October 2026
-
Workflow texts are delivered through PlaidCloud and confirmed, to members who opted in. The Notify: SMS step now texts workspace members or a distribution list. Each member opts in themselves from Text alerts in the user menu, with a US mobile number confirmed by a code, and workspace admins see each member’s status on the Member Info tab. A text that can’t be delivered is reported on the step, which fails by default or warns, and the member receives the message by email instead. Messages can use
{workflow_name},{project_name}and{run_url}, repeats within a set time are collapsed into one, quiet hours hold texts until they end, and Send test to me checks your own number. Carrier-gateway texting, which no longer delivers, is gone: a step still saved with a mobile carrier and typed phone number doesn’t fail the workflow. With no members or distribution list chosen it completes with a warning, No text was sent: this step still uses the retired mobile provider and number. Open the step, choose members who’ve opted in to text alerts, and save it., and sends nothing; once you choose recipients it texts them and ignores the leftover carrier and number. See Notify Via SMS and Text Alerts. -
Microsoft 365 Copilot gives reliable answers and corrects its own mistakes. Copilot reads the errors and hints PlaidCloud returns, fixes its request and tries again instead of saying the tools are unavailable. For a business question it finds the analysis path and passes the project and table itself, and a filtered total such as one year’s EBITDA for a business unit comes back in a single call. An analysis path can be given by id or by name,
query_data_readcan preview only the columns you name, and a misspelled column name lists the closest matches. A person who isn’t in a Copilot access group is told to ask an administrator to add them to Microsoft 365 Copilot Read Only. Administrators update by downloading the Copilot package again and updating the app in Teams; users start a new chat. See Microsoft 365 Copilot and Analysis Paths. -
Moving a project to Lakehouse v2 is guided from readiness to undo. Check Migration Readiness reports each area — tables, views, steps, dashboards, data shares and capacity — as clear, needs review, blocked or checked during migration, with a plain-language explanation of every finding; an area PlaidCloud can only check while it migrates is never shown as clear, and a project already on Lakehouse v2 is told it has nothing to migrate. A project that other projects read through a data share is migrated after those projects, or after the share is removed. Try on v2… makes a private trial copy of the project on Lakehouse v2 with schedules and sensors turned off and ERP posting in simulate mode. A migration can start now or at a time you choose. The project’s own workflow schedules pause while it runs and are restored afterwards; writes made during a migration are lost, so a workflow started then shows a warning. When it finishes, a What Changed… report lists each table’s outcome, the views that were skipped and the schedules restored, and Undo Migration… returns the project to Lakehouse v1 within the undo window after you type the project name. A failed migration shows why it failed and what will be lost, and offers Resume. You are notified, by message and by email, when a migration finishes or fails. Views that can’t run on Lakehouse v2 are skipped and listed, JSON values keep their types, and a number inside JSON too large for exact storage is stored with double precision and reported. Migrate Project to Lakehouse v2… appears for members who can edit projects, and only a project’s Architects can migrate it — start, schedule, cancel or undo — and the project must be unlocked. Before a run starts, PlaidCloud checks that your plan has room for the copy: on a plan with a storage limit it refuses a move that wouldn’t fit, counting other migrations in progress, and on a plan billed for extra storage it warns you of the expected overage. A migration can’t be stopped once it is switching over, and if the switch-over itself fails partway, the run shows Contact support. Don’t retry. instead of offering Resume. A finding you accept is accepted for that item only. See Migrate a Project to Lakehouse v2.
-
Copying a project copies its data, with a choice of how much. Copy Project offers Structure only, Full data and Sample, and every table’s rows are copied, on the same lakehouse and across lakehouses. A review step before the copy shows its size, the number of tables, a rough estimate, the target lakehouse and any warnings. A copy with data is private to the person who made it, and a copy of a project with row-level security stays private. A Copy Results window lists each table’s outcome by name with the reason for any failure, and Retry failed tables copies only those. Copying data into an existing project needs write access there. You are notified, by message and by email, when a copy finishes or fails, and clicking Copy Project again while a copy is starting does not start a second one. See Copying a Project.
-
You choose which security groups can see each dashboard, in one dialog. Who can see this? opens from a dashboard’s Home tile, its row in My Dashboards, or the Audience column, and sets the dashboard to Everyone in the project, Specific groups or Only owners (Draft), with a preview of who gains or loses access. Owners and workspace admins always see their dashboards, and group changes reach dashboards within about a minute. A copy keeps the original’s audience, and anyone can copy a dashboard that has no restriction. Someone blocked from a group dashboard gets a Request access page that emails its owners, who grant or dismiss the request in PlaidCloud. Workspace admins get a Dashboard Access Review with filters and CSV export, and My Dashboards can Set audience… on up to 50 dashboards at once. A project’s Default Dashboard Audience sets who sees its new dashboards from their first publish, and the AI assistant manages audiences too. A dashboard’s audience hides the dashboard, not its data: chart data still follows project access, and Row Access limits rows. See Control Who Can See a Dashboard.
-
The Posting Register API lists outstanding reversals and ERP types. The exception list gains a reversal outstanding category, with its own count: a posted entry whose reversal was sent but never settled, which stays listed until someone resolves it. A separate list returns every ERP type on the postings you can see, for building an ERP type filter. See Reversals Still Outstanding.
-
The fix assistant answers common errors straight away. When a step fails because an expression or its column mapping names a column that isn’t in the table it reads, a setting it needs was left empty, a workflow it runs failed, or a table it names can’t be found, the first reply in AI Assistant explains what usually causes that error, which words in the error message to look at, and how to fix it. A SQL Extract step gets the same for SQL that can’t be read as written, a function the database doesn’t recognize, a table that doesn’t exist, a function given a type of value it can’t work with, or a value that can’t be converted to the type asked for. A Table Extract step gets the same for a source table that doesn’t exist, an expression using a function the database doesn’t recognize, a function given a value of the wrong type, and a step with no output columns, with fixes that point to the step’s own tabs and fields. Reply to have the assistant look at the step itself and propose a change. See Common Errors.
-
Fix a Weave finding with the AI fix assistant, straight from the Weave tab. Select a problem in a project’s Weave tab and click Fix to open the fix assistant on it, in a window of its own. Fix is offered for Allocation column mapping and Step expressions problems, and for Last run failed when one step failed in that run. The assistant starts from the problem as Weave reports it now, proposes a change, and applies it only once you approve. Closing the chat reads Weave’s findings again, so a problem the fix resolved leaves the list. See Fix a Finding with the AI Assistant.
-
The fix assistant re-runs the step it fixed, when you ask it to. After it applies a fix, the assistant asks whether to re-run the step. Say yes and it runs the step and tells you whether it succeeded, finished with a warning, or failed again, and it diagnoses a new failure. It doesn’t offer a re-run for a step that posts to an ERP system or runs another workflow, which you re-run from its workflow, or when your role can’t run workflows. See How It Works.
-
Weave tells you when a step’s run changes how a column’s values spread. After each run, Weave compares every table the step wrote with the table as it stood before the run, and reports a decimal-number column whose values spread very differently, with a shift score where 0.25 or more is a large change. It compares with the last version that held rows, so the first good run after a failure is judged against the last good data. Whole-number columns, usually codes, periods or flags, are not compared. A table with Row Access, with more than 5,000,000 rows, that takes longer than 10 seconds to compare, or whose earlier version is no longer kept, is reported as unchecked rather than passed. See What Weave Checks Today.
Changed
Section titled “Changed”-
Steps that build their own results now load them directly, and faster. Solver, Location Optimizer, Forecast, Directory Listing, Import XML reading an Alteryx XML input, and — when they run in pandas — Pivot, Melt, Allocation Split, Allocation with Dimension and Rule-Based Tagging now load what they produce straight into the target table as typed data, rather than through a temporary text table. A million-row result from Solver, Forecast or a pandas step loads in about a fifth of the time on StarRocks and in under half on Databend.
-
Those steps write an empty value as a null. On StarRocks an empty text value used to be written as an empty string and an empty decimal number as 0, and the pandas Melt wrote empty strings on every lakehouse. A later step that finds those values with
= ''or= 0needs to test for null instead. -
A scheduled event keeps its own ERP posting mode. Set an event to Live, Simulate or Off through the API or an AI assistant, and every run it starts uses that mode, still capped by the project’s own setting. Editing, pausing or re-enabling the event in the Event Scheduler keeps the mode, so a Simulate schedule stays simulated; an event with none set runs Live. Run Selected Events starts a plain Live run — use Run With Posting Mode on the workflow to run it simulated on demand. See ERP Posting Mode.
-
Security group changes made outside PlaidCloud reach dashboards on their own. A membership change made directly in Keycloak, or by single sign-on placing someone in a group at sign-in, reaches row access in dashboards within about 15 minutes, with nothing to save or retry. A new member who joins your default security groups gets their dashboard rows within about a minute, like every other membership change made in PlaidCloud. See Keeping Dashboards in Sync.
-
Document steps finish with a warning when their source folder is missing or empty. Convert Encoding, Convert to UTF-8 and UTF-16, Compress PDF, Merge Multiple PDFs, Convert to PDF, Convert to JPEG, Crop to Headshot, Fix File Extension and Text Substitution report “Nothing to process” with the path, do nothing, and the workflow continues, so a scheduled run over a folder with no files that day no longer fails. See Document Workflow Steps.
-
Duplicate Step opens the step form. Duplicating a step from the workflow table, the canvas or the project’s step list opens the step form on its General tab, filled in from the step you are copying, so you can rename the copy and choose where it goes. The copy keeps the original’s configuration. See Advanced Workflows.
-
Steps and screens always open in the current forms. Holding Ctrl or Cmd while opening a step or a screen no longer switches to the old-style form, and the old application layout can no longer be loaded instead of the current one.
-
Steps check their settings when you save them, again. As in the old-style form, saving a step whose settings would fail its run, or give the wrong result, is refused with a message that says what to change. Saves through the API and AI assistants get the same checks, except that a setting they leave empty isn’t checked until it’s filled in. Each step’s page lists what it checks:
- Report: Generate Single and Report: Generate Batch — source, constant and batch column names must each be distinct and readable by the template: letters, digits and underscores, starting with a letter or underscore, and not one of the eight words the template reserves, such as
trueorself. New sources are namednew_source,new_source_2and so on. - Table: Union Distinct and Table: Union All — every source must produce the first source’s columns.
- Table: Pivot (Rows to Columns) — the category and value columns must be among the step’s output columns.
- Table: Faker — each fake data column needs a name of its own.
- SAP: Attach File to Document — the output columns must include
relative_file_path, as text. - SAP PCM: Hyper Loader — each source must match its loader table, and two sources can’t share a name.
- SCD-2 As-Of Join — a column takes one role, once, and a Literal As-Of Date must be a real date in YYYY-MM-DD form.
- Document: Save Dashboard as PDF — at least one Column Filter, each with a Mapped Filter Column that is one of the dashboard’s filters, and only one File Name.
- Forecast — the mapping needs source columns.
- Text: NLP (AI) — a source table is required, and an ID column can’t share its name with a column the task writes.
- AI: LLM Step — a result schema must be a JSON object declaring
"type": "object", and bindings need an Anthropic connection, whose Agent Access allows writes for a binding with Write checked. - Table: Append and Table: Upsert — when the target table already exists, the mapping must fit its columns and types, and an upsert must map every one of its columns. Numeric and currency count as the same type.
An Alteryx workflow is imported through the same checks. Re-importing one into a project whose Append or Upsert target tables already exist with different column types now fails the import, rather than that step’s first run.
- Report: Generate Single and Report: Generate Batch — source, constant and batch column names must each be distinct and readable by the template: letters, digits and underscores, starting with a letter or underscore, and not one of the eight words the template reserves, such as
-
Saving a step with an empty column mapping fills it from its source, as the old-style form did. In Table: Append, Table: Upsert, Table: Pivot (Rows to Columns), Table: Melt (Columns to Rows), SAP: Attach File to Document, and each source of Table: Union Distinct and Table: Union All, saving with a source table chosen but no source or no target columns fills the empty side, as Populate Both Mapping Tables would. Report: Generate Batch fills its batch mapping the same way.
-
Table: Project to Project Copy names its target project again, and checks the data shares it copies through. The step’s Write To section has a Target Project picker, which starts on the current project, and Target Table browses whichever project you pick; a step created in the current step form had no target project and failed every run. Such a step now copies into its own project, without needing to be opened and saved again. It also reads its source through a data share: copying from a project that shares with this one used to fail with You do not have access to this project, while Import Project Table, reading through the same share, worked. A copy needs the source project to allow the target to Read and, when it writes into another project, that project to allow this one to Write. A run without a share it needs fails, saying which share to add, and saving such a step is refused. A copy within one project needs no share, and a refused copy no longer leaves an empty target table behind. See Data Sharing Management.
-
Full agent access is deprecated and will be removed on January 15, 2027. Until then, an LLM connection’s Agent Access and a Microsoft 365 Copilot user’s access level can still be set to Full, and an LLM step that uses Full access logs a warning when it completes. Move to Read & write: agents then make changes through PlaidCloud’s write tools rather than with SQL that writes, and an LLM step writes only to bindings with Write checked, and cannot run SQL that writes or create tables. See Agent Access.
-
A member with no apps lands on the Launcher, which says it has nothing to show yet, instead of a blank Home tab.
-
Report: Generate Batch no longer shows Report Constants. Its Report Constants (Fixed Values) section was never used: each batch row supplies the template’s values. See Reports Batch.
-
Manage Accounts no longer shows a Backup icon. Backup sets were never available, and the window it opened could not load. To keep a copy of an account’s files in another account, use a scheduled workflow — see Backing Up Document Accounts.
-
Row Access handles column names with special characters, and its sync status says what is wrong. A table with a column named like Fiscal Year & Period, with an
&,/,(or%in the name, no longer raises an error such as “Period is not defined” when you pick the column to restrict, preview a table for a group, or save. A restricted column that also sits on a table that was never published now ends in Error naming that table, instead of staying on Waiting; publish the table or restrict the column on a published table. A sync being retried after a failure reads Retrying with the reason and a Retry button. See Keeping Dashboards in Sync. -
The AI assistant changes nothing until you approve, and shows table and column names as written. Asking it to build a step into a new table used to create the table before you had approved anything. The proposal now says the table is new and where it will go, and the table and step are created together only after you approve. Creating a project, workflow or dimension, copying a table, changing table properties, and adding or removing labels also ask first. An approval counts only in your very next reply, and if you change the request, the assistant shows you the new version to approve instead of building the old one. Proposals name tables rather than showing internal ids. In every AI chat, including the expression assistant, names with underscores such as
agg_freight_by_countrydisplay exactly, instead of turning into italics with the underscores dropped. See Building a Workflow Step. -
Weave findings name things properly. A workflow with no name reads “unnamed workflow” instead of an id, and a check that couldn’t run is named by its title, such as “Last run failed”. Two different duplicate steps in one workflow are now separate findings, so marking one read no longer hides the other. Some findings you had already read can show as unread once after this update. See What Weave Checks.
-
Excel imports read whole-column ranges and binary workbooks. In the Import Excel step, a selection such as
Original$A:BJimports those columns of that worksheet, and XLSB workbooks import worksheets and cell ranges, with the sheet picker listing them. See Import Excel. -
An ERP answer PlaidCloud can’t confirm is held as in doubt, and a reversal is sent only once. A Workday or Dynamics 365 Finance & Operations posting that timed out or got a server error could be recorded as rejected, so the Posting Register suggested reversing a journal that might already be in the general ledger, and reversals on those systems and on NetSuite, Sage Intacct, QuickBooks and Xero could be recorded the same way. Any answer PlaidCloud can’t confirm — a timeout, a server error, a status it doesn’t recognize — is now held as in doubt for you to check. A reversal from a workflow and one from the Posting Register share one lock, so a posting can’t be reversed twice by a re-run or by two requests at once, and Workday and Dynamics 365 Finance & Operations settle an in-doubt reversal by looking it up in the ERP the next time it is attempted. See Reversal.
-
LLM steps run on older Claude models again. An LLM step using an Anthropic model older than Claude 4.6 — Claude Sonnet 4.5, for example — failed every run with adaptive thinking is not supported on this model. The step now works with any Claude model. See LLM Step.
-
Updating a member or group through MCP changes only what you name. A partial update to a member through
identity_member_upsertcleared the fields it left out and could change whether the member was active, and adding or removing a group’s members could change the group’s default status. Both now leave everything you didn’t name as it was. -
Table Explorer says when a column’s details fail to load. A column whose details failed to load stayed blank or kept loading with no reason given, even when the cause was a problem with the filter. The column now shows Profile failed, with the reason when you hover over it, and a failure on PlaidCloud’s side is reported with an ID the PlaidCloud team can trace. See Column Data and Unique Counts.
-
Bring your own data imports your CSV. Choosing Bring your own data on an empty Projects screen or on Home uploaded the file and created a project, then failed at the import and removed the project again. It now loads your file into a table in the new project and opens the project’s Tables list. See Start With Your Own CSV.
-
Pivot and Allocation Split in pandas mode keep date-and-time values. On StarRocks those columns were written empty, and on Databend the step failed. An infinite value in their results — a division by zero, for example — is now written as a null where Databend failed the step.
-
Table: Upsert steps save again. Once a step’s mapping had target columns, the step form refused every save, because the mapping had lost its Update Key column. The column is back, right after the target column’s name, and ticked by default. A column with no Update Key setting counts as a key, and at least one column must stay ticked. See Update Key.
-
Document: Save Dashboard as PDF keeps each source column’s type. A step saved in the current step form lost the types of its source columns, and failed every run. The types are now kept. A step saved before this fix needs its source inspected again, with Inspect Source › Populate Mapping Table, which now keeps the Column Filter and File Name tags you’ve set; until then, saving it names the columns with no type. See What’s Checked When You Save.
-
Table: Union Distinct and Table: Union All match each source’s columns by name. A source that named the same columns as the first source, in a different order, was combined by position, so its values could land in the wrong columns. See Table Union All.
-
SCD-2 As-Of Join takes a workflow variable as its Literal As-Of Date, as the field’s tooltip says. A variable such as
{report_date}wasn’t filled in when the step ran. See As-Of Date and Options. -
A step that writes a table in a locked project no longer fails at the automatic backup taken after its rows load.
-
App Runner apps keep themselves current, and older ones work for viewers on a project that restricts rows. An App Runner app made before run answers were held for one run only saved them on the workflow, which a project that restricts rows refuses for anyone but its Architects, so the app failed for its viewers. Every App Runner app is now refreshed to the current version and rebuilt when PlaidCloud is updated, and again on each Rebuild or edit. A locked app is left alone until you unlock it and click Rebuild, and hand edits to its generated files are replaced, with the earlier versions kept in its Git history. See Keeping the App Current.
-
Where Used includes the notification steps that use a connection or an agent. A connection used only by Notify: Slack or Notify: Microsoft Teams steps, or an agent used by Notify: PlaidCloud Agent steps, was reported as not in use, so it could look safe to change or delete. Where Used now lists those steps.
-
Members with Org Admin permissions no longer see an empty Org Admin tab. There was no screen behind it.
-
Opening a step from anywhere opens the step form. A step opened from a table’s or a UDF’s dependencies, Where Used, the project’s step list, the workflow log or the Inspector’s Edit Step Details opens in the same form as from the workflow table. A step with no configuration form of its own, such as some steps the Alteryx converter creates, opens on its General tab instead of failing.
-
Importing a project archive tells you when it is done. A progress window follows the import, and when it finishes you are told so, along with any warnings it raised. An import that cannot start, because the project you chose is locked for example, leaves the window open and says why, where it used to close at once. See Restoring an Archive.
-
A workflow import sent again while it is still loading no longer loads twice. When a run resumed or retried an import step while that step’s import was still loading, a second load of the same files could start alongside the first. The repeat now joins the load already running. A step whose settings use a variable that changes every run, such as
{date}, still starts a new load. -
Run history counts the rows every step writes. Some steps record their output table by its name, and run history found no row count for them: the step’s Rows Out was blank, and the workflow’s Rows Out total left it out. Runs from now on include those steps. See Run History.
-
Parquet and Avro imports inside a Macro load directly. An Import Parquet or Import Avro step inside a Macro always took the slower route of converting its files first, even where the same step outside a Macro loads them straight into the table. It now loads them the same way inside a Macro as outside one.
-
An action that ends in a server error is no longer sent again. When the server returned an error or timed out, PlaidCloud resent many requests up to three more times, even though the server may already have carried them out, so the same action could happen twice. They are now sent once. A request that fails because the server is briefly unavailable is still retried.
-
Retrieving column values through the REST API now works.
POST /analyze/query/retrieve-column-valuesrejected every request that sent its filters as a list, the only shape it can apply, and a request without filters, so the endpoint could not be used. It now takes filters as a list of dimension and item pairs, and filters can be left out. -
The allocation trace API says what was wrong with a request. A request to an allocation trace endpoint under
/analyze/stepthat named a column that isn’t on the table, gave an unsupported direction ormax_depth, or supplied both a table and a step, or neither, came back as a server error with no explanation. It now returns a 422 that names the problem and, for a missing column, lists the columns the table does have. -
A table bundle’s import log says when a table’s column settings weren’t restored. Importing a bundle restores each table’s column dimensions, notes, display formats and vector widths. If that restore failed, the table still imported and the import log listed it as imported, with nothing to show its column settings were missing. The table’s entry in the log now includes
column_config_restored: false, so you know to set them again. -
The faithfulness check catches a figure given to a what-if result that couldn’t be measured. A what-if answer lists the results it couldn’t measure as having an unknown impact, not a zero one, but a reworded version that quoted another result’s figure against one of them still passed the check. A clause that names such a result beside a figure must now also say it wasn’t measured, and the check explains how to fix one that doesn’t. It also no longer rejects a what-if answer’s own wording when a result’s name contains a dollar amount. See The Written Summary Is Checked, Not Just Written.
-
A SQL Server login that is refused fails only its own step. When SQL Server refused a connection’s login, for example because the password was changed at the source, the step using that connection stopped the PlaidCloud service running it. Any other workflow steps running there at the same time stopped too, and each retry of the step stopped the service again. The step now fails with SQL Server’s own reason, such as Login failed for user, and nothing else is affected. If the password has changed, update it on the connection.
Security
Section titled “Security”-
Only a workspace admin can change a workspace admin. Editing an admin, changing their email or password, deactivating, re-enabling or deleting them, ending their sessions, changing their groups, and making someone an admin all need a workspace admin. Any other member is refused, and so is a project or agent service account, whatever member permissions it holds. A Deactivate Workspace Members step whose list includes admins deactivates everyone else and names the admins it left active. See Changing a Workspace Admin.
-
Export templates read only the data they’re given. An Export Templated step’s template, and a templated export through the API or MCP, renders in a sandbox. Each source is a read-only list of rows, where
first(),all(),mappings(),scalar()and the other read methods still work; with Use Pandas Dataframes for Table Data on, it is a read-only table withcolumns,itertuples(),iterrows(),head(),tail()and column totals such asinvoices['amount'].sum(). Other pandas methods, such aslocandgroupby, are no longer available, and any method whose name starts withto_is refused. The older REST step’s request body and a report’s RML template render under the same kind of restriction, so a template that reaches past its data fails the step, and report formulas no longer run as code. See What a Template Can Use. -
Dashboard thumbnails show only what you can see. A dashboard’s thumbnail is rendered as you, so it follows your row access, and is kept for up to 7 days.
-
Dashboards take accounts from PlaidCloud sign-in only. Self-registration pages in Superset are closed.
-
Dashboards and datasets import only from the ZIP file that Export produces. An older JSON or YAML export is refused, so export the dashboard again and import the new file. See Importing Existing Dashboard.
-
Multi-line credentials are masked as you type. A NetSuite private certificate, an Anaplan certificate and private key, a Postman API key and a Slack or Teams webhook URL show as dots while you paste them, with browser spell checking turned off. Leave one blank when you edit a connection to keep the saved value; a replacement made only of spaces is refused. See Create and Manage a Connection.
-
With segregation of duties on, ERP reversals go through the Posting Register. A reversal requested through the project-level ERP reversal API — the path a project, a user-defined function or a service account uses — is refused, with a message to reverse from the Posting Register, where approval applies. Posting is unaffected, and Business Central, Oracle Fusion and Acumatica keep saying that they don’t support reversal. See Segregation of Duties.
-
Imports and project archives refuse unsafe content. An import no longer accepts a loading query from whoever calls it: PlaidCloud builds the query from the import’s own settings. A project archive holding files or settings that a PlaidCloud archive never contains is refused before anything is restored. See Restoring an Archive.
-
An import through MCP runs as you, in the project you name. The
table_data_importtool’soptionscould replace the person and project an import ran as, so the import was checked against their permissions instead of yours.optionsnow only fills in import settings the call leaves out. -
A read-only AI connection can no longer export files or send changes through a REST connection. Through Microsoft 365 Copilot or another AI agent connected over MCP, an agent with read-only access could export a table to a file in a document account, save a dashboard as a PDF document, copy a table’s rows into another project, or send a request that changes data to an external system through a REST connection. Through MCP, exporting a table to a file or saving a dashboard PDF now needs permission to write documents, copying into another project needs permission to write tables, and a REST connection request other than GET or HEAD needs permission to write connections, so a read-only agent is refused. This applies to people using MCP directly too, for example through the Claude connector: without those permissions, these actions are refused. An AI agent below Full access can also explain-analyze only a single read query through MCP. Exports, dashboard PDFs and REST connection requests in the PlaidCloud app are unchanged. An agent at Read/Write or Full access can still do all of them if the person it acts for has those permissions. See Access Levels.
-
A copied or imported project no longer inherits permission to post to an ERP. Copying a project, or creating one from a project archive, used to carry over the original project’s authorization to write to an ERP connection, so the new project could post without an Architect ever authorizing it. An Architect now authorizes each project separately. The project’s ERP posting mode is still copied.
-
A data share speaks only for members of the project it was granted to. Anyone who named the receiving project could act on the sharing project as an Architect — reading its project, table and dimension details, and creating tables and dimensions in it — without a role in either project, and a Read share allowed those writes too. No row data was exposed. Reading through a share now needs a role in the receiving project, and writing needs a Write share and the Manager or Architect role there. Import Project Table and Export Project Table steps work as before. See Sharing Data Between Projects.
-
Restoring an earlier version always restores the item itself. Restoring a project or dimension version checked permission against the target named in the request but restored the item it was called on, so a Manager on a project that restricts rows could restore that project’s settings by naming another project as the target. Restoring a project, dimension, user-defined function, step, workflow or data editor now applies in place, a different target is refused, and the permission check is on the item restored. Through the AI assistant or MCP,
project_versionsrestores in place with the target left out, where it used to fail. See Version History. -
An undocumented API endpoint that could post to Sage Intacct without the ERP write checks has been removed. It posted a journal entry without checking that the project was authorized for the connection, and kept no record of the post. Post journal entries with the Intacct: Post Journal Entry step, which applies those checks.
-
SAP and EBS postings can no longer be sent to an agent directly. The agent queue, reached through the API or the MCP
agent_payloadtool, would pass any saved payload to an on-premises agent, so an SAP or EBS posting could skip the ERP write checks, or be sent a second time. The queue now refuses those postings. An SAP function call sent through the queue is now checked against the same list of blocked administrative functions as one from a workflow step. -
An SAP Post step in Test Only Mode needs the same permission as a live posting. Test Only Mode still sends the documents to SAP, and whether SAP treats them as a test is up to your SAP posting function. A test run now needs write permission on the SAP connection, or the project’s authorization to post to it, just as a live posting does. A test run still doesn’t stop a later live run of the same documents.
-
A dimension backup file can only write to the dimension it names. Restoring a dimension from a backup file applied every entry the file carried, so a file edited by hand could write into a dimension in another project — including one the person restoring it could not otherwise open. A file whose contents do not belong to the dimension named in its own header is now refused, nothing in it is applied, and the dimension being restored is left as it was. Restoring a backup into a different dimension, which is supported, is unaffected: it is the file’s own contents that have to agree with the file’s own header.
-
An AI assistant conversation can be continued only by the person who started it. Someone who sent the assistant another person’s conversation ID, including the ID of a deleted conversation, was given that conversation’s history and could add to it. The assistant now refuses, and deleting a conversation removes all of it. See Manage Past Conversations.
-
The environment that runs user-defined functions no longer includes PySpark’s Java libraries. They weren’t usable there, and they carried known security vulnerabilities. PySpark’s DataFrame and SQL API still reaches your workspace’s Spark Compute Cluster, but a UDF that imports
SparkContextorRDD, or passes a Spark DataFrame to statsforecast or Fugue, now fails. See Getting Started with PySpark.