更新日志
我们已发布的内容——8200.dev 的最新改进,最新优先。
RSS feedJun 29, 2026
Okta connector — live identity-security scanning
新增Connect Okta in minutes with a read-only API token (no OAuth app to register) and scan your organization for identity-security risks: users without MFA, Super Admin sprawl, weak password and session policy, AI / OAuth apps with user-data access, dormant "zombie" apps, deactivated users that still hold access, and legacy authentication. AI agent and machine-to-machine apps flow into Agent Guard. Read-only by design.
Jun 28, 2026
AI accountability positioning + AI liability page
改进A new AI accountability overview at /ai-liability explains the 2026 legal shift — courts and regulators increasingly hold the company deploying AI responsible for what its agents do — and positions 8200.dev as the proof layer: visibility, governance, and audit-ready evidence. Informational only, not legal advice.
Jun 27, 2026
Custom Detection Rules
新增Write your own detection rules with a no-code visual builder — combine resource and identity attributes with AND/OR logic to flag exactly what matters to your organization. Ships with ready-made templates, a dry-run tester, and JSON import/export. Available on Business and Enterprise plans.
External Sharing Governance
新增A dedicated center unifies every external exposure — public links, external collaborators, and external domains — with risk ranking and batch approve/revoke. An approval workflow suppresses reviewed shares on future scans, and trusted-domain controls reduce noise from partners you trust.
Security Awareness Scores
新增Each team member gets an educational 0–100 awareness score from real signals — two-factor status, sharing hygiene, and stale OAuth grants — with a leaderboard, a personal self-view, badges, and encouraging nudges. The score is educational only and is never used for HR decisions.
User & Entity Behavior Analytics (UEBA)
新增Per-user behavioral baselines flag anomalies over time — sharing spikes, bulk access, new external domains, dormant-account reactivation, OAuth bursts, and off-hours activity. A behavior heatmap and confidence scoring help you focus on the changes that matter.
Interactive API Documentation
改进The /docs/api reference now documents the full Developer API — more than 40 endpoints across 16 categories, each with copy-paste examples in curl, Python, Node.js, and Go, plus ready-to-use TypeScript and Python SDK snippets. Webhook event payloads ship with HMAC signature-verification examples, alongside an authentication guide, rate limits, an error reference, and a versioning policy. Programmatic access is available on Business and Enterprise plans.
Jun 26, 2026
MSP / Partner Management
新增Manage many client organizations from one consolidated partner dashboard, with consent-based organization linking, portfolio rollups, and partner-level billing. Built for managed service providers running security across a fleet of tenants.
Multi-framework Compliance Dashboard
新增Track SOC 2, ISO 27001, GDPR, HIPAA, and NIST CSF 2.0 side by side, with cross-framework gap analysis, per-control ownership and notes, and a gap-analysis export. This maps your evidence to each framework — it is not, and never claims to be, a certification.
SSO / SAML enhancements
安全Enterprise SAML single sign-on gained downloadable service-provider metadata, one-click IdP metadata import for Okta, Azure AD, Google Workspace, and OneLogin, and configurable attribute mapping. We also added just-in-time provisioning controls, SAML assertion replay protection, and enforcement and disconnect controls.
Smart Alerts
新增Scan findings are grouped into a real-time alerts feed with severity routing, suppression rules, quiet hours, and alert analytics. You see what changed without the noise of one notification per finding.
Jun 25, 2026
Compliance Evidence Collection
新增Generate an auditor-ready evidence package (SOC 2 / ISO 27001 / GDPR oriented) as a downloadable ZIP — one folder per control, populated with the product data that backs it. Secrets are never included, and monthly auto-generation is available.
Ticketing Integration
新增Push findings into Jira, Linear, GitHub Issues, Asana, or a generic webhook. Tickets are created automatically for new findings, and two-way status sync resolves a finding when its ticket is closed.
Risk Timeline & Incident Tracking
新增A unified chronological security feed sits alongside a documented incident-response workflow — open, investigating, contained, resolved, closed — with severity, assignees, and an append-only investigation log. Export a documented incident as a PDF for your auditors.
Blog
新增A new blog publishes practical guides to Google Workspace security, OAuth audits, data security posture management, and compliance, with full SEO and an RSS feed.
Jun 24, 2026
Shared Drive Scanner
新增The Google Workspace scan now covers Shared Drives (Team Drives) — drive-level membership and restrictions, external members, open-sharing detection, and stale-drive detection — all under the same read-only metadata scope, with no new permissions.
Custom RBAC roles
改进Custom roles gained fine-grained, per-feature permissions and ready-made templates — Compliance Officer, SOC Analyst, External Auditor, and IT Admin — on top of the built-in Owner, Admin, and Viewer roles.
Executive Reports
新增Generate a board-ready executive summary of your security posture as a polished PDF, written for leadership rather than practitioners.
Jun 23, 2026
Flow Guard
新增An interactive data-flow map visualizes how information moves and is shared across your connected sources, making risky external flows easy to spot at a glance.
Prevention Rules
新增Define proactive “watch for X, do Y” rules that act on new findings within each scan cycle — alert in-app, by email, by webhook, or in Slack. Detection windows are honest: the platform connects read-only, so prevention is scan-based, not real-time interception.
Agent Guard Dashboard
新增A dedicated dashboard inventories every AI agent and service account, maps what each can reach, and surfaces over-privileged and sensitive access so non-human identities are governed like any other.
Asset Inventory
新增A positive “what do I have” view of users, files, and Shared Drives — searchable, filterable, and exportable — complements the findings view so you can see your whole estate, not just what is wrong.
Status Page
新增A public status page shows uptime history and incident updates, backed by automated health checks that run every five minutes.
IP Allowlisting & Session Controls
安全Enterprise network controls let you restrict access to allowlisted IP ranges and set session maximum-duration and idle-timeout policies, with safeguards against locking yourself out.
Two-Factor Authentication (MFA)
安全Two-factor authentication (TOTP with backup codes) is available to every user, with optional organization-wide enforcement and trusted-device memory so people are not prompted on every login.
Slack Bot
新增Install the 8200.dev Slack app to receive finding alerts and run quick security queries directly from your workspace.
Industry Benchmarking
新增Compare your posture against anonymized peers in your industry and company-size band. Privacy-preserving minimum bucket sizes ensure no individual organization is ever identifiable.
Billing Portal
新增A self-serve billing portal provides a usage dashboard, invoice history, and self-serve cancellation, so owners can manage their plan without contacting anyone.
Help Center
新增A searchable in-app help center with real articles and contextual links throughout the product helps teams find answers without leaving the app.
Product Tour & Onboarding
改进Guided spotlight tours and an activation checklist help new teams reach their first scan faster.
AI Sales & Support Assistant
新增An in-app assistant grounded in the product knowledge base answers setup, pricing, and security questions in your language, without inventing features it does not have.
31 Languages
新增The interface ships in 13 fully-maintained languages, with on-the-fly translation for 20 more — 33 in total — plus automatic language detection and full right-to-left support.
Marketing & Transparency Pages
改进New public pages — how-it-works, use-cases, features, and a data-access transparency page — explain what the product does and exactly what it can and cannot see.
Jun 22, 2026
Production hardening
改进Full security headers (HSTS, CSP, frame-deny), global API rate limiting, request access logging, and branded error pages across the platform.
Email notifications
新增Transactional email for welcome onboarding, connector-health alerts, the weekly posture summary, and plan-limit warnings — each with a per-category opt-out in Settings.
Plan entitlement enforcement
新增Plan limits (connected sources, scan rate, features) are now enforced per organization, with a 30-day grace window so existing orgs are never broken by the rollout.
Pricing page with comparison and FAQ
新增A full pricing page with a feature-by-tier comparison table and a frequently-asked-questions section, so you can self-serve the right plan.
Compliance evidence reports
新增Generate an access-control evidence report (SOC 2 / ISO 27001 / GDPR oriented) for your organization; paid tiers can export it as a polished PDF.
Admin analytics dashboard
新增A platform analytics view (organizations, connector health, scan activity, onboarding, support usage) for operators.
Getting-started onboarding wizard
新增A guided four-step setup at the top of the dashboard — connect your first source, run a scan, and review your posture score.
AI support assistant
新增An in-app assistant grounded in the product docs that answers setup and security questions in your language.
Jun 21, 2026
AI Agent Governance
新增Detect AI agents and service identities across your sources, map what they can access, and (opt-in) enforce least-privilege policies.
Connector Health Daemon
新增Connected sources are now monitored continuously, with automatic recovery of stalled syncs and alerts when a source loses access.
Jun 12, 2026
Google Workspace connector, posture scoring, and findings
新增Connect Google Workspace for a read-only permission scan that builds your access graph, surfaces risky exposure as findings, and computes a posture score.