The Willow July Digest: The Fastest Way to Put AI to Work Is to Govern It

Most of what shipped in Willow this July has the same shape. Somewhere, an admin was stuck between two bad options: block a capability outright, or hand it over and hope. Every feature below closes that gap a little further, so the answer stops being "no" or "trust me" and starts being a policy you actually set.
A few of these started as requests customers sent us directly. Here's what changed.
Roll out Claude Code from one console, not one machine at a time
Claude Code Policy Console is now generally available. Before this, locking down Claude Code across an org meant touching settings machine by machine, or waiting for the console to leave beta. Now it's one screen: MDM export, deny-list tiers, model settings, hooks, and a scenario builder, with per-OS install instructions built in. If your rollout was paused waiting for GA, it's ready now.

Delegate the busywork, not the risk
Custom org roles replace all-or-nothing admin access. Until now, giving someone admin capability meant giving them everything, whether they needed to manage skills and connectors or not. Custom roles scope access to exactly what a person's job requires, so a teammate can run day-to-day admin work while security and policy settings stay with whoever should hold them. It's enforced across every API endpoint and admin page, not just the parts of the UI someone happens to click through.

Stop choosing between block and allow
Guard rules can now pause a risky tool call and loop in a human before it runs, instead of forcing a binary decision to block it outright or let it through. A new warn-and-approve action holds the call until someone signs off, with a live notification the moment it fires. This is the same false choice we've been writing about all month: block it and you lose the capability, allow it and you're exposed. A pause is a third option, and now it's a real one.

Guard your org on Chrome, without asking every employee to install anything
The Claude Guard Chrome extension now installs via MDM. IT can push it to every managed machine in one action instead of asking each employee to install it themselves, which in practice meant partial coverage and no way to guarantee everyone was protected. Fleet-wide rollout is now the default path, not the aspirational one.

Your SIEM already watches this. Now it can watch Willow too
CrowdStrike is a supported log destination as of this month. Willow's logs flow into the SIEM your security team already has open, with a delivery-audit view and a one-click test send to confirm it's actually landing. For teams where "does it show up in our SIEM" is a hard requirement before sign-off, this closes that gap directly.

Also shipped this month
Audit logs now redact sensitive data by default, with full detail available on demand for anyone who needs it. Analytics graduated to general availability. Group-level AI Champion roles let teams delegate governance responsibility to a named owner instead of routing everything through central IT. Slack alerts now fire when shadow AI activity is discovered. And a set of reliability fixes landed across the gateway and dashboard that you should notice mostly by not noticing them.

New to watch and read
Two things worth your time if you haven't seen them yet:
- Shalev, Willow's CTO, wrote up how Claude Tag actually works, and why identity is the hard part (7 min read).
- And we put out a new video walking through shadow AI, skills, and plugins, and how to get all three under control in about two minutes (1 min watch).
The pattern, if you're tracking it
None of this month's releases are about adding a new AI capability. They're about making the capabilities you already have safe enough to turn all the way on. That's the bet behind Willow: the fastest way to put AI to work isn't to loosen the controls, it's to build controls precise enough that loosening them stops being the only way to move fast.
Questions about anything above? Reach out to us and the team would love to discuss!
FAQS
Yes. SCIM and Okta provisioning for team plans. The extension stays free.
Today, Claude on Chrome. ChatGPT Operator, Gemini in Chrome, and others are on the roadmap.
No. It activates only when Claude takes an action. It does not read your tabs, keystrokes, or content otherwise.
Everything you need to get your Basecamp running.
Your agents are already in the wild.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.