← Back to all sparks
M

Mattermost

COLLAB
Velocity5.0

Open-source secure collaboration platform for technical teams.

Mattermost v11.11 adds a post exposure radius report as v12.0's compliance-focused overhaul takes shape.

zero-trustenterprise-securityabacai-agentson-premisecompliance
◆Current state
Mattermost is executing a deliberate security roadmap for regulated and sovereign deployments. The v11.10 release extended ABAC governance to team-level membership, added native user attributes, and gave AI agents dynamic tool calling with model fallback. v11.11 follows with a post exposure radius report that lets content reviewers see immediately who may have seen a flagged message. A sustained multi-part Zero Trust series and posts on air-gapped AI deployment reinforce that Mattermost's primary audience is defense, government, and regulated enterprises.
◆Where it's heading
v12.0, targeting October 2026, is positioned as a major capability reset with breaking changes significant enough to warrant advance warnings on RHEL 7/8 deprecations, plugin APIs, and integration points. The combination of expanding ABAC coverage, AI agents with fallback logic, and the forthcoming v12.0 suggests Mattermost is trying to build a compliance-certifiable AI-and-collaboration platform — not just a Slack alternative. Each release tightens the gap between what's visible in audit logs and what actually happened in the system.
◆Prediction
v12.0 will likely surface the AI agent and audit trail work as first-class compliance features — expect formal access-governance documentation for AI agents and deeper integration between the ABAC policy engine and AI agent permissions.

◆Recent moves

  1. 11d ago

    Zero Trust in Practice: Identity, Part 3 — The Roadmap to Optimal

    Part 3 of Mattermost's Zero Trust Identity series covers the Optimal maturity stage — CISA model alignment, continuous access enforcement, and how Mattermost maps to each control. It's a thought-leadership piece, not a product change, but it maps directly to the compliance narrative the product team is building toward v12.0.

    View source ↗
  2. 12d ago

    Mattermost v11.11: Data Spillage Exposure Radius Report

    v11.11 adds a post exposure radius report: when a message is flagged, content reviewers can now see a full list of who may have seen it, giving incident responders immediate scope clarity. This is the kind of targeted compliance tooling that enterprise buyers ask for but rarely get from general-purpose collaboration platforms.

    View source ↗
  3. 13d ago

    Operational Resilience: Why It Must Be a Daily Practice

    An editorial piece on operational resilience practices — not a product release. Consistent with the pattern of recent Mattermost content, which pairs product releases with thought leadership aimed at security and compliance buyers.

    View source ↗
  4. 18d ago

    Zero Trust in Practice: Identity, Part 2 — Advanced Identity, from Static Roles to Dynamic Access

    Part 2 of the Zero Trust Identity series, covering the Advanced maturity stage: ABAC, dynamic policy evaluation, and continuous access enforcement. Content mirrors the policy capabilities Mattermost shipped in v11.10, suggesting the blog series is deliberately timed alongside product releases.

    View source ↗
  5. 20d ago

    AI Audit Trails: The Missing Piece of Enterprise AI Adoption

    A post on AI audit trails for enterprise AI adoption — covering proof-of-action requirements as AI takes more operational decisions. Contextualizes the AI agent features Mattermost has been shipping and the compliance gap those features are meant to close.

    View source ↗
  6. 27d ago

    Zero Trust in Practice: Identity, Part 1 — Building the Identity Foundation

    The first entry in the Zero Trust Identity series, covering Foundation-stage controls: federated identity, MFA, directory sync, and audit logging. Framing Mattermost as the collaboration platform that supports the full Zero Trust journey — from basic SSO to continuous verification.

    View source ↗