> Source: https://docs.nometa.az/changelog/4-7

# SAMURAI 4.7

_Released July 9, 2026._

## Features

- **AI:** feed recently-rejected proposals to the council as decline context
- **AI:** keep rejection tombstone conservative + observable
- **AI:** operator-tunable retention for terminal memories
- **AI:** state_reason — why a memory is in its current state
- **Ai Tools:** shared list-query layer — filter/fields/page + iteration hints
- **Ai Tools:** temporal sync-lag annotation + at_change snapshot reads
- **Ai Tools:** trigger-condition descriptions + schema enums + protocol example
- **Apic Ui:** parse src_port/dst_port search tokens end-to-end
- **Apic Ui:** render contract lookups at top-of-page notification stack
- **Apic Ui:** single-row contract badges + shared NotificationBanner for lookups
- **Apic Ui:** Source/Destination Port in the Add-Filter dropdown (both tabs)
- **Cisco ACI:** contract port search matches unspecified-port (permit-any) filter entries
- **Cisco ACI:** entry-aware Filters-tab search + source-port contract search (#972 #973)
- **Cisco ACI:** plain-text filter search is entry + port aware
- **Cisco ACI:** selected tenant as a URL path segment, not ?tenant=
- **Datatable:** animate expandable rows open + closed
- **Filters:** ACL operators (eq/in) on action/protocol
- **Filters:** eq/ne/in operators across all datatables
- **Filters:** generic filter-catalog registry + migrate Memories
- **Filters:** migrate ACL (router+switch) field catalog to backend
- **Filters:** migrate APIC Contracts field catalog to backend
- **Filters:** migrate Endpoints to backend catalog + operators
- **Filters:** migrate Routes field catalog to backend
- **Filters:** numeric operators gt/lt/gte/lte on Endpoints vlan
- **Filters:** operator engine + Changes filter-field catalog backend (#980 #981)
- **Filters:** operator-aware AdvancedFilterBar + backend metadata on Changes
- **Filters:** Routes operators (eq/in) on categorical fields
- **Cisco FTD/ASA:** canonicalize gt/lt service operators to searchable port ranges
- **Cisco FTD/ASA:** make services: search any-aware for unrestricted access rules
- **Palo Alto:** make service: search any-aware for permit-all rules
- **Policy Analyzer:** Access rules tab (browse the actual rules)
- **Policy Analyzer:** ACI access-policy explorer + host search (reuse topology)
- **Policy Analyzer:** auto-select the first device on open
- **Policy Analyzer:** canonical PolicyRule model + pure Palo adapter
- **Policy Analyzer:** compute App-ID / users / URL categories
- **Policy Analyzer:** device + tab in the URL path (/policy-analyzer/:device/:tab)
- **Policy Analyzer:** expand anomaly/optimize findings to show the actual rule(s)
- **Policy Analyzer:** export button on every tab (CSV/XLSX/HTML/PDF)
- **Policy Analyzer:** extend the analyzer to Cisco FMC (multi-vendor)
- **Policy Analyzer:** extend to Cisco ACI/APIC (order-free contracts)
- **Policy Analyzer:** extend to Cisco FTD (deployed running-config)
- **Policy Analyzer:** extend to FortiGate (adapter, unit-tested)
- **Policy Analyzer:** frontend page surfacing risk/zones/anomalies/hygiene
- **Policy Analyzer:** hit-stats capture, PermPolicyAnalysis, config collections
- **Policy Analyzer:** merge adjacent same-action rules
- **Policy Analyzer:** merge vendor/device/scope into one device-focused control on the tab row
- **Policy Analyzer:** named level dropdowns for zone trust/criticality
- **Policy Analyzer:** NGFW scoping narrows risk breadth
- **Policy Analyzer:** one flat device list, drop the vendor field
- **Policy Analyzer:** OpenAPI 3.0 contract, served live
- **Policy Analyzer:** optimizer - derived removal/cleanup recommendations
- **Policy Analyzer:** Palo hygiene runner + gated trigger endpoint
- **Policy Analyzer:** per-framework compliance report
- **Policy Analyzer:** per-policy/section filter (drill into one FTD cluster)
- **Policy Analyzer:** persist active tab in the URL (?tab=)
- **Policy Analyzer:** pure firewall hygiene evaluators
- **Policy Analyzer:** relational anomaly engine + negate flag
- **Policy Analyzer:** resizable policy drill-down sheet + full-row expand
- **Policy Analyzer:** scope FMC findings by access policy (FTD cluster)
- **Policy Analyzer:** server-side filter/sort/pagination + AdvancedFilterBar (all tabs)
- **Policy Analyzer:** sigma.js graph visualization (ACI + firewalls)
- **Policy Analyzer:** split anomalies into actionable vs advisory
- **Policy Analyzer:** Tier-2 exact effective-space engine (union coverage)
- **Policy Analyzer:** triage + group relational anomalies
- **Policy Analyzer:** vendor-native config candidates + reachability diff
- **Policy Analyzer:** YAML policy-as-code compliance packs
- **Policy Analyzer:** zone rating + per-rule risk scorer (pure)
- **Policy Analyzer:** zone rating storage + risk endpoint + zone discovery
- **Policy Analyzer:** zone-aware compliance (CDE least-privilege checks)
- **Policy Analyzer:** zone-pair baseline matrix + segregation check
- **Policy Analyzer:** zone-pair segregation matrix (AlgoSec-style)
- **Policy Graph:** contracts (ACI) / rules (firewall) as clickable nodes
- **Policy Graph:** node click opens a policy-analysis panel
- **Policy Graph:** searchable, contract-first node panel with filter-&gt;entry drill-down
- **Policy Graph:** unify the ACI + firewall graph palette
- **UI:** animate role-permission group collapse + wider role/user dialogs
- **UI:** show read-only provenance in the Edit memory dialog

## Bug Fixes

- **Apic Ui:** badge single-row means per-badge, not per-cell
- **Cisco ACI:** stop tenant-switch render loop on filtered tabs
- **Cisco ACI:** use a space (not a literal NUL) as the filter-key separator
- **Ci:** regenerate frontend lockfile in linux node:22
- **Filters:** add not_contains operator + enum-first operator ordering
- **Filters:** honest fallback operators for operator-less fields
- **Filters:** preserve operators through per-field URL round-trip + browser e2e (#982 #983)
- **Palo Alto:** attribute clone+rename rules + surface admin source IP
- **Policy Analyzer:** ACI per-filter deny + vzAny relations (fidelity review)
- **Policy Analyzer:** conform page to platform design system
- **Policy Analyzer:** correlation requires shared App-ID / URL-category scope
- **Policy Analyzer:** embed finding rule cards server-side
- **Policy Analyzer:** graph renders — aggregate parallel contract edges
- **Policy Analyzer:** make the device selector a single direct dropdown
- **Policy Analyzer:** soundness fixes from high-effort code review
- **Policy Analyzer:** vendor selector as a dropdown, not a segmented control
- **Policy Analyzer:** zero_hit uses Palo native last_hit, not first-capture
- **Policy Analyzer:** zones are a match dimension in shadowing analysis
- **Policy Graph:** firewall graph crash on parallel zone edges (zone:any-&gt;zone:any)
- **UI:** header leading icons only on Panels-section pages
- **UI:** make the whole pending-review bar clickable
