Skip to content

May 2026

You can now create service accounts — named, non-human identities with their own API credentials — for programmatic access to the Adversarial API. Service accounts support OAuth2 client credentials and are subject to the same role-based access controls as human users, so you can scope them to exactly the permissions your integrations need.

Service accounts are managed from Settings > Team alongside human team members, in a dedicated Service Accounts section of the same page.

Service accounts support a Reset Credentials action in Settings → Service Accounts. Resetting rotates the client secret and immediately invalidates the previous credentials, making it easy to cycle secrets as part of a security rotation without deleting and recreating the account.

Risk and incident detail modals now include an Activity tab that shows the full change history of the record: every field edit, status change, and comment in chronological order. Each entry displays the author, timestamp, and a before/after diff of the changed fields.

The risk slide in PPTX deck exports now includes an AI-generated executive summary. The summary is scoped to the risk’s description, scoring rationale, and linked findings, giving stakeholders a concise narrative without requiring manual authoring.

“Updated By” on Risk & Incident Registers

Section titled ““Updated By” on Risk & Incident Registers”

The risk and incident register tables now surface an Updated By column, showing the user who most recently modified each record. The field is also visible in the record’s detail modal. Additionally, the risk and incident registers now support filtering by the user who last updated a record. Select one or more team members in the Updated By filter to narrow the register to records they touched most recently — useful for reviews, audits, and handoff workflows.

All date columns on the risk and incident registers — including Discovered, Expected, Closed, Occurred, Detected, Contained, and Responded dates — now show a precise YYYY-MM-DD HH:mm timestamp on hover, matching the behavior already present on the Created and Updated columns.


Notification emails have a new look-and-feel aligned with the latest Adversarial design system: a clean white card layout, pill-style logo header, and a shared footer with manage-notifications and unsubscribe links. Severity and urgency level words are now color-coded in the email body to match their in-app treatment (e.g. Critical appears in red).

Section titled “In-App Guidance Panels Replaced with Docs Links”

The embedded Guidance panels in the Threats, Risks, Incidents, and Compliance modules have been replaced with a compact ? icon that opens the relevant guide on docs.adversarial.com in a new tab. This keeps the interface clean and ensures guidance content stays up to date as documentation evolves.

Threat objective icons throughout the platform now display a tooltip on hover identifying the objective by name. This makes it easier to interpret threat data without needing to cross-reference a legend.

Scoring: Re-score Findings on Description Change for Integration Sourced Entries

Section titled “Scoring: Re-score Findings on Description Change for Integration Sourced Entries”

When AI Scoring is enabled for an integration — Wiz, HackerOne, BugCrowd, and WatchTowr, GreyMatter — scoring is refreshed automatically whenever the source tool updates the description of an existing entry. The automatic rescore covers the same outputs as a manual run — Likelihood and Impact for Risks and Severity for Incidents, scoring rationale, and Threat Objectives. This auto scoring feature supports the continuous lifecycle updates until a risk or incident is completely remediated. For integration sourced records, users should capture any new details in the Comments section, rather than edit the Description field. Edits to the Description will be overwritten by the integration when the sync runs between ARM and the integrated tool. If users prefer to manually adjust the scoring of these entries, they can capture their reasoning for the adjustment in the reasoning section.

Scoring summary notifications are now delivered to the user who requested the scoring run, and the notification body shows cleaner counts (e.g. findings scored, findings skipped) instead of raw debug output.

The GreyMatter integration (formerly listed as “GreyMatter SIEM”) has been renamed to GreyMatter. Incident syncs now correctly use the resolvedAt timestamp — rather than closedAt — as the contained date, improving accuracy for incidents that are resolved before they are formally closed.

Risk and incident registers now render a single vertical scrollbar instead of multiple nested scrollbars, reducing visual clutter and making large registers easier to navigate.

Filter panels with many options are now scrollable instead of being clipped.

The risk and incident tables in the Compliance deck have been restyled for improved readability and visual consistency with the rest of the deck.

Labels previously displayed as “Analysis” — including “Severity Analysis”, “Likelihood Analysis”, and “Impact Analysis” — have been renamed to “Reasoning” throughout the platform to match the underlying field names. This change affects the activity history, notification change diffs, and CSV export column headers.