April-July 2026
July 31, 2026
Role-based Access Control
Granular roll-based access control for Workflows has finally arrived! This feature is available under Organization > Early Access.

Once you opt-in to the above, you can browse to Organization > Administrators > Roles > Create custom roles. After selecting a name (e.g., Workflows-execute), you can choose from any of the following permissions:
- Deny - No access to Workflows and the Automation menu is hidden.
- Read-only - Full access to the Automation menu but for viewing or auditing only.
- Write - Full access to the Automation menu as an administrator and workflow creator.
- Execute - Full access to the Automation menu as an operator who can only run available workflows
You no longer need someone to be in the Org Admin role to create, manage, or run workflows. Granular control will allow teams to operationalize automation by allowing a subset of users to only run workflows.
New Cisco Workflows Adapters for Infrastructure, Operations, Observability, and Security Automation
We are introducing six new Cisco Workflows adapters that extend automation across Splunk Cloud Platform, Cisco Intersight, Nexus Hyperfabric, Splunk Observability Cloud, Webex Control Hub, and Security Cloud Control. These adapters connect workflows to supported management APIs for infrastructure lifecycle, fabric configuration, search and event operations, observability, organization administration, and cloud security and firewall management.
-
Cisco Splunk — Search, saved-search, index, user and role management, plus HTTP Event Collector automation. For detailed information see Cisco Splunk Endpoint Target.
-
Cisco Intersight — Infrastructure inventory, lifecycle, search, workflow, and webhook automation. For detailed information see Cisco Intersight Endpoint Target.
-
Nexus Hyperfabric — Fabric, device, VRF, VNI, and staged-configuration automation. For detailed information see Nexus Hyperfabric Endpoint Target.
-
Splunk Observability — Dashboard, detector, muting-rule, incident, SLO, and token automation. For detailed information see Splunk Observability Endpoint Target.
-
Webex Control Hub — Organization, people, group, authorization, license, and audit automation. For detailed information see Webex Control Hub Endpoint Target.
-
Security Cloud Control — SCC inventory, audit, health, deployment, and CLI operations, plus Cloud-Delivered FMC object, policy, NAT, and deployment automation. For detailed information see Security Cloud Control Endpoint Target.
For the full list of supported targets, see Target Types.
New Automation Remote 3.0+ and Docker Compose Deployment
Automation Remote now supports deployment by OVA or Docker Compose. When creating a new Remote or regenerating an existing Remote package, use Remote Appliance version 3.0 or later. Existing connected Remotes can continue to run; however, older Remote Appliances must be upgraded before generating or regenerating a package.
For Docker Compose deployments, download the Docker Compose package from Download appliance, generate the Remote configuration package, and deploy it on a supported Docker host. Remote Appliance 3.0 and later requires outbound TCP port 5671 to the regional Remote endpoint.
See Automation Remote for network requirements and Remote Setup and Deployment for OVA and Docker Compose deployment instructions.
July 12, 2026
Webhook API Key Exposure Vulnerability Remediation
A vulnerability was identified where the webhook API key was being returned in plaintext in API responses (GET and UPDATE operations), allowing any authenticated user with read access to retrieve the secret key after initial creation. This remediation ensures that the API key is only visible once — at the time of creation or explicit refresh — and is masked in all subsequent responses and UI views.
Please see the Webhook for additional information.
June 18, 2026
Production Ready Workflows
A production-ready workflow is a locked workflow that meets a set of quality requirements and is approved for general use.
Please see the Production Ready Workflows page for additional information.
June 15, 2026
AI Activities in Cisco Workflows
- AI Prompt — Send a prompt to a large language model and use its text response directly in your workflow, with no tools or setup beyond picking a model.
- AI Agent — Let an AI agent reason over a request and automatically run the workflows you authorize, returning both its answer and the workflow run details.
May 25, 2026
Webhook Authentication Update
Webhook API keys can now be passed via the x-automate-api-key request header (recommended over query parameters) for improved security. API keys are now valid for 1 year by default — you can choose a shorter duration at creation and update it anytime before expiry, making rotation and lifecycle management easier. Existing query-parameter-based integrations continue to work, but header-based auth is now the preferred approach.
Please see the Webhooks page for additional information.
May 11, 2026
Region Availability Update
Workflows is now available in Canada and India, joining the existing supported regions: Asia-Pacific, Europe, and the United States.
Please see the Workflows Access page for additional information and note that Meraki auto-target creation is not yet available in Canada or India.
New Activity: Parse JSON
The new Parse JSON activity allows you to parse JSON content into a structured set of properties. Once parsed, the resulting properties are accessible through the variable browser for use in subsequent activities within your workflow.
April 30, 2026
New Infoblox Adapter for Universal DDI and Threat Defense API Integration
Workflows introduces an Infoblox adapter that enables integration with Infoblox Universal DDI and Threat Defense APIs. Use automation workflows to send generic DDI API requests to Infoblox resources through a configured Infoblox Endpoint target.
This adapter is now included in the supported list of endpoint targets in Workflows, allowing users to add Infoblox as a new target. It supports Infoblox Token-Based Credentials and provides a Generic DDI API Request activity to help execute API calls.
For detailed information on how to add the target and configure account keys, see Target Types, Infoblox Endpoint Target, and Infoblox Token-Based Credentials.

