The Willow August 2026 Digest

We're sending this month's digest a few days early, before August 1st, because the team is heads-down at Black Hat next week. Here's what changed: the releases and fixes that actually change how you run the platform day to day, including a few that started as requests you sent us.
The shift this month has one shape. AI that does more on its own, with the controls to match. Agents that run without a person driving every step, and safeguards that keep pace as adoption grows.
Come meet us at Black Hat. Booth #5905, the calmest spot on the show floor, packed with demos, games, prizes, and outdoor SWAG. We're also hosting a private dinner for security leaders on Wednesday, August 5. Limited seats. Register and pre-book your time.
Stop babysitting the work that doesn't need you: Background Agents are live
Background Agents are now generally available. Until now, a recurring task like prospect research or support triage still needed a person to kick off every run. Now you set an agent up once to own the task, and it carries the work forward and reports back, with the same identity, scope, and audit you already have everywhere else in Willow. Autonomy without a blind spot. We run these ourselves. Set up your first background agent.
Put your security policy inside the coding agent: Guard Hooks
Guard Hooks run your Willow policy directly inside Claude Code, Cursor, and Codex, inspecting every prompt, tool call, and output before the model acts. Malicious prompts get blocked, risky commands need approval, and secrets or PII are masked on the fly. No proxy, no code changes. It deploys in minutes as a one-click plugin, so the policy travels with the coding agent instead of stopping at the network edge. Turn on Guard Hooks.
Oversight without the wait: Slack Ranger
Oversight doesn't have to mean a bottleneck. When an agent is about to take an action that needs sign-off, the request lands in Slack with the full picture, and anyone can approve or decline in seconds. Risky moves still get a human yes. It's just a fast one, and it's how our own team signs off on agent actions every day. Connect Slack Ranger.
One line of control, wherever agents run: AWS Bedrock AgentCore
Agents don't stay in one place, so governance shouldn't either. Agents built on Amazon Bedrock AgentCore now run through Willow with the same oversight and controls as everything else. Where an agent lives stops deciding whether it's governed. Bring in your Bedrock agents
The data-residency blocker is gone: EU hosting
If data residency requirements have been holding back your rollout, that blocker is gone. Willow now runs entirely on European servers, so teams with strict requirements can move forward with confidence. Nothing to reconfigure, just where it runs. Teams are already live on it. Move to EU hosting.
Connect any tool in about two minutes
Setup used to mean someone learning each integration one at a time. A guided, step-by-step flow now gets any tool connected in about two minutes, and anyone can run it themselves. It's the same flow we use internally. Connect your first tool.
Also shipped this month
Agent Memory Discovery surfaces the notes and instructions your agents rely on. Integration Conditions let you set rules for when an automated action should or shouldn't run. Teams can now set their own login session limits. Safety checks now catch hidden or disguised text. A new On-Prem page centralizes self-hosted setup. POV Management tracks every pilot in one view. Realtime Alerts send safety warnings straight to Slack. Group Admin Roles give each team its own owner, viewer, and lead. And Run Impersonate lets an admin sign in as another user for support.
New to watch and read
A few things worth your time if you haven't seen them yet:
- Shalev introduces Governed Background Agents with Willow (1 min watch).
- Wix x Willow: The Access Layer Behind 1M+ AI Tool Calls a Week (1 min watch).
- Shalev on Willow x Claude's Compliance API: closing the audit gap for agents (2 min read).
- Shalev's framework: How to Deploy AI Background Agents in the Enterprise (5 min read).
The pattern, if you're tracking it
Last month the releases were about making the capabilities you already had safe enough to turn all the way on. This month the capability itself grew. Agents that run on their own, without a person driving every step. What did not change is the rule underneath it: every bit of new autonomy shipped with a matching control. A background agent that owns a task, and the same audit trail behind it. A coding agent that acts, and a policy running inside it. A faster human yes, not a removed one. That's the bet behind Willow. The fastest way to give AI more room to work is to build the controls precise enough that giving it that room stops being a risk.
Questions about anything above? Reply or reach out, the team would love to discuss.
Background Agents in the Enterprise
Most teams can spin up an agent. Few can deploy one their security team signs off on. Here's the framework that does both.
FAQS
Everything you need to get your Basecamp running.
Your agents are already in the wild.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.