> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/april-2023.md).

# April 2023

This section describes the main features of the Cortex XSOAR 8.2 release.

## Feature enhancements

The Cortex XSOAR 8.2 release includes the following enhancements:

| Feature                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cortex XSOAR Multi-Tenant            | <p>XSOAR 8 now offers Cortex XSOAR Multi-Tenant, which is designed for managed security service providers and enterprises that require strict data segregation with the flexibility to share and manage critical security practices across tenant accounts.</p><p>You can centrally manage resources and reporting from the main account, push custom content to one or more tenants, search across incidents, and run commands across multiple tenants, without exposing any data across tenants.</p><p>To use Cortex XSOAR Multi-Tenant, you need to create a main tenant and child tenant from the Cortex Gateway. In the Gateway, you can create, delete, and manage child tenants.</p><p>For more information, see <a href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Multi-Tenant-Guide/Introduction-to-Cortex-XSOAR-Multi-Tenant">Introduction to Cortex XSOAR Multi-Tenant</a>.</p>                                                                                                                                                                                                                                       |
| Role Permissions                     | <p>Role permissions have been updated to separate some of the administration permissions. In the Settings section you can now do the following:</p><ul><li>Integrations: Limits permissions for adding, editing or deleting instances and integrations, pre-process rules, classifying and mapping incidents and indicators.</li><li>Integration Permissions: Limit permissions in the Integration Permissions page.</li><li>Objects Setup: Limits permissions to edit or view fields, types and layouts in indicators, incidents and Threat Intel Reports.</li><li>Administration: Limits permissions for server configurations, and audit trails.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Automations Page                     | The Automations page has been renamed Scripts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| War Room Filters                     | You can now filter by tags in the War Room.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Marketplace                          | You can now subscribe to content pack updates in Marketplace.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Login Messages                       | You can now display a custom message to users before every login to Cortex XSOAR.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Indicator/Incident fields            | You can now choose to wrap the label text for incident and indicator fields when displayed in a layout. When creating or editing a section of fields, Edit section settings and select Wrap the labels.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Engines                              | A "last seen" timestamp was added to the engines table, which represents the last time the engine connected successfully.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Playbooks                            | <ul><li>Improved UI for Data Collection and Ask tasks in Playbooks.</li><li>Simplified search for playbooks and scripts with free text search.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Management Audit Log Notifications   | You can now forward management audit log notifications to email distribution lists and syslog servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| External Dynamic List Management     | You can now manage EDLs (Settings & Info > Settings > Integrations > External Dynamic List Integrations).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Integration Log Access               | You can now view and export integration log details, including status and error messages (Settings & Info > Settings > Integrations > Integration Log).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Improvements to the Default Playbook | <p>The Default playbook has been improved with the the following capabilities:</p><ul><li>Extracts and enriches indicators in an incident using one or more integrations.</li><li>De-duplicates incidents by linking and closing similar incidents.</li><li>Retrieves related files from endpoints using hash/file path.</li><li>Hunts for occurrences of suspicious files in the organization's endpoints.</li><li>Unzips zipped files, and extracts indicators from them.</li><li>Detonates files and URLs in sandbox integrations.</li><li>Calculates a severity for the incident.</li><li>Allows the analyst to remediate the incident by blocking malicious indicators that were found.</li><li>A new Default layout, which can be associated with any incident type. The layout includes dynamic sections, so it displays dynamic fields for the relevant incident. It has quick remediation action buttons, like isolating endpoints and tagging indicators to allow/block. The layout has a Utilities tab that provides quick access to a vast number of useful automations to help the analyst as well as some references to documentation.</li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2023/april-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
