Release notes — July 2026
Product updates released through July 20, 2026.
Third-Party Apps
Controlled pilot
The canonical inventory, Browser Security evidence projection, new evidence views, and Access Review suggestions below are rolling out workspace by workspace. They are not yet generally available; workspaces outside the pilot retain the existing Third-Party Apps experience.
Unified application inventory
In workspaces included in the controlled pilot, Third-Party Apps combines identity and direct-application integrations, OAuth grants, email activity, Browser Security usage, AI account status observations, and installed browser extensions into one application record. The Users tab preserves each signal's source and first and last detection, and explains whether it was Confirmed by a connected source, Supported by email activity, or Observed in the browser. Browser evidence remains current for 30 days and is shown as Not recently detected afterward; it never becomes a verified account.
High-confidence applications that do not yet match elba's catalog can appear as organization-private profiles marked Identification in progress. Catalog assessment is performed by elba's automated enrichment and review pipeline, not a manual human reviewer; the Usage policy remains a separate administrator decision. Ambiguous websites, devices, operating systems, and platform components stay outside the default application inventory. The application detail now separates Reputation score, Access exposure, Observed users, and Usage policy instead of blending them into one risk score. Browser-only records show Reputation score not yet available and No account access confirmed by a connected source; SSO adoption and account-remediation actions are unavailable without connector-confirmed account access.
Access Review preparation
For workspaces included in the pilot, Access Review suggestions show verified-account and browser-observed user counts separately. A browser-only application is marked Verification required and must be connected or supplied with an authoritative account import before access decisions begin. Inferred browser users are never copied into review account rows or given revoke or role-change decisions. This update does not change the review workflow, screenshot import behavior, or connector-specific role and entitlement coverage.
Privacy-safe AI account status and extension information
Browser Security reports the observed AI account status as Work account, Personal account, No account signed in, or Unknown. During the canonical-inventory pilot, Third-Party Apps can additionally show Work and personal accounts only when current work and personal evidence coexist for the same user and application. This combined status is computed by the inventory rather than reported by the browser, and Browser Logs cannot filter by it. Neither view exposes detected account email addresses or domains, page content, tenant-specific hostnames, or full URLs. Installed-extension evidence includes privacy-safe installation metadata, state, and a permission summary: allowlisted browser API permission names, an unknown-permission count, a host-permission count, and a coarse No sites, Specific sites, All sites, or Unknown scope. Raw extension identifiers, unrecognized permission strings, host patterns, and host-permission domains are never exposed. Extension installations remain browser observations and do not affect OAuth access exposure, SSO adoption, risky-permission issues, or remediation eligibility.
Permission summaries roll out first on Chrome and Edge. Firefox remains on the 0.4.2 installation-metadata behavior until its self-hosted distribution has an explicit-consent path that satisfies Firefox's background-data requirements; the release process prevents its public update manifest from advancing in the meantime.
Browser Security
Safari support
Browser Security now supports Safari 26 or later on macOS 26 or later. Teams can use application visibility, AI prompt and supported file-upload controls, browser logs, enrollment reporting, and Playbooks that block sensitive actions. Administrators can download the signed and notarized package and Safari management declarations from the Deployment Center. Production rollout requires macOS MDM; manual installation is intended for pilot validation. Okta administrators must add the Safari sign-in redirect URI shown in the Deployment Center to their existing Okta OIDC application before rollout. Safari cannot inventory other installed extensions or query download history because those APIs are not available to Safari extensions. See Deploy the browser extension for rollout requirements and instructions.
Work and personal account visibility for AI tools
Browser Security can now classify the AI account status observed on ChatGPT, Claude, Gemini, and Microsoft Copilot as work, personal, no account signed in, or unknown. Administrators can review these raw observations in Browser Logs and filter them by AI provider or one of those four account statuses. Browser Logs does not report or filter the combined Work and personal accounts status; in workspaces included in the canonical-inventory pilot, Third-Party Apps computes it only when current work and personal evidence coexist for the same user and application. These account-status observations do not send detected account email addresses or domains, page content, or full URLs to elba.
Sensitive file-upload protection for AI tools
Browser Security can now inspect file names and a limited content excerpt from supported text-based files uploaded to ChatGPT, Claude, Gemini, and Microsoft Copilot. It records sensitive-upload findings, and a configured Playbook can block an upload with a clear in-browser warning when sensitive data is detected. For binary formats, including PDFs, Microsoft Office files, most image formats, and archives, only file metadata is available for inspection; their contents are not extracted. Incomplete or unavailable inspection does not by itself block an upload.
Sign-in
Sign-in now handles organizations sharing the same domain and invalid Okta-initiated requests more gracefully.
Usability
Member onboarding is more resilient when a page cannot be preloaded, and reminder dialogs remain usable on smaller screens.