← Back to all sparks
ActiveCollab logo

ActiveCollab

PM
Velocity6.3

Project management for creative teams

AI agents got the keys in June; in July ActiveCollab added the locks.

mcpagent-governancesecurity-controlsnative-desktop-appsproject-management
Current state
ActiveCollab ships small, self-contained changes on a roughly weekly cadence, and this window covers three fronts. Security gained an IP allowlist and per-tool permissions for MCP agents, both filed under Security settings. The client layer was rebuilt, with native macOS and Windows desktop apps replacing Electron and distributed through the platform app stores, followed by dark themes that match system appearance. Collaboration picked up chat favorites and self-expiring mute, plus an activity heatmap on My Work.
Where it's heading
The clearest thread runs through MCP. In mid-June the product made individual comments linkable specifically so an AI agent could retrieve one; four weeks later it shipped controls restricting which MCP tools those agents may call. That is a reach-then-govern sequence, and putting agent permissions in Security settings next to the IP firewall says an agent is being treated as a principal to scope rather than an integration to enable. Everything else in the window is steady quality-of-life and platform hygiene.
Prediction
Expect the governance layer around MCP to keep filling in - audit logging of agent actions, or per-role rather than per-account tool limits, is the natural next step given both new controls landed in Security settings on the same day.

Recent moves

  1. 9d ago

    Light, Dark, or Automatic

    Two dark themes plus a Match System Appearance toggle that follows the OS setting. It arrives right after the native desktop rebuild, where hooking into system appearance is far cheaper to do properly. Quality-of-life work against the security and agent items that dominate this window.

  2. 27d ago

    Better Control of Chat Conversations

    Favorites pin conversations to the top of the list, and mute expires on its own after an hour instead of waiting to be undone. These are small, well-observed fixes to how busy threads actually behave. They suggest chat is being maintained as a first-class surface rather than a bolted-on one.

  3. 1mo ago

    IP Firewall

    An IP allowlist that blocks everything not explicitly trusted, shipped the same day as the MCP tool limits. On its own this is standard enterprise hardening rather than a new direction. Paired with the agent controls, it shows Security settings being built out as a real surface instead of a checkbox page.

  4. 1mo ago

    Limit MCP Tools

    ⚡ SPARK

    Four weeks after making comments individually addressable so an AI agent could fetch them, ActiveCollab shipped the controls that restrict what those agents may do. Putting per-tool permissions in Security settings, beside the IP firewall, scopes an agent like an account rather than enabling it like an integration. This is the governance half of the MCP arc the feed has been building since June.

  5. 1mo ago

    Rebuilt Desktop Apps

    The macOS and Windows apps were rebuilt on native OS toolkits instead of Electron and now ship through the Mac App Store and Windows Store. What the product does is unchanged, but its footprint, speed, and distribution channel all move. It is the heaviest engineering item in this window, and the reason system-appearance matching could follow four weeks later.

  6. 1mo ago

    Completed Task Notifications