Sigma’s August release puts agents, tenants and secrets on one access model
The practical upgrade question is not which AI feature to enable first, but whether OAuth permissions, tenant audit settings and external credentials still form one governable path.
Sigma’s August release is less a list of AI features than a test of whether an analytics platform can extend beyond the browser without creating a second security model. The company made its command-line interface and multi-tenant architecture generally available while keeping agent-built workbooks, webhook triggers, Anthropic model access and external secret-manager integration at various beta stages, according to its August product roundup.
One identity path for people and agents
The generally available Sigma CLI exposes the company’s public REST API on macOS, Linux and Windows. It authenticates as an OAuth API client and carries the account types and permissions already configured in Sigma, so a command issued by a person or coding agent follows the same governed route into workbooks, data models, connections and permissions, Sigma says.
That design matters because the accompanying Workbooks as Code capability remains in private beta. It represents workbooks as YAML, while Sigma Skills can guide coding agents through requirements before they generate an application. Sigma’s example produced a scenario-planning app with approval routing, an AI summary and writeback through Input Tables; the company says the agent built it in eight minutes, compared with a few hours by hand for its product advocate. The human decisions about edit rights, approvals and what the agent may answer did not disappear, the post cautions.
The beta features widen the control surface
Webhook triggers, now in public beta, allow an external system to POST to Sigma and start an action sequence. Anthropic support is also in public beta: customers can supply their own API key for Claude-backed Sigma Assistant, Sigma Agents, Formula Assistant and chart explanations. Sigma notes that Anthropic cannot supply the separate embedding model needed for semantic search. Workbook generation through the MCP server is still in development, as is a plugin pairing MCP tools with migration skills for Claude, Codex and Cursor, according to the same release summary.
The secret-manager integration is another public beta. Sigma says it retrieves warehouse, external-service and MCP-tool credentials at authentication time from HashiCorp Vault or AWS Secrets Manager, retains no copy, and picks up rotations or revocations from the customer’s store. That makes credential inventory a prerequisite for enabling agent tools, not cleanup work after deployment.
A practical rollout order
Teams evaluating the release should separate generally available foundations from beta execution paths. First, verify that CLI automation receives only the permissions its OAuth client needs. Second, enable audit logging tenant by tenant: Sigma says the parent setting does not automatically turn logging on in each tenant. Third, inventory webhook destinations and every credential reachable by an MCP tool before activating external actions. Finally, test writeback and approval behavior against a non-production tenant before promoting agent-built workbook specifications.
Sigma says hundreds of customers already operate thousands of its now-generally-available tenants. The release’s real enterprise claim is therefore not merely faster app generation; it is that agents, automation and isolated organizations can share a governable access path. The beta labels are a reminder that customers still need to prove that claim in their own deployment.
sources
comments · 0