Skip to main content

StackJack 0.1.0.4310+42b5dc9

StackJack 0.1.0.4310+42b5dc9

This release focuses on directory sync and on role-based access control. Directory sync gains run recovery, stricter mapping validation, per-load permission checks, and accurate run results; role and invitation handling no longer reports success or failure inaccurately. Bring-your-own-key changes and behavior during a lapsed subscription are also more reliable.

New features

  • Custom Tool Roles Create reusable permission sets around how your team actually works—Help Desk, Billing, Security Operations, and more—then assign them to team members, invitations, and MCP clients.
    ✅ Grant specific tools or use dynamic rules
    ✅ Combine multiple roles for flexible access
    ✅ Automatically include new tools that match your rules
    ✅ Manage permissions once instead of endpoint by endpoint
  • Existing MCP clients retain their current behavior until roles are assigned—no breaking changes or surprise access changes.

  • Microsoft Entra Directory Sync Connect Microsoft Entra and map groups or directory attributes directly to your StackJack roles.
    ✅ Preview and review users before provisioning
    ✅ Enable automatic provisioning when you’re ready
    ✅ Keep team membership and tool access aligned with Entra
    ✅ Safely deactivate access when sync-managed users leave mapped groups
    ✅ Review sync history, conflicts, and diagnostics
    ✅ Pause synchronization or run it immediately from the Portal

  • StackJack only lifecycle-manages identities created through directory sync, keeping manually managed users protected.
  • Recover a stalled directory sync run. Runs now record their progress as they work. If a run stops reporting activity for a sustained period, you can mark it abandoned from the Runs tab and free the connection for a new sync. This previously required a configuration change when runs were allowed to run without a time limit. Runs that are still reporting activity cannot be marked abandoned.

Improvements

  • Directory sync pages re-check your permissions on each load and tell you plainly when your access to the page has been removed while it was open.
  • Concurrent-run limits are now applied consistently across every way a run can start, including resuming a run that is waiting for input. Resuming while you are at your limit returns a clear capacity message instead of starting an extra run, and queued runs are no longer held behind work that direct launches were able to ignore.
  • Actions that previously ended in a generic server error when a subscription had lapsed now return a clear explanation of why they were refused.
  • Deleting agents and cleaning up their associated resources now works while a subscription is lapsed. Previously a lapse could leave you unable to remove or stop them.

Bug fixes

  • Directory sync results now reflect the actual outcome of the run. A run that was blocked or failed no longer reports as a completed sync.
  • Directory sync mapping saves failed with an unhelpful error when a value was too long for storage. Matching values that exceed the limit are now refused before the save, with a message naming both the limit and the length you entered. Group display names, which come from the directory and are not editable, are shortened automatically so the save can succeed instead of failing on every retry.
  • Sending a team invitation with roles selected could remove roles already attached to an existing pending invitation for the same person, while still reporting success. Invitation role selection is now additive; role removal continues to be done from the Edit Roles dialog.
  • After deleting a role, the list now refreshes before any confirmation appears. A deleted role no longer stays on screen with working Edit and Delete buttons, and a confirmation for one role can no longer appear over a dialog you have since opened for a different role.
  • A transient error occurring after a role change had already been saved was reported as though the change had not been saved.
  • Saving, rotating, or removing your own Anthropic API key could fail when other activity touched the account at the same moment — after the key change had already been stored. This left the account temporarily unable to start runs and unable to cleanly retry. These operations now complete reliably under concurrent activity.
  • A key change that failed partway through no longer alters how your existing key is treated afterwards.
  • Migrating agent memory to your own API key showed a generic failure when the subscription had lapsed; the specific reason is now shown.
  • Deleting an agent that had no provisioned remote resources while the subscription was lapsed marked it as needing cleanup and required a second attempt. It now archives in a single pass.

UI & UX changes

  • The confirmation dialog for marking a directory sync run abandoned now shows when the run last reported activity, so you can judge whether it is genuinely stalled.
  • The invitation form now states that the role selection adds roles rather than replacing them.
  • Notices shown when role information cannot be loaded now accurately describe, on each page, whether saving is blocked and what to do next.

Known issues

  • After the run service restarts, work that was already in progress continues to count against your concurrent-run limit until it is accounted for. Launches and resumes may therefore be queued or refused for capacity for a period afterwards, and scheduled runs whose start window passes during that period will be skipped rather than delayed.