Tracecat
Open-source workflow automation and case management platform.
Tracecat is drawing hard boundaries around what its agents are allowed to touch
◆Recent moves
- 1d ago
Nested execution constrained and MCP auth forwarding stopped
Constrains nested action execution, stops forwarding inbound auth to user MCP servers, and excludes run_python from agent tools while adding MCP resource content blocks. The clearest single statement of where the agent trust boundary now sits.
View source ↗ - 6d ago
Batch agent approvals and a Mistral provider
Adds batch approvals for agent actions, a Mistral provider and catalog IDs for custom models, plus batch case update and delete endpoints. Approval batching is what makes human-in-the-loop workflows survive volume.
View source ↗ - 9d ago
OAuth refresh locking and MCP resource overrides
Takes a row lock during OAuth refresh, allows an optional oauth_resource override for MCP, pins stdio catalog integrations and fixes Okta SAML audience restriction. Integration reliability work under the agent surface.
View source ↗ - 13d ago
Action Gateway becomes mandatory
⚡ SPARKMakes the Action Gateway mandatory as an explicit breaking change, alongside SentinelOne alert lifecycle actions and prioritised interactive turns on the agent queue. It forces every action through one enforcement point, which is the architectural decision the rest of this window builds on.
View source ↗ - 16d ago
Model catalog additions and stdio MCP connection tests
Adds platform catalog models and tests for stdio MCP connections, plus an API reference reorganisation. Small additions between the heavier candidates.
View source ↗ - 16d ago
Subagent input alignment and table dialog fixes
Removes a duplicate token remint, aligns subagent tool input with execution, and fixes several table and bulk delete behaviours. Cleanup within the candidate run.
View source ↗