WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Quick Start
User Guide
User Guide
Policies - GuardRails
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Anywhere: Remote Device Security
Witness Attack
Witness Attack
Administrator Guide
Administrator Guide
404
404
WitnessAI Release: June 11, 2026
Note: New and updated features may not be immediately available on your dedicated deployment due to participation in limited availability releases, beta programs, or regional configurations.
If you don't see a feature you expect, please reach out to Customer Success. We're happy to help!
New Features
Agentic Tool Use Policy
Admins can now block or allow specific MCP servers and Tools for Agents. They can now use the new Agent Tool Use Policy to configure a Blocklist or Allowlist of MCP Servers or Tools. They can also block MCP servers and Tools from the new MCP Servers page in discovery, making it easy to take action on the new MCP servers discovered.
GitHub Copilot (VS Code)
Admins can now block or allow specific MCP tools and servers for GitHub Copilot agent sessions in VS Code, covering both the standard chat path and the Anthropic model path. Per-request latency metrics for tool block decisions are now visible in the monitoring dashboard, labelled by policy type, tool name, and tenant — making it straightforward to identify which tools are being evaluated and where delays occur.
New capabilities: Agentic Control
Claude Code
WitnessAI now fully supports the Claude Code Desktop, CLI and VS Code Extension. Prompts, responses, and agentic tool calls are captured and visible in the console. All AI policies — including content redaction, blocking, warnings and modified response content is correctly delivered to the user. The Witness Anywhere registration script for macOS and Windows automatically configures the Claude Code proxy settings — no manual setup required.
Supported capabilities: Prompt/Response Observability, Blocking, Warning, Redact, Route, Agentic Observability
OpenAI Codex (CLI, VS Code Extension, Desktop)
Full prompt and response capture, blocking, warning, and modification support is now in place across all three Codex surfaces. The Codex WebSocket conversation path now has history-rewrite protection, preventing prior-turn PII from being re-submitted to the model. The macOS Witness Anywhere registration script automatically configures the Codex environment file with the correct proxy settings.
New capabilities: Prompt/Response Observability, Blocking, Warning, Redact, Agentic Observability
Feature Updates
Claude Desktop & Claude Co-Work
Policy-modified response content is now correctly applied and delivered to users in Claude Desktop and Claude Co-Work. Previously, content redacted or rewritten by policy was silently discarded and the raw model output was forwarded instead.
New capabilities: Agentic Observability
Notion AI
Warning pop-ups now appear correctly when a policy is triggered in Notion AI, and full response content is now captured in the Conversations page. Previously, responses were only partially captured or not captured at all, and warnings were silently suppressed.
New capabilities: Warning (restored), Prompt/Response Observability
Google Docs & Google Sheets (Inline Mode)
Inline prompt submissions in Google Docs and Google Sheets are now captured and visible in the Conversations page. Previously, inline prompts were missing from the console while sidebar prompts appeared normally.
New capabilities: Prompt/Response Observability (inline mode)
Writer.com — Playbook Threads
WitnessAI governance now extends into Writer.com Playbook threads. Block, warn, and observe policies apply to prompts and responses within Playbook conversations — a workflow surface that was previously outside the inspection boundary.
New capabilities: Prompt/Response Observability, Blocking, Warning (Playbook workflow)
Custom Data Types — UI Improvements
The policy configuration experience for custom data types has been improved: the edit/delete popover now closes automatically after a deletion is confirmed, and example patterns in the custom data type creation flow no longer include anchoring characters that could cause unexpected matching behavior.
Per-Request Tracing for Proxy Traffic
End-to-end request tracing using a unique request identifier is now propagated across both HTTP/1.1 and HTTP/2 proxy paths. This allows operators to correlate a specific prompt’s full lifecycle — from the client through inspection — using a single identifier in observability tooling, significantly reducing time to diagnose issues.
Tool Block Metrics
Metrics are now emitted at each stage of the tool-blocking flow, both on the proxy side and in the console. This gives administrators visibility into where latency occurs when tool calls are evaluated and blocked, and enables per-request correlation between proxy-side logs and console-side records.
Claude Code CLI — Proxy Registration
The Witness Anywhere macOS and Windows registration scripts now automatically configure Claude Code CLI to use the proxy. The settings are written to the Claude configuration file as part of registration and can also be deployed via MDM (Jamf, Intune, or equivalent).
Performance, Reliability & API Updates
- Binary file downloads (installers, update packages) are no longer buffered through the inspection pipeline, reducing memory usage when users download large binary files over a proxied connection.
- Large streamed responses that appeared stalled now display correctly.
- The device registration service now correctly logs vendor labels in the provisioning database, making troubleshooting registration errors faster.
- A duplicate authentication header edge case that caused prompt extraction issues has been resolved.
- The console data table library has been migrated to a lighter-weight implementation, reducing bundle size and improving page load performance across settings tables.
- The app-catalog service no longer performs an immediate sync on startup, reducing unnecessary load during rolling restarts and deployments.
- Hotfix deployment pipeline now supports hotfix branches, enabling faster out-of-band releases without requiring a full release cycle.
- Stable conversation identifiers for Claude models in VS Code ensure that multi-session chat history groups correctly in the console even after reconnection.
Fixed Issues
- Microsoft Copilot (iOS — Dictation) A compatibility issue with the Dictation feature in the Copilot Corporate iOS app has been resolved. Text entered via the dictation button now populates correctly and is captured by the proxy.
- VS Code sometimes generated a duplicate response for the very first prompt in a session when a DLP warning guardrail was active.
- Warning messages were occasionally not rendered in Visual Studio when policies were configured in Warn mode for GPT-5.3 Codex, GPT-5.4, and GPT-5.5 models via PAC Proxy.
- The edit/delete popover for custom data types remained open after a deletion was confirmed, requiring an extra click to dismiss.
Known Issues
There are no known issues in this release.