Release · v3.8.0
Guardrail node, the ORBY assistant, and inbound webhooks
Check content against your own policies with a dedicated canvas node, build workflows by chatting with an AI assistant, and let outside systems start workflows automatically.
This release adds three major capabilities. A new Guardrail node checks content against policies you write. ORBY, the assistant built into MagOneAI Studio, builds and edits workflows from plain-language requests. Inbound webhooks let outside systems such as GitHub or Stripe start your workflows automatically. You can also choose from three new AI model providers, and we've closed several security gaps.
Highlights
Guardrail node
In MagOneAI, a workflow (also called a use case) is a series of steps, called nodes, that you lay out on a visual canvas in MagOneAI Studio. The new Guardrail node is a step that checks a piece of content, such as an agent's draft reply, against a policy you write in plain language. For example: "never share personal data" or "only answer questions about our products".
The node has two exits: an Allowed branch for content that passes and a Blocked branch for content that doesn't. Blocked content is withheld from the workflow's output, so it never reaches the person on the other end. You decide what happens on the Blocked branch, for example sending a safe fallback message or stopping the run.
Why it matters: Until now you had to assemble this kind of check from several other nodes. It's now one purpose-built step, so your workflows are safer and easier to read.
Where to find it: Drag the Guardrail node from the node palette onto the canvas, or ask ORBY to add one for you.
Learn more: Guardrail node
ORBY, the Studio assistant
ORBY is an AI assistant docked beside the canvas in MagOneAI Studio. Describe what you want in plain language, for example "add a step that summarizes the uploaded contract and emails it to the legal team", and ORBY builds or changes the workflow while you watch.
What's new in this release:
- Nothing changes until you save. ORBY proposes changes to the canvas and to your agents and lists them in its side panel. They are written only when you click Save, so you can review everything first.
- ORBY can add guardrails. Ask it to protect a step and it sets up a Guardrail node for you.
- A redesigned side panel, with a new loading indicator, a setup card for when a model needs configuring, and a clear list of every change ORBY has proposed.
- Built-in safeguards. ORBY only shows you runs you are allowed to see, never repeats secrets back in its replies, and refuses requests that try to make it reveal its internal instructions.
Why it matters: You don't need to know every node type to build a working workflow. Describe the outcome you want and refine it in conversation.
Learn more: Build with ORBY · ORBY limits and safeguards
Inbound webhooks
A webhook is an automatic message one system sends to another when something happens. GitHub sends one when code is pushed, and Stripe sends one when a payment succeeds. With inbound webhooks, these messages can now start a MagOneAI workflow, with nobody needing to press Run.
- Several webhooks per workflow, for example one for each system that should be able to trigger it.
- Map the incoming message to your inputs. Pick which fields of the incoming message feed which inputs of your workflow, so it receives exactly the data it needs.
- Files and audio are supported. If the message contains links to files or audio recordings, they are passed into the workflow.
- Built to be safe and reliable. The public endpoint is rate-limited to protect you from floods of requests, and if the same message is delivered twice, the workflow only runs once.
Why it matters: Your workflows can now react to events in the tools your team already uses, the moment they happen.
Learn more: Inbound webhooks
Three new AI model providers
MagOneAI lets you choose which large language model (LLM) powers each agent. You can now connect three more providers alongside the ones you already use:
Why it matters: If your organization already uses AWS or Google Cloud, you can use the models available in those accounts. You also have more choice when balancing quality, speed and cost.
Improvements
Models and knowledge bases
- A default model for each organization. Admins can set one model configuration as the organization's default, so new agents start with the right model.
- Safer deletion of model configurations. If a configuration is still used by agents or knowledge bases, MagOneAI lists them first and stops you deleting it by accident.
- New Edit Knowledge Base panel. A knowledge base is a collection of your documents that agents search to answer questions. You can now change a knowledge base's settings from a single panel.
- Faster updates to edited documents (early access). When you re-upload an edited document, only the parts that changed are processed again, instead of the whole file. This is off by default while we roll it out.
Workflows and executions
- Pin use cases. Pin the workflows you use most so they stay at the top of the list.
- Filter executions by date. An execution is a single run of a workflow. The Executions page now has a date range filter with ready-made presets.
- Files from child workflows appear on the parent. When a workflow calls another workflow (a child), any files the child produces now show up on the parent run as well. In chat, they're only shown to people allowed to see them.
- Long-running helper tools no longer time out. Enhance prompt (which improves an agent's instructions), documentation generation and test-case generation now run in the background, so they finish even on large workflows. Test cases also accept file and image inputs and show the real error when a run fails.
- Clearer error messages across MagOneAI Studio, MagOneAI Hub and the Superadmin portal.
Tools and connections
Tools let agents act in other systems, such as sending email or reading a CRM. They connect to MagOneAI through tool servers that use the Model Context Protocol (MCP).
- Vendor-hosted tool servers, such as HubSpot, are now supported. MagOneAI also checks connections regularly and reports whether each connection's credentials are healthy. See Tool credential health.
- Reconnect after OAuth changes. If your organization changes the credentials of an app it uses for sign-in to a connected service (an OAuth app), you're prompted to reconnect, with a clear explanation of why.
- Tool servers no longer hold platform credentials. Tool servers now read and write MagOneAI files through the platform itself, so they no longer need direct access to our database or file storage. See Platform access for tool servers.
Users and administration
- Bulk import for single sign-on (SSO) users. You can bulk-import users who sign in through your company's identity provider, without setting a password for them.
- Resend expired invitations, with safeguards on the admin side.
- A display name is now required when users are created during organization setup or by bulk import.
- More detail in the Superadmin portal: each user's last login time, Superadmin and email-verified columns, filters for active and inactive workspaces and users, and a searchable organization picker in Access Control.
Bug fixes
- Chat workflows called through the API now remember the details given at the start of the conversation on every turn.
- Newer OpenAI models now pass Test Config when you set them up.
- Scheduled runs now use the input saved with the schedule.
- Steps inside a Parallel node now load large stored values correctly.
- Values containing hidden "null" characters no longer fail to save.
- On the canvas, the variable menu is no longer cut off, the START node's type picker works again, and the tool selector has a search box.
- In the Superadmin portal, the notifications dropdown scrolls correctly and organization member counts are accurate.
- Tool servers now enforce the sign-in fields they declare, and a badly formed configuration returns a clear error instead of a server failure.
Security
- Critical fixes in how secrets are looked up, and in our protection against server-side request forgery (SSRF), a technique that tricks a platform into making requests to internal systems. The protection now also blocks shared carrier-grade (CGNAT) and other non-public network addresses.
- Closed data exposure on pages served before sign-in, and removed an unused public endpoint that reported sign-up counts.
- ORBY safeguards, described above, keep ORBY within your permissions and keep secrets out of its replies.