Skip to content
SmiKar Software

Burrow Release Notes

63 min read · Last updated · Page version 46

Notable changes to the Burrow security and audit layer of Squirrel. Customer-facing release notes - updates that affect what you see, do, or rely on in the dashboard and email.

Burrow ships as continuous deploy - there are no versioned releases. Entries below are dated and describe the change in customer-observable terms.

2026-08-14

  • You can now name the domains you consider risky, and have alerts about them shout louder. The Internal Domains page gains an Untrusted domains list - the opposite of a partner. Where a partner domain can quieten an alert, an untrusted domain raises its severity to a level you pick (High, Critical, or one level up from wherever it landed). Personal mail services are the case this was built for: company data heading to someone's private mailbox deserves a louder alarm than the same share to a known business. It only ever raises - an untrusted domain can never make an alert quieter - and a share that reaches both a partner and an untrusted recipient always escalates, because the riskiest recipient sets the tone. A domain cannot be a partner and untrusted at the same time; adding it to one list removes it from the other.
  • Everything now lands in one History. Actions taken from the Suggestions panel and edits to sensitivity-label rules were being written to a separate journal that History never read, so they were invisible there. Both now write to the same trail as every other administrative action, and the existing entries have been migrated in - nothing was lost, and History is now the single place to answer "who changed this, and when".
  • A severity pin can quieten an alert, but it cannot overstate one. Pinning a severity on the Posture page still lowers freely. Raising is now capped at what the evidence for that alert actually supports, so a pin cannot mark something Critical when nothing in the alert justifies it. When a pin is capped, History records it, and the alert shows the severity it was allowed to reach.

2026-08-13

  • Alert emails now show why the AI reached its verdict. Under the triage pill, per-alert emails and incident cards carry a "Why the AI says this" box naming the evidence actually weighed - baseline, geography, working hours, whether the activity was platform machinery - plus, on an incident, a line for each other alert in the cluster. Two things make it trustworthy rather than decorative: verdicts reached on precedent rather than a full review say so outright ("recurring pattern for this user, 13 similar in 30 days - dismissed without full AI review"), and reused reasoning is checked against the alert in front of you, so it never quotes figures belonging to an earlier one. See Email types.

  • Incident emails are scannable. The attack-chain summary is now an overview sentence followed by one short line per event in time order, instead of a paragraph that restated the timeline printed directly beneath it. The suggested next step is called out separately. The same structure is produced whether or not the AI is available.

  • The status select tells you when a disposition was set, and by whom. Hovering an alert's inline status on the Alerts page shows the date and the analyst - the quickest way to tell a month-old dismissal from an alert that has just recurred.

  • Labelled files in OneDrive are now investigatable. Sensitivity-label rules have always followed labelled documents into personal OneDrive - a Confidential file shared externally from someone's OneDrive raises an alert, because a label protects the file rather than a location. The evidence behind those alerts was being discarded, so the alert could not be examined in Hunt. Labelled OneDrive events are now retained. Behavioural analysis is unchanged: baselines, volume rules and profiles still cover team and group SharePoint sites only, and personal OneDrive sync is still deliberately left out of them. Monitored-user counts and baselines are unaffected. See what Burrow watches.

  • Dismissing is now reversible, and clearing your queue no longer counts as judging it. Two related changes. First, any dismissed alert can be reopened - from a Reopen button on its History row or by setting its inline status to the new Reopened value. A reopened alert returns to Active and Open immediately, even if the AI had judged it not real, because an operator override always wins. Second, every bulk dismissal is now recorded as a single batch you can undo - an Undo bar appears on the Alerts page straight after, and History keeps a Recent bulk actions list. If you bulk-dismiss a pile of alerts by mistake, one click brings them back.

  • Bulk dismissals now show you what you are about to hide. Before a bulk Dismiss runs, an impact preview states how many alerts are affected, their severity mix, any the AI judged likely real, any belonging to a watchlisted user, and whether you are close to auto-quieting that pattern.

  • The dialog asks whether this is a queue sweep or a judgement, and the answer matters. A queue sweep is recorded and reversible but never feeds the learned quieting. Judged benign does. Previously the two were indistinguishable, so routine clean-outs could quietly train Burrow to stop alerting on things nobody had actually looked at. Only deliberate judgements train it now, and reopening an alert cancels its earlier contribution. See Tuning a noisy rule.

2026-08-05

  • You can now choose whether partner guest-adds are quietened - it is off by default. A second selector on the Internal Domains page, "When guests added to groups are all partners", decides whether adding partner guests to a SharePoint group reduces the alert's severity, and by how much. The default is keep full severity, because a group membership is standing access - no expiry, everything the group can reach, harder to revoke than a sharing link - so it deserves a look even from a trusted partner. If your teams routinely onboard partner guests, pick a reduction level. It applies only when every added guest is from a partner domain, and the reduced severity is capped so co-occurring signals cannot quietly push back up something you have declared expected.
  • Offboarding no longer produces a false alert. After someone is disabled, Microsoft's compliance engine keeps processing their content server-side and attributes those events to the disabled account. That was enough to trip the new disabled-account rule and email a High alert for what is really routine cleanup. Burrow now recognises compliance-engine activity - it carries no device address - and does not count it as the account acting. The same operation from a real device still counts, so a genuine leaver-with-live-sessions still alerts.
  • New page: Setup - the onboarding checklist, checked live. A Setup page has been added to the left navigation (Admin group). It shows each setup step as done, needs attention or optional, checked against your actual configuration rather than being a list you tick off yourself - "3 domain(s) confirmed", "1 recipient(s), min severity 'medium'" - with an Open button on each row that takes you to the page where the work is done. Required steps are separated from recommended ones, with a banner reporting how many required steps remain. New steps appear automatically as the product grows. See the onboarding checklist, which follows the same order.
  • You can now see how much of your organisation Burrow is covering. The dashboard home page and the Setup page both show "monitoring X of Y users" - people with meaningful SharePoint activity in the last 30 days, against the enabled accounts in your directory. Dormant accounts and service identities are not counted. It answers "is Burrow actually watching our organisation?" without an export or a support ticket.
  • Identities can show your whole directory, not just active people. Three new chips on the Identities page: No SharePoint activity (enabled accounts doing nothing - dormant accounts are unwatched attack surface), Disabled, and Whole directory. The default view is unchanged - it is still the monitored risk roster - and a free-text search now covers the whole directory whichever chip is set, so "is user X covered?" always returns an answer instead of an empty table. Rows carry a status badge, and a disabled account with recent SharePoint activity is called out specifically.
  • Data retention is now a fixed product behaviour, and it is documented in full. The hot window - how long per-event detail and alert files stay instantly searchable in Hunt - is 14 days on every deployment. It was previously a per-deployment setting that had drifted out of step with the documentation, so it is now a constant rather than something that can differ between tenants. Nothing is lost at 14 days: events and alerts are compressed and archived into your own Azure Storage account, and a rehydrate brings any month back into Hunt in minutes. The full picture - what is kept hot, what is archived, what is never deleted, and who owns it - is now on one page: Data retention and storage.
  • New rule: activity from a disabled account. Any SharePoint activity from an account that is disabled in your directory now alerts at High, with no volume threshold - a disabled account has no legitimate activity, so one event is already wrong. This is the leaver with lingering access case: disabling an account does not kill live sessions, cached tokens or app passwords. Activity in the first hour after the disable is shown at Low rather than High, because open Office apps and OneDrive keep draining for a short tail after IT disables someone mid-session. When it fires, check the account's sessions and app passwords rather than dismissing it. See disabled_account_activity.
  • New-country sign-ins are louder by default - you may see more email. The default for New-country sign-in sensitivity has changed. A country that is new for one user now fires High even when a colleague already works from that country; previously it was demoted to Low and never emailed. This is a deliberate choice of sensitivity over quiet, and on a globally distributed tenant it means a noticeable increase in new-country email. If that is not the trade you want, set Settings → New-country sign-in sensitivity to Tenant-aware to restore the previous behaviour.
  • The External Partners list was not working between 23 July and 4 August - re-check yours. A defect meant recipient domains were not recorded for guest recipients, so no share could be matched against your trusted-partner list and the partner discount never applied. Sharing alerts in that window were scored as though the recipient were an unknown outside party, even when the domain was on your list. Now fixed. Two follow-ups: check your list is complete (while it was inert, nothing could tell you an entry was missing), and note that matching is exact-domain-or-subdomain - a partner's per-country domain is a separate entry, not covered by the main one. See External Partners.
  • Guest-to-group additions now carry partner context, but are still not discounted. A guest add from a listed partner records that fact for the AI to reason from. The rule severity is unchanged on purpose - a group add grants standing access rather than access to one file, so partner status is context, not grounds for automatic quietening.
  • Burrow now knows which countries each person normally works from. Alerts previously carried the region the service runs in - the same value for everyone, which told the AI nothing. The AI's baseline context now carries the countries that account actually operates from. It also cannot mark an alert "not real" with high confidence while the account is working from a country never seen for it; the alert can still be dismissed, but not with certainty, so the call stays visible for audit. Quiet by design: silent until an account has at least 7 days of country history, silent when today resolves no country, and silent on an empty baseline, so a thinly covered account never reads as "everything is new". Nothing to configure. See Known Networks.
  • A short visit from a new country is no longer missed. The new-country check reads countries already resolved by the routine background pass, so a brief burst from a genuinely new country could start and finish before that country was known - and never alert. It can now resolve a small, strictly bounded number of unseen addresses during the pass itself, catching a short visit in the same cycle. The bound is what keeps a slow lookup from delaying detection.

2026-08-04

  • The AI-routine email policy is now graded on evidence, not the AI's own confidence. The two middle options of the "When the AI marks a high-stakes alert routine" setting have changed meaning. They no longer ask how confident the AI said it was; they ask whether something independent of the AI supports the call - a reorganisation or sync verdict computed from the raw events, one file re-fetched repeatedly (moving no new data), a recipient on your trusted-partner list, or a long-established pattern for that person. The reason for the change: a language model's self-rated certainty is not a measurement. Across roughly 960 verdicts the model rated itself "high" about three-quarters of the time and "low" not once, so a confidence grade that never declines was no safeguard. Burrow now derives the grade from the underlying signals and takes whichever is lower - the AI may be less sure than the evidence, never more. Always email remains the default.
  • Sensitive Labels explains unresolved label IDs. The Sensitive Labels page now shows label IDs seen on files that the catalog cannot name, and distinguishes the two causes: a recently created label (resolves itself on the next refresh, within about four hours) versus a label deleted or retired from your tenant while files still carry its stamp (never resolvable). Burrow also learns label names from the audit stream, so an ID resolves automatically - retroactively - if any event names it. Unwanted entries can be dismissed.

2026-08-01

  • New page: System Activity - what Burrow did and why. A read-only feed of Burrow's own actions over the last 48 hours: emails sent, alerts suppressed and the reason for each, detection scans, incidents scored, and system self-management. It is the counterpart to the History page (which records what your analysts changed), and it answers "why didn't I get emailed about that?" directly, without digging through an inbox. Filter chips per entry type, free-text search across entry, entity and reason, 100 entries per page, and a one-minute auto-refresh. Nothing on it is editable. See System Activity.

2026-07-31

  • A cluster of quiet alerts no longer arrives as one loud email. A consolidated incident card is now only emailed if it has something to consolidate: when every alert in the cluster would have been silenced on its own - below your minimum-severity floor, or dismissed by the AI within your suppression policy - the incident is silenced too. Previously such a cluster could bypass your severity floor entirely. A cluster containing even one alert that would have emailed on its own is unaffected.
  • One action seen by several rules is no longer treated as an escalation. A new device, at a new hour, from a new country is one sign-in described three ways. When every alert in a cluster covers a read-only session (previews, page views, searches) with no data movement and nothing sensitive touched, the consolidated incident is capped at Low and marked as a single-cause cluster - visible on the Cases page, but it does not page anyone. The individual alerts still email on their own merits.
  • The home page now leads with what needs a human. A new Operations strip adds Needs attention (the same figure the Alerts page shows on its Active tab, so the two screens always agree), Triage queue, Triaged / hour, and Latest alerts. The disposition donut now separates Open from AI-dismissed, so alerts the AI has already quietened never inflate your to-do count. See the dashboard tour, which also explains why the home page and Alerts page can legitimately show different totals.
  • Alerts page: date-range filter and easier paging. A From / To date range narrows the list to alerts last seen in that window, and the bulk Suppress matching and Dismiss ALL actions honour it (the confirmation dialog tells you when a range is in effect). Paging now shows Page 6 of 20 - showing 1,001-1,200 of 3,949 and adds a Jump to page box for moving across a long history quickly.

2026-07-28

  • Your own office networks stop setting off password-spray alerts. aad_password_spray now has a second demotion lane: if the failing IP belongs to a network already learned as shared office, VPN, or proxy egress on Known Networks, the alert drops to Low. Previously the only demotion looked for successful sign-ins from the same IP in the same window - so a large office could produce a window where too few of the targeted staff happened to sign in successfully, and the same known network re-fired as critical day after day. Failed sign-ins from a network that is not on the list still raise a full-severity alert.

2026-07-27

  • The weekly briefing stops flagging noise you already suppressed. The weekly executive briefing now honours your entity exceptions: an entity you have blanket-suppressed (a suppress exception covering all categories) is treated as expected noise in the incident-chain narrative and left out of the Active-incidents tile, rather than surfacing as a "notable chain requiring investigation". Category-scoped suppressions are unaffected. This closes a gap where a suppressed service-app chain could still headline the exec briefing.
  • New control: how far to trust the AI on high-stakes "routine" verdicts. A new email policy on the Settings page governs what happens when the AI calls one of the serious categories (mass deletion, data exfiltration, ransomware, password spray, risky sharing, privilege / DLP) "likely routine". The default - Always email - still sends them (stamped "AI: likely routine") so a small local AI can never silence a real-threat category on its own; if you want a quieter inbox you can opt to suppress those emails only when the AI is highly confident, medium-or-more confident, or always. Everything stays on the dashboard regardless; this only changes what reaches the inbox. (The two middle options were re-graded on evidence rather than the AI's self-reported confidence on 2026-08-04 - see that entry above.)
  • Incident-card emails now wait for the AI verdict too. The brief hold-for-verdict that per-alert emails got on 2026-07-22 now also applies to consolidated incident-card emails, so they arrive with a settled AI read and "Verdict pending" is rarer still.

2026-07-26

  • Behavioural baselines can't be slowly "trained" by a patient insider. The behavioral_deviation rule now keeps a slow reference built only from days at least two weeks old and checks the user's recent normal against it. If that normal has quietly ramped past essentially their whole history and to at least twice their long-term median, the alert flags that the baseline itself has been climbing and additionally scores today against the long-term reference - so a gradual ramp can't hide under an adapting baseline. It only ever adds detection; steady accounts are untouched.
  • Rules and Settings pages reorganised. Detection posture now lives only on the Settings page - the Rules page shows the current posture read-only and links there. The Rules page is now split into Built-in, Label rules, and Custom rules tabs, and each built-in rule gains three controls: edit sev (pin a rule's severity without touching thresholds - the tidy way to keep a chatty rule on the dashboard but off email), an enable/disable checkbox, and an AI Explain button. Tuning suggestions remain on the separate Suggestions page.
  • Internal Domains can be locked. A new Auto-learning toggle on the Internal Domains page lets you freeze the learned list once it has settled, so only manual additions change it. Suggested domains carry Approve / Ignore and promoted domains a Remove button.

2026-07-25

  • The time-of-day rules now think in each user's local time. unusual_hour_activity, dow_drift, and weekend_posture_drift judge hours, day-of-week, and weekends in the user's own local time (inferred from their activity pattern), not the server's - so an Australia- or Chile-based user's ordinary Monday morning is no longer flagged as off-hours, a wrong-day, or weekend work. The identity dossier and the AI explanations now show typical hours in local terms, e.g. "09:00-17:00 local (UTC+10)".

2026-07-24

  • Re-downloading one file isn't treated as data theft. When a data_exfiltration alert's whole volume is a single file fetched over and over - a stuck or retrying download, say a 277 MB PDF pulled dozens of times in minutes - it is demoted and the AI is told this is a re-fetch loop, not exfiltration. Genuine exfiltration moves many distinct files, so the count of distinct files, not the raw byte total, is the discriminator.

2026-07-23

  • Ransomware detection ignores a phone camera-roll upload. The ransomware_signature rule now recognises an upload-dominated burst - where new uploads meet or exceed the file modifications, with no deletes, renames, or ransomware extensions - as content arriving rather than files being encrypted in place, and demotes it to Low. The common trigger is the OneDrive mobile app bulk-uploading a phone's camera roll (each photo also registers a modify event for its thumbnail). Genuine encrypt-in-place creates almost no uploads, so real detection is untouched.
  • Alert emails always show the current verdict. A refinement to the wait-for-AI email gate: when the same user and category re-fire with materially different evidence, the email now waits for the AI verdict written for this alert rather than briefly showing a stale cached one from an earlier alert.
  • The AI agrees with the partner-list demotion. On every sharing alert the AI is now told each recipient domain's status from your External Partners list, so its written explanation and the severity demotion always match - the AI never guesses whether an outside organisation is trusted from how its name looks.
  • The History log records who did what. The History page's By column now captures the signed-in operator on every dismissal, disposition, case action, and configuration change.

2026-07-22

  • Alert emails now wait a moment for the AI verdict. A new alert is held for a few minutes before its per-alert email goes out, so the email arrives with the AI's read (Likely REAL / Likely routine) instead of "Verdict pending" - and a false positive the AI would dismiss is quietened before it ever reaches your inbox. The wait is bounded, so a slow or stuck triage never delays a genuinely urgent alert. Net effect: fewer "Verdict pending" emails and less routine noise.
  • Ransomware detection shrugs off more benign bulk activity. The ransomware_signature rule's delete-and-upload arm now also demotes to Low when the pattern is clearly not encryption - an application's embedded-database files syncing in (.sst / MANIFEST / LOCK internals), or plain content turnover where there are no ransomware extensions and more uploads than deletes (bulk document management adds more files than it removes; encrypt-and-replace swaps them one-for-one). Any ransomware-extension signal still vetoes the demotion and keeps the alert Critical.

2026-07-21

  • Alert emails now read in plain English. Every rule-engine trigger string in an alert email is translated to plain language at send time - you read "1,953 manual download events" instead of a raw downloaded_manual=1953, and countries appear by name with their code ("Maldives (MV)"). The underlying machine values are still kept on the alert record for anyone who wants to pivot on them. See Email types.
  • behavioral_deviation uses a more robust baseline. The behavioral_deviation rule now measures each person's "typical day" with a robust median rather than an average. On the bursty, uneven day-counts real people produce, this stops two long-standing failure modes: a near-zero average inflating one ordinary day into a huge spike, and a single wild past day widening the baseline so much that a genuinely anomalous later day scores low. Because one outlier day barely moves the median, a compromised account can no longer fold its own attack into the baseline. Fewer false alarms for staff returning from leave or in seasonal-spike work.
  • New FAQ answers for the common "why did / didn't it..." questions. The FAQ page gained plain answers to the questions that come up most in the first weeks: why an alert you can see did not email, why a severity was reduced, why a colleague shows on the External Sharing report, whether Burrow ever changes anything in your tenant, where your data goes, and who to call for a real incident.
  • CSV export on three more pages. The Watchlist, Investigations (Cases), and Known Networks pages each gained a CSV button that exports the current (filtered) list - the watch roster, the case list, and the learned-egress networks respectively. See the dashboard tour, Watchlist, and Known Networks.
  • Choose how long a watch runs. When you place a watch on a user you can now set its duration in days - still 30 by default, but up to 120 days (about 4 months) to cover a long notice period. It still auto-expires on the date you set.
  • Mass-deletion alerts recognise a whole day's reorganisation. The mass_deletion rule already demoted deletes that were really a folder reorganisation or move; that check is now day-aware - it looks at the whole day's uploads and folder operations rather than just the short detection window. So a OneDrive sync where a delete burst and its matching re-upload land at different moments of the day is correctly read as reorganisation, not destruction. A genuine wipe (deletes with no uploads or folder activity) still fires High, and any ransomware-extension signal overrides the demotion.
  • A quietened new-country alert is not re-escalated by a sensitive site. When account_compromise_new_country has been demoted to Low (the country is already established across your tenant), touching a sensitive site no longer bumps it back up - the geography is not the concern, so it stays dashboard-visible and off email. A genuinely risky co-signal, such as an external share of a labelled file, still fires and escalates under its own category.

2026-07-20

  • New-user-agent alerts are quiet by default now. The ua_anomaly rule used to be one of the noisiest - every browser update or Microsoft platform rollout could mint a wave of "never-before-seen user-agent" alerts. Three suppression layers fix that: version numbers and build IDs are stripped before the never-seen check (so a version bump of a client you already run does not fire); server-side machinery and Microsoft first-party client rollouts are structurally ineligible; and genuine attacker-tool fingerprints (python-requests, curl, PowerShell, and the like) are always eligible and fire at High.
  • External Partners are badged on the External Sharing report. Domains on your External Partners list now carry a green partner badge in the External Sharing report tables and drawers, so an access review can tell "shared with our auditor" from "shared with an unknown outside party" at a glance.
  • New-country sign-in alerts name the country and recognise more proxies. New-country alerts now show the country name with its ISO code ("Maldives (MV)", not a bare "MV") in the alert text, key metrics, and per-IP rows. And the infrastructure / proxy exclusion now resolves each IP's network owner live from the internet registry rather than from a maintained list, so Microsoft and the major secure-web-gateway vendors (Zscaler, Cloudflare, Netskope, iboss, Forcepoint) are recognised by owner with no upkeep when a vendor changes ranges. See the rule catalog and Known Networks.
  • New detection - malware sitting in a document library. A new malware_in_library rule fires Critical when Microsoft Defender has flagged a file in a SharePoint document library as malware. It is always Critical and is never auto-downgraded.
  • New detection - a DLP policy block was overridden. A new dlp_policy_bypass rule fires Critical when a Microsoft Purview DLP policy block is overridden and the action goes through anyway. By default it fires on overrides that sent content to an external recipient; internal-only overrides can be included per rule if you want them.
  • New detection - an anonymous link was actually used. A new anon_link_used rule fires High when an "anyone with the link" share is actually opened to access content - a stronger signal than a link merely being created.
  • Tor and known-bad-IP alerts now scale with volume. anonymizer_access (Tor exit nodes) and malicious_ip_access (threat-intel IPs) now raise High on a single event and escalate to Critical at sustained volume, instead of being Critical on every event. Fewer all-caps pages for a single stray connection, still zero blind spots.
  • Search alerts tell retrieval from reconnaissance. The search-enumeration rules now separate someone pulling specific known items (mostly ID-like search terms) into a lower-severity search_enumeration_targeted signal, so broad "what's in here" reconnaissance stands out from routine targeted retrieval.
  • App-storage sites no longer count as exfiltration. Activity in SharePoint Embedded app-storage sites (the hidden containers behind Designer, Loop, Copilot Pages, and Forms) is excluded from data_exfiltration download counts, so normal use of those Microsoft apps no longer inflates an exfil alert.
  • Password-spray alerts point at the source IP. The aad_password_spray alert now fires on credential-guess failures against five or more distinct valid accounts, and the alert's entity is the source IP (not any one user) - because the users are the targets, not the actor.
  • Settings is now a single page of cards. The Settings page has been reorganised from tabs into one scrollable page of cards: Detection posture, System status, Stack health, Baseline maturity, New-country sign-in sensitivity, Email notifications, and Activity audit log. Two things are new: a skip auto-downgraded alerts email toggle (keep routine pre-filtered activity out of the inbox while it still shows on the dashboard), and the Baseline maturity gate is now self-service (toggle, minimum-days slider, and a per-rule selector) instead of a support request. See the dashboard tour and Postures and overrides.
  • SharePoint activity now has its own new-country arm. The account_compromise rule gained an account_compromise_new_country arm that fires on the first-ever country seen for an account's SharePoint client IPs - the file-activity mirror of the Entra ID new-country sign-in rule, with the same proxy filtering. It respects your New-country sign-in sensitivity setting: under the default Tenant-aware mode a country already established elsewhere in your tenant stays Low (visible, no email), and only a country new for the whole tenant emails High. Countries are named with their ISO code.
  • Export the Identities roster to CSV. The Identities page has a CSV button (top right) that downloads the full filtered roster - not just the visible page - with each entity's risk score and band, alert counts, active days, top geo and app, typical hours, last-active, and the AI narrative. It respects whatever filters and search are active, so it drops straight into a periodic access or risk review.
  • CSV downloads on three reports. On the Reports page, the User Activity, Stale Guest Access, and External Sharing Audit reports each now have a CSV button next to "Open report" - the same rows as the printable page, one line per guest or share, ready for a spreadsheet. (The Security Posture Snapshot and Weekly Executive Briefing remain narrative, printable / PDF documents.)

2026-07-19

  • Quick actions on ignored domains. On the Internal Domains page, domains you have dismissed now collect in an Ignored list where each row has one-click actions to re-classify it without retyping: Internal (promote to your internal-domains list), Partner (add to External Partners), or Restore (send back to the pending suggestions). Each action also clears the domain from Ignored.

2026-07-15

  • New-country sign-in alerts can now tell "new for the user" from "new for the company". Global organisations get a lot of benign "new country" sign-ins as staff connect from their home offices. A new Settings → New-country sign-in sensitivity control lets you choose how those are treated: Tenant-aware (default) keeps a country already seen elsewhere in your tenant at Low - visible, no email - and only emails High when the country is new for the whole tenant; Alert on every new country fires High on every first-time country (the default under a Strict or Paranoid posture). Either way, if a quieted sign-in is followed by risky activity, the daily escalation re-escalates the combined picture, so you never go blind on an account that is actually acting. See the rule catalog.
  • External Sharing: click through the drawer, and export. In the External Sharing report, the people and domains listed inside a detail drawer are now clickable - jump straight from an external recipient to the colleague who shared with them, or the other way around, without closing the drawer. Three export options were added: Export view downloads the current table (respecting your search filter), All shares downloads every individual share as its own row (timestamp, sharer, recipient, domain, type, file, site), and each detail drawer has its own CSV button to export just that one recipient, user, or domain. All open in Excel.
  • External Partners - quieten routine sharing with trusted organisations. A new External Partners list at the bottom of the Internal Domains page lets you mark outside organisations you share with routinely - an auditor, a contractor, a JV partner. They stay external (still recorded and shown on the External Sharing report), but Burrow lowers the severity of a sharing alert when every external recipient is a partner, with a policy you choose (lower one tier, straight to Low, or lower-and-can-hide). The discount is narrow: a mixed share with an unknown outside party is not demoted, and a co-occurring anonymous link or label downgrade keeps its own severity. See the rule catalog.

2026-07-14

  • The activity search is now called "Hunt". The cross-entity activity search - the tool you use to answer "what did this person do?" over your audit data - has been renamed from Forage to Hunt. Only the name and the menu label have changed; the filters, aggregate cards, CSV export, and Cold Storage panel all work exactly as before. See Hunt 101. Old links to the Forage page redirect to Hunt automatically.

2026-07-13

  • New - "Configuring Burrow for your environment" setup guide. A single walkthrough of the five things you tune to match your organisation - Internal Domains, Sensitive Sites, Sensitive Labels, Notifications, and the Watchlist - each with what it is, why it matters, how to set it up, and how to know it's right. See Configuring Burrow for your environment.
  • New - the Known Networks page. A read-only transparency page (Tuning → Known Networks) showing the corporate-egress networks - office gateways, VPNs, and cloud proxies such as Zscaler - that Burrow has learned to treat as shared infrastructure. It explains why Burrow stays quiet on sign-ins that egress through your proxy from another country. Nothing to configure. See Known Networks.
  • New-country sign-in alerts stop crying wolf on proxy egress. The new-country sign-in rule now ignores Microsoft's own infrastructure IPs and auto-detects your shared corporate egress (a network used by many different users is a proxy or VPN, not one person's location), excluding those countries from each user's baseline. The rule now fires only on a residential or mobile IP in a genuinely new country - the real account-takeover signal. The learned networks are visible on the Known Networks page.
  • Proxy-egress suppression now covers SharePoint activity too. The same learned corporate-egress intelligence now also quiets the SharePoint-side new-country alert (account_compromise), not just Entra ID sign-in alerts - so a user editing documents while their traffic exits through a foreign proxy node is treated consistently across both layers. It also handles the way cloud proxies scatter users across many address ranges: a range too new to be flagged shared on its own is still recognised as corporate egress when a neighbouring range in the same block is already known shared for that country. See the rule catalog and Known Networks.
  • Known Networks: world map + per-network drill-down. The Known Networks page now shows a world map of your shared egress points (dot size = number of users; click a country to filter), and clicking any network row opens a side panel listing the users who sign in from it - a quick way to confirm an egress really is shared infrastructure.
  • A cross-site file move no longer fires a cluster of alerts. Re-filing a folder from one SharePoint site to another (download → upload → delete) was already recognised so it did not fire the ransomware rule; that same recognition now also quiets the deletion, deviation, and velocity rules it used to trip. A genuine cross-site move now produces at most one low record instead of a bundled "prioritise this" incident. A genuine wipe (deletes with no matching uploads elsewhere) is untouched. See the rule catalog.

2026-07-11

  • New - the Reports page. A dedicated Reports page (the sidebar's Reports entry now opens it) with five on-demand, read-only, printable reports: User Activity (any user + time period, with a downloadable CSV of the raw activity), Security Posture Snapshot (tenant exposure at a glance), Stale Guest Access (external users with access but no recent activity - a cleanup list that recommends only, never revokes), External Sharing Audit (a printable point-in-time sharing inventory), and the Weekly Executive Briefing now generatable on demand with past briefings listed. Every report opens as a printable page you can save to PDF or forward. See Reports.
  • The weekly briefing no longer waits for Monday. The weekly executive briefing can now be generated on demand from the Reports page, and previous briefings are listed there.
  • ransomware_signature recognises a cross-site file move. Re-filing a folder from one SharePoint site to another shows up as download → upload → delete (SharePoint has no cross-site move), which used to fire a Critical "isolate the account" alert. Burrow now demotes it to Low when it is genuinely a move - no ransomware extensions, the delete and upload sites are completely separate, and the uploaded files match what was downloaded/deleted - leading with "NOT ransomware - a user is re-filing content". Anything that fails those checks stays Critical. See the rule catalog.
  • Guest-added-to-group alerts count people, not events. Microsoft can log one guest addition as several events; the alert now counts distinct guests and names them ("added external guest X (12 add events)") instead of reading "added 12 Guest user(s)". See the rule catalog.

2026-07-10

  • Watchlist daily digest reworked - now a deterministic daily activity report, and it actually sends. The daily digest for a watched user is now a last-24-hour activity report built deterministically from the raw events (no AI) - activity tiles (events, downloads, MB, uploads, edits, deletes, sharing ops, labelled touches, files / sites), top downloads by size, deletions, sharing / permission operations, the real search terms, the device IPs, and the alerts that fired for the user in the window - with the watch reason at the top. This replaces the old behaviour of emailing the generic 30-day AI identity profile (that profile is still available on demand from the identity-page Report button). Along the way the digest was fixed to actually deliver - it had been failing silently and marking the day "done" so it never retried. Because the new digest needs no AI call, it generates in under a second and all watched users' digests send in one daily pass.
  • Watchlist digest now attaches a CSV evidence file. Each daily digest carries a <user>_<date>_activity.csv of that day's raw actions - an exportable evidence record for a departing or suspect user. SharePoint / Office machinery is stripped, leaving the user's own actions in chronological order (timestamp, operation, target, site, IP, app, extension, size, share scope, managed-device flag, geography, and the sensitivity label with both its friendly name and GUID). See Watchlist → the daily digest.
  • Worker watchdog now guards a second background process. The self-healing watchdog added on 2026-07-09 now also supervises the daily-escalation scorer (it was found silently stopped and the watchdog's first pass restarted it). Its guarded set is extensible.

2026-07-09

A morning-triage pass that cleaned up a cluster of related false positives and presentation gaps, plus a reliability addition:

  • Site provisioning no longer fires three admin emails. When a normal user creates a Team or Plan, Microsoft's provisioning pipeline automatically stamps the new site with a site-admin grant and a sharing-policy change - under the user's identity - which used to fire permission_escalation + site_collection_admin_grant + tenant_policy_change all at once (three emails for one action). Burrow now recognises the provisioning burst by correlating the operations to a just-created site, suppresses the two noise alerts, and keeps a single Low record for the cluster (visible, no email). A real admin grant to a specific person, or any grant on a pre-existing site, is untouched and stays Critical. See Noise gates.
  • "Capped at medium" is now a real ceiling. Some alerts declare a maximum severity. Previously the sensitive-site severity bump could push such an alert past its cap (medium → critical). The cap is now enforced after the bump, so a capped-at-medium alert stays medium.
  • The alert story leads with the actual trigger. The investigation digest's "Sequence" spine now includes admin, policy, and permission events (a site-admin grant, a sharing-policy change, a permission-level change), and anchors on the first security-relevant event rather than an earlier unrelated download burst. So a permission alert's story now shows the permission change, not just the day's downloads.
  • data_exfiltration names the sensitivity label. Labelled-file involvement is now reported with the label name (e.g. "Confidential") instead of a bare count. See the rule catalog.
  • mass_deletion stops crying ransomware on a plain delete. The alert copy only mentions ransomware when there is an actual encryption signal. A plain recycle now reads as a recoverable bulk delete to confirm - "recycled, not rewritten - recoverable from the recycle bin" - because deletion and encrypt-in-place are different things (the latter has its own rule).
  • Azure AD authentication IPs are no longer labelled "the user's own device." The device-vs-infrastructure split now recognises the stable Azure AD auth IPv4 ranges (40.126.x / 20.190.x) as Microsoft infrastructure, so an admin action routed through Azure AD auth is not misattributed to the user's device. See the investigation digest.
  • Self-healing background processing. Burrow's background workers (including the one that pre-builds the heavy dashboard views) are now supervised by a watchdog that restarts any that stop, within about a minute. Previously a stopped worker could leave the dashboard quietly falling back to slower computation with some views going stale for hours; that gap is closed with no operator action needed. See Recovering from an outage.
  • New - External Sharing audit report. A standing inventory of every share to someone outside your tenant (direct guest shares, anonymous links, guests added to groups) over roughly the last 30 days, aggregated by external recipient, domain, and who shared, each external party named by its real address. Where the risky_sharing rules alert on risky sharing as it happens, this new page answers the standing question "who outside currently has access to what?" - the page for an access review or guest-sprawl audit. See External Sharing audit report.
  • External-share alerts name the recipient. A risky_sharing_external alert now names the actual external recipient (de-mangled from Microsoft's internal encoding), and the investigation digest lists external recipients individually while collapsing internal ones into a single line - so a benign internal fan-out cannot bury the external recipient that matters.
  • Guest-added-to-group alerts name the guest. An external_user_group_add alert's digest now reads "Added EXTERNAL guest X directly to a SharePoint group on /sites/… - standing access", naming the guest and site, instead of a generic "shared an item" line.
  • The AI states why THIS alert fired. The AI "why this matters" note is now fed the rule's exact trigger - the specific guest, sensitive term, or count that crossed the threshold - so it explains why the alert tripped rather than describing the category in general. It still only uses the values it is given (no invention), with the same safety check and deterministic fallback. See Reading the evidence box.
  • Honest verdicts when evidence ages out. A triage verdict is kept ~30 days but the raw events behind it only ~7. Opening an older alert whose events have aged out now shows an explicit "evidence no longer available - verdict retained" marker rather than a misleading reconstruction of a different day, and every verdict now carries the date it was made. See the investigation digest.

2026-07-08

Two new operator features, a detection re-architecture, the Suggestions page, and a fix to the behavioural narrative:

  • Watchlist - heightened monitoring (new). Put a specific user under bounded, audited elevated scrutiny - the classic case is a departing employee on notice. A watched user's alerts are surfaced (un-demoted and floored so they email), a daily "what did they do today" AI report is sent to a configurable digest address, and each watch carries a reason, an owner, and a default 30-day expiry so the list self-cleans. Manage everyone under watch from the new Watchlist view in the main navigation, with a live expiry countdown and a full watch / un-watch audit trail. Start from any identity page → Watch. See Watchlist: heightened monitoring. (This is distinct from the automatic top-risk entities panel on the home page - different feature, same everyday word.)
  • Identity report and log export (new). Every identity page now has two header actions for HR / legal / audit hand-off: Report opens a polished, AI-written activity report grounded strictly in that account's real figures (executive summary, activity overview, alerts and risk, assessment, with a KPI bar and hour sparkline - print to PDF); Logs downloads the account's raw audit event log as CSV or JSONL as verbatim evidence. See Identity report and log export.
  • Detection re-architecture (three-step model). The false-positive-suppression model was consolidated from a growing pile of per-rule gates into three composable steps shared by every rule: (1) a single activity-shape classifier - add a benign shape once and it demotes in every rule; (2) download-intent tagging at ingestion, so rules key on deliberate pulls rather than raw volume (an unknown user-agent counts as deliberate, so a novel exfil tool is never silently demoted); (3) a corroboration model that holds a lone weak signal below the email threshold unless something independent corroborates it. Demote-only, primary threat rules untouched. See Detection architecture.
  • Behavioural narrative is now numberless. The AI summary at the top of an identity's Profile is now purely qualitative - who the entity is, their routine, region, and tools - with no counts baked in. Every number lives in the live stats panel beside it, so the narrative (which regenerates only periodically) can no longer drift from the live totals. See Using the Identity dossier.
  • Investigation digest names the label and secure-link shares. The investigation digest now resolves each file's sensitivity label and surfaces recipient-less secure-link shares, so a labelled-content external share reads "Shared 'X' (labelled Confidential) via a secure link" instead of a generic event count.
  • Suggestions is now its own page. The tuning suggestions moved off the top of the Rules page into a dedicated Suggestions view in the main navigation. Candidates are evidence-sorted (strongest first) with one-click Apply, and the list is capped at roughly the top 50 per kind so a busy environment cannot flood it. Four kinds: add exception from dismissals, add sensitive site, chronic pattern, and noisy app. See Tuning a noisy rule.
  • Dismissal-suggestion accuracy fix. The "add exception from dismissals" suggestion now counts only named-operator dismissals (not system or automated ones) and requires them across three or more separate days rather than three raw clicks. This removed a large backlog of junk auto-generated exception suggestions and leaves only the genuinely useful ones. A related change makes every dismissal attributable to the operator who made it, going forward.
  • Clearer alert emails. The Event Details block now renders each fact on its own line instead of running them together, and the deterministic reconstruction block is labelled "analysed by Burrow" (not "Burrow AI") - that block is produced by code, not the language model, so an AI label would be inaccurate.

2026-07-08 (evening)

  • New Tuning menu group. Exceptions, Sensitive Sites, Sensitive Labels, and Suggestions now sit together under Tuning in the left navigation - one toolkit for adjusting how loud Burrow is. Sensitive Sites / Labels escalate (↑), Exceptions silence (↓), and Suggestions is the advisor that proposes entries for both. See The Tuning menu. (Nav pointers throughout the docs now read "main nav → Tuning → …".)
  • Suggestions page: Open / Applied / Dismissed tabs with Undo. The Suggestions page is now three paginated tabs (40 per page). Applied and dismissed state persists server-side - it survives a refresh and an actioned item does not reappear even though the candidate list regenerates every cycle. Undo on the Applied tab reverses the exact config edit (removes the sensitive-site entry by pattern, or the exception by id); Dismissed items can be restored to Open or applied directly. The two informational kinds (chronic pattern, noisy app) no longer carry an Apply button - only the two that map to real config (add sensitive site, add exception) can be applied, which also fixed a bug where applying an informational card wrote stray empty rows. Applied exception suggestions are tagged "→ also on Exceptions page" since they share the same store. Noisy-app cards are no longer raised for standard service identities (app@sharepoint*, SHAREPOINT\system), where the downgrade is expected. See Tuning a noisy rule.
  • Investigation digest: sensitive terms first, recon → retrieval, and a chronological spine. When a search rule fires, the digest now lists the term that actually matched a sensitive keyword first (flagged "matched sensitive term 'X'"), so it can't be crowded out by unrelated searches, and follows it with an "After the sensitive search, downloaded: …" line tracing recon into the files pulled afterward. Every alert now also carries a "Sequence (UTC): a → b → c" spine - the user's searches, downloads, shares, deletes, and label changes in time order, anchored on the first sensitive search so a busy morning cannot truncate the relevant cluster. Deterministic as ever - a reordering of facts, not an interpretation. See The investigation digest.
  • Three false-positive fixes. ransomware_signature: an encrypt-in-place modify burst with no renames / deletes / ransomware extensions on a synced folder now demotes to Low only when it is within the account's own established file-spread (≥7 days of history); a novel or above-baseline burst stays Medium and emails, and any corroboration keeps it Critical - the OneDrive sync client alone is no longer treated as proof of benign. risky_sharing: org-wide / company links are internal-only sharing and now sit at Low, with the sensitive-site bump no longer escalating a pure-internal-sharing alert (anonymous and external shares are unchanged). Noisy-app suggestions are no longer generated for service principals. See the rule catalog.

2026-07-05 / 06

A second noise-reduction pass, this one focused on identity and geography truth, service-account separation, and unblocking the AI weekly briefing. Driven by real operator-reported alerts:

  • AI triage verdict on every alert email. Per-alert and incident emails now carry an AI triage badge - "Likely REAL - prioritise this one", "Uncertain - needs human review", "Likely routine for this user", or "Verdict pending (triage running)". Rank your inbox without opening Burrow. Advisory only; severity stays the primary signal and the wording never says "false positive". See Email types.
  • Emails now show where the user actually connected from. A new Source IP country (registered) row shows the registered country of each source IP (e.g. 211.144.19.102 = CN). The old "Location" row - which was actually the SharePoint datacenter region hosting your content, a tenant-wide constant like "NAM" - is relabelled SharePoint region (tenant, not user) so it can't be mistaken for the user's whereabouts. This closed a real blind spot: a China-registered session had been rendering as "Location: NAM (North America)". See Reading the evidence box.
  • Impossible-travel now measures real travel. account_compromise was measuring tenant data residency, not location - it is reframed to Low with honest wording. A rebuilt impossible_travel_signin now baselines each person's real connection countries from their own sign-in IPs, and a new aad_new_country_signin rule flags a sign-in from a never-before-seen country at the authentication layer - the earliest point credential theft shows up. Split-tunnel users (e.g. Australia direct plus a US proxy egress) baseline both countries and stay silent. These arm gradually as about 7 days of history accumulate. See the rule catalog.
  • "Downloaded a folder as a ZIP" is now called what it is. Clicking Download on a SharePoint folder makes the platform fetch every file individually to build the zip - which used to read as "150 manual downloads" and fire several alerts. Burrow now recognises the folder-zip packager and says "downloaded an entire folder as a ZIP: one click packaged N files". The download stays visible (a whole-folder copy is a real exfil route worth verifying), but the co-firing deviation / velocity / sensitive-extension alerts demote to low. See Noise gates.
  • Service accounts no longer masquerade as top risks. The document-pipeline service principals legitimately look like ransomware and mass-deletion. Per-alert they demote to low when within their own baseline (with an explanation, never silently). In the weekly briefing, the risk leaderboard and top-category list are built from human actors only; automated-account volume is summarised in a separate, clearly-labelled line. The all-actor total and week-over-week trend stay whole-tenant.
  • One large file is no longer "exfiltration". A day whose byte spike is essentially a single large file - a CAD model, a training video, a meeting recording (80% or more of the day's bytes in one file) - demotes to low and names the file, instead of firing a "40× baseline" data-exfiltration / deviation alert. A genuine multi-file bulk pull is unaffected.
  • Office-Online editing stopped looking like an unmanaged device. Excel and Word Online render-farm and co-authoring requests (MSWAC / MSOCS) report "unmanaged device" because there is literally no device in the request path; they no longer count toward unmanaged-device rules. Real BYOD traffic still does.
  • The weekly executive briefing is finally AI-written. The accuracy guard that rejects fabricated numbers had been over-firing on ordinary words ("Notable", "Focus", "Investigating") and the exec briefing fell back to a terse template every week. Fixed structurally - sentence-opening capitals are grammar, not invented names - while the number-invention protection is untouched. The briefing now reads as prose with every figure still verified.

2026-07-03 / 04

A batch of noise-gate hardening, a new deterministic reconstruction card, and a formalised five-layer tuning model, shipped alongside a full rule catalog audit:

  • The "What actually happened" investigation digest. Every alert email and every alert drawer now leads with a highlighted, plain-English reconstruction of the flagged user's UTC day, built entirely by code from raw audit events. Sharing recipients are named directly, browser-viewer opens are flagged as "not a download to a device", bursts are explained ("97 events in 2 minutes = one page render fanning out"), and machinery events are counted separately from user actions. No AI is involved in the digest - every bullet is verifiable. See the investigation digest article.
  • Drawer trust hierarchy. The alert drawer now reads top-down as: deterministic headline → investigation digest → AI verdict & note → rule-engine rationale + metadata + metrics + evidence. An analyst can answer "who did what, to whom, when" from the top two cards without ever trusting AI prose. See Reading the evidence box.
  • Suppressed entities hidden from every dashboard aggregate. Adding a Suppress exception now removes the matching user from Top items, the trend chart, the watchlist, identity alert counts, rule stats, and the tenant-wide severity strip in emails - not just from the Alerts page and email. The Alerts history view is the deliberate exception (kept as forensic record). See Entity exceptions.
  • Noise-gate catalog. Ten new deterministic noise gates now stop platform machinery from being misread as human attack behaviour: thumbnail / viewer / renderer fetches, office-web-viewer file opens, site-icon fetches, PDF-viewer chunks, org-wide share fanout, office-egress-IP spray shape, stale-session retries, delete-matched-by-upload, Microsoft-provisioning-identity site-admin grants, and passive off-hours browsing. Every demoted alert exposes the specific gate in the Trigger Why text. See Noise gates.
  • Distinct-incident severity strip. The tenant-wide severity strip at the top of every email now counts distinct incidents (each user + category once, at its highest severity in the last 24 hours) rather than raw alert instances. The numbers match what an operator would count on the Alerts page.
  • Escalation pattern table in daily summaries. The daily-escalation email now includes an escalation pattern table - every contributing alert in time order with severity, category, and what it triggered on. Chronological, deterministic, auditor-friendly.
  • Five-layer tuning model formalised. The way to control a rule is now laid out as five layered controls - posture, per-rule override, baseline-maturity gate, persistence gate, entity exception - with automatic modifiers (service-app multipliers and noise gates) running underneath. Documented in the tuning model article. Nothing changes about existing tuning - the model just makes explicit what to reach for when.
  • Rule tunings - new_site_access Balanced threshold raised from 2 to 10 (was firing on ordinary intranet browsing); risky_sharing.org_links now counts distinct files newly shared, not raw fanout events; dow_drift now scores against the rollup day, not the wall-clock day, and skips weekends (owned by weekend_posture_drift) to stop the double-alert on weekday workers active on a weekend; mass_deletion_med demoted when deletes are matched by uploads in a single site (SharePoint Move pattern); unusual_hour_activity demoted when the off-hours session is pure page browsing; aad_password_spray gated to credential-guess failures only and demoted when the same users also succeed from the same IP; data_exfiltration excludes office-web-viewer fetches from download counts; site_collection_admin_grant demoted for Microsoft's own provisioning identities. Every change is applied via the tuning model - no rule was disabled.
  • Detection latency fix. Under heavy load the audit scanner had been falling well behind real time on some tenants. A caching rework of the baseline builders restored near-real-time alerting - alerts land within the normal one-cycle window again, even during audit-volume spikes.
  • Alert volume reduction. Across the noise-gate catalog, the investigation digest, and the rule tunings above, per-alert email volume dropped substantially without loss of true-positive signal, measured across a two-day observation window on live tenants.

2026-07-02

Performance and reliability:

  • Alerts page hero redesign. The top of the Alerts page is now a four-panel layout: severity donut (with in-view total), total-signals card with cycle stats, "Top categories" card (clickable tag cloud + four priority tiles - Critical / High / AI-dismissed / Unassigned), and a right-side Quick Views sidebar (AI-dismissed audit, Critical only, All unresolved, Recently dismissed, Reset all filters). Tile counts capture the baseline queue and stay stable when you click a tile to drill in - no more "did the number just change?" confusion.
  • Alerts list is a table. Alert cards became a proper table with columns: Signal / Severity / Verdict / User / Status / Last seen / Actions. Under narrow viewports the less-critical columns auto-hide.
  • Redesigned drill drawer header. Opening an alert shows a prominent header (prettified category name, user email, right-aligned severity block, copy-key button) plus an amber "insight bar" summarising AI verdict, fired-N-times count, emailed indicator, span duration, and last-seen time - so the shape of the alert reads instantly.
  • Active filter strip. A dashed strip above the pager shows every filter currently applied, each with an inline × to clear it, plus a "Reset all" link.
  • Categories tag cloud. The top of the Alerts page has a chip cloud of the top eight categories in the current view, weighted by occurrences. Click a chip to filter.
  • Faster dashboard under multiple users. The dashboard's request handling was split so that slow work (like an AI chat call) can no longer stall a routine dashboard tile refresh. No configuration on your side.
  • Pre-built dashboard views. The heavy dashboard views (alert history, dispositions, trends, rule stats, watchlist, identities) are now regenerated in the background on a short cadence and served ready-made, instead of being computed on each request. The slow first-page-load rebuild is gone - first load is sub-second even under multi-user load.
  • Lighter, faster responses. The dashboard now transfers far less data on routine page navigation - large views are trimmed to what the page needs, and an unchanged view is not re-transferred on refresh. Noticeably snappier navigation, no behavioural change.
  • Identity page stability. The Identities list and detail pages tolerate accounts with no baseline yet (missing risk score or alert counts) instead of erroring, and the Identities list reliably returns a full page of results.
  • 7-day default lookback on alert history. The alert-history view now defaults to the last 7 days (matching on-machine retention) instead of scanning back to the deployment's inception, fixing a slow path on mature deployments.
  • Bounded memory footprint. The dashboard now releases memory back to the system on a regular cycle, keeping its footprint steady under continuous traffic.

2026-07-01

Focused release around UEBA precision, AI narrative reliability, and label management consolidation:

  • UEBA rules no longer trip on pure page-load browsing. Every rule in the behavioural family (behavioral_deviation, peer_group_deviation, intraday_velocity_burst, unmanaged_baseline_spike) now requires a minimum count of human-initiated operations (modify / download / upload / delete / move / copy) before it can fire. A user simply browsing many SharePoint pages generates dozens of file-touch audit events under the hood - those no longer inflate distinct-files or unmanaged-events counters into false-positive exfil alerts. Passive operations still show up in the Operation breakdown so operators can see what actually happened.
  • Operation breakdown on every UEBA alert. Alert emails and the drill drawer now show a compact one-line summary - FileAccessed: 312, FileModified: 198, FileDownloaded: 4 - that instantly answers "was this editing, exfiltration, or browsing?" without opening individual events.
  • UEBA emails collapse to one per user per hour. When a single unusual event trips several behavioural rules at once (typical: behavioral_deviation + peer_group_deviation + unmanaged_baseline_spike on the same activity), the operator no longer gets three separate emails. First alert of the hour for a given user wins; the rest are journaled with reason dedup and skipped for email.
  • intraday_velocity_burst requires 10% overshoot, severity now scales. Previously fired High on a one-file overshoot of the user's historical max (today=74 vs max=73). Now requires ≥ 10% above the historical max to fire at all, and severity scales - Low for 1.10–1.50× the max, Medium for 1.50–2.00×, High for ≥ 2.00×. The alert summary leads with the percentage overshoot in plain language. See the rule catalog entry for the updated behaviour.
  • behavioral_deviation alert summary rewritten. Now leads with which metric spiked, from what baseline, to what today, in one line ("distinct_files spiked: today=576 vs 21-day baseline avg=33 (17.3x, 4.4sigma)"). The metrics grid shows the spiked metric, today's value, and the baseline average as their own tiles.
  • AI narrative stops inventing numbers. Alerts had been arriving with prose that cited numbers absent from the underlying evidence ("3.51 GB" when actual was 3.8 GB; "686 distinct files" when actual was 576). The AI narrative safety-check is now back in strict mode - attempts that invent numbers are rejected and the deterministic template ships in their place. The AI is now also explicitly told which metric triggered the rule and is required to describe THAT metric rather than picking any baseline number from context.
  • More non-human download events excluded. The exclusion list for the manual-downloads metric now also catches _Thumbnail, OfficeXLCA, WebExcelObserver, ClientSidePage, and anything starting with Render or Preview. These are SharePoint preview and rendering components - no human clicked download. Previously they inflated data_exfiltration alert counts for users who had merely opened content-heavy pages.
  • Sample evidence deduplicated by filename. When one PDF was previewed 5 times in 7 seconds, the Top Evidence sample used to show 5 identical rows. Now shows up to 8 distinct files (largest downloads first) so the sample gives real signal about what was actually accessed.
  • Sensitive Labels page consolidated onto sidebar. The duplicate Sensitive Labels tab inside the Rules page has been removed - everything now lives on the sidebar Sensitive labels page. The catalog is a checkbox list over your tenant's label catalog; ticking a label adds it to the watchlist that governs three things: which files bump alert severity, which sites the sensitive-site learner suggests, AND which label changes fire the label_tampering rule. See Sensitive labels.
  • label_tampering rule now scoped to the sensitive-labels watchlist. Previously fired on every label change in the tenant. Now fires only when the changed label is one you have marked as sensitive on the Sensitive Labels page. Empty watchlist keeps the old fire-on-all behaviour for backward compatibility. The Rules page shows the current scope inline on the label_tampering row.
  • Improved label evidence rendering. Some Microsoft label-change audit variants do not carry the old / new label under the standard field names, which used to produce ? → ? on file.xlsx evidence. Extraction now also tries PriorSensitivityLabel(Id) / NewSensitivityLabel(Id) and scans ModifiedProperties for label-change triplets. When Microsoft truly reports nothing, the detail reads (not in audit event) → (removed) on <file> so the operator at least sees the operation type.
  • aad_username_enumeration posture-aware severity + enrichment. The alert now shows the source geo, an error-code breakdown, and a UserNotFound only flag. Severity is dynamic: pure recon (all attempts against non-existent usernames) fires High; any non-UserNotFound in the mix (attacker has found a valid username and is now guessing credentials) fires Critical. Paranoid posture forces Critical regardless.
  • Incident-email duplicate-send flood - fully closed. A prior fix stopped the dedup state from being wiped on a mid-cycle crash. The root cause of the crash itself - a specific alert shape triggering a parse error - is now also fixed.

2026-06-30 (afternoon and evening)

  • AI-dismissed audit toggle split into two chips. The single + AI-dismissed chip is now + AI-dismissed (silent) and + AI-dismissed (emailed). Silent covers AI dismissals you were never emailed about; emailed covers ones the AI marked "not real" after an email had already been sent. Each toggles its own bucket independently, and both default off so the Active queue stays focused. See Auditing the AI's dismissed alerts.
  • Emailed alerts stay visible in Active even after the AI dismisses them. Deliberate exemption to close a credibility gap - if you got an email for it, you can find it on Active. The audit chip is there for reviewing the bucket as a set.
  • New "Alert" tab on the drill drawer. Clicking an alert now opens the drawer on a new Alert tab (not Profile). The Alert tab holds the AI verdict badge and narrative, the rule engine's own rationale, alert metadata (category / rule / MITRE / severity / detected time), a metrics grid, operation breakdown, download-method hint, and up to 8 sample events. Profile / Events / Chat remain as later tabs for entity context after the alert is understood. See Reading the evidence box.
  • "Download method" field on every alert. Alert emails and the drill drawer now show which client(s) produced the events - "OneDrive Sync", "Office Desktop", "Teams", "Browser", "CLI / Script", or the raw client identifier when nothing else matches. Immediately distinguishes "user mass-downloaded via browser" from "sync client did its job".
  • new_site_access is now tunable per posture. The rule fires when a user accesses sites they have never touched in their recent history. Previously fired on the first new site. Now takes a minimum-new-sites threshold that scales by posture: Permissive 5, Relaxed 3, Balanced 2, Strict 1, Paranoid 1.
  • Disabling a rule now uniformly stops it firing. Previously the disable list handled the static rule engine but missed the behavioural-baseline layer (new_site_access, peer-group outlier, weekend-drift, day-of-week drift, unusual-hour, UA anomaly, custom rules). A disabled rule of that family kept emitting alerts. Now disabling applies across every detection path.
  • Alerts page cache staleness fixed. Alerts written in the 10-to-30 minute window after the last cache build were invisible to the dashboard until the cache expired. Particularly affected Entra ID alerts (mfa_fatigue, impossible_travel_signin) whose collection cadence is independent of the SharePoint side. Cache is now strict TTL - past 10 minutes, the next request rebuilds.
  • Per-alert Suppress + Downgrade pair actions. Every Alerts page row now has two icon buttons - Suppress and Downgrade - that create an entity exception for the (user, category) pair in one click, no need to open the Exceptions page first. Bulk versions available in the selection bar. See Suppress and Downgrade pair actions.
  • AI-dismissed alerts auto-hide from Active. The Active tab now excludes alerts the AI judged not real, filed alongside operator-dismissed under the Dismissed tab. Operator override always wins - setting Acknowledged / Investigating / Escalated on an AI-dismissed alert returns it to those tabs.
  • Every UEBA alert now carries evidence. The behavioural-baseline family used to ship the alert with only comparison scalars - sigma, ratio, mean, max - leaving the operator to ask "which files? which IP?" before they could act. Each rule now attaches sample file records, top apps, user agents, and the Download method hint, routed by which metric drove the spike. search_baseline_deviation now surfaces the actual sensitive search terms.
  • AI email preamble stripped. Some alert emails were opening with a leaked AI instruction line ("Here is the rewritten paragraph:"). Those phrases are now explicitly forbidden as opening lines, and any that slip through are stripped before send. File-type invention (the AI made up "cache files and images" for an alert whose evidence was actually CAD files) is now also on the do-not-invent list.
  • Server-side / non-human events excluded from manual-download counts. SharePoint's own infrastructure (page rendering, workflow service, search indexer, migration tooling) generates download events as it touches files internally - no human clicked Download. These are now excluded from the manual-downloads metric so they no longer inflate data_exfiltration alerts on users who merely browsed heavy pages.
  • Dashboard performance. The two heaviest dashboard endpoints (status snapshot and alerts history) now serve cached results when their source files have not changed, so quiet browsing costs near-zero CPU on the backend. Site feels noticeably more responsive.

2026-06-30 (early)

A batch of usability and reliability improvements:

  • Identity dossier AI summary card now visible. The 2 to 4 sentence AI summary of each user's typical behaviour now appears at the top of the Profile tab on the Identity dossier. Previously the dashboard was not surfacing the summary even though it was being generated.
  • Hunt "Search this entity" button on cold-storage jobs. Every READY rehydrate row in the Cold Storage panel now has a one-click blue button that auto-fills the User filter, populates the date range to span the rehydrated months, and runs the Hunt search. No more retyping entity names after a rehydrate completes.
  • Top MITRE tab populates correctly. The Top MITRE tab on the Burrow home page now shows real adversary-technique counts for the lookback window (T1078 Valid Accounts, T1486 Data Encrypted for Impact, etc.). Previously the tab showed "No data" due to a tag-handling issue.
  • Entity exceptions now suppress emails immediately. When you add a Suppress entity exception, the very next detection pass picks it up and per-alert emails (plus consolidated incident card emails) skip the matching alerts. Previously there was a brief window where new alerts could email even though the exception was loaded. Every suppression is journaled in the suppression journal with the reason for audit.
  • Search button on Identities page replaces type-as-you-go. Typing in the search box no longer fires a query per keystroke. Press Enter or click Search to submit - feels faster and avoids partial-input flicker.
  • Identities page filter no longer leaks service-account rows. Searching for a user no longer accidentally returned app@sharepoint* rows alongside the intended match. Multiple defence-in-depth fixes applied.
  • Cold-storage rehydrate stability improvements. Three reliability fixes: failed jobs now stop and report instead of looping indefinitely; status is preserved across the full job lifecycle; failure logs are more diagnosable.
  • Hunt handles single-result searches correctly. Searches that returned exactly one matching user no longer occasionally produced a client-side error on the aggregate cards. Backend and frontend both made defensive.
  • Audit collection chunked catch-up. After an outage, Burrow now collects historical events in chunks back-to-back, producing live alerts progressively as catch-up runs. Memory stays bounded regardless of gap size.
  • Audit collection retries transient errors. Microsoft-side 5xx, 429, and timeout errors on individual audit blobs are now retried up to three times with backoff. Truly-lost data is logged distinctly so operators can see what was unrecoverable.
  • Weekly briefing now auto-runs. The Monday morning executive briefing generates and emails automatically every week at around 06:00 local. Previously required a manual trigger.
  • Ransomware rule co-authoring false-positive fix. Multi-user Office co-authoring (Excel, PowerPoint, Word) was occasionally tripping the ransomware_signature rule. A ratio gate now distinguishes real ransomware (many files, ~1 modification each) from co-authoring (few files, many modifications each).

Earlier

Before June 2026:

  • The five-posture detection-tuning model (Permissive / Relaxed / Balanced / Strict / Paranoid) shipped, with per-rule overrides on top.
  • The deterministic-rules-plus-AI-narration architecture became the default across alerts, investigations, and the weekly briefing - with the AI safety check verifying every number and name against the source data.
  • The Suggestions panel on the Rules page began surfacing tuning recommendations based on operator disposition patterns.
  • The daily pattern escalation summary was introduced, replacing N raw per-alert emails for a noisy user-day with one consolidated summary.
  • Per-alert Chat persistence between SOC shifts was added.

For changes older than the entries above, contact support@smikar.com - engineering keeps a full change history.


Need help? support@smikar.com.

More in Squirrel

See all pages →