No-code agent controls
Google gave no-code agents identities, stops, and logs
The workflow exposes Test and Turn off controls. That makes the flow an administrable object, not just a prompt. See the original ↗
- What changed
New Workspace Studio flows can use least-privileged identities. Admins can attribute actions, revoke OAuth scopes, suspend flows, gate external sharing, and apply DLP on eligible plans.
- Why you should care
A no-code flow can now look more like a managed service account. Existing flows do not inherit every control yet.
- What to do next
Create one low-risk flow. Remove a permission, suspend it, and save the visible events in
workspace-flow-control-record.md.
The control plane
The new-flow boundary is the decision
- Identity
- Least-privileged identity for newly created flows first.
- Attribution
- Unique ID and flow context in audit events during beta.
- Stop
- Revoke a selected OAuth scope or suspend the flow.
- Data
- Approval gates and DLP on eligible higher-control plans.
The decision: test identity, stop, and log together before production data.
Primary source: Google Workspace. Verified August 25, 2026. Controls apply to newly created flows first. DLP varies by plan.
Model economics
Gemini 3.7 Flash launched with a price-expiry date
DVx calculation · 100k input + 20k output
The standard rate doubles on January 1
One workload, one scale, and published API rates make the scheduled change visible.
The decision: use the January rate in recurring forecasts unless the workload ends first.
Sources: Google and Anthropic pricing. Verified August 25, 2026. Output includes thinking tokens. Excludes quality, caching, tools, grounding, regions, subscriptions, and discounts.
- What changed
Gemini 3.7 Flash became generally available August 13 at $0.75 per million input tokens and $3.75 per million output tokens through December 31. Both rates double January 1, 2027.
- Why you should care
A December pilot and a January production budget are not the same forecast.
- What to do next
Compare one task with your current model. Record success, tokens, latency, and cost in
model-cost-and-quality.csv.
Persistent agents
Grok Bot made the agent desktop persistent
A named Bot is operating a cloud desktop after the user delegates the job. Watch the original ↗
- What changed
Named Bots get a persistent cloud computer, browser, terminal, app sessions, memory, and routines. Access expanded August 21 across eligible Grok and Cursor plans.
- Why you should care
Every Bot owned by one user shares its computer, files, browser sessions, logins, and local permissions. Separate Bots are not security boundaries.
- What to do next
Pilot one read-only job with a new account and no local access. Save sessions, approvals, data settings, spend, and cleanup in
grok-bot-boundary-record.md.
The actual security boundary
One user gets one shared computer
- Storage
- Cloud storage required. Legacy Privacy Mode unsupported.
- Actions
- Approval rules and Auto Review exist. Use least privilege.
- Models
- Product-managed routing and failover. No admin model picker.
- Oversight
- Action audit view and Bot-specific spend cap are still coming.
The decision: scope credentials to the user’s entire Bot roster and keep consequential actions behind approval.
Primary sources: xAI and Cursor. Verified August 25, 2026. Launch was August 11. Access expanded August 21.
Agentic engineering
Codex reached GitLab
The issue or merge-request trigger runs in Codex cloud and returns to a human review step. Open setup details ↗
- What changed
The August 19 beta lets every ChatGPT plan connect GitLab to Codex cloud.
@codexcan start from an issue or merge request and review the result.- Why you should care
GitLab teams get an issue-to-agent-to-MR loop without moving repositories. Self-Managed installations need admin setup and GitLab 19.0 for webhook activity.
- What to do next
On one small repository, record cloud execution, webhook permissions, branch rules, diff coverage, and reviewer in
codex-gitlab-pilot.md.
One workflow to try · 30 minutes
Run a Grok Bot boundary test
- TaskGive one Bot a read-only, reversible research task.
- ApprovalStop sending, publishing, deleting, and local commands.
- InspectCheck cloud files, browser session, actions, and usage.
- Clean upRemove files, sign out, and revoke the connector.
Keep the task, evidence, approval, and cleanup record.
Portfolio watchlist
Three checks before the next run
Engineering
GPT-5.6 Sol Ultrafast reports up to 750 output tokens per second. Access is limited and price is missing.
Data
OpenAI previewed cross-session safety processing for ZDR customers. Keep today’s endpoint matrix until the September paper arrives.
Education
ChatGPT for Teens adds safeguards and parent links. Test classification and escalation.
Term of the week
Agent identity
A distinct identity used by an automated workflow, with its own permissions and audit trail. It lets you stop the workflow without revoking a person’s entire account.
Field Manual impact
Manual 02 changes
The Overnight Build should add the Grok Bot shared-computer boundary, cloud-storage requirement, approval rules, cleanup procedure, and missing action audit and spend cap.
Source ledger
| Development | Announced | Available or effective |
|---|---|---|
| Workspace Studio controls | August 17 | New controls first. End-user actions from August 20. Existing flows later. |
| Gemini 3.7 Flash | August 13 | Generally available August 13. New price January 1, 2027. |
| Grok Bot | August 11 | Early beta August 11. Access expanded August 21. |
| Codex for GitLab | August 19 | Beta August 19. |
Verification notes
- Core research covered August 13 through August 19. Revision links and assets were checked August 25.
- Every development exposes a primary source before its decision brief.
- Product claims show an official product image or official demo frame.
- The Gemini comparison is a DVx calculation with fixed token counts and visible exclusions.
- The Codex diagram is a DVx workflow artifact linked to OpenAI’s primary text.
- Announcement, availability, rollout, and scheduled-price dates remain separate.
- No confidential portfolio information is included. The published copy contains no em dashes.