the Docker web image build, causing video embeds to fail in deployed environments

Date: 2026-05-20 Version: 1.12.0 Summary: Agent Reports for compiling structured documents from conversations and generating periodic rollups, custom budget cap controls, DAP plan target group visibility with member host lists, HITL confirmation card deep links back to DAP, and improved billing plan name display.

Features added:

  • Agent Reports — Compile structured, shareable reports directly from any agent conversation. A Compile Report button in the chat toolbar triggers the report compiler; a progress card appears inline while the report streams, and you click through to a dedicated report canvas when ready. Reports support Share links, PDF export, and one-click Regenerate. See Reports.
  • Rollup reports — Generate weekly or monthly summaries of agent activity for yourself or your entire team. The Your Reports card on the dashboard home page lists your recent reports and offers a Generate rollup menu with four options: My week, Team week, My month, and Team month. See Reports.
  • Custom budget cap — Set a monthly spending limit for your team's AI usage from the Billing page. Enter a dollar amount and save, or leave blank to remove the hard cap. When the cap is reached, chat and scheduled tasks pause until the next cycle. See Credits and Usage — Custom Budget Cap.
  • DAP plan target group visibility — The plan detail sidebar now displays the target group name, ID, and a list of member hosts with links to their node detail pages. Plans without a target group show an explanatory note. Empty groups display a warning. See Change Plans — Target Group and Host Visibility.
  • HITL confirmation card deep links — After a DAP confirmation card resolves (approved or already terminal), a View in DAP link appears that opens the affected plan or execution directly in the Automation Platform. See DAP Confirmation Cards.

Improvements:

  • Credit-depleted banner shows plan name — When your budget is exhausted, the banner in the chat interface now displays your actual plan name instead of a generic label.
  • HITL card terminal state stability — Confirmation cards that have already been resolved (approved, cancelled, expired, or already-terminal) now render as stable, non-interactive pills on page refresh or scroll-back, preventing stale clickable cards from appearing.
  • 409 conflict handling for HITL — When a DAP action has already been completed by another user or process, the confirmation card shows the current status with context instead of a generic error, so you know exactly where the resource stands.
  • Insights suggestion prompts — The Orchestrator chat start page now includes suggestion prompts that help you get started with fleet insights queries.

Fixes:

  • Fixed credit-depleted banner showing a generic plan label instead of the team's actual plan name
  • Fixed DAP confirmation cards showing stale interactive state after the underlying action was already resolved

Date: 2026-05-18 Version: 1.11.0 Summary: Human-in-the-loop (HITL) confirmation cards for all destructive DAP actions, inline plan drafting from agent chat, cross-provider web search reliability improvements, new Claude 4.7 Opus default model, and certificate search improvements.

Features added:

  • DAP confirmation cards — All destructive Automation Platform actions now require explicit approval via interactive confirmation cards in the agent chat. When a DAP agent proposes an action — approving a plan, executing a rollout, deleting a plan, revoking an enrollment token, modifying host groups, or any other sensitive operation — a confirmation card appears showing the action name, description, and target identifiers (plan ID, host ID, group name). You click Approve or Cancel directly in the chat. Cards expire after 10 minutes and can be re-issued on request. See DAP Confirmation Cards.
  • Inline plan drafting — DAP agents can now author remediation change items directly in the chat and submit them as plan drafts. The confirmation card displays every change item in a structured layout grouped by host, app, config file, and stanza, with change type sigils (+ addition, ~ modification, - deletion) so you can audit every proposed change before approving. Oversize drafts that cannot be fully displayed are automatically rejected — the agent splits them into smaller drafts. See Inline Plan Drafting.
  • Claude 4.7 Opus — Anthropic's latest frontier model is now available and set as the default model for new agents. Supports web search, 1M context window, and agentic workflows. See Supported AI Models.

Improvements:

  • Cross-provider web search reliability — Web search now works more reliably across all supported providers (OpenAI, Anthropic, Google, xAI). Quota errors and transient failures are handled gracefully with automatic fallback, so agents recover without interrupting your conversation.
  • Certificate search defaults to 30-day window — The search_certificates tool now defaults to a 30-day expiry window when no explicit threshold is specified, giving agents a practical default for certificate monitoring.
  • Updated model catalog — Added GPT-5.5, GPT-5.4, GPT-5.4 Nano, GPT-5.3 Chat, and GPT-5.3 Codex from OpenAI; Claude 4.7 Opus from Anthropic; Gemini 3 Pro and Gemini 3 Flash previews from Google. See Supported AI Models.
  • App Deployment Agent seed updated with improved instructions for compliance remediation and fleet management workflows

Fixes:

  • Fixed certificate search filtering by incorrect host identifier — results now correctly match the host agent UUID
  • Fixed web search quota errors surfacing as unhandled exceptions instead of graceful error messages
  • Fixed LiteLLM reset_budget_job failing with a Prisma error when filtering nullable JSON fields

Date: 2026-05-12 Version: 1.10.1 Summary: Skill sandbox security hardening with input file sanitization, supply-chain protection via pinned sandbox images, and improved on-premise startup resilience when the OpenTelemetry Collector is unavailable.

Improvements:

  • Skill input file sanitization — Skills that accept user-provided data files now enforce strict validation before execution. Only data-file extensions (.txt, .md, .json, .yaml, .csv, .xml, .html, .log, and others) are accepted. Executable extensions (.py, .js, .ts, .sh) are rejected to prevent untrusted code from running inside the sandbox. Path traversal (../) and absolute paths are also blocked. See Agent Skills.
  • Pinned sandbox image — The skill execution sandbox container is now pinned to a specific SHA256 image digest instead of a floating tag, protecting against supply-chain attacks via tag manipulation.
  • On-premise startup resilience — The application no longer requires the OpenTelemetry Collector to be healthy before starting. If the OTel Collector is temporarily unavailable during startup, the application starts normally and telemetry forwarding resumes once the collector is reachable. See On-Premise Deployment.

Fixes:

  • Fixed Piston sandbox health check using an unavailable binary — the check now uses python3 which is available in the container image

Date: 2026-05-11 Version: 1.10.0 Summary: ITSI toolset toggle for Splunk MCP, Splunk Monitoring Use Cases catalog integration with a new Splunk UC Catalog agent, conversation artifacts with download support, and improved orchestrator reliability for long-running agent sessions.

Features added:

  • ITSI toolset toggle — The Splunk MCP integration now includes an optional IT Service Intelligence (ITSI) toggle. Enable it to give agents access to 70+ ITSI tools for service health monitoring, KPI analysis, episode investigation, and notable event management. Uses the same Splunk credentials — no extra configuration. Available in both the integration editor and the welcome onboarding wizard. See Splunk MCP — ITSI Tools.
  • Splunk Monitoring Use Cases — A new read-only catalog integration that lets agents browse Splunk monitoring use cases by category, sourcetype, CIM data model, compliance regulation (GDPR, PCI-DSS, HIPAA, NIST), and MITRE ATT&CK technique. Includes compliance gap analysis and coverage scoring. No Splunk connection required — the catalog is hosted externally. See Splunk Monitoring Use Cases.
  • Splunk UC Catalog agent — A new purpose-built agent pre-configured with the Splunk Monitoring Use Cases integration. Ask it to find monitoring scenarios for your data sources, check compliance coverage, or identify MITRE ATT&CK gaps. See Purpose-Built Agents — Splunk UC Catalog.
  • Conversation artifacts — Agents now store large outputs (configuration files, reports, data exports) as downloadable artifacts instead of pasting them inline. The subagent detail dialog includes an Artifacts tab listing each file with its title, type, size, and summary. Click Download to save any artifact. See Chatting with Agents — Artifacts.

Improvements:

  • Orchestrator sessions are more reliable during long-running delegations — an internal wait bridge reduces unnecessary polling, and context window management automatically compresses older tool results to prevent token exhaustion
  • Subagent detail dialog now includes tabbed views for Instructions, Results, tool trace, and Artifacts for better visibility into delegated work
  • Enterprise pricing page updated with Splunk Cloud (Contact Sales) line item and Standard to Elite support SLAs

Fixes:

  • Fixed MCP tool argument normalization that caused Pydantic validation errors on some integrations
  • Fixed expected MCP tool errors being incorrectly reported to Sentry error tracking
  • Patched LiteLLM container for urllib3 CVEs (pip security update)

Date: 2026-05-07 Version: 1.9.0 Summary: DAP API Keys management for self-service Observer API key creation, Enterprise Administration console for organization-wide member, role, tenant, and governance management, integration allowlist for controlling which integrations are available to members, and improved tool display in agent chat.

Features added:

  • DAP API Keys — A new API Keys tab on the DAP Platform page lets you create, manage, and revoke Observer API keys directly from the dashboard. Choose from three scopes: read (view-only), tools (AI agent and automation), or admin (full control). The optional Connect to AI integration setting automatically wires a key into your Deslicer AI integration so agents can call DAP tools without manual configuration. See API Keys.
  • Enterprise Administration console — Enterprise plan subscribers now have a dedicated admin console accessible from the Enterprise sidebar section. The console includes member management (invite, suspend, remove, bulk actions), role management with presets (Enterprise Admin, Tenant Admin, Member, Auditor), tenant and team management, governance policies (SSO, JIT elevation, audit trail, domain allowlist), audit log with CSV export, and organization settings. See Enterprise Administration.
  • Integration allowlist — Enterprise admins can restrict which integration templates are available across the organization. Switch between All integrations (default open) and Restricted mode to explicitly allow or block specific integration types. Smithery marketplace integrations support wildcard allowlisting. See Enterprise Administration.

Improvements:

  • Agent chat now shows readable tool names for dynamically routed integration tools — you see the actual tool name (e.g., "Search Splunk") instead of internal routing labels
  • MCP-prefixed tool names in the activity timeline display shortened, human-readable labels
  • Subagent activities appear as compact cards with live status tracking, elapsed time counters, and expandable activity timelines
  • DAP API key creation includes Observer compatibility detection — if the tools scope is not supported by your Observer version, a clear message guides you to upgrade or use read instead
  • Enterprise role presets provide quick-start configurations when creating new roles with pre-selected capabilities

Fixes:

  • Fixed enterprise integration allowlist scope enforcement for edge cases where restricted integrations could bypass the policy
  • Fixed DAP proxy admin-gating for API key list requests to enforce tenant:manage consistently

Date: 2026-04-30 Version: 1.8.0 Summary: AI Safety & Guardrails for organization-wide LLM prompt and completion protection, DAP self-repair and connectivity management, Deslicer App Registry v2 tools for deep Splunkbase inspection, and improved scheduled task budget controls.

Features added:

  • AI Safety & Guardrails — A new guardrails management page under Security Settings lets you create, test, and enforce safety rules on every LLM request across your organization. Guardrails mask sensitive data (PII, emails, phone numbers) or block prompts that violate compliance policies. Includes pre-built templates, custom policy builder, single-guardrail and end-to-end testing, real-time monitoring with per-request logs, and team permission controls. See AI Guardrails & Policies.
  • DAP self-repair — The DAP Platform page now lets you repair a degraded connection with a single click. The Reconnect Integration button re-provisions the backend connection without losing enrolled nodes or change plan history. A Support Contact Card displays diagnostic details (tenant ID, Observer API URL, HTTP status, error message) you can share with your administrator. See Getting Started with DAP.
  • DAP connectivity warnings — When the DAP backend is unreachable, an amber warning banner appears at the top of Insights, Plans, and Execution pages linking to the Platform page for diagnostics and repair.
  • Deslicer App Registry v2 — The Splunkbase integration now includes expanded registry tools: inspect individual files inside release archives, discover app capabilities (sourcetypes, inputs, dashboards), look up Splunk Enterprise and Universal Forwarder builds by version and architecture, check trust and vetting status, and query index health. See Splunkbase & App Registry.

Improvements:

  • Scheduled task budget banner now displays a visual progress bar with current spend and maximum budget (e.g., $7.50 / $10.00) — warning state shown in amber, exhausted state in red with disabled task controls
  • DAP error states show structured diagnostics with HTTP status codes, support reference IDs, and links to Open DAP Platform for self-service repair
  • DAP provisioning automatically probes both internal and public Observer API URLs side-by-side for faster troubleshooting
  • DAP backend management in platform admin now supports backend delete, structured save errors, and auto-reconciliation on page load

Fixes:

  • Fixed LiteLLM team list reconciliation failing on transient API errors — retries are now applied automatically
  • Fixed scheduled task claim service returning tasks already claimed by another worker in concurrent execution scenarios

Date: 2026-04-25 Version: 1.7.0 Summary: Scheduled Agent Tasks for automated recurring agent runs, plan-driven budget caps with trial spending limits, DAP plan diff viewer with Monaco editor, and DAP provisioning improvements including enrollment validation and node connectivity probing.

Features added:

  • Scheduled Agent Tasks — Automate recurring agent runs with cron-style schedules. Create tasks from the new Scheduled Tasks page or directly from an agent card. Each task runs an agent with a specific prompt on a defined schedule, delivering results to your conversation history or via email. You can pause, resume, edit, delete, and trigger tasks manually with Run Now. Run history shows status, duration, token usage, cost, and tool calls. A budget banner warns when your team's usage budget is exhausted. See Scheduled Agent Tasks.
  • Plan-driven budget caps — Trial users now have an automatic €10 spending cap during the 7-day trial period. Paid-tier users receive higher or unlimited budget caps aligned with their plan. Budget enforcement applies to both chat sessions and scheduled tasks. See Credits and Usage.
  • DAP plan diff viewer — Config change plans now display a side-by-side Monaco diff editor showing the original and proposed values for each changed file. You can expand individual change items to see the full diff with syntax highlighting for Splunk .conf files.

Improvements:

  • DAP enrollment page now validates backend connectivity and shows provisioning status before onboarding nodes
  • DAP nodes page includes enhanced connectivity probing with status indicators for each enrolled node
  • DAP executions page shows improved run detail with expanded metadata
  • Agent cards and list view now include a Schedule button linking directly to the Scheduled Tasks page pre-filtered to that agent
  • Dashboard sidebar includes Scheduled Tasks entry under the main navigation
  • Trial-period billing caps are enforced consistently across both email/password and OAuth signup flows

Fixes:

  • Fixed LiteLLM budget sync clearing budget_duration and soft_budget on plan transitions — paid users no longer lose their budget configuration when changing plans
  • Fixed hotfix script incorrectly bumping trial users to unlimited budget caps
  • Fixed trial spending cap not applying to Standard and Enterprise subscriptions during the trial period

Date: 2026-04-14 Version: 1.6.0 Summary: On-premise deployment, native web search for agents, Dashboard Studio skill, OIDC authentication with automatic team provisioning, and SMTP email support. Deslicer can now run entirely within your own infrastructure.

Features added:

  • On-premise deployment — run Deslicer AI within your organization's network using Docker Compose. The on-prem stack includes PostgreSQL with pgvector, LiteLLM proxy, Redis, and OpenTelemetry. All users get enterprise-tier features with billing disabled. See On-Premise Deployment.
  • OIDC authentication — on-premise deployments authenticate users through your Identity Provider (PingIdentity, Okta, Azure AD, Keycloak, or any OIDC-compliant provider). Users sign in via Sign in with your organization and are redirected to your IdP. A local admin account is available for setup and fallback access. See Creating Your Account.
  • Automatic team provisioning — when your IdP sends group claims during OIDC login, Deslicer automatically creates organizations and teams based on those groups. The first user in a group becomes the owner; subsequent users join as members.
  • Native web search — agents with web search enabled now use provider-native search tools (OpenAI, Anthropic, Google, xAI). The system selects the best web search implementation based on the agent's model. See Chatting with Agents.
  • Dashboard Studio skill — a new skill that guides agents through building Splunk Dashboard Studio dashboards. The agent follows a structured workflow: gather context, construct JSON definitions, apply theming (including Deslicer brand defaults), deploy to Splunk via MCP, and verify. See Agent Skills.
  • SMTP email provider — on-premise deployments send invitation and notification emails through your organization's SMTP server instead of the managed cloud email service.
  • Air-gapped installation — export Docker images on a connected machine and install on-premise without internet access.

Improvements:

  • Web search reliability improved for Anthropic models — the system routes around proxy limitations when web search is active
  • Orchestrator task and plan rendering improved — structured plans, task lists, and progress updates display more clearly in the chat interface
  • Dashboard layout now shows recent conversations with scroll-to-load and pending team invitations in the sidebar
  • Auth error page now displays clear error messages with a retry button and guidance to contact IT

Fixes:

  • Fixed chat transport reconnection handling for improved session stability
  • Fixed subagent switcher and workflow switcher display in the chat start view

Date: 2026-04-02 Version: 1.5.0 Summary: Three new agent skills (Splunk Alerting, Dashboard Studio, DAP Onboarding), DAP security compliance auditing with baseline profiles and remediation plans, DAP inputs inventory, enhanced plan detail pages with dry-run previews, live workflow progress tracking in chat, and improved agent cloning.

Features added:

  • Splunk Alerting skill — a new skill that guides agents through creating, managing, and troubleshooting Splunk alerts. Covers scheduled and real-time alerts, trigger conditions, throttling and suppression, and alert actions (email, webhook, log event, CSV output). See Agent Skills.
  • Dashboard Studio skill — a new skill for building themed Splunk Dashboard Studio dashboards. Agents follow a structured workflow to construct JSON definitions with 20+ visualization types, data sources, inputs, tokens, dynamic options syntax, and layout configuration with Deslicer brand theming. See Agent Skills.
  • DAP Onboarding skill — a new skill that structures Git repositories for Splunk app deployment via the Deslicer Automation Platform (DAP). Supports mono-app and multi-app repository layouts, CCA metadata files, and CI/CD workflow configuration. See Agent Skills.
  • DAP security compliance — a new Security Insights page in the DAP dashboard that runs compliance audits against your Splunk fleet using versioned baseline profiles. Shows compliance percentages per host, violation details with severity levels, trend charts over time, and lets you create remediation plans directly from violations. Includes CSV export. See Deslicer Observer API & Automation Platform.
  • DAP inputs inventory — a new Inputs Insights page in the DAP dashboard that shows a cross-host inventory of all inputs.conf entries. Filter by input type, app, config layer, and status. See Deslicer Observer API & Automation Platform.
  • Live workflow progress tracking — workflow execution in the chat interface now shows real-time node-by-node progress. Each node displays its status (pending, running, completed, failed) with expandable tool call details and duration. See Running Workflows.

Improvements:

  • Agent cloning now preserves skills, skill settings, tool optimization configuration, telemetry preferences, and tool choice overrides from the source agent
  • DAP plan detail pages redesigned with a sidebar layout showing plan metadata, timeline, and execution history alongside change items, dry-run previews, and approval dialogs
  • DAP fleet insights page now includes a compliance posture summary card linking to the full security audit
  • Improved error handling in DAP pages with consistent error states and classification

Fixes:

  • Fixed invite code values appearing in authentication verification logs — codes are now redacted in all log output
  • Fixed agent cloning not carrying over skill and tool optimization settings from the source agent

Date: 2026-04-01 Version: 1.4.0 Summary: Starter Workspace dashboard, apply-to-starter-agents onboarding step, Orchestrator context loading indicator, and secret field masking in the integration editor. Onboarding improvements and stability fixes for workspace provisioning.

Features added:

  • Starter Workspace dashboard — the home dashboard now shows a Starter Workspace card that tracks the setup status of your integration, starter agents, and starter workflows. A progress bar shows how many assets are configured and each row displays a Ready or Pending status with a direct action button. See Creating Your Account.
  • First Steps guidance — a new Your first steps card on the dashboard guides new users through opening Orchestrator chat, updating the Splunk integration, and running a starter workflow.
  • Apply Splunk to starter agents — when you add a Splunk MCP integration through the welcome onboarding flow, a new step lets you choose which starter agents should use your new Splunk connection. Non-Splunk integrations on the agents are preserved. See Connecting Splunk.

Improvements:

  • The Orchestrator chat now shows a "Loading workspace context..." indicator while subagents, workflows, and tool configurations are being fetched, replacing an empty state
  • Sensitive fields (passwords, tokens, API keys) in the integration editor are now automatically masked when editing an existing integration — previously saved values are preserved if you leave the field unchanged
  • Deslicer Guide is now included in the default onboarding clone so new users see it in their workspace
  • Improved error handling in memory tools — read, write, list, and search operations return structured error responses instead of failing silently

Fixes:

  • Fixed onboarding rebind preserving non-Splunk bindings on starter agents — previously, switching a Splunk integration could remove other tool bindings from the agent
  • Fixed starter workspace provisioning edge cases during the signup flow

Date: 2026-03-30 Version: 1.3.0 Summary: Automatic workspace provisioning for new users — starter agents, workflows, and a demo Splunk integration are created at signup so you can explore immediately. Free-trial billing is now initialized correctly during the signup flow.

Features added:

  • Automatic workspace setup — when you create a new account, Deslicer provisions starter agents (GDI Agent v4, Splunk Data Explorer, Splunk CIM Normalizer Orchestrator, and more), starter workflows (Data Ingestion Monitor, Daily Health Check, Data Quality Check), and a pre-configured demo Splunk integration. You can start chatting with agents and running workflows immediately after signup with no manual configuration. See Creating Your Account.
  • Demo Splunk integration — a shared Splunk instance with sample data is automatically connected to your starter agents. You can explore Splunk tools and run queries before connecting your own Splunk environment. See Connecting Splunk.

Improvements:

  • Starter agents are excluded from the orchestrator subagent list to avoid duplication when using multi-agent orchestration
  • Free-trial billing initialization now runs reliably during both email/password and OAuth signup flows

Fixes:

  • Fixed free-trial credit activation not running during the signup flow — new users now receive trial credits immediately upon account creation
  • Fixed edge case where billing follow-ups could fail silently during OAuth-based signup

Date: 2026-03-27 Version: 1.2.0 Summary: Deslicer Automation Platform (DAP), GDI Onboarding Agent enhancements (Splunk readiness validation, data quality scoring, config packaging with download), GitHub MCP migration for write operations, public documentation portal with search, improved integration onboarding flow, and invite-code trial fixes.

Features added:

  • Deslicer Automation Platform (DAP) — a new dashboard section for observing, automating, and governing Splunk configuration changes across your fleet. Includes Insights Nodes enrollment, Change Plans with approval workflows, Executions tracking, fleet health Insights Dashboard, and a Configuration Browser for inspecting .conf files across enrolled nodes. See Automation Platform.
  • Splunk readiness validation — the GDI Onboarding Agent now checks your live Splunk environment before finalizing configs. It verifies index existence, detects sourcetype conflicts, and validates host availability. Results appear as pass/warn/fail with recommended actions. See Data Onboarding.
  • Data quality scoring — generated configs receive a score from 0 to 100 with a letter grade covering Magic 8 compliance, props/transforms validity, line breaking, timestamp parsing, and CIM alignment. Configs scoring below 90 are iterated automatically.
  • Config packaging and download — finalized GDI configs are packaged into a .tar.gz archive. The agent provides a download link in the chat that remains valid for one hour.
  • GitHub MCP migration — the GDI agent now uses standard GitHub MCP tools (search_repositories, create_branch, push_files, create_pull_request) instead of custom Git tooling. Enable the GitHub integration with a personal access token to push configs and open pull requests. See GitHub Integration.
  • Public documentation portal — product documentation is now publicly accessible at /docs with built-in keyword search (Cmd+K / Ctrl+K). Accessible from the landing page navigation and footer. No login required. See Public Documentation Portal.
  • Data quality validation skill — a new splunk-data-quality skill with seven validation scripts for scoring generated configurations against best practices.

Improvements:

  • Integration onboarding flow now shows loading states, improved field validation, and dedicated setup guidance for GitHub (branch selector, connection probing) and Deslicer Observer (platform connection status)
  • Beta programs card is hidden when no programs are available, reducing dashboard clutter
  • Improved GDI agent workflow linearity — the agent follows a stricter step order (analyze → generate → finalize → validate → readiness → score → download/GitHub)
  • Enhanced integration quick-start and tool editor with platform connection status for Deslicer Observer

Fixes:

  • Fixed invite-code trial expiration handling — trial dates and opt-out messaging now reflect correct expiration
  • Fixed Jest ESM errors with @ai-sdk/devtools mock
  • Fixed pgvector type qualification in product documentation migrations

Date: 2026-03-19 Version: 1.1.0 Summary: Agent Skills — a modular skill system for extending agent behavior. Eight built-in skills, slash command activation in chat, permanent skill attachment via agent settings, and a dedicated Skills page in the dashboard.

Features added:

  • Agent Skills system — modular capabilities that you attach to agents to shape how they respond, research, and execute tasks. Skills can be attached per-message via / slash commands in chat or permanently via the agent edit page. See Agent Skills.
  • Skills page in dashboard — a new Skills entry in the sidebar lets you browse, search, and filter all available skills. Each skill card shows its name, description, tags, capability indicators, and slash command.
  • Eight built-in skills — Search Splunk, Deep Research, Web Research, Research, CIM Modeling, Incident Response, Structured Output, and Concise.
  • Slash commands in chat — type / in the chat input to open the skills menu, filter by name, and attach a skill to a single message.
  • Skills tab in Agent Builder — permanently attach skills to agents from the agent edit page under the new Skills tab.
  • CIM Add-on prerequisite check — the CIM Modeling skill validates that the Splunk CIM Add-on (Splunkbase app 1621) is installed before mapping data models.
  • Sandbox companion file uploads — skills that include scripts and reference files upload companion files to the execution sandbox automatically.

Improvements:

  • Improved orchestrator web search and sandbox code execution reliability
  • Enhanced semantic tool selection to preserve orchestrator default tools
  • Skill tool schemas are registered for history validation

Fixes:

  • Fixed orchestrator default tools being dropped during semantic selection
  • Fixed sandbox script execution argument injection
  • Resolved PyJWT and pyasn1 security vulnerabilities (Trivy HIGH CVEs)

Date: 2026-03-02
Version: 1.0.0
Summary: Initial product documentation release. Use cases, teams and billing, deployment, and reference sections added.

Features added:

  • Use case documentation: SPL assistance, data quality monitoring, ITSI episode analysis, daily health checks, data onboarding
  • Teams and billing: organizations, plans, pricing, credits, subscription management
  • Deployment: Cloud SaaS, On-Premise Docker, security and compliance
  • Reference: supported AI models, FAQ, glossary
  • Changelog page template

Improvements:

  • Consolidated product documentation structure for end users, sales/marketing, and LLM agents
  • Navigation blocks and cross-references across all sections

Fixes:

  • N/A (initial release)

For older releases, check the repository history or contact Deslicer support.

Changelog | Deslicer AI Docs