September 2026
Reports become canvases, sanda search, the modelling layer, the OData feed, cherry across the console, three editions and the reports portal.
28 to 30 September
Documentation
- docs.sanda-os.com.au is open: guides for every part of sanda, a page for each connector, and the MCP and OData references.
- Every console page has a Docs link in the top bar that opens the guide to that page. The product page links each chapter to its guide, the pricing page links the billing guide, and the site footer has a Docs column.
Plans and billing
- Owners and admins move between Basic and Standard themselves: Move to Standard or Move to Basic in Settings · Plan & budget, then confirm. The new edition's features and limits apply at once. A move up bills Standard's fee for the month you moved in, and a move down bills Basic's from the next month. A move to Basic waits until the workspace fits it, and the message says what to delete or trim. Leaving a trial, Enterprise and agreed fees are still asked for. See editions.
- A change of edition now applies the new edition's query and connection limits to every warehouse straight away, not at the warehouse's next measurement.
- sanda search holds an index to your edition's row limit when an agent points it at a different table, and counts a view that has no row estimate instead of passing it on a sample.
- Enterprise adds up to 10 times faster analytical queries from an in-memory columnar engine, a 99.99% uptime SLA that includes maintenance, read replicas for reports and dashboards, and continuous backup with point-in-time recovery. See editions.
- MCP and agents are included on Basic, so every edition can connect Claude and other assistants. sanda search stays on Standard and Enterprise.
- Standard holds up to 3 warehouses of 100 GB each and 5 search services. A warehouse's compute can burst to 4 vCPU on Basic and 8 on Standard. Enterprise runs on a plane of its own with its own storage and compute rates. See editions.
- A trial now freezes when it reaches its end date, as the terms and the pricing page say, as well as when its credit is spent. The banner, the top bar pill (Trial · ended), the email and every refusal name which of the two it was. A paid edition lifts either.
- Messages that send you to the budget now name its real place, Settings · Plan & budget · Budget & alerts, and the budget emails link straight to it. The Remind me at hint says the suspension notice goes whenever alert emails are on.
- All AI is billed under a daily limit. Every AI call sanda makes on your workspace's data counts against it, including sanda's own learning work and calls from console buttons and from MCP. Owners and admins set the limit in the Daily AI limit field under Settings · Plan & budget, up to a ceiling. sanda support can set a higher one on request. The top bar meter shows today's spend, and its card explains what counts and shows the month.
- A trial is A$10 of free credit. Everything an invoice would meter since signup draws it down at the invoice's own prices, and nothing is billed. When the credit is spent, the workspace freezes: every warehouse is suspended and sanda makes no AI calls for it. Your data, connections and reports are kept. See trial.
- The AI meter updates while a reply is running, and a reply's cost chip shows the billed amount rather than the supplier's, learning passes included.
Workspace and security
- An expired sign-in link says so and asks for a new one. If you asked for the link from the same browser, your address is already filled in, so one press of Email me a sign-in link sends it.
- The console's left rail names your role as Settings · Team does ("Read-only", not "viewer"), and the Admin hint lists everything that stays with the owner.
- Region copy says what is true today: every workspace runs in Australia (Sydney).
- Owners can delete a workspace immediately. Delete workspace now in Settings · Close or delete asks for the workspace's short name, then closes the workspace and deletes its warehouse databases, its sync connections and its data. Anyone whose only workspace it was is removed too, so their address can sign up again. You land on signup, or on sign-in if your address belongs to another workspace.
- Fixed: deleting a workspace failed if it had ever accepted the terms or been invoiced. Deleting now works, and sanda rehearses every delete before it removes anything.
- Signup is one short form: name, work email, company, an optional role, the terms box and Start free trial. It no longer asks about your systems. The console asks when it matters.
- The privacy policy and terms are rebuilt from an audit of what sanda does, including exactly what is sent to AI models. A closed workspace stays read-only for 90 days before deletion, up from 30, and the governing law moves from New South Wales to Victoria.
- Settings · Team can invite a Reader, who sees the reports portal and nothing else.
cherry
- Setup is warehouse first. A checklist reads the workspace as five steps in order: a warehouse, a source, learn from my data, review the suggestions and a first report. A CSV loaded into the warehouse counts as a source, and the source step is done once rows have landed, not when a connection exists. A first sync that has not started, is running, failed or finished empty says so, with a link to the connection.
- Setup runs one step per press. Nothing runs by itself: a first sync lands tables and stops, and learn counts as done only after a pass has run. cherry does not chain steps or move you to another page beside a checklist that already offers the button. It no longer opens with a recap or a correction of an earlier reply.
- The first report step asks for a name and a purpose, then builds a whole report: KPIs, trends, breakdowns and an analysis.
- Learn from my data in the checklist takes you to the semantic fluid first, with cherry beside it, so you watch the pass land on the map. Once suggestions are accepted, cherry offers to tidy the map, and the map highlights its arrange button with a tip when relationships appear.
- The conversation docks beside the page it opens instead of disappearing mid-reply. When the checklist scrolls out of view, a compact pinned copy sits at the top of the thread. You can unpin it.
- Fixed: the text cursor in the Overview's question box was clipped by the box's rounded corner.
- Fixed: after Learn from my data, every question over the learned tables was refused with "permission denied for schema raw". Learn now publishes each table it proposes before writing the proposal, and a map already written on landing tables moves onto its published views the next time it is read.
Connections
- Replace on a loaded CSV works when something is built on the table. sanda swaps the rows in place, so your views keep working, and rebuilds the semantic map's own view when the new file drops or retypes a column it reads. If one of your own views reads such a column, the load is refused and names the view. See load a CSV.
- Next sync is written in the schedule's own time zone, which the line under it names, so it agrees with the schedule wherever you open the page.
- Only owners and admins can add a connection, as only they can register, run or delete one.
- Zuora and BigCommerce are offered by arrangement: their connectors are no longer maintained. Connector notes no longer mention controls sanda does not have.
- A running sync says how far it has got and how fast. The Status tab shows rows this run, rows per second, data this run and running time. A queued run reads "Queued for 3s · waiting for the sync engine", and the page checks as soon as it opens. When a run settles, a note says how it ended, such as "Sync finished: 1,990,700 rows in 6m 33s". Every successful run in the Timeline shows its average rows per second. A syncing row in the Connections list shows rows so far and rows per second, and cherry and MCP report the same progress.
- A sync reads as a run: queued, launching the connector, syncing each stream, landed. Fixed: a running sync showed 0 rows and 0 B for minutes before jumping to its final count.
MCP and OData
- The consent screen says what the grant you are giving can do. It says "can write nothing" only when no ticked permission writes, and it names each write permission you tick. It points to Settings · Integrations to disconnect.
- The workspace brief and context resources need the fluid:read permission, like the tools that read the fluid. A connection without it is listed no resources.
- Approval requests are emailed to every owner and admin, since either can decide them, and follow the workspace's alert email switch.
- The OData feed declares
timecolumns as a time of day, andintervalandmoneycolumns as text, so they arrive with their values instead of empty. See OData reference.
Semantic fluid
- Fixed: editing a metric in the metrics panel, or renaming one that others refer to, reset its Shown as to a plain number. Every field the panel does not show now keeps its value.
- The list view's forms fill in from what is stored. The pencil on a row opens its current values, and typing a name that already exists does the same, so re-saving a table no longer blanks its grain, key, event time and notes or resets its row count. The bin on a table retires it, as removing it from the map does, instead of deleting it.
- A new metric's or category's name keeps a hyphen you type:
on-time delivery %stayson-time delivery %. - A metric built from metrics on other tables is refused by name in the workbench and
run_query, instead of running against one table. The metrics panel's examples and Insert chips offer only metrics on the same table. - Learn from one connection reads that connection's own tables, so a small connection beside a large one is no longer told nothing has landed.
- Fixed: the Ask the fluid card slid over the top bar as you scrolled, and its lists handed the scroll wheel to the page at their ends.
sanda search
- The consent screen says plainly what is sent to be embedded: the text of the columns a service indexes, and the text of every search. Owners who agreed to the earlier wording will be asked to read the new one.
- The personal details warning looks only at the columns that are sent, and suggests keeping such a column as a filter.
- A table only suggested for the semantic map, or retired from it, can no longer be a service's source. The picker offers the tables the map draws.
Warehouse and modelling
- Columns such as
passenger_countorcompass_headingare no longer withheld as secrets: sanda matches the words in a column's name, not letters inside them. - Dropping a view that another view reads is refused before anything changes, so the view stays on the semantic fluid.
- The visual builder can draw on tables in
mapping. - The compute limit hint says what happens at the limit: sanda narrows queries and pauses loading, and the hours used are billed.
- Pipeline copy says task and step, as the console does, instead of graph.
Reports portal
- The reports portal launches for the people a workspace builds reports for. They sign in, see the reports published to them, open one as a page and ask cherry about the numbers. They never see the console. See reports portal.
- An owner or admin publishes from a Publish pane on the report canvas, to everyone or to chosen people, with a group and an optional featured flag. Later canvas edits stay on the canvas until someone presses Update, and the pane says when a report has changed since it was published and how many people have read it.
- A reader can be given data rules: a field and the values that reader may see. Rules apply to every portal query, both report blocks and cherry's answers, and cannot be replaced by a report's own filters. A block that cannot reach a rule's field is refused, never shown whole. Portal cherry can search the fluid, describe tables and run queries, and nothing else. An owner or admin can view the portal as any member.
- The Reports page in the console has two tabs, Reports and Portal. The Portal tab sets the portal's name and welcome text, whether it is open, whether cherry is on, what a reader with no rules sees, the order of published reports and each reader's rules.
- The portal home opens with a greeting, your workspace's welcome text and a box for cherry with first questions as chips, with the report library underneath. Asking takes you to a full page with your conversations down the left, and a Conversations link in the top bar returns to the list. On a phone the list is a drawer. A published report fills the page and sits centred, with a zoom bar for zooming out, zooming in, returning to the width and fitting the whole report on screen.
Reports
- A kpi's comparison with the previous period shows on shared links and the reports portal, as it does on the canvas.
- A metric's Shown as and Unit decide how its figures read on kpi, bar and line blocks, everywhere a report goes, the email included.
- An Excel download keeps hidden sheet columns as hidden columns, so formulas that read them stay live.
- A formula is refused, with the reason, past 500 characters, and the formula button says so when a sheet already holds 12.
- A logo over 146 KB is refused with its size. Changing a theme's preset keeps the logo.
- Read-only members are no longer offered Duplicate, new report from this, or save as template.
- cherry can change a report that already exists. It can find a report, read its filters and blocks, set report-wide filters, change blocks in place and remove blocks. "Last 7 days" becomes one filter that every block runs with, including blocks added later. Before saving, sanda checks each chart against the fluid with the filters applied. If any block could not run, nothing changes and that block is named. On an open report the change arrives live as one edit you can undo, and any other report is saved as a new version.
- The report toolbar sits in its own row above the board instead of floating over blocks, and every control has the same size and border.
24 and 25 September
Workspace and security
- Emailed sign-in links now need a click. Opening a link shows a button on the sign-in page, and you are signed in when you press it. This stops mail scanners spending your link and closes a cross-site sign-in trick.
- A session ends after 14 days unused. Settings lists your sessions, with Sign out everywhere else.
- Two-step sign-in works with an authenticator app and comes with recovery codes. An owner can require it for the whole workspace. See workspace security.
- Workspace credentials are one list. Owners and admins can revoke any credential, and an owner can hand the workspace to an admin.
- An approval queue for risky agent actions is available and is off by default.
- Invitations no longer reveal whether an address already has a workspace. Pages shared by link return rows only, never SQL or database errors. Some actions that any member could take are now for owners and admins: the SQL preview in the view builder, and creating a schedule that emails a private report to any address.
- Fixed: a single question could spend about twice the daily AI limit, because the limit was compared in the wrong currency.
- Fixed: after signing in, sanda now goes to the page you were heading for, so approving Claude's connection survives the sign-in.
- Pages load faster. The first download is about a third of its former size.
Reports
- A delivered report email is drawn like the canvas: a masthead, then each block in its place, in your report's colours. KPI cards show the change on the previous period, tables keep their sheet formatting, and on phones the blocks stack. Each email attaches the report as a PDF and a PNG. If the files would make the message too large, sanda leaves the PNG off first, then the PDF.
- Reports can also be delivered to Slack or to a webhook, and you can limit recipients to your own email domains. Delivery schedules keep their local time across daylight saving changes.
- Fixed: a delivery that failed to start stayed queued for ever, and blocks with the same id could reuse each other's results.
- Fixed in sheets:
=now works on warehouse numbers,ROUNDmatches Excel, and a CSV export can no longer run a synced value as a formula. - Fixed: filter chips showed the UTC date instead of yours. The hourly schedule now shows its next run.
Semantic fluid
- Wipe clears the semantic fluid (tables, datasets, metrics, relationships, suggestions and the map layout) so a workspace can start fresh. It is for owners and admins, behind a typed confirmation, in a danger zone at the bottom of the page. It is a hard delete, so re-adding a table does not bring back its old name.
- Accept all on suggestions is faster. It accepts six at a time, and a failure puts back only the rows that were refused.
Modelling
- The modelling assistant always drafts. It takes the most reasonable reading of your columns, states its assumptions, and asks any follow-up question alongside the code instead of in place of it. It can switch a new view between a view and a materialized view when you ask.
Connections
- Fixed: once a table was on the semantic fluid, a sync could fail on its next run with an error about dependent objects. sanda now lands each stream so that views on the fluid survive a full refresh and a schema change. Check status repairs any view still reading the sync engine's own tables, says what it found, and restarts the run when it removes the cause. A connection page shows which views still read those tables, and a repair that cannot run says why instead of failing silently.
- Connector forms show only the fields that need an answer up front. PostgreSQL asks for host, database, username and password, and the update method defaults to a user-defined cursor, because change data capture needs a replication slot and a publication in your database. See connections.
- The stream picker offers the five sync modes and defaults new streams to Full refresh · Overwrite. It shows a cursor and primary key only where the mode uses them, will not save a stream that is missing a required one, and has a bar that sets the mode, cursor or key on every visible stream at once. Streams saved with the older values keep syncing exactly as before.
cherry
- cherry arrives as one data agent across the console. It is a pane docked on every page (⌘ J or the top bar toggle), a full page at cherry chat, and a thread that follows you around. In one thread you can ask a question of your data, define a relationship, build a view, create a report and be walked through setting up the workspace. See cherry.
- Threads can be pinned, renamed, archived, deleted and searched. Chat fills the window, shows your question straight away with a typing indicator, and draws tables and charts in replies.
- Settings · cherry chooses how cherry acts. In Ask first, each change appears as a card with its SQL and a 50 row preview for you to Confirm or Decline. In Autonomous, changes run at once. Dropping a view, retiring a table and deleting a definition always ask. The same section has a model library (up to five models on at a time, with a default), permissions per capability, and memory.
- A reply shows all of cherry's words, with the steps between them as one quiet line saying what they were, how many and how long. The Overview opens on cherry.
- cherry and MCP can schedule and send reports. Six MCP tools list, create, change, send, pause and delete deliveries, behind a new privileged permission. They are email only, for owners and admins, and follow the workspace's recipient domains and the schedule grid. A delivery given a timezone keeps its local time across daylight saving.
- Ask cherry to learn reads one source at a time with progress in the step label, runs one relationship pass over the whole map, keeps the full result as a card in the thread, then refreshes the map and opens the suggestions. It draws the joins your learning dataset declares, considers the whole map rather than only the tables it just proposed, profiles map tables it missed, and never proposes a join you rejected.
- Several changes of one kind show as one grouped card, with Confirm all and Decline all. The active thread survives closing the pane and reloading, and the pane header has a labelled new chat button.
- All cherry usage counts against your daily AI limit. The allowance card lists today's spend by model.
Plans and billing
- sanda now sells three editions: Basic, Standard and Enterprise. They bill storage and compute at the same rates and differ in fee, room and features. MCP and agents and sanda search are not part of Basic, and included support is part of Enterprise. Enterprise is Talk to us: its pricing card opens the enquiry form. A trial has every feature and is priced and limited as Standard. Prices and limits are on editions.
- Every feature stays in the navigation, tagged with the edition that has it. A page your edition does not include says so and links to Settings · Plan & budget and to the pricing page. Settings shows the fee as it will bill and all three editions, and an owner can ask to move, which files a support ticket. A warehouse above its edition's storage limit pauses loading until it is back under, and a workspace above its search service limit keeps its services but cannot add more.
- Faults and billing questions are supported at no charge on every edition. How-to help is included on Enterprise and billed by the hour below it.
- Each pricing card lists only what its edition includes.
- Fixed: compute readings taken close together were ignored, so an active workspace read "not metered" and its compute was missing from invoices. Every reading now gets a rate.
- Fixed: deleting a warehouse and provisioning a new one made the Overview read $0.00 for the month, and dropped the deleted warehouse's month from billing. That usage is kept, and the card is now Account usage and spend, which sums every warehouse including deleted ones.
- Tax invoices carry a validated ABN and have an A4 print layout. Draft and void invoices are no longer emailed.
21 to 23 September
Reports
- You can build a block by hand. A drawn box asks which door first. pick from the fluid opens a builder pane on the right with the fluid browser, aggregate and grain pickers and a condition builder, and the drawn box previews the result live. sanda suggests the mark and title from your selection: one measure becomes a KPI, a measure over time becomes a line, otherwise a bar, and no measure a table. ask cherry keeps the sentence box, with written analysis, a visual or "cherry decides" as chips. Edit a chart later from its toolbar's edit.
- Fixed: reports and KPIs could not be built in a workspace whose fluid had tables but no connection, such as uploaded or hand-added tables. It said there was no data behind it. The map now decides whether there is data.
- Date filters gain last 3 months and last 6 months, which resolve to whole calendar months ending with the previous month.
- You can deliver a report by email on a schedule. Choose the report, the recipients, a cadence and a closing note, then send now, pause or remove it from the Report schedules page. A KPI in the email shows the figure, the change on the previous period and its distance from any target.
- A KPI or line block can hold a target. A KPI states the gap in words, and a line draws a dashed rule. The target appears on shared pages and in delivered emails, in neutral terms: a distance and a direction, never a colour.
Pipeline
- Monitor · Pipeline puts every stage's timing on one canvas, in four columns: Sync, Transform, Fluid and Deliver. A wire is drawn only where a real link exists, such as a task that runs after a sync or a delivery that reads the fluid. Press a card to open an inspector with the same schedule picker everywhere: sync time and Sync now for a connection, schedule, run-after-sync, Run now and Pause for a task, and cadence and recipients for a delivery. A next 24 hours list shows every upcoming run. The Sync times and Report schedules entries leave the navigation, and tasks now sit inside Modelling.
Semantic fluid
- Learn from my data draws the joins your schema declares, then finds more by checking that the values on one side exist on the other. The table picker now infers joins from column names, as MCP imports already did, and no longer stores the first id-looking column as the key of every table, which was wrong for bridge tables.
- Fixed: Learn from my data returned nothing when a workspace held both the learning dataset and its own tables of the same shape. It now compares only against your active model.
Plans and billing
- A budget is a ceiling. When the month's metered spend reaches the budget you set under Settings · Plan & budget, sanda suspends every warehouse in the workspace. Nothing can be queried, loaded, rebuilt or indexed, by the console, by agents over MCP, by the OData feed or by syncs. Your data is kept. The suspension never lifts on its own: an owner or admin resumes it once spend is back under the budget or the budget has been raised or removed.
- Prices, invoices, budgets and allowances are in Australian dollars.
Workspace and security
- Everyone who signs in to the console reads and accepts the current privacy policy before anything else. It is shown once per person, and again whenever the policy changes. Machine credentials are not asked.
MCP and agents
- An owner or admin can open a table for intake, and an agent with the intake permission can then append rows to that table, but never create one. Settings has an Intake tables panel with a close button. Members, viewers included, can grant this permission, because its reach is only the tables the owner has opened.
definecan now set a table's grain, primary key, time column, description and kind over MCP, and rename it.
14 to 17 September
Site
- The public site is redesigned around the semantic fluid, sanda search and MCP. The homepage leads with the business problems they solve, and a new product page walks through sanda with interactive samples that are labelled as illustrations. Pricing, signup, sign-in, terms, privacy and the not-found page share the new look. Signup checks each step as you go and works with the keyboard.
Console
- The console gets the same design, with grouped navigation, a drawer on phones and section navigation in Settings. Semantic fluid, sanda search and Agents sit together under Intelligence. The report toolbar works on narrow screens.
- The Search your data link in the top bar is gone. sanda search stays under Intelligence.
sanda search
- sanda search is rebuilt around finding records. Pick an index, ask in the query box, add typed filters, read results as cards and open a full record. Index settings and build logs move to their own tabs, which keep your current query. Creating an index needs a current cost estimate, and changing a field that affects price discards it.
Semantic fluid
- Fixed: Learn from my data could propose nothing and reject all of its own suggestions as "must be fully qualified". Its results also no longer stretch the page header.
- Fixed: one column could get two dimensions, such as
customer_countrybesidecustomer country. Names now treat underscores like spaces, a second dimension on a column that already has one is refused with the existing name, and existing duplicates are merged with the old names kept as synonyms.
Connections
- Fixed: a connection set to sync at 7:00 AM ran every morning while sanda kept saying "Last sync 11h ago". sanda now sees runs the sync engine starts on its own schedule.
- Fixed: a run could appear two or three times in a connection's Timeline under one job number, and a failed run showed no reason. Each run appears once, and a failure shows its reason, or says plainly that none was given.
Workspace and security
- From Settings · Team, owners and admins invite people as an admin or a read-only member, change roles and remove people. An invitation opens a join page in the workspace that sent it. One address belongs to one workspace, nobody edits their own role, an admin cannot change an owner, and the last owner stays. See workspace.
- Owners can close a workspace by typing its short name under Settings · Close or delete. The workspace goes read-only, for the console and for agents over MCP, and a banner shows the date it will be deleted. The owner can reopen it until then. The closed period is 30 days at this point and is extended on 29 September.
Warehouse
- The SQL shell lets owners and admins run one SQL statement at a time against a warehouse. It is read-only by default, enforced by a read-only transaction. In read-write mode each statement commits at once, and the page says so. Results are capped, statements stop at your account's time limit, every statement is recorded, and the page opens on a warning you must acknowledge.
Reports
- A table block is a sheet. You can add formula columns in Excel's own language (
[net revenue]is this row, and the same reference insideSUMorAVERAGEis the whole column), set a format per column, and add a totals row, a sort and hidden columns. A sheet stores instructions, never rows, so a margin column defined in June is a margin column in July. Exports to Excel keep the formulas live. Cells cannot be overtyped, so every figure stays traceable to the semantic fluid. - A report can be private, visible to its author, owners and admins and the people you name, with edit rights if you choose. It can also be shared by link with people who have no sanda account. A link can expire, can be revoked and counts its opens. It opens a page rather than a canvas, and a visitor can sort and export a table but cannot ask for anything the author did not put on the page. See reports.
OData
- The OData feed lets Excel, Power BI and Power Query Online connect to the semantic fluid without installing anything. Columns arrive under your names, metrics arrive already calculated, and you refresh instead of exporting. Each refresh is a live warehouse read, billed like any other question. See OData.
- The credential is now an integration token, and the Settings panel is Integrations rather than Agents, because Excel can hold one too. Tokens you already hold keep working. The panel lists the Excel steps: choose Basic, leave the user name empty and paste the token as the password.
MCP and agents
- Fixed:
define,set_table_kindandretire_tablescould act on the wrong copy of a table when the learning dataset was present, ending in "can't tell which table sales is measured on". They now resolve names through your active model, so whatdescribe_tableshows is what they can write to. Answers come back sorted, and table and column names match without regard to case. execute_sqllets an agent run a SQL statement in your warehouse under a new privileged permission. It reads landed tables and your own modelling layer and writes only to your own modelling layer, with the same row cap, time limit and audit record as the SQL shell, plus the reason the agent gave.
9 to 13 September
sanda search
- sanda search launches. Point a service at one table on the semantic map, choose a key column and the text columns worth searching, and sanda keeps an index that finds rows by meaning and by exact words. A query returns the keys of matching rows, and you can use those keys as a filter on a metric. The index refreshes after the sync that feeds it. See sanda search.
- Search is off until an owner accepts a data-processing permission, because the text of the columns you index is processed outside Australia to create search vectors. Withdrawing the permission pauses your services, cancels queued builds and drops queries to exact words.
- Indexing is metered like other AI use. sanda shows an estimate before you create a service, and pauses indexing before your daily AI limit is spent so you can still ask questions.
- Fixed: creating, estimating and editing a search service failed with an internal error.
- A queued build shows when it will start, and Run now indexes the next slice straight away.
- Results say why a row is in the answer: meaning, words, or meaning + words. This replaces a number that looked like a confidence score but was only a rank. When no row contains your words, the page says the results are the nearest by meaning alone.
- The build panel says what a build is doing. It reads "Indexing now" only while a slice runs, otherwise "Part way through, not running" or "Waiting to start", with progress such as "640 of ~3,000". A build that runs out of time names the step the warehouse was too slow on.
- Large tables finish. A table too big for one pass used to cycle between queued and running without end. sanda now keeps the embeddings it has already computed and carries on from where it stopped. Requests run in parallel and in larger batches, so big tables index several times faster.
- Fixed: a search build against an unreachable warehouse failed with an unhelpful message. Connecting to a warehouse now has a time limit, and the build names what failed.
Modelling
- Schedules, tasks and search builds run on a grid so that sanda's scheduler can rest between ticks. The grid is 30 minutes from 9 September and 15 minutes from 13 September, and it applies to connection sync schedules too. A time off the grid is not accepted, the time picker only offers legal times, and queued work says when it will start.
Warehouse
- The learning dataset is rebuilt every night over a rolling ten-year window that ends today, so its newest orders are never months old.
MCP and agents
- MCP tools let an agent create, query and manage search indexes and start a build. See MCP.
- Intelligence · Agents shows whether your MCP setup is working. Harness lists the four things that must be true before an agent can do anything, each linking to the page that fixes it. Agents lists each token and connected app with what it may do and when it was last used. Activity shows sessions, the call feed, refusal rates per tool, and what sanda refused outright.
Workspace and security
- Signup asks you to accept the terms and privacy policy with an unticked box, and signup is refused without it. sanda records which dated version you were shown, and when.
Plans and billing
- Fixed: the pricing page could quote a fee that differed from what invoices use. The page now shows the price sanda bills.
Site
- A new Why sanda page explains, first in plain terms and then in technical detail, how sanda compares with a conventional cloud data warehouse. A chapter rail keeps your place on a wide screen.
7 and 8 September
Plans and billing
- Storage and compute prices changed. Compute bills at the warehouse's minimum size for every minute it is awake, plus the work it does on top, instead of at its ceiling. A warehouse that idles no longer pays as though it were busy. Current prices are on editions.
- The estimator on the pricing page prices what the meter bills: the storage you hold and the compute hours your team's questions are expected to use. It shows one figure instead of a range, and the number of people asking questions drives the compute estimate.
Warehouse
- Data · Explorer opens the warehouse like a database console. One tree lists each warehouse, its schemas, tables and views with row estimates. Choose a table or view to see its columns, a preview of its first 50 rows and, for a view, its definition. The explorer is read-only and open to every member.
- Optimise reads what is slowing a warehouse down or costing it storage, and offers fixes you choose: indexes your relationships would use, unused or duplicate indexes, indexes left broken by a cancelled build, and vacuum and analyse. sanda shows each statement before it runs, and reading the advice uses none of your AI limit. It never runs a full vacuum by default, because that locks the table while it rewrites. Partitioning is advice only. See warehouse.
Modelling
- A new Modelling section under Data builds your own layer on top of landed data: views, materialized views and procedures, with schedules that rebuild and run them. Draw a view in the drag-and-drop builder, using your warehouse's tables and joins suggested from the relationships you have drawn, or write the SQL. Each object shows what it affects: the fluid table it is published as, the objects that read it and the schedules that rebuild it. New views publish to the semantic fluid by default. See modelling.
- Save as view in Ask the fluid turns your current selection into a view or a materialized view and publishes it.
- Tables you have modelled lead in the semantic fluid, and chat is told to prefer them where they can answer the question.
- Every rebuild is measured and billed as compute. A scheduled run that fails emails owners, at most once a day for each task, and alert settings have a switch for it.
- Fixed: the view builder listed the tables of the wrong warehouse, or none, and said "Nothing has landed in this warehouse yet" when tables were there. It lists the tables of the warehouse you select, and a warehouse selector always shows.
MCP and agents
- Eleven MCP tools let an agent create and refresh views, create and call procedures, and create, run and pause schedules, behind a new permission. Three more list a warehouse's sources and read and apply its optimisation advice.
4 to 6 September
MCP and agents
- Agents can hold a token. Under Settings you mint a token that lets Claude Code, the Claude API's MCP connector or your own agents work with the semantic fluid over MCP. A token is shown once, and it stops working when the person who made it leaves the workspace.
- sanda is now its own sign-in server for MCP, so a person can add it as a custom connector in Claude and approve access on a consent screen. Connected apps are listed under Settings, each with a Disconnect button.
- Fixed: adding sanda to Claude failed with "Couldn't register with sanda's sign-in service".
- Fixed: Claude's consent screen offered a single permission. It now lists every permission, and the ones that reach beyond asking questions start unticked.
- Twelve more MCP tools let an agent change the semantic fluid (import tables, define metrics and relationships, review suggestions), see the workspace (connections, sync status, warehouses, never a credential or connection string) and start a sync. Each sits behind its own permission, and a tool you have not granted is not listed. Definitions an agent writes go live at once, so only an owner or admin can grant that permission.
load_rowslets an agent land its own table of rows in your warehouse, by replacing or appending, with types inferred or declared, and optionally put it on the semantic map in the same call. It sits behind its own privileged permission and respects your storage limit.
Semantic fluid
- An arrange button lays every table out by how they join, with the most-joined table in the middle and dimensions at the edge. The fact or dimension badge on a card is now a one-click switch, and dragging near the edge of the map pans it.
- A metric you describe to sanda can be saved as a metric straight away, instead of only as a proposal you then review.
- Fixed: dragging one column onto another could draw extra relationships when several columns shared a key. sanda now warns when the key you type already sits on other columns, and before an unlink would take other relationships with it.
- Fixed: a table you removed from the map could not be added back. Tables in the picker are compared against your active model only, and groups collapse and show how many of their tables are on the map.
Workspace and security
- The guard in front of free-form SQL now refuses more ways of hiding a second statement, and every response carries browser security headers, so another site cannot frame the console.
- Signup no longer reveals whether an email address already has an account.
Plans and billing
- Usage is the bill. Storage is billed on the gigabyte-months you hold and compute on the hours you run. Nothing is bought in advance, so the storage plan ladder is gone from the pricing page and from Settings. Editions set limits (warehouses, storage and compute per warehouse, and features), not a different price for the same storage. Current prices are on editions.
- Compute is billed by the compute hour, which is one vCPU running queries for an hour. The Overview shows a month of usage as three charts that share a cursor (storage, compute and accrued cost) in place of two meters.
- Fixed: compute was not being metered on any warehouse, so the Overview read "not metered" and compute did not appear on invoices. Compute is now metered per warehouse.
- The sizing calculator becomes the pricing page. It has an enquiry form for Enterprise and for sizing questions. Fixed: Email me this estimate never sent an email. It does now.
1 to 3 September
Reports
- Reports become canvases. A report is now a pan-and-zoom page of blocks: KPI tiles, bar and line charts, tables and written analysis. Draw a box on empty space and describe what you want in it, or ask cherry for a whole pack ("Build a June board pack: P&L vs budget, cash, top debtors"). Blocks drag by their header, resize from a corner, snap to a grid, and can be redrawn as a KPI, bar, line or table. A block stores the question rather than the rows, so next month's report shows next month's numbers. See reports.
- Blocks appear as they are placed, while cherry is still working, and you can draw several boxes at once. When a request could mean two things, cherry asks with buttons instead of guessing.
- A filters pane applies conditions to every block on a report. Add one by writing a sentence or with the condition builder. Named periods such as last 12 months stay unresolved, so they move with the calendar.
- A selected chart gets a grain picker (day, week, month, quarter or year). Bar charts show as many bars as the block's height allows and say what they left out.
- Fixed: a chart of sales by month showed one row per day.
- The canvas is drawn as a white page on a darker desk, and the view is held so the page can never scroll out of sight.
- Report colours in Settings · Appearance sets the accent and status colours every report uses, from eight presets or your own. A single report can override them from its toolbar.
- You can delete a report from the list or the canvas, duplicate it, and save it as a template. Templates sit in their own list with new report from this.
- Recent versions of a report are kept, and you can restore one from a history menu. Undo and redo work as you expect (⌘ Z).
- Reports print to PDF with export pdf in the more menu. A header block carries your logo, the report's name and a subtitle. You can leave comments on any block, refresh one block or all of them, and click a bar to filter the whole report by that category.
- A generated board pack lands in tidy bands across the page, and new blocks come in sizes that tile it: four KPI tiles fill a row.
Connections
- Each stream in a connection's list has its own live status (queued, syncing, in or failed) and the rows it has read so far. The columns stay lined up however long a table name is.
- Fixed: for a short time on 3 September sanda could not reach its sync engine, so syncs could not start. Syncing is restored.
Semantic fluid
- Fixed: choosing a metric and a dimension that are joined through a table you did not pick, such as revenue by an employee's job title by way of orders, failed with "no stated relationship". sanda now finds the shortest route through the relationships you have drawn and joins the tables along it.
- Learn from my data says why it dropped a proposal, and shows the model's own notes and unanswered questions, such as "which currency are these amounts in". It runs one pass per connection, so each source gets the whole table budget.
Workspace and security
- Password sign-in is removed, and you sign in with an emailed link. When sanda cannot send email, the sign-in page says so instead of promising an inbox.
- Fixed: Settings showed a blank page in some workspaces.
Site
- Every page on the site has its own title and description, the site publishes a sitemap, and an address that does not exist now returns a proper "not found" page.
Something unclear or out of date? Tell us, and we will fix the page.