Changelog

July 17, 2026v1.7.4

The people behind the prompts

A hostname is not a person. As AI spreads across a company, understanding the work means knowing who it belongs to and how that person fits into the organization.

Directory integrations are now generally available for Microsoft Entra ID, Google Workspace, and Okta. Connect the directory you already maintain and Origin brings its people, groups, and organization details into the graph. When an endpoint can be matched to its directory owner, Explore rolls that person's activity together across devices, with their department and email alongside it.

All three integrations can sync a full directory. Microsoft Entra can instead start with selected groups, including nested membership, so a focused rollout does not require bringing in the whole organization.

Traces attributed to a person

Microsoft 365 Copilot, in context

AI adoption does not stop at developer tools. With Microsoft 365 Copilot, the same people are working with AI in Word, Excel, Outlook, Teams, and Copilot Chat.

Enable capture on a connected Microsoft Entra directory, and Origin brings those conversations into the same activity view as the rest of your captured AI work, attributed to their authors. The same review workflow now covers coding agents and the work happening across Microsoft 365.

Microsoft 365 Copilot activity in a trace

Improvements
IntegrationsExpired directory credentials can be updated in place from the integration's settings, without deleting and re-adding it.
IntegrationsMicrosoft Entra directory integrations can sync selected groups, including nested membership, or the whole directory.
IntegrationsOrigin's MCP server can search prior work and finds similar past sessions even when the wording differs.
IntegrationsOrigin's MCP endpoint now uses streamable HTTP transport, which more clients support.
IntegrationsThe dashboard assistant can use Origin-managed inference, enabled on request, so you don't have to connect your own gateway.
EndpointsEndpoint last-seen times now come from agent heartbeats.
EndpointsEndpoint Inventory search runs server-side across the whole fleet.
EndpointsInventory detects AI extensions across VS Code forks, including VSCodium, Insiders, and Windsurf.
EndpointsInstalled agents are grouped under friendly product names, and search matches the names you see.
EndpointsCanvases arrange tiles in a flexible grid with cleaner tile chrome.
EndpointsTables and heatmaps handle wide results better, and PNG exports can span the full width.
EndpointsYou can launch a steered clustering pass from Explore's generation picker.
EndpointsExplore's Memories dimension is now driven by the memory signal.
EndpointsWeekly prompts-per-user distributions report levels beyond 1,000.
DetectionSignal firings are highlighted in place in trace detail, with tooltips and a whole-trace scan.
DetectionSignals beyond the built-in baseline can be enabled per organization.
IT & rolloutCapture and detection updates can now roll out to endpoints between agent releases.
Fixes
Chat is hidden for roles that don't have permission to use it.
The skill signal now catches slash-command invocations.
Malformed analytics time ranges return a clear error instead of failing the query.
Treemap values stay legible over cell patterns, and cells show tooltips.
Every install path now configures the agent's backend connection.
AI tools with spaces in their executable paths are detected more robustly.
Tray diagnostics only flag issues for capture paths enabled on that endpoint.
Trace and command deep links open in their page context instead of the chat panel.
Captured activity is labeled with its true source instead of showing as proxy capture.
Prompts that arrive out of order are recovered more robustly.
Very long sessions and agent reconnects no longer truncate traces, and the current turn always renders.
Captured events survive agent reconnects to the backend.
Agent-harness scaffolding and tool output are no longer misclassified as prompts.
Signal-scoped token counts are no longer under-reported.
Microsoft Entra directory sync no longer stalls on empty pages or spawns duplicate runs, and large groups sync fully with scope changes applying within one cycle.
Removing a directory integration shows its status correctly until it finishes.
Microsoft 365 Copilot content renders fully instead of showing unknown blocks.
The dashboard assistant no longer errors on models that require extended thinking, and model errors surface instead of failing silently.
Chat's save suggestion appears after the response instead of interrupting it.
Dashboards load for organizations whose names contain parentheses.
Credential detection is consistent between browser and endpoint capture.
The MCP server handles JSON-RPC notifications correctly.
Installed AI tools no longer appear twice when detected through multiple paths.
July 2, 2026v1.6.7

Signals

Signals are deterministic rules that annotate the graph. Each looks for a specific, well-understood pattern in prompt text, tool calls, tool results, or tool definitions, and marks the exact activity where it matches. A signal is a finding, not a guess: it fires because a rule matched, not because a model thought something looked off.

The first set we’re publishing is security detections, on by default and maintained by Origin: credential and financial data, prompt injection, risky commands and exfiltration, tool poisoning. Each firing is anchored to the activity it found, so you can jump straight from a finding to the surrounding trace, or read it as a dimension across the fleet in Explore.

Signals firing in trace detail

Role-based access control

Not everyone who uses Origin needs the same view of it. Until now, everyone who wasn’t an admin collapsed into a single "Member" role, so access was effectively all or nothing.

Role-based access control replaces that with a set of built-in roles that allow for more granular control, assigned by admins from User Management. Enforcement runs across both the interface and the underlying data: each role sees only the sections it should, analytics queries are scoped to the endpoints and data it’s allowed to read, and prompt content stays gated even for users who can see that a signal fired. Roles can map to your directory groups, so access follows the structure you already maintain.

Improvements
IntegrationsSync selected groups from your identity provider so people and devices become first-class dimensions in analytics, with support for Microsoft Entra, Google, and Okta.
IntegrationsMicrosoft Entra can be connected through Origin-managed admin-consent onboarding, with no app to register or maintain yourself.
IntegrationsPoint the dashboard assistant at your own OpenAI-compatible LLM gateway with a custom URL and token, governed by a per-organization host allowlist.
IntegrationsOrigin's MCP server is now available at a stable first-class endpoint at mcp.originhq.com.
IntegrationsDirectory sync surfaces each user's country from your identity provider as a jurisdiction-attribution source.
EndpointsExplore has a new structured query bar: type filters with autocomplete and editable pills, and click a chip to select its range in the query.
EndpointsSearch clusters and endpoints by label in Explore, and refine any sidebar breakdown in place with a layered filter.
EndpointsEstimated cost now appears alongside token usage across charts, footers, and trace details.
EndpointsA new dashboard home brings canvases and chat together as a single front door, with pre-built read-only kernels and canvases to start from.
EndpointsEndpoint inventory adds a fleet-composition view with agent and OS mix, install footprint, and first-seen and last-seen trends.
EndpointsInventory dedupes duplicate and re-registered endpoints, including VM clones, by hardware identity.
EndpointsTool and MCP-server detail pages show their definitions, how they drift over time, and how they are being called.
EndpointsExplore adds a Memories dimension showing the agent memory each person's sessions touch.
EndpointsCodex activity is now captured with per-turn tokens and the tools it runs.
EndpointsSessions are labeled by their most recent prompt summary instead of a raw identifier.
EndpointsThe trace sidebar shows where a session originated: the launching agent, the user, and the command.
EndpointsTrace detail captures more session context from the full request, including working directory, git branch, and platform.
EndpointsNetwork, DNS, file, and process-spawn events are deduplicated per process and session.
IT & rolloutUninstalling the agent captures a diagnostics bundle and files it automatically.
Fixes
Expired assistant tokens now return a clear error and refresh proactively instead of an empty response.
Web-based AI prompts show the real model instead of "unknown".
Prompt cards now render for claude.ai, Claude Desktop, and DeepSeek web.
Chat tables render with clean headers, working tooltips, and matching PNG exports.
The activity surface now sizes correctly in Safari.
The dashboard keeps your saved theme on the sign-in screen instead of flashing the default.
Added a recovery path out of a wedged dashboard sign-in.
Hardened attachment serving against a stored cross-site scripting risk.
Analytics results resolve endpoint IDs to readable names in bars, rows, and timelines.
Trace log entries no longer get stuck on "Pending": harness scaffolding reads "Infrastructure", promptless terminal steps are labeled, and outlier traces show their cluster badge.
The analytics assistant now answers cluster-scoped token questions instead of dead-ending.
Endpoint inventory closes AI-tool detection gaps on Windows and macOS.
Endpoint inventory now shows the macOS version.
macOS capture keeps working under encrypted DNS and iCloud Private Relay.
Prompt and usage capture now reads Brotli-compressed responses.
Microsoft 365 Copilot capture no longer duplicates prompts from control frames.
Claude.ai telemetry beacons and ChatGPT prewarm requests are no longer captured as prompts.
macOS capture self-heals if the network extension's flow limit saturates, and recovers from filter revert loops.
Windows installs honor the selected drive and install directory.
The macOS installer reports a clear error for a malformed enrollment token instead of failing silently.
The agent recovers cleanly from watchdog restarts, avoids crash-loops when the network is unreachable at boot, and no longer rolls updates back during a coordinated restart.
Directory sync is more resilient to transient identity-provider errors across Microsoft Entra, Google, and Okta.
Improved coverage of built-in credential and secret detection, restoring long-tail detectors and closing false negatives.
June 12, 2026v1.5.15

The proxy-less agent

Version 1.5.15 introduces a proxy-less agent for collecting AI prompt activity from endpoints without placing anything in the network path.

The agent captures supported prompt activity directly from AI tools on the machine and ties it to the person, device, and surrounding endpoint activity. Prompts land in the same context graph as processes, files, and network connections, and show up in the same traces, analytics, and inventory, so teams can investigate AI-assisted work alongside the rest of the endpoint record.

Proxy-less collection requires no traffic interception, certificate changes, or new network trust. Install the agent and supported activity starts flowing into Origin. For organizations starting their AI visibility journey, this is the fastest path to a live record of AI work, and everything it captures carries forward as endpoints later move to the full agent.

The full agent remains the deepest view of an endpoint, observing activity on the wire in addition to endpoint context. The proxy-less agent is designed for faster deployment and coverage of tools that report their own activity.

Both paths build the same graph of AI work in Origin.

Improvements
EndpointsPrompt activity from Claude Cowork sessions is now captured on both macOS and Windows.
EndpointsClaude's browser-based agents now show up in activity, including the tools they execute.
EndpointsProxy-less collection drops model response bodies on the endpoint instead of uploading them.
EndpointsCapture recovers automatically if other software stops the agent's collection session.
EndpointsFleet health reads proxy-less endpoints correctly: the network capture component shows as not applicable instead of unhealthy.
EndpointsThe agent adoption chart stays readable at fleet scale, and endpoint detail now shows version skew and stability.
EndpointsEndpoint details now omre robustly distinguish Windows 11 from Windows 10.
EndpointsToken usage is attributed at a finer grain, includes provider-reported cache tokens, and breaks down into input, output, cache, and reasoning tokens across charts and trace details.
EndpointsPrompt usage can be broken down by the client surface it came from.
EndpointsTrace detail adds Context, Tree, and Raw views and now leads with the prompt summary and endpoint.
EndpointsExplore adds a Skills dimension showing activity by the skills agents used.
EndpointsExplore can pin a clustering generation and drill through cluster hierarchies.
EndpointsFlow links in Explore connect model and cluster scopes, with hover pop-outs and drag-to-pan.
EndpointsExplore's Context and Chat panels moved to a right-edge mode rail.
EndpointsEndpoint and session chips in event detail are clickable and jump to that scope.
EndpointsThe dashboard assistant runs on Claude's newest models and can open Explore scopes and Studio items for you.
EndpointsDashboard chat adds rewind and fork, markdown rendering, and kernel save suggestions.
EndpointsSigning out clears Origin's local browser data, and Settings can clear it on demand.
EndpointsDashboard session tokens are no longer persisted in browser storage.
EndpointsCleaner dashboard URLs with no # in the address bar, direct settings links, and shared links that survive the sign-in redirect.
EndpointsLarge datasets render faster across the dashboard: chats lazy-load, long trace views virtualize, and canvases coalesce redraws.
DesktopRun Diagnostics in the endpoint tray shows the agent's service identity, snapshot age, and backend target.
IT & rolloutThe macOS agent now runs on Intel Macs as well as Apple silicon, from a single universal installer.
IT & rolloutEndpoints move between full and proxy-less capture without reinstalling, including changes made while an endpoint was offline.
IT & rolloutThe local port used for proxy-less collection is configurable per organization.
IT & rolloutAgent logs on endpoints are size-capped so they can no longer grow without bound on disk.
Fixes
macOS network capture no longer conflicts with SASE tunnel traffic.
ChatGPT response capture no longer drops streamed chunks.
Endpoints deployed proxy-less no longer see macOS approval prompts for components they don't use.
Tool calls no longer appear twice in traces.
AI tool inventory now refreshes on its regular schedule instead of only scanning at startup.
Session metrics now respect the selected time window.
Charts no longer shift time buckets across time zones.
Trace detail rendering: non-prompt frames are labeled, embedded scripts no longer break into spurious command chips, and chips render correctly inside tables.
Execution logs no longer appear empty for older sessions.
The full-screen activity view no longer collapses on reload.
Analytics filter values containing backslashes now match correctly.
Python analysis in chat recovers automatically instead of hanging.
Expired dashboard sessions re-authenticate cleanly instead of returning empty chat responses.
Sign-in retries transient identity-provider errors instead of failing.
The Windows tray app no longer opens duplicate instances.
Uninstalling the agent fully removes local credentials and certificates.
June 9, 2026v1.4.4

Managed rollout controls

Not every environment tolerates updates the same way. Some fleets want every endpoint on the newest agent as soon as it ships; others need version changes to follow their own validation and rollout schedule.

Agent auto-update is now a configurable policy, so Origin can adapt to either. Leave it on and endpoints stay current automatically. Switch it off and update timing moves into your own deployment tooling, while endpoints keep capturing and reporting as before. Turning it back on later requires no reinstall.

Improvements
IT & rolloutIT teams can keep selected organizations on their own agent rollout schedule instead of receiving automatic agent updates.
IT & rolloutWindows deployments can omit the full network capture component when supported prompt activity is collected through another approved path.
EndpointsPrompt records keep a model label even when response-side usage data is incomplete.
EndpointsOrigin now reports the AI tools installed on every endpoint, even ones that aren't running full activity capture, so AI tooling is visible across the whole fleet instead of only on monitored machines.
EndpointsEndpoint inventory now finds more AI tools, including the Claude and Codex desktop apps and command-line tools installed in less common locations that earlier versions could miss.
IT & rolloutSupport reports can include attachments up to 250 MB, making it easier to send larger logs and diagnostic bundles.
Fixes
Codex capture no longer records unrelated background beacon traffic.
Fresh Windows wizard installs no longer fail before local agent data is initialized.
Endpoints with no assigned policy no longer restart repeatedly during session processing.
Windows endpoints installed without the full network capture component no longer restart repeatedly when that component is absent.
Perplexity web searches now appear as their own trace turn.
Chat exports no longer loop through forked conversation branches.