Squirrel Release Notes
48 min read · Last updated · Page version 1
Notable changes across the Squirrel platform: the archive itself, Nutshell AI summarisation, and the Burrow security layer. Customer-facing only - updates that change what you see, do, or rely on.
Squirrel ships continuously rather than in numbered releases. Changes are gathered into fortnightly sprints, each dated to the Friday it closed, and grouped by the part of the platform they affect. Anything not listed under a heading did not change in that area that fortnight.
Sprint ending 2026-09-11
Archive
- File History - one search for what happened to a file or folder. A new page that answers “where did it go?” in one place instead of three. Give it a site and a folder, a file path or a filename prefix, and it merges the archive, recycle-bin capture, the processing-site inventory and the restore history into a single per-file answer: who deleted it, whether Squirrel captured it, whether it is archived, orphaned or already restored, and where the copy is now. It leads with a plain-English summary - including saying outright when Squirrel did not delete the files, which is the first thing people assume. Each row links to the page that can recover it, carrying the filename so the search is already run when you arrive. See File History.
- Recycle Bin search finds things it used to miss. Two fixes that customers would have experienced as “the file isn’t there” when it was. Searching with a file’s extension never matched, because a captured copy is stored under a stamped name - matching is now on the base name, so either form works. And only the currently configured processing site was searched, so anything captured before that setting changed was unfindable; search now covers every processing site Squirrel has used. Recovery was never affected either way - it resolves a copy’s location from the record, not the current setting - so nothing was ever actually lost. See Recycle Bin capture.
- Log entries stay on one line. The Log Viewer now scrolls sideways rather than folding a long entry across several rows, which keeps the timestamps aligned and a run of entries scannable. A Wrap long lines switch turns folding back on when you would rather read one long entry in full. The scrolling is contained to the log panel, so the rest of the page stays put.
- The archive overview reworked. Storage Distribution is now two lines on one scale by invoiced month - what remains in SharePoint against the archived running total - which shows one falling as the other rises. The bottom row carries five cards rather than three, and each metric tile shows its own change against the previous period instead of a sparkline, with the fuller trend a click away. See the dashboard.
Nutshell AI
- Two new summary types: Lite and Extract. Nutshell now offers five types rather than three. Both new ones read the whole document, pick out its key passages automatically, keep the document’s own headings where it has them, and finish with a line of the dates, amounts and reference codes found in it. The difference is the last step: Lite hands those passages to the AI for one short pass, so the result reads as written prose at well under half of Brief’s processing per document. Extract skips the AI entirely and shows the passages as they appear, labelled as an extract - for maximum throughput, or where policy says no AI at all. The temperature slider greys out while Extract is selected, because that type never calls the AI. See summary types.
- Moving a stub no longer costs you its summary. A summary is written into the stub shortly after archiving, so a user can move or re-file it in between. Nutshell now follows the stub and corrects the archive path. Previously it tried to drag the file back to the recorded path, which failed outright once the old parent folder was gone - the file was retried a few times and then given up on, with no summary ever written. See stub files.
- Non-English text in PDFs is no longer garbled. Cyrillic, Turkish, accented Latin and CJK characters extracted from PDFs were arriving as mojibake and going into summaries in every mode. Fixed at the extraction step, so affected documents summarise correctly from now on. Documents summarised before this keep the old text until they are re-summarised.
Burrow security
- The System Activity feed exports to CSV. A CSV button on the System Activity page downloads what your current filters show - the entire filtered set, not just the page on screen. Filter to one user and export, and you have every action Burrow took about that person in the window as a single file, which is the quickest way to attach "here is why that alert never emailed" evidence to a ticket.
Sprint ending 2026-08-28
Archive
- A refreshed admin portal. Both the archive dashboard and the security dashboard moved to a new visual language - new typography, softer surfaces, and consistent dialogs and tables throughout. Nothing moved that you need to relearn; the layout and the navigation are unchanged.
- Jump to any page with Ctrl+K. Press Ctrl+K (Cmd+K on a Mac) anywhere in the portal for a Go to page box: type a few letters, arrow through grouped results, Enter to go. It is the quickest route to the analytics pages, which sit a level below the main navigation. A button in the top bar does the same for people who would rather click.
- Being refused a page now explains itself. Access is by group membership, so you can sign in successfully and still be refused a particular page. Instead of a silent redirect you get a screen naming the page, a button that copies the support address to your clipboard, and - usefully - the attempt is logged, so support can see it without asking you to reproduce it. See logging in.
- Site actions say what they will do before you click. Hovering the Archive, Restore or Preview action on a site in Site Archive Settings now states its scope. Worth reading: a site-wide Archive takes every file regardless of your age thresholds, while Preview counts what the policy would take and changes nothing.
Nutshell AI
- Brief mode is actually brief. Brief had been given the same writing instructions as Standard, so although it read less of the document its summaries came out at the same length and level of detail. It now produces a genuine executive summary that leads with the single most important point. If you evaluated Brief before and found it indistinguishable from Standard, it is worth another look.
- Boilerplate is dropped rather than summarised. Disclaimers, forward-looking-statement notices and confidentiality, copyright or trademark notices are omitted from summaries entirely rather than paraphrased. A summary that spends its closing sentence noting that a document “includes a disclaimer” has wasted it.
- Large backlogs drain faster. The surge capacity that clears a build-up was capped low enough that it stopped scaling on backlogs of a few hundred files. The ceiling is substantially higher, so a catch-up run after onboarding a large site clears at a higher sustained rate without anyone intervening.
Burrow security
-
The Investigations page now shows everything under investigation, not just cases. Marking an alert Investigate or Escalate puts it in its own section at the top of the Investigations page, with its status, severity, who marked it and when - and clicking it deep-links back to the alert. Until now those two statuses existed only as filters on the Alerts page, so an alert somebody had explicitly flagged for follow-up never appeared on the page called Investigations.
-
Cases can track people, not just alerts. A case now has a Users under investigation section. Attach a user - or name one when you create the case - and the case shows their live picture rather than a snapshot: current active alert count, risk band, and a DISABLED marker if the directory account has since been disabled, with one click through to the full entity drill. The eye button puts them on the heightened-monitoring watchlist for 30 days, which is the "monitor everything this person does while the case is open" switch. It is the same watchlist used everywhere else, so someone already watched is shown as watched rather than quietly added again, and attaching or detaching a user is recorded in History.
-
Every alert email now tells you why it was sent. A "Why you received this" line sits under the verdict: the AI rates it likely real; the AI is uncertain, and uncertain verdicts always email; or - the case this was built for - the AI called it routine and it emailed anyway, in which case the line names the policy that forced it and why the AI's confidence fell short ("only at low confidence... this account's short history, 6 days of baseline"). An email carrying a "likely routine" verdict used to read as a contradiction, and working out which rule had overridden which meant reverse-engineering your severity floor against your AI-suppression policy. The email answers it itself now. See Email types.
-
Password-spray alerts say what the source IP actually is. The rule always knew whether an IP was familiar; it now says so in plain English rather than rule shorthand. Each spray alert states the IP's registered network owner and country, whether it is or is not one of your learned office and proxy egress networks, and how many of your users have ever signed in successfully from it - including the blunt version, "NO user has ever signed in successfully from this IP". Where the IP belongs to Microsoft, it adds that a Microsoft cloud source on failed sign-ins often means legacy-auth attempts proxied by Exchange Online, which masks the attacker's real IP - a trap worth knowing before you write the source off as benign. See the rule catalog.
-
The "Why the AI says this" box never passes machine text off as the model's reasoning. When the AI's own written reasoning fails its evidence checks, the box still shows the deterministic factual summary - but relabelled "What the AI was judged on - its own written reasoning did not pass evidence checks, so the factual summary is shown instead". You can tell at a glance which of the two you are reading.
-
Reasoning is refreshed at send time when it has fallen behind. Alerts re-fire as activity accumulates, and the AI deliberately does not re-review a verdict when only the volume has changed - so its reasoning can legitimately describe a smaller, earlier version of the event. For alerts actually being emailed, Burrow now asks the model once for reasoning grounded on the current alert. It faces the same evidence checks as any other generated text, and falls back to the labelled earlier-snapshot note if it fails. The verdict itself is never changed - only the explanation of it.
-
Entra ID sign-in narratives are held to the strict number check.
aad_password_sprayandaad_new_country_signinbecame primary-threat rules on 14 August; their AI narratives now run under the same strict invention guard as the rest, after a note shipped carrying an invented sign-in date. In a credential alert a wrong date is not cosmetic - it is the difference between "this happened today" and "this happened two years ago". -
"Why the AI says this" now grades its own reasoning three ways instead of two. Reasoning that matches the alert is shown as written. Reasoning describing an earlier, smaller stage of the same accumulating activity is still shown, but labelled as describing that earlier snapshot - the common case, and not an error. Reasoning that actively contradicts the alert is withheld, with a note that the verdict carries over. The box never quotes figures as though they described the alert in front of you when they do not.
Sprint ending 2026-08-14
Burrow security
-
You can now name the domains you consider risky, and have alerts about them shout louder. The Internal Domains page gains an Untrusted domains list - the opposite of a partner. Where a partner domain can quieten an alert, an untrusted domain raises its severity to a level you pick (High, Critical, or one level up from wherever it landed). Personal mail services are the case this was built for: company data heading to someone's private mailbox deserves a louder alarm than the same share to a known business. It only ever raises - an untrusted domain can never make an alert quieter - and a share that reaches both a partner and an untrusted recipient always escalates, because the riskiest recipient sets the tone. A domain cannot be a partner and untrusted at the same time; adding it to one list removes it from the other.
-
Everything now lands in one History. Actions taken from the Suggestions panel and edits to sensitivity-label rules were being written to a separate journal that History never read, so they were invisible there. Both now write to the same trail as every other administrative action, and the existing entries have been migrated in - nothing was lost, and History is now the single place to answer "who changed this, and when".
-
A severity pin can quieten an alert, but it cannot overstate one. Pinning a severity on the Posture page still lowers freely. Raising is now capped at what the evidence for that alert actually supports, so a pin cannot mark something Critical when nothing in the alert justifies it. When a pin is capped, History records it, and the alert shows the severity it was allowed to reach.
-
Alert emails now show why the AI reached its verdict. Under the triage pill, per-alert emails and incident cards carry a "Why the AI says this" box naming the evidence actually weighed - baseline, geography, working hours, whether the activity was platform machinery - plus, on an incident, a line for each other alert in the cluster. Two things make it trustworthy rather than decorative: verdicts reached on precedent rather than a full review say so outright ("recurring pattern for this user, 13 similar in 30 days - dismissed without full AI review"), and reused reasoning is checked against the alert in front of you, so it never quotes figures belonging to an earlier one. See Email types.
-
Incident emails are scannable. The attack-chain summary is now an overview sentence followed by one short line per event in time order, instead of a paragraph that restated the timeline printed directly beneath it. The suggested next step is called out separately. The same structure is produced whether or not the AI is available.
-
The status select tells you when a disposition was set, and by whom. Hovering an alert's inline status on the Alerts page shows the date and the analyst - the quickest way to tell a month-old dismissal from an alert that has just recurred.
-
Labelled files in OneDrive are now investigatable. Sensitivity-label rules have always followed labelled documents into personal OneDrive - a Confidential file shared externally from someone's OneDrive raises an alert, because a label protects the file rather than a location. The evidence behind those alerts was being discarded, so the alert could not be examined in Hunt. Labelled OneDrive events are now retained. Behavioural analysis is unchanged: baselines, volume rules and profiles still cover team and group SharePoint sites only, and personal OneDrive sync is still deliberately left out of them. Monitored-user counts and baselines are unaffected. See what Burrow watches.
-
Dismissing is now reversible, and clearing your queue no longer counts as judging it. Two related changes. First, any dismissed alert can be reopened - from a Reopen button on its History row or by setting its inline status to the new Reopened value. A reopened alert returns to Active and Open immediately, even if the AI had judged it not real, because an operator override always wins. Second, every bulk dismissal is now recorded as a single batch you can undo - an Undo bar appears on the Alerts page straight after, and History keeps a Recent bulk actions list. If you bulk-dismiss a pile of alerts by mistake, one click brings them back.
-
Bulk dismissals now show you what you are about to hide. Before a bulk Dismiss runs, an impact preview states how many alerts are affected, their severity mix, any the AI judged likely real, any belonging to a watchlisted user, and whether you are close to auto-quieting that pattern.
-
The dialog asks whether this is a queue sweep or a judgement, and the answer matters. A queue sweep is recorded and reversible but never feeds the learned quieting. Judged benign does. Previously the two were indistinguishable, so routine clean-outs could quietly train Burrow to stop alerting on things nobody had actually looked at. Only deliberate judgements train it now, and reopening an alert cancels its earlier contribution. See Tuning a noisy rule.
-
You can now choose whether partner guest-adds are quietened - it is off by default. A second selector on the Internal Domains page, "When guests added to groups are all partners", decides whether adding partner guests to a SharePoint group reduces the alert's severity, and by how much. The default is keep full severity, because a group membership is standing access - no expiry, everything the group can reach, harder to revoke than a sharing link - so it deserves a look even from a trusted partner. If your teams routinely onboard partner guests, pick a reduction level. It applies only when every added guest is from a partner domain, and the reduced severity is capped so co-occurring signals cannot quietly push back up something you have declared expected.
-
Offboarding no longer produces a false alert. After someone is disabled, Microsoft's compliance engine keeps processing their content server-side and attributes those events to the disabled account. That was enough to trip the new disabled-account rule and email a High alert for what is really routine cleanup. Burrow now recognises compliance-engine activity - it carries no device address - and does not count it as the account acting. The same operation from a real device still counts, so a genuine leaver-with-live-sessions still alerts.
-
New page: Setup - the onboarding checklist, checked live. A Setup page has been added to the left navigation (Admin group). It shows each setup step as done, needs attention or optional, checked against your actual configuration rather than being a list you tick off yourself - "3 domain(s) confirmed", "1 recipient(s), min severity 'medium'" - with an Open button on each row that takes you to the page where the work is done. Required steps are separated from recommended ones, with a banner reporting how many required steps remain. New steps appear automatically as the product grows. See the onboarding checklist, which follows the same order.
-
You can now see how much of your organisation Burrow is covering. The dashboard home page and the Setup page both show "monitoring X of Y users" - people with meaningful SharePoint activity in the last 30 days, against the enabled accounts in your directory. Dormant accounts and service identities are not counted. It answers "is Burrow actually watching our organisation?" without an export or a support ticket.
-
Identities can show your whole directory, not just active people. Three new chips on the Identities page: No SharePoint activity (enabled accounts doing nothing - dormant accounts are unwatched attack surface), Disabled, and Whole directory. The default view is unchanged - it is still the monitored risk roster - and a free-text search now covers the whole directory whichever chip is set, so "is user X covered?" always returns an answer instead of an empty table. Rows carry a status badge, and a disabled account with recent SharePoint activity is called out specifically.
-
Data retention is now a fixed product behaviour, and it is documented in full. The hot window - how long per-event detail and alert files stay instantly searchable in Hunt - is 14 days on every deployment. It was previously a per-deployment setting that had drifted out of step with the documentation, so it is now a constant rather than something that can differ between tenants. Nothing is lost at 14 days: events and alerts are compressed and archived into your own Azure Storage account, and a rehydrate brings any month back into Hunt in minutes. The full picture - what is kept hot, what is archived, what is never deleted, and who owns it - is now on one page: Data retention and storage.
-
New rule: activity from a disabled account. Any SharePoint activity from an account that is disabled in your directory now alerts at High, with no volume threshold - a disabled account has no legitimate activity, so one event is already wrong. This is the leaver with lingering access case: disabling an account does not kill live sessions, cached tokens or app passwords. Activity in the first hour after the disable is shown at Low rather than High, because open Office apps and OneDrive keep draining for a short tail after IT disables someone mid-session. When it fires, check the account's sessions and app passwords rather than dismissing it. See
disabled_account_activity. -
New-country sign-ins are louder by default - you may see more email. The default for New-country sign-in sensitivity has changed. A country that is new for one user now fires High even when a colleague already works from that country; previously it was demoted to Low and never emailed. This is a deliberate choice of sensitivity over quiet, and on a globally distributed tenant it means a noticeable increase in new-country email. If that is not the trade you want, set Settings → New-country sign-in sensitivity to Tenant-aware to restore the previous behaviour.
-
The External Partners list was not working between 23 July and 4 August - re-check yours. A defect meant recipient domains were not recorded for guest recipients, so no share could be matched against your trusted-partner list and the partner discount never applied. Sharing alerts in that window were scored as though the recipient were an unknown outside party, even when the domain was on your list. Now fixed. Two follow-ups: check your list is complete (while it was inert, nothing could tell you an entry was missing), and note that matching is exact-domain-or-subdomain - a partner's per-country domain is a separate entry, not covered by the main one. See External Partners.
-
Guest-to-group additions now carry partner context, but are still not discounted. A guest add from a listed partner records that fact for the AI to reason from. The rule severity is unchanged on purpose - a group add grants standing access rather than access to one file, so partner status is context, not grounds for automatic quietening.
-
Burrow now knows which countries each person normally works from. Alerts previously carried the region the service runs in - the same value for everyone, which told the AI nothing. The AI's baseline context now carries the countries that account actually operates from. It also cannot mark an alert "not real" with high confidence while the account is working from a country never seen for it; the alert can still be dismissed, but not with certainty, so the call stays visible for audit. Quiet by design: silent until an account has at least 7 days of country history, silent when today resolves no country, and silent on an empty baseline, so a thinly covered account never reads as "everything is new". Nothing to configure. See Known Networks.
-
A short visit from a new country is no longer missed. The new-country check reads countries already resolved by the routine background pass, so a brief burst from a genuinely new country could start and finish before that country was known - and never alert. It can now resolve a small, strictly bounded number of unseen addresses during the pass itself, catching a short visit in the same cycle. The bound is what keeps a slow lookup from delaying detection.
-
The AI-routine email policy is now graded on evidence, not the AI's own confidence. The two middle options of the "When the AI marks a high-stakes alert routine" setting have changed meaning. They no longer ask how confident the AI said it was; they ask whether something independent of the AI supports the call - a reorganisation or sync verdict computed from the raw events, one file re-fetched repeatedly (moving no new data), a recipient on your trusted-partner list, or a long-established pattern for that person. The reason for the change: a language model's self-rated certainty is not a measurement. Across roughly 960 verdicts the model rated itself "high" about three-quarters of the time and "low" not once, so a confidence grade that never declines was no safeguard. Burrow now derives the grade from the underlying signals and takes whichever is lower - the AI may be less sure than the evidence, never more. Always email remains the default.
-
Sensitive Labels explains unresolved label IDs. The Sensitive Labels page now shows label IDs seen on files that the catalog cannot name, and distinguishes the two causes: a recently created label (resolves itself on the next refresh, within about four hours) versus a label deleted or retired from your tenant while files still carry its stamp (never resolvable). Burrow also learns label names from the audit stream, so an ID resolves automatically - retroactively - if any event names it. Unwanted entries can be dismissed.
-
New page: System Activity - what Burrow did and why. A read-only feed of Burrow's own actions over the last 48 hours: emails sent, alerts suppressed and the reason for each, detection scans, incidents scored, and system self-management. It is the counterpart to the History page (which records what your analysts changed), and it answers "why didn't I get emailed about that?" directly, without digging through an inbox. Filter chips per entry type, free-text search across entry, entity and reason, 100 entries per page, and a one-minute auto-refresh. Nothing on it is editable. See System Activity.
Sprint ending 2026-07-31
Burrow security
-
A cluster of quiet alerts no longer arrives as one loud email. A consolidated incident card is now only emailed if it has something to consolidate: when every alert in the cluster would have been silenced on its own - below your minimum-severity floor, or dismissed by the AI within your suppression policy - the incident is silenced too. Previously such a cluster could bypass your severity floor entirely. A cluster containing even one alert that would have emailed on its own is unaffected.
-
One action seen by several rules is no longer treated as an escalation. A new device, at a new hour, from a new country is one sign-in described three ways. When every alert in a cluster covers a read-only session (previews, page views, searches) with no data movement and nothing sensitive touched, the consolidated incident is capped at Low and marked as a single-cause cluster - visible on the Cases page, but it does not page anyone. The individual alerts still email on their own merits.
-
The home page now leads with what needs a human. A new Operations strip adds Needs attention (the same figure the Alerts page shows on its Active tab, so the two screens always agree), Triage queue, Triaged / hour, and Latest alerts. The disposition donut now separates Open from AI-dismissed, so alerts the AI has already quietened never inflate your to-do count. See the dashboard tour, which also explains why the home page and Alerts page can legitimately show different totals.
-
Alerts page: date-range filter and easier paging. A From / To date range narrows the list to alerts last seen in that window, and the bulk Suppress matching and Dismiss ALL actions honour it (the confirmation dialog tells you when a range is in effect). Paging now shows
Page 6 of 20 - showing 1,001-1,200 of 3,949and adds a Jump to page box for moving across a long history quickly. -
Your own office networks stop setting off password-spray alerts.
aad_password_spraynow has a second demotion lane: if the failing IP belongs to a network already learned as shared office, VPN, or proxy egress on Known Networks, the alert drops to Low. Previously the only demotion looked for successful sign-ins from the same IP in the same window - so a large office could produce a window where too few of the targeted staff happened to sign in successfully, and the same known network re-fired as critical day after day. Failed sign-ins from a network that is not on the list still raise a full-severity alert. -
The weekly briefing stops flagging noise you already suppressed. The weekly executive briefing now honours your entity exceptions: an entity you have blanket-suppressed (a suppress exception covering all categories) is treated as expected noise in the incident-chain narrative and left out of the Active-incidents tile, rather than surfacing as a "notable chain requiring investigation". Category-scoped suppressions are unaffected. This closes a gap where a suppressed service-app chain could still headline the exec briefing.
-
New control: how far to trust the AI on high-stakes "routine" verdicts. A new email policy on the Settings page governs what happens when the AI calls one of the serious categories (mass deletion, data exfiltration, ransomware, password spray, risky sharing, privilege / DLP) "likely routine". The default - Always email - still sends them (stamped "AI: likely routine") so a small local AI can never silence a real-threat category on its own; if you want a quieter inbox you can opt to suppress those emails only when the AI is highly confident, medium-or-more confident, or always. Everything stays on the dashboard regardless; this only changes what reaches the inbox. (The two middle options were re-graded on evidence rather than the AI's self-reported confidence on 2026-08-04 - see that entry above.)
-
Incident-card emails now wait for the AI verdict too. The brief hold-for-verdict that per-alert emails got on 2026-07-22 now also applies to consolidated incident-card emails, so they arrive with a settled AI read and "Verdict pending" is rarer still.
-
Behavioural baselines can't be slowly "trained" by a patient insider. The
behavioral_deviationrule now keeps a slow reference built only from days at least two weeks old and checks the user's recent normal against it. If that normal has quietly ramped past essentially their whole history and to at least twice their long-term median, the alert flags that the baseline itself has been climbing and additionally scores today against the long-term reference - so a gradual ramp can't hide under an adapting baseline. It only ever adds detection; steady accounts are untouched. -
Rules and Settings pages reorganised. Detection posture now lives only on the Settings page - the Rules page shows the current posture read-only and links there. The Rules page is now split into Built-in, Label rules, and Custom rules tabs, and each built-in rule gains three controls: edit sev (pin a rule's severity without touching thresholds - the tidy way to keep a chatty rule on the dashboard but off email), an enable/disable checkbox, and an AI Explain button. Tuning suggestions remain on the separate Suggestions page.
-
Internal Domains can be locked. A new Auto-learning toggle on the Internal Domains page lets you freeze the learned list once it has settled, so only manual additions change it. Suggested domains carry Approve / Ignore and promoted domains a Remove button.
-
The time-of-day rules now think in each user's local time.
unusual_hour_activity,dow_drift, andweekend_posture_driftjudge hours, day-of-week, and weekends in the user's own local time (inferred from their activity pattern), not the server's - so an Australia- or Chile-based user's ordinary Monday morning is no longer flagged as off-hours, a wrong-day, or weekend work. The identity dossier and the AI explanations now show typical hours in local terms, e.g. "09:00-17:00 local (UTC+10)". -
Re-downloading one file isn't treated as data theft. When a
data_exfiltrationalert's whole volume is a single file fetched over and over - a stuck or retrying download, say a 277 MB PDF pulled dozens of times in minutes - it is demoted and the AI is told this is a re-fetch loop, not exfiltration. Genuine exfiltration moves many distinct files, so the count of distinct files, not the raw byte total, is the discriminator. -
Ransomware detection ignores a phone camera-roll upload. The
ransomware_signaturerule now recognises an upload-dominated burst - where new uploads meet or exceed the file modifications, with no deletes, renames, or ransomware extensions - as content arriving rather than files being encrypted in place, and demotes it to Low. The common trigger is the OneDrive mobile app bulk-uploading a phone's camera roll (each photo also registers a modify event for its thumbnail). Genuine encrypt-in-place creates almost no uploads, so real detection is untouched. -
Alert emails always show the current verdict. A refinement to the wait-for-AI email gate: when the same user and category re-fire with materially different evidence, the email now waits for the AI verdict written for this alert rather than briefly showing a stale cached one from an earlier alert.
-
The AI agrees with the partner-list demotion. On every sharing alert the AI is now told each recipient domain's status from your External Partners list, so its written explanation and the severity demotion always match - the AI never guesses whether an outside organisation is trusted from how its name looks.
-
The History log records who did what. The History page's By column now captures the signed-in operator on every dismissal, disposition, case action, and configuration change.
-
Alert emails now wait a moment for the AI verdict. A new alert is held for a few minutes before its per-alert email goes out, so the email arrives with the AI's read (Likely REAL / Likely routine) instead of "Verdict pending" - and a false positive the AI would dismiss is quietened before it ever reaches your inbox. The wait is bounded, so a slow or stuck triage never delays a genuinely urgent alert. Net effect: fewer "Verdict pending" emails and less routine noise.
-
Ransomware detection shrugs off more benign bulk activity. The
ransomware_signaturerule's delete-and-upload arm now also demotes to Low when the pattern is clearly not encryption - an application's embedded-database files syncing in (.sst/MANIFEST/LOCKinternals), or plain content turnover where there are no ransomware extensions and more uploads than deletes (bulk document management adds more files than it removes; encrypt-and-replace swaps them one-for-one). Any ransomware-extension signal still vetoes the demotion and keeps the alert Critical. -
Alert emails now read in plain English. Every rule-engine trigger string in an alert email is translated to plain language at send time - you read "1,953 manual download events" instead of a raw
downloaded_manual=1953, and countries appear by name with their code ("Maldives (MV)"). The underlying machine values are still kept on the alert record for anyone who wants to pivot on them. See Email types. -
behavioral_deviationuses a more robust baseline. Thebehavioral_deviationrule now measures each person's "typical day" with a robust median rather than an average. On the bursty, uneven day-counts real people produce, this stops two long-standing failure modes: a near-zero average inflating one ordinary day into a huge spike, and a single wild past day widening the baseline so much that a genuinely anomalous later day scores low. Because one outlier day barely moves the median, a compromised account can no longer fold its own attack into the baseline. Fewer false alarms for staff returning from leave or in seasonal-spike work. -
New FAQ answers for the common "why did / didn't it..." questions. The FAQ page gained plain answers to the questions that come up most in the first weeks: why an alert you can see did not email, why a severity was reduced, why a colleague shows on the External Sharing report, whether Burrow ever changes anything in your tenant, where your data goes, and who to call for a real incident.
-
CSV export on three more pages. The Watchlist, Investigations (Cases), and Known Networks pages each gained a CSV button that exports the current (filtered) list - the watch roster, the case list, and the learned-egress networks respectively. See the dashboard tour, Watchlist, and Known Networks.
-
Choose how long a watch runs. When you place a watch on a user you can now set its duration in days - still 30 by default, but up to 120 days (about 4 months) to cover a long notice period. It still auto-expires on the date you set.
-
Mass-deletion alerts recognise a whole day's reorganisation. The
mass_deletionrule already demoted deletes that were really a folder reorganisation or move; that check is now day-aware - it looks at the whole day's uploads and folder operations rather than just the short detection window. So a OneDrive sync where a delete burst and its matching re-upload land at different moments of the day is correctly read as reorganisation, not destruction. A genuine wipe (deletes with no uploads or folder activity) still fires High, and any ransomware-extension signal overrides the demotion. -
A quietened new-country alert is not re-escalated by a sensitive site. When
account_compromise_new_countryhas been demoted to Low (the country is already established across your tenant), touching a sensitive site no longer bumps it back up - the geography is not the concern, so it stays dashboard-visible and off email. A genuinely risky co-signal, such as an external share of a labelled file, still fires and escalates under its own category. -
New-user-agent alerts are quiet by default now. The
ua_anomalyrule used to be one of the noisiest - every browser update or Microsoft platform rollout could mint a wave of "never-before-seen user-agent" alerts. Three suppression layers fix that: version numbers and build IDs are stripped before the never-seen check (so a version bump of a client you already run does not fire); server-side machinery and Microsoft first-party client rollouts are structurally ineligible; and genuine attacker-tool fingerprints (python-requests, curl, PowerShell, and the like) are always eligible and fire at High. -
External Partners are badged on the External Sharing report. Domains on your External Partners list now carry a green partner badge in the External Sharing report tables and drawers, so an access review can tell "shared with our auditor" from "shared with an unknown outside party" at a glance.
-
New-country sign-in alerts name the country and recognise more proxies. New-country alerts now show the country name with its ISO code ("Maldives (MV)", not a bare "MV") in the alert text, key metrics, and per-IP rows. And the infrastructure / proxy exclusion now resolves each IP's network owner live from the internet registry rather than from a maintained list, so Microsoft and the major secure-web-gateway vendors (Zscaler, Cloudflare, Netskope, iboss, Forcepoint) are recognised by owner with no upkeep when a vendor changes ranges. See the rule catalog and Known Networks.
-
New detection - malware sitting in a document library. A new
malware_in_libraryrule fires Critical when Microsoft Defender has flagged a file in a SharePoint document library as malware. It is always Critical and is never auto-downgraded. -
New detection - a DLP policy block was overridden. A new
dlp_policy_bypassrule fires Critical when a Microsoft Purview DLP policy block is overridden and the action goes through anyway. By default it fires on overrides that sent content to an external recipient; internal-only overrides can be included per rule if you want them. -
New detection - an anonymous link was actually used. A new
anon_link_usedrule fires High when an "anyone with the link" share is actually opened to access content - a stronger signal than a link merely being created. -
Tor and known-bad-IP alerts now scale with volume.
anonymizer_access(Tor exit nodes) andmalicious_ip_access(threat-intel IPs) now raise High on a single event and escalate to Critical at sustained volume, instead of being Critical on every event. Fewer all-caps pages for a single stray connection, still zero blind spots. -
Search alerts tell retrieval from reconnaissance. The search-enumeration rules now separate someone pulling specific known items (mostly ID-like search terms) into a lower-severity
search_enumeration_targetedsignal, so broad "what's in here" reconnaissance stands out from routine targeted retrieval. -
App-storage sites no longer count as exfiltration. Activity in SharePoint Embedded app-storage sites (the hidden containers behind Designer, Loop, Copilot Pages, and Forms) is excluded from
data_exfiltrationdownload counts, so normal use of those Microsoft apps no longer inflates an exfil alert. -
Password-spray alerts point at the source IP. The
aad_password_sprayalert now fires on credential-guess failures against five or more distinct valid accounts, and the alert's entity is the source IP (not any one user) - because the users are the targets, not the actor. -
Settings is now a single page of cards. The Settings page has been reorganised from tabs into one scrollable page of cards: Detection posture, System status, Stack health, Baseline maturity, New-country sign-in sensitivity, Email notifications, and Activity audit log. Two things are new: a skip auto-downgraded alerts email toggle (keep routine pre-filtered activity out of the inbox while it still shows on the dashboard), and the Baseline maturity gate is now self-service (toggle, minimum-days slider, and a per-rule selector) instead of a support request. See the dashboard tour and Postures and overrides.
-
SharePoint activity now has its own new-country arm. The
account_compromiserule gained anaccount_compromise_new_countryarm that fires on the first-ever country seen for an account's SharePoint client IPs - the file-activity mirror of the Entra ID new-country sign-in rule, with the same proxy filtering. It respects your New-country sign-in sensitivity setting: under the default Tenant-aware mode a country already established elsewhere in your tenant stays Low (visible, no email), and only a country new for the whole tenant emails High. Countries are named with their ISO code. -
Export the Identities roster to CSV. The Identities page has a CSV button (top right) that downloads the full filtered roster - not just the visible page - with each entity's risk score and band, alert counts, active days, top geo and app, typical hours, last-active, and the AI narrative. It respects whatever filters and search are active, so it drops straight into a periodic access or risk review.
-
CSV downloads on three reports. On the Reports page, the User Activity, Stale Guest Access, and External Sharing Audit reports each now have a CSV button next to "Open report" - the same rows as the printable page, one line per guest or share, ready for a spreadsheet. (The Security Posture Snapshot and Weekly Executive Briefing remain narrative, printable / PDF documents.)
-
Quick actions on ignored domains. On the Internal Domains page, domains you have dismissed now collect in an Ignored list where each row has one-click actions to re-classify it without retyping: Internal (promote to your internal-domains list), Partner (add to External Partners), or Restore (send back to the pending suggestions). Each action also clears the domain from Ignored.
Sprint ending 2026-07-17
Burrow security
-
New-country sign-in alerts can now tell "new for the user" from "new for the company". Global organisations get a lot of benign "new country" sign-ins as staff connect from their home offices. A new Settings → New-country sign-in sensitivity control lets you choose how those are treated: Tenant-aware (default) keeps a country already seen elsewhere in your tenant at Low - visible, no email - and only emails High when the country is new for the whole tenant; Alert on every new country fires High on every first-time country (the default under a Strict or Paranoid posture). Either way, if a quieted sign-in is followed by risky activity, the daily escalation re-escalates the combined picture, so you never go blind on an account that is actually acting. See the rule catalog.
-
External Sharing: click through the drawer, and export. In the External Sharing report, the people and domains listed inside a detail drawer are now clickable - jump straight from an external recipient to the colleague who shared with them, or the other way around, without closing the drawer. Three export options were added: Export view downloads the current table (respecting your search filter), All shares downloads every individual share as its own row (timestamp, sharer, recipient, domain, type, file, site), and each detail drawer has its own CSV button to export just that one recipient, user, or domain. All open in Excel.
-
External Partners - quieten routine sharing with trusted organisations. A new External Partners list at the bottom of the Internal Domains page lets you mark outside organisations you share with routinely - an auditor, a contractor, a JV partner. They stay external (still recorded and shown on the External Sharing report), but Burrow lowers the severity of a sharing alert when every external recipient is a partner, with a policy you choose (lower one tier, straight to Low, or lower-and-can-hide). The discount is narrow: a mixed share with an unknown outside party is not demoted, and a co-occurring anonymous link or label downgrade keeps its own severity. See the rule catalog.
-
The activity search is now called "Hunt". The cross-entity activity search - the tool you use to answer "what did this person do?" over your audit data - has been renamed from Forage to Hunt. Only the name and the menu label have changed; the filters, aggregate cards, CSV export, and Cold Storage panel all work exactly as before. See Hunt 101. Old links to the Forage page redirect to Hunt automatically.
-
New - "Configuring Burrow for your environment" setup guide. A single walkthrough of the five things you tune to match your organisation - Internal Domains, Sensitive Sites, Sensitive Labels, Notifications, and the Watchlist - each with what it is, why it matters, how to set it up, and how to know it's right. See Configuring Burrow for your environment.
-
New - the Known Networks page. A read-only transparency page (Tuning → Known Networks) showing the corporate-egress networks - office gateways, VPNs, and cloud proxies such as Zscaler - that Burrow has learned to treat as shared infrastructure. It explains why Burrow stays quiet on sign-ins that egress through your proxy from another country. Nothing to configure. See Known Networks.
-
New-country sign-in alerts stop crying wolf on proxy egress. The new-country sign-in rule now ignores Microsoft's own infrastructure IPs and auto-detects your shared corporate egress (a network used by many different users is a proxy or VPN, not one person's location), excluding those countries from each user's baseline. The rule now fires only on a residential or mobile IP in a genuinely new country - the real account-takeover signal. The learned networks are visible on the Known Networks page.
-
Proxy-egress suppression now covers SharePoint activity too. The same learned corporate-egress intelligence now also quiets the SharePoint-side new-country alert (
account_compromise), not just Entra ID sign-in alerts - so a user editing documents while their traffic exits through a foreign proxy node is treated consistently across both layers. It also handles the way cloud proxies scatter users across many address ranges: a range too new to be flagged shared on its own is still recognised as corporate egress when a neighbouring range in the same block is already known shared for that country. See the rule catalog and Known Networks. -
Known Networks: world map + per-network drill-down. The Known Networks page now shows a world map of your shared egress points (dot size = number of users; click a country to filter), and clicking any network row opens a side panel listing the users who sign in from it - a quick way to confirm an egress really is shared infrastructure.
-
A cross-site file move no longer fires a cluster of alerts. Re-filing a folder from one SharePoint site to another (download → upload → delete) was already recognised so it did not fire the ransomware rule; that same recognition now also quiets the deletion, deviation, and velocity rules it used to trip. A genuine cross-site move now produces at most one low record instead of a bundled "prioritise this" incident. A genuine wipe (deletes with no matching uploads elsewhere) is untouched. See the rule catalog.
-
New - the Reports page. A dedicated Reports page (the sidebar's Reports entry now opens it) with five on-demand, read-only, printable reports: User Activity (any user + time period, with a downloadable CSV of the raw activity), Security Posture Snapshot (tenant exposure at a glance), Stale Guest Access (external users with access but no recent activity - a cleanup list that recommends only, never revokes), External Sharing Audit (a printable point-in-time sharing inventory), and the Weekly Executive Briefing now generatable on demand with past briefings listed. Every report opens as a printable page you can save to PDF or forward. See Reports.
-
The weekly briefing no longer waits for Monday. The weekly executive briefing can now be generated on demand from the Reports page, and previous briefings are listed there.
-
ransomware_signaturerecognises a cross-site file move. Re-filing a folder from one SharePoint site to another shows up as download → upload → delete (SharePoint has no cross-site move), which used to fire a Critical "isolate the account" alert. Burrow now demotes it to Low when it is genuinely a move - no ransomware extensions, the delete and upload sites are completely separate, and the uploaded files match what was downloaded/deleted - leading with "NOT ransomware - a user is re-filing content". Anything that fails those checks stays Critical. See the rule catalog. -
Guest-added-to-group alerts count people, not events. Microsoft can log one guest addition as several events; the alert now counts distinct guests and names them ("added external guest X (12 add events)") instead of reading "added 12 Guest user(s)". See the rule catalog.
-
Watchlist daily digest reworked - now a deterministic daily activity report, and it actually sends. The daily digest for a watched user is now a last-24-hour activity report built deterministically from the raw events (no AI) - activity tiles (events, downloads, MB, uploads, edits, deletes, sharing ops, labelled touches, files / sites), top downloads by size, deletions, sharing / permission operations, the real search terms, the device IPs, and the alerts that fired for the user in the window - with the watch reason at the top. This replaces the old behaviour of emailing the generic 30-day AI identity profile (that profile is still available on demand from the identity-page Report button). Along the way the digest was fixed to actually deliver - it had been failing silently and marking the day "done" so it never retried. Because the new digest needs no AI call, it generates in under a second and all watched users' digests send in one daily pass.
-
Watchlist digest now attaches a CSV evidence file. Each daily digest carries a
<user>_<date>_activity.csvof that day's raw actions - an exportable evidence record for a departing or suspect user. SharePoint / Office machinery is stripped, leaving the user's own actions in chronological order (timestamp, operation, target, site, IP, app, extension, size, share scope, managed-device flag, geography, and the sensitivity label with both its friendly name and GUID). See Watchlist → the daily digest. -
Worker watchdog now guards a second background process. The self-healing watchdog added on 2026-07-09 now also supervises the daily-escalation scorer (it was found silently stopped and the watchdog's first pass restarted it). Its guarded set is extensible.
Earlier
Burrow's first weeks were its build-out, and the day-by-day notes from that period have been consolidated here. Everything below still describes how Burrow works today - the difference is that these are capabilities rather than changes, and each one is documented properly on its own page. Individual bug fixes and false-positive tunings from this period have been dropped; they are of no ongoing consequence.
What shipped
- Watchlist - put a specific user under bounded, audited elevated scrutiny, the classic case being a departing employee on notice. Alerts are surfaced and floored so they email, a daily AI report goes to a digest address, and each watch carries a reason, an owner, and a 30-day default expiry so the list self-cleans.
- Identity report and log export - an AI-written activity report grounded strictly in one account's real figures, and the raw audit log as CSV or JSONL. Built for HR, legal, and audit hand-off.
- External Sharing audit report - a standing inventory of every share to someone outside your tenant over roughly the last 30 days, aggregated by recipient, domain, and sharer. Where the sharing rules alert as it happens, this answers the standing question "who outside currently has access to what?"
- The investigation digest - every alert leads with a plain-English reconstruction of the flagged user's day, built entirely by code from raw audit events. Sharing recipients named, browser-viewer opens flagged as "not a download to a device", bursts explained, machinery counted separately from user actions. No AI involved, so every line is verifiable.
- Suggestions and the Tuning menu - Exceptions, Sensitive Sites, Sensitive Labels and Suggestions grouped as one toolkit for adjusting how loud Burrow is, with an advisor that proposes entries for them. Applied and dismissed state persists, and Undo reverses the exact config edit.
- Cold storage rehydrate with one-click hand-off into Hunt, and per-alert Chat that persists between shifts.
How detection was shaped
- The five-posture model - Permissive, Relaxed, Balanced, Strict, Paranoid - with per-rule overrides layered on top, and the wider five-layer tuning model built out around it: posture, per-rule override, baseline-maturity gate, persistence gate, entity exception.
- Detection architecture - false-positive suppression was consolidated from per-rule gates into three composable steps every rule shares: an activity-shape classifier, download-intent tagging at ingestion so rules key on deliberate pulls rather than raw volume, and a corroboration model that holds a lone weak signal below the email threshold. Demote-only; primary threat rules are untouched.
- Noise gates - a catalog of deterministic gates that stop platform machinery being misread as human attack behaviour: thumbnail and viewer fetches, PDF-viewer chunks, org-wide share fanout, folder-download-as-ZIP packaging, Microsoft's own provisioning identity, stale-session retries and more. Every demoted alert names the gate that demoted it.
- Behavioural rules require human-initiated operations. Simply browsing SharePoint pages generates dozens of file-touch audit events; those no longer inflate the counters behind exfiltration alerts. Passive operations still appear in the operation breakdown so you can see what actually happened.
Getting the truth straight
- Geography means the user, not the tenant. Alerts show the registered country of the source IP. The old "Location" row was actually the SharePoint datacenter region hosting your content - a tenant-wide constant - and is now labelled as such. This closed a real blind spot where a China-registered session rendered as "North America". See Reading the evidence box.
- Impossible travel measures real travel. Rebuilt to baseline each person's genuine connection countries from their own sign-in IPs, with a companion rule flagging a sign-in from a never-before-seen country at the authentication layer - the earliest point credential theft surfaces. Split-tunnel users baseline both countries and stay silent.
- Service accounts stopped masquerading as top risks. Document-pipeline service principals legitimately resemble ransomware and mass deletion. They demote within their own baseline, with an explanation rather than silently, and the weekly briefing's risk leaderboard is built from human actors only.
- The AI does not invent numbers. Narratives had cited figures absent from the evidence. The safety check verifies every number and name against the source data and ships the deterministic template instead when a generation fails it. The AI is also told which metric triggered the rule, so it describes that metric rather than any figure in context.
Reading and responding
- The Alerts page became a table with a four-panel hero, quick views, an active-filter strip, and a drill drawer that reads top-down as deterministic headline, then digest, then AI verdict, then rule rationale - so an analyst can answer "who did what, to whom, when" without ever trusting AI prose.
- Emails gained the AI triage badge, a download-method field distinguishing a browser mass-download from the sync client doing its job, and an operation breakdown answering "was this editing, exfiltration, or browsing?" at a glance. Behavioural alerts collapse to one email per user per hour, and daily pattern escalation replaces a noisy user-day's worth of alerts with a single summary.
- Entity exceptions suppress across every dashboard aggregate, not just the alert list, and every suppression is journaled with its reason.
- Heavy dashboard views are pre-built in the background, so first load is sub-second on mature deployments.
For changes older than the entries above, contact support@smikar.com - engineering keeps a full change history.
Need help? support@smikar.com.
For changes older than the entries above, contact support@smikar.com - engineering keeps a full change history.