This page documents production updates to Google Security Operations SOAR. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
September 06, 2026
Release 6.3.100 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Reaction triggers
This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to real-time case or alert updates during active investigations, such as changes to the case assignee, case tags, alert priority, or newly added entities.
For more information, see Use reaction triggers in playbooks.
Case playbooks
This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather than individual alerts, consolidating response tasks and reducing redundant operations during investigations.
For more information, see Case playbooks overview.
September 05, 2026
Release 6.3.99 is now available for all regions.
August 30, 2026
Release 6.3.99 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
August 29, 2026
Release 6.3.98 is now available for all regions.
August 27, 2026
Scheduled maintenance
SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will experience a brief period of downtime. You don't need to take any action.
August 16, 2026
Release 6.3.98 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
August 15, 2026
Release 6.3.97 is now available for all regions.
August 13, 2026
Scheduled Maintenance
SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will experience a brief period of downtime. No customer action is required.
August 09, 2026
Release 6.3.97 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Updated rich-text editor
Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.
Key changes include:
- Simplified typography: Choose font sizes using semantic options (Small, Normal, Large, Huge). Legacy font sizes on existing text are preserved.
- Streamlined tables: You can insert or remove entire tables. Formatting inside table cells is no longer supported.
- Toolbar cleanup: Removed the Cut, Copy, and Paste buttons from the toolbar. Standard OS keyboard shortcuts remain supported.
- Visual alignment: Improved visual consistency between editor content during editing and after submission.
August 08, 2026
Release 6.3.96 is now available for all regions.
August 03, 2026
The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026. For more information, refer to the SOAR migration guide.
August 02, 2026
Release 6.3.96 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
August 01, 2026
Release 6.3.95 is now available for all regions.
July 26, 2026
Release 6.3.95 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
July 25, 2026
Release 6.3.94 is now available for all regions.
July 19, 2026
Release 6.3.94 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
July 18, 2026
Release 6.3.93 is now available for all regions.
July 12, 2026
Release 6.3.93 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Publisher Agent Version 2.7.0
Publisher Agent Version 2.7.0 is now available for all regions.
July 11, 2026
Release 6.3.92 is now available for all regions.
July 07, 2026
SOAR migration to Google Cloud validation status
You can now check if the SOAR migration was successful by going to the SOAR Settings > License Management page. After successful completion of Stage 1, it will say Google.com after the system version number. After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both Google.com and CloudIAM Enabled after the system version number.
For more information on the migration, see the SOAR migration guide
July 05, 2026
Release 6.3.92 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Publisher Agent Version 2.7.0
Publisher Agent Version 2.7.0 is being rolled out to the first phase of regions.
This release includes the following updates for the remote agent:
- High Availability support: Adds applicative support for Publisher high availability.
- File transfer support: You can now upload and download files using playbooks and the SDK on agents that have been migrated to the GCOM infrastructure.
July 04, 2026
Release 6.3.91 is now available for all regions.
June 28, 2026
Release 6.3.91 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Remote Agents Version 2.6.7
Remote Agents Version 2.6.7 is now available. This release contains minor bug fixes.
June 27, 2026
Release 6.3.90 is now available for all regions.
June 26, 2026
Improved documentation portal navigation
Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed to align with your workflows, providing a logical path through the documentation.
We've also added:
- A Support tab for technical support, changelogs, and release notes
- A Use cases tab for persona-driven CUJs and workflows
June 23, 2026
Critical Notice: Upcoming reservation of siemAlertId field
Effective July 5, 2026, the siemAlertId field will be strictly reserved for
internal Chronicle SIEM alert IDs.
Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named
siemAlertId in any of your alert ingestion configurations, please
migrate to a different field name immediately to prevent data loss.
June 21, 2026
Release 6.3.90 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Scheduled Maintenance
CloudSQL will undergo a scheduled minor upgrade.
June 20, 2026
Release 6.3.89 is now available for all regions.
June 16, 2026
New Documentation changelogs
Google SecOps is now releasing a monthly changelog to capture major documentation updates.
For more information, refer to Documentation changelog.
June 14, 2026
Release 6.3.89 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
June 13, 2026
Release 6.3.88 is now available for all regions.
June 07, 2026
Release 6.3.88 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
June 06, 2026
Release 6.3.87 is now available for all regions.
May 31, 2026
Release 6.3.87 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
May 30, 2026
Release 6.3.86 is now available for all regions.
May 28, 2026
Unified and Upgraded Chronicle API
Chronicle API has been unified with API resources from legacy SOAR API. This unification provides a more robust, secure, and extensible experience. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for a more robust, secure, and extensible experience. Learn more about API Stability.
This update includes the following resources: Case, CaseAlert, CaseStageDefinition, CaseTagDefinition, CaseQueueFilter, CaseCloseDefinition, ContextProperty, InvolvedEntity, Task, CaseComment, CaseWallRecord, ChatMessage, View, VisualFamily, ChatMessages.attachment, ContentPack, SocRole, EmailTemplate, DynamicParameter, EntitiesBlocklist, Environment, EnvironmentGroup, Integration, Integrationaction, UserNotification, Integrationactionrevision, Connector, ConnectorInstance, RemoteAgent, Connectorlog, Connectorrevision, IntegrationInstance, UniqueEntity, Integrationsjob, JobInstance, JobInstances.log, Jobs.revision, Integrationmanager, Integrationmanagerrevision, AlertGroupingRule, Announcement, Attachment, CustomList, FormDynamicParameter, MarketplaceIntegration, ModuleSetting, SlaDefinition, NotificationSetting, PropertySchemaDefinition, RequestTemplate, SoarDomain, SoarNetwork, WorkdeskLink, SystemNotification, WorkdeskContact, WorkdeskNote, LegacySoarUsers.localization.
For a full list of updated resources and links to the documentation, please see the Chronicle API documentation.
May 24, 2026
Create and manage calculated fields
The Calculated Fields feature is now available in Preview. With Calculated Fields, you can dynamically derive new data points within Google Security Operations cases and alerts. By defining logical formulas, you can compute values based on existing system or custom fields. The calculated value is automatically evaluated and stored in a user-selected, pre-existing custom field (labeled Target Field) in real time.
For more information, see Create and manage calculated fields.
Release 6.3.86 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
May 23, 2026
Release 6.3.85 A Missing Authorization vulnerability (CVE-2026-15587) in DataPlaneAuthenticationHandler and a SQL Injection vulnerability (CVE-2026-15623) in a legacy dashboard widget API in Google SecOps were patched with version 6.3.85. No customer action is needed.
Release 6.3.85 is now available for all regions.
May 17, 2026
Release 6.3.85 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
May 16, 2026
Release 6.3.84 is now available for all regions.
May 03, 2026
Release 6.3.84 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Enhanced "Time to respond" options for multi-choice questions
Google SecOps now provides more granular control over playbook execution when the "time to respond" for a MultiChoiceQuestion step is exceeded. When configuring a multi-choice question, you can now choose to proceed with one of the predefined answer branches or to create a dedicated branch to handle this scenario.
For more information, see Add a multi-choice question flow.
May 02, 2026
Release 6.3.83 is now available for all regions.
April 12, 2026
Release 6.3.83 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
April 11, 2026
Release 6.3.82 is now available for all regions.
April 05, 2026
Release 6.3.82 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Playbook Condition and Multi-Choice Question Flows
The maximum number of branches supported in Playbook Conditions and Multiple Choice Questions has been increased from 6 to 20. This allows for more complex branching logic within a single step.
For more information, see Use flows in playbooks.
April 04, 2026
Release 6.3.81 is now available for all regions.
March 29, 2026
Release 6.3.81 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
March 28, 2026
Release 6.3.80 is now available for all regions.
March 17, 2026
SOAR Permission Groups migration to Google Cloud IAM is now in General Availability (GA). You can now leverage Google Cloud IAM for precise, granular feature access, moving away from legacy permission groups.
You can enable it by migrating the legacy SOAR permission groups and permissions to Google Cloud IAM through a self-service migration available from January 26, 2026. Please check the documentation and video for full instructions.
This update is available to all customers who have completed Stage 1 of the SOAR migration to Google Cloud.
March 16, 2026
Stage 2 of the SOAR migration to Google Cloud deadline has been extended from June 30th to September 30th, 2026.
March 15, 2026
Release 6.3.80 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
March 14, 2026
Release 6.3.79 is now available for all regions.
March 08, 2026
Release 6.3.79 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
March 07, 2026
Release 6.3.78 is now available for all regions.
March 01, 2026
Release 6.3.78 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
February 28, 2026
Release 6.3.77 is now available for all regions.