
Azure, Loops, and an Inbox That Knows What Is On Fire
Most of this release is about making the platform act without being asked — and making what it does legible.
Loops close a gap the automation model has promised since it shipped. Recurring schedules could create work on a timer, but nothing could say "when a critical finding is raised, open a remediation task and draft the ticket." Now a Loop binds a trigger and a filter to plain-language instructions, and when it fires the agent plans and executes the work through the same pipeline every other agent run uses. You see the result in Runs. Loops are edited as drafts and published deliberately, because something that acts on your workspace by itself should not change behavior while you are halfway through a thought.
Azure joins AWS, Microsoft 365, Google Workspace, and the PaaS connectors. It is a separate integration from Microsoft 365 for a reason that is not cosmetic: Entra app permissions grant nothing in Azure Resource Manager, so an Azure-only customer should never be asked for tenant-wide directory access they do not need. Setup was rebuilt around one observation — the token episki already holds carries the service principal's identity, and the tenant root group's id is the tenant id — so there is nothing to look up and nothing to paste that can fail on a permission unrelated to the task.
The inbox now answers the question an inbox exists for. It used to list everything you owned grouped by kind, so "assessment" outranked "task" whether or not anything was on fire. The Priority tab orders by urgency, shows why each item is there, and the sidebar badge finally reaches zero.
- Loops — event- and schedule-driven agent automation, capability-gated, with draft and publish
- Azure cloud posture with one-click role assignment
- Priority inbox ranked by urgency, with per-member signal choices
- Versioned evidence — one record per stream, re-verified on every collection, no duplicate rows
- Command sees attached images
- Per-channel notification settings and a badge that counts what matters
Turning Security into a Core Competency
Security stops being a cost center the moment it becomes something the organization is genuinely good at. Here's what it takes to move from reactive to exceptional.
PCI Vulnerabilities: Finding Them Is Easy — Proving You Fixed Them Is the Hard Part
ASV scans and internal vuln programs generate noise by default. Here's how to run PCI vulnerability management so findings become remediation, evidence stays audit-ready, and scope doesn't quietly expand.