What's new
Recent additions to SecureAuth Agent Authority. This page collects the current year's highlights, newest first.
August 2026
Set rate limits on tool calls
You can now cap how many tool calls agents make. This contains a runaway agent, protects an upstream service from a flood of calls, and stops one team using up everyone's quota. Count the budget per user, agent instance, MCP server, or tool, over a window you choose. Set a rule to Log only first to see what it would catch, then switch it to refuse calls. See Rate limits. SecureAuth turns enforcement on for each organization, so contact SecureAuth if you don't see the Rate Limits page.
See AI spend by team, model, and person
The Cost page now breaks spend down by team, so you can see which teams drive your AI spend and which licensed seats nobody uses. Each team shows its model mix and how many of its seats are active. To see one person's spend, open their profile, then select the Cost tab. GitHub Copilot appears next to your other assistants in usage, cost, and session data once you send its telemetry to the gateway.
Connect an agent to one resource instead of all of them
The connect dialog now offers a scope picker, so you can give an agent only the resource it needs instead of all of them. Keep the default, All resources, or pick one resource by name. The agent then loads fewer tools and can reach nothing else. See Connect an agent.
Tools grouped by the service they come from
A resource that covers several upstream services, such as Microsoft 365, now groups its tools by service. The grouping appears on the resource details page and in the policy tool picker, so you can grant access to one service instead of the whole bundle. See Resources.
Webhooks are open to every organization
Every organization can now use webhooks. They push audit events to your own systems as they happen, so alerts reach your SIEM or chat tool without anyone polling the audit log. Built-in destinations cover Slack, Microsoft Teams, PagerDuty, CrowdStrike, Datadog, and Splunk HEC, plus any HTTPS endpoint. You create and manage them yourself, and a condition on each webhook narrows which events it delivers.
Run data protection checks on your own AI provider
Data protection can use an AI judge to spot sensitive data that no fixed pattern would catch. You can now point that judge at your own AI provider instead of a shared one. The tool responses it reads then stay with a provider you control, which is what you need when data residency rules require your data to stay in your own region. See Inference. SecureAuth turns this on for each organization, so contact SecureAuth if you don't see it.
Microsoft 365 Graph covers Teams
Microsoft 365 Graph adds tools for Teams chats, channels, and teams, so agents can read and post in Teams under your policies. If you added this resource earlier, add the 13 new delegated scopes to your Entra app registration and grant admin consent again. Each user also needs to reconnect before the Teams tools appear.
More resource integrations
More resource integrations joined the catalog, which now covers more than 30 services. Every one runs under the same policies and audit trail as the rest. See Resource integrations for the full catalog.
More agents you can connect
Gemini CLI and Antigravity join the agent catalog. See Agent integrations for every agent you can connect and its setup steps.