Structured Agentic Workflows logs now expose searchable fields, giving release owners faster evidence when an automated security workflow fails or behaves unexpectedly.
Unified policies migration now has a firm operating window
Semgrep will begin migrating some organizations to unified policies on August 24, 2026. The current Policies experience is scheduled to sunset on November 1, 2026. Organizations that are not ready can contact Support, but postponement should not replace a migration plan.
This is a governance event, not merely an interface update. Features that depend on unified policies, including Autofix draft fix requests, now prompt organizations to upgrade when they have not migrated.
Release and security leaders should establish:
- An accountable owner for each detection policy domain
- A catalog of policy exceptions and their business justification
- Change approval requirements for scan-scope modifications
- Evidence that critical repositories retain required controls after migration
- A communications plan for teams affected by Autofix and policy workflow changes
Policy ownership needs decided before the cutoff. Waiting until the final weeks raises the likelihood that delivery teams discover dependencies during active releases.
Structured workflow logs improve investigation quality
Agentic Workflows step logs now use a structured viewer. Instead of reviewing a single unstructured log block, users can search and filter individual fields from each run.
For enterprise teams, the operational benefit is faster triage and better review evidence. A release owner can more quickly determine whether an automated workflow failed because of an input condition, an execution step, a repository state, or an external dependency.
This change is useful for:
- Incident investigations where response time matters
- Release approvals that require traceable automated checks
- Workflow reliability analysis across repositories or teams
- Internal audit requests for execution records
Teams should standardize what they retain from workflow investigations, including run identifiers, affected repositories, decision points, and remediation actions. Searchable logs improve analysis, but they do not by themselves define an evidence-retention process.
File-link resilience reduces dead ends in security reviews
Semgrep fixed an issue where Agentic Workflows findings lacked a source-file link when the SCM connection was disconnected or unhealthy. The platform now builds links from stored repository metadata and shows a repository or settings fallback when code cannot be loaded.
This is a practical workflow correction. Reviewers can maintain context even when the source-control integration has a temporary problem, reducing the chance that a valid finding is deferred simply because the direct code path is unavailable.
Security operations teams should still monitor SCM integration health. Metadata-based links are a useful fallback, while persistent integration failures can affect scan confidence, source availability, and remediation speed.
Policy APIs gain two important scan controls
The public beta policies API vocabulary now includes breaking_change and full_scan for organizations using unified policies. These additions allow those scan-policy options to be represented through API-based configuration.
For platform engineering, this strengthens the case for managing policy configuration through controlled automation rather than isolated console changes. API-driven administration can support:
- Versioned policy definitions and peer review
- Promotion controls between development and production organizations
- Detection of configuration drift
- Change records tied to service-management processes
- Repeatable policy rollout across business units
Because the API remains in public beta, teams should confirm endpoint behavior, permissions, and failure handling in a non-production organization before making it part of a required deployment gate.
Reporting and administration become more accurate
Projects page finding counts now include findings in Reviewing and To fix statuses, in addition to Open. The page includes a tooltip explaining the revised count definition.
This improves visibility into the full active remediation queue, but it can alter trend lines. Security leaders should annotate dashboard changes and update KPIs that previously treated Open findings as the entire outstanding population. Otherwise, the organization may report an apparent increase in exposure when the underlying change is measurement scope.
The release also resolves two policy-administration issues:
- Detection policies now load when a policy contains a rule without a path, avoiding blocked policy edits.
- The scanning behavior drawer now distinguishes included from excluded projects when users switch modes.
- The Detection policies rules table retains its actions column on narrow screens, keeping primary actions accessible.
These corrections reduce administrative friction, particularly for centralized teams managing exceptions, repository scope, and policy changes under time pressure.
Recommended actions for August
- Confirm whether your organization has been scheduled or is prepared for unified policies migration.
- Inventory policies, exception paths, API integrations, and Autofix dependencies.
- Test
breaking_changeandfull_scanpolicy representation through the public beta API. - Update remediation dashboards for the expanded Projects page count definition.
- Add structured workflow-log review steps to incident and release procedures.
- Validate that SCM connection monitoring and fallback review procedures are documented.
How Merito helps
Merito helps enterprises treat application-security configuration as a governed delivery capability. We can assess unified policies readiness, map policy controls to release workflows, establish API-driven change controls, and revise executive reporting for the new finding-count definition.
For teams adopting Agentic Workflows, Merito can also define operational logging, incident-review, and audit-evidence practices so the new structured data supports accountable decisions rather than creating another isolated tool view.
Merito is an authorized Semgrep reseller and services partner. Our Semgrep team can scope licensing, sizing, and rollout for August 2026, and our enterprise upgrade services help you plan and validate the upgrade with minimal disruption to release schedules.

.png&w=2560&q=75)