SAMURAI 4.7
Released July 9, 2026.
Features
- AI: feed recently-rejected proposals to the council as decline context
- AI: keep rejection tombstone conservative + observable
- AI: operator-tunable retention for terminal memories
- AI: state_reason — why a memory is in its current state
- Ai Tools: shared list-query layer — filter/fields/page + iteration hints
- Ai Tools: temporal sync-lag annotation + at_change snapshot reads
- Ai Tools: trigger-condition descriptions + schema enums + protocol example
- Apic Ui: parse src_port/dst_port search tokens end-to-end
- Apic Ui: render contract lookups at top-of-page notification stack
- Apic Ui: single-row contract badges + shared NotificationBanner for lookups
- Apic Ui: Source/Destination Port in the Add-Filter dropdown (both tabs)
- Cisco ACI: contract port search matches unspecified-port (permit-any) filter entries
- Cisco ACI: entry-aware Filters-tab search + source-port contract search (#972 #973)
- Cisco ACI: plain-text filter search is entry + port aware
- Cisco ACI: selected tenant as a URL path segment, not ?tenant=
- Datatable: animate expandable rows open + closed
- Filters: ACL operators (eq/in) on action/protocol
- Filters: eq/ne/in operators across all datatables
- Filters: generic filter-catalog registry + migrate Memories
- Filters: migrate ACL (router+switch) field catalog to backend
- Filters: migrate APIC Contracts field catalog to backend
- Filters: migrate Endpoints to backend catalog + operators
- Filters: migrate Routes field catalog to backend
- Filters: numeric operators gt/lt/gte/lte on Endpoints vlan
- Filters: operator engine + Changes filter-field catalog backend (#980 #981)
- Filters: operator-aware AdvancedFilterBar + backend metadata on Changes
- Filters: Routes operators (eq/in) on categorical fields
- Cisco FTD/ASA: canonicalize gt/lt service operators to searchable port ranges
- Cisco FTD/ASA: make services: search any-aware for unrestricted access rules
- Palo Alto: make service: search any-aware for permit-all rules
- Policy Analyzer: Access rules tab (browse the actual rules)
- Policy Analyzer: ACI access-policy explorer + host search (reuse topology)
- Policy Analyzer: auto-select the first device on open
- Policy Analyzer: canonical PolicyRule model + pure Palo adapter
- Policy Analyzer: compute App-ID / users / URL categories
- Policy Analyzer: device + tab in the URL path (/policy-analyzer/:device/:tab)
- Policy Analyzer: expand anomaly/optimize findings to show the actual rule(s)
- Policy Analyzer: export button on every tab (CSV/XLSX/HTML/PDF)
- Policy Analyzer: extend the analyzer to Cisco FMC (multi-vendor)
- Policy Analyzer: extend to Cisco ACI/APIC (order-free contracts)
- Policy Analyzer: extend to Cisco FTD (deployed running-config)
- Policy Analyzer: extend to FortiGate (adapter, unit-tested)
- Policy Analyzer: frontend page surfacing risk/zones/anomalies/hygiene
- Policy Analyzer: hit-stats capture, PermPolicyAnalysis, config collections
- Policy Analyzer: merge adjacent same-action rules
- Policy Analyzer: merge vendor/device/scope into one device-focused control on the tab row
- Policy Analyzer: named level dropdowns for zone trust/criticality
- Policy Analyzer: NGFW scoping narrows risk breadth
- Policy Analyzer: one flat device list, drop the vendor field
- Policy Analyzer: OpenAPI 3.0 contract, served live
- Policy Analyzer: optimizer - derived removal/cleanup recommendations
- Policy Analyzer: Palo hygiene runner + gated trigger endpoint
- Policy Analyzer: per-framework compliance report
- Policy Analyzer: per-policy/section filter (drill into one FTD cluster)
- Policy Analyzer: persist active tab in the URL (?tab=)
- Policy Analyzer: pure firewall hygiene evaluators
- Policy Analyzer: relational anomaly engine + negate flag
- Policy Analyzer: resizable policy drill-down sheet + full-row expand
- Policy Analyzer: scope FMC findings by access policy (FTD cluster)
- Policy Analyzer: server-side filter/sort/pagination + AdvancedFilterBar (all tabs)
- Policy Analyzer: sigma.js graph visualization (ACI + firewalls)
- Policy Analyzer: split anomalies into actionable vs advisory
- Policy Analyzer: Tier-2 exact effective-space engine (union coverage)
- Policy Analyzer: triage + group relational anomalies
- Policy Analyzer: vendor-native config candidates + reachability diff
- Policy Analyzer: YAML policy-as-code compliance packs
- Policy Analyzer: zone rating + per-rule risk scorer (pure)
- Policy Analyzer: zone rating storage + risk endpoint + zone discovery
- Policy Analyzer: zone-aware compliance (CDE least-privilege checks)
- Policy Analyzer: zone-pair baseline matrix + segregation check
- Policy Analyzer: zone-pair segregation matrix (AlgoSec-style)
- Policy Graph: contracts (ACI) / rules (firewall) as clickable nodes
- Policy Graph: node click opens a policy-analysis panel
- Policy Graph: searchable, contract-first node panel with filter->entry drill-down
- Policy Graph: unify the ACI + firewall graph palette
- UI: animate role-permission group collapse + wider role/user dialogs
- UI: show read-only provenance in the Edit memory dialog
Bug Fixes
- Apic Ui: badge single-row means per-badge, not per-cell
- Cisco ACI: stop tenant-switch render loop on filtered tabs
- Cisco ACI: use a space (not a literal NUL) as the filter-key separator
- Ci: regenerate frontend lockfile in linux node:22
- Filters: add not_contains operator + enum-first operator ordering
- Filters: honest fallback operators for operator-less fields
- Filters: preserve operators through per-field URL round-trip + browser e2e (#982 #983)
- Palo Alto: attribute clone+rename rules + surface admin source IP
- Policy Analyzer: ACI per-filter deny + vzAny relations (fidelity review)
- Policy Analyzer: conform page to platform design system
- Policy Analyzer: correlation requires shared App-ID / URL-category scope
- Policy Analyzer: embed finding rule cards server-side
- Policy Analyzer: graph renders — aggregate parallel contract edges
- Policy Analyzer: make the device selector a single direct dropdown
- Policy Analyzer: soundness fixes from high-effort code review
- Policy Analyzer: vendor selector as a dropdown, not a segmented control
- Policy Analyzer: zero_hit uses Palo native last_hit, not first-capture
- Policy Analyzer: zones are a match dimension in shadowing analysis
- Policy Graph: firewall graph crash on parallel zone edges (zone:any->zone:any)
- UI: header leading icons only on Panels-section pages
- UI: make the whole pending-review bar clickable
Last updated on