[{"data":1,"prerenderedAt":168},["ShallowReactive",2],{"changelog-2026-09-14-azure-loops-priority-inbox":3,"changelog-2026-09-14-azure-loops-priority-inbox-surround":157},{"id":4,"title":5,"api":6,"authors":7,"body":13,"category":81,"date":82,"description":83,"extension":84,"faq":6,"features":85,"fixes":110,"highlight":123,"image":132,"improvements":134,"meta":151,"navigation":152,"path":153,"seo":154,"stem":155,"__hash__":156},"posts\u002F3.blog\u002F2026-09-14-azure-loops-priority-inbox.md","Azure, Loops, and an Inbox That Knows What Is On Fire",null,[8],{"name":9,"to":10,"avatar":11},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":12},"\u002Fimages\u002Fjustinleapline.png",{"type":14,"value":15,"toc":77},"minimark",[16,20,27,33,39],[17,18,19],"p",{},"Most of this release is about making the platform act without being asked — and making what it does legible.",[17,21,22,26],{},[23,24,25],"strong",{},"Loops"," close a gap the automation model has promised since it shipped. Recurring schedules could create work on a timer, but nothing could say \"when a critical finding is raised, open a remediation task and draft the ticket.\" Now a Loop binds a trigger and a filter to plain-language instructions, and when it fires the agent plans and executes the work through the same pipeline every other agent run uses. You see the result in Runs. Loops are edited as drafts and published deliberately, because something that acts on your workspace by itself should not change behavior while you are halfway through a thought.",[17,28,29,32],{},[23,30,31],{},"Azure"," joins AWS, Microsoft 365, Google Workspace, and the PaaS connectors. It is a separate integration from Microsoft 365 for a reason that is not cosmetic: Entra app permissions grant nothing in Azure Resource Manager, so an Azure-only customer should never be asked for tenant-wide directory access they do not need. Setup was rebuilt around one observation — the token episki already holds carries the service principal's identity, and the tenant root group's id is the tenant id — so there is nothing to look up and nothing to paste that can fail on a permission unrelated to the task.",[17,34,35,38],{},[23,36,37],{},"The inbox"," now answers the question an inbox exists for. It used to list everything you owned grouped by kind, so \"assessment\" outranked \"task\" whether or not anything was on fire. The Priority tab orders by urgency, shows why each item is there, and the sidebar badge finally reaches zero.",[40,41,42,48,54,60,66,71],"ul",{},[43,44,45,47],"li",{},[23,46,25],{}," — event- and schedule-driven agent automation, capability-gated, with draft and publish",[43,49,50,53],{},[23,51,52],{},"Azure cloud posture"," with one-click role assignment",[43,55,56,59],{},[23,57,58],{},"Priority inbox"," ranked by urgency, with per-member signal choices",[43,61,62,65],{},[23,63,64],{},"Versioned evidence"," — one record per stream, re-verified on every collection, no duplicate rows",[43,67,68],{},[23,69,70],{},"Command sees attached images",[43,72,73,76],{},[23,74,75],{},"Per-channel notification settings"," and a badge that counts what matters",{"title":78,"searchDepth":79,"depth":79,"links":80},"",2,[],"changelog","2026-09-14","Azure cloud posture joins the connector estate with one-click role assignment, Loops turn \"when X happens, do Y\" into agent work you can see in Runs, the inbox ranks by urgency instead of alphabet, and evidence collapses into versioned records that stay verified without piling up.","md",[86,89,92,95,98,101,104,107],{"label":87,"text":88},"Cloud","Azure cloud posture is a new integration — Microsoft Defender for Cloud, Azure Policy compliance, subscription RBAC, and storage and network exposure across every subscription episki can reach. Eleven operations, ten assertions, each writing a verdict against the control.",{"label":90,"text":91},"Integrations","Azure setup needs nothing looked up. episki already knows the service principal and the tenant root group from consent, so role assignment is one command — or one Deploy to Azure button — with a named management group still available when an admin deliberately does not hold root.",{"label":93,"text":94},"Automation","Loops, covered above. Existing recurring schedules were folded in with their ids preserved, so every work item that points back at the schedule that created it still does.",{"label":96,"text":97},"Inbox","A Priority tab ranks your queue by urgency — overdue, critical — instead of grouping by kind and sorting alphabetically. Each card shows its priority and the strongest reason it is there (\"Overdue 5d\"), and you choose which of eight signals count.",{"label":99,"text":100},"Evidence","Collected evidence is now one durable record with a version history. An unchanged re-collection writes nothing new and simply confirms the record is still true, so a config unchanged for 90 days reads as verified this morning — not stale, and not ninety duplicate rows.",{"label":102,"text":103},"Notifications","Each notification channel — email, Slack, in-app — has its own settings page, and the sidebar badge counts what actually needs you rather than everything you have ever owned.",{"label":105,"text":106},"AI Chat","Command can see the images you attach, so a screenshot of a console or a config panel is something it can reason about rather than a filename.",{"label":108,"text":109},"Coverage","Link all and Dismiss all on the coverage suggestions page, for the evidence that obviously belongs where the analysis says it does.",[111,113,115,118,121],{"label":108,"text":112},"The MFA check could attest from an empty credential report. It now returns inconclusive, and verdicts are keyed by assertion so two checks against the same evidence can no longer overwrite each other. Findings are de-duplicated by provenance, not by evidence row.",{"label":31,"text":114},"The custom role could not be created at all, one check could never pass, admin consent was not resolvable, and the tenant name came from the wrong API. All fixed during rollout.",{"label":116,"text":117},"Sync","A failed write reports the server's own explanation, cancelled requests are no longer logged as errors, and reconcile pages its server-id read.",{"label":119,"text":120},"Auth","A refused members query is no longer read as a missing profile, and invitee addresses are normalised before deciding whether they are new or existing.",{"label":90,"text":122},"Customers no longer see a raw fetch error when a connection fails.",{"title":124,"description":125,"icon":126,"items":127},"Loops — automation that acts on events, not just a calendar","Recurring schedules could create work on a cadence. They could not react. A Loop binds a trigger — an event in the workspace, or a schedule — plus a filter to plain-language instructions. When it fires, the agent picks up a work item, plans it, and does it, and every run lands in Runs where you can read exactly what happened. Loops are gated by capability: a Loop allowed to send internal mail cannot reach an external recipient, because the check happens where the tool's real action is known.","i-lucide-repeat",[128,129,130,131],"Trigger on a workspace event or a cadence, filtered to the records you care about","Instructions in plain language, executed by the agent and visible in Runs","Per-Loop capability gate, enforced at dispatch rather than on the tool's default","Edit into a draft and publish to make it live, so a running Loop never changes mid-thought",{"src":133},"\u002Fimages\u002Fchangelog\u002Fazure-loops-priority-inbox.webp",[135,137,140,142,145,148],{"label":90,"text":136},"Microsoft 365 verifies its Graph app roles at connect instead of failing on the first sync, handles a missing Entra licence honestly instead of erroring, and adds a conditional-access check. Providers a deployment cannot install are no longer offered.",{"label":138,"text":139},"Work","Bulk changes to work items go out as one batched write, so editing fifty tasks is one round trip, not fifty.",{"label":99,"text":141},"Evidence types show a human name everywhere they appear.",{"label":143,"text":144},"Issues","Findings are a filter on the issues list rather than a separate tab.",{"label":146,"text":147},"Billing","Attached modules show their trial state, and Manage subscription opens the Stripe portal.",{"label":149,"text":150},"Profile","Members and admins can remove an avatar.",{},true,"\u002Fblog\u002F2026-09-14-azure-loops-priority-inbox",{"title":5,"description":83},"3.blog\u002F2026-09-14-azure-loops-priority-inbox","gTEEkoIo9DoQwLdmzzf-L1rsvaTJwOjxoV52SESTWZo",[158,163],{"title":159,"path":160,"stem":161,"description":162,"children":-1},"Turning Security into a Core Competency","\u002Fblog\u002F2026-09-03-security","3.blog\u002F2026-09-03-Security","Security stops being a cost center the moment it becomes something the organization is genuinely good at. Here's what it takes to move from reactive to exceptional.",{"title":164,"path":165,"stem":166,"description":167,"children":-1},"PCI Vulnerabilities: Finding Them Is Easy — Proving You Fixed Them Is the Hard Part","\u002Fblog\u002F2026-09-14-pci-vulnerabilities","3.blog\u002F2026-09-14-pci-vulnerabilities","ASV scans and internal vuln programs generate noise by default. Here's how to run PCI vulnerability management so findings become remediation, evidence stays audit-ready, and scope doesn't quietly expand.",1790735152250]