Skip to main content
Sticky

Skylar Compliance: Inside the 6.0 Preview

  • August 10, 2026
  • 0 replies
  • 13 views

Forum|alt.badge.img

It's been a few weeks since my last update, here's what's changed since then and what's coming next.

We've been working on some significant improvements to the compliance feature, both for existing users looking to reduce day-to-day friction and for anyone who hasn't explored this part of the product yet. These improvements are going into a 6.0 release. Below, you'll find what's included in the preview and what's coming further down the line.

What's in the 6.0 Preview

Rule creation wizard: Replacing the current single-form rule builder with a guided six-step flow, basic information, filters, rule logic, remediation, test data, and review, so you can build and validate a rule before it ever goes live.

Alongside the wizard, a set of quality-of-life improvements aimed at reducing day-to-day friction for existing compliance users:

  • New rule filters: A new step before a rule runs that allows ignoring specific Devices, based on their Assets, Additional Infos, and Labels. e.g. Assign a policy to all Cisco IOS devices, but only run the Rule if the device Firmware matches "IOS-XE".

  • New rule test data: Add test data to a rule to document what should and shouldn't pass. Test from inside the Rule when writing complex Regex or Lua Functions.

  • New rule Phrase and Regex sub-types: Additional options when writing Phrase and Regex based rules that allow entering multiple phrases and passing or failing if one, any, or all of them match.

  • Combined Must & Must Not Match: 'Must Match' and 'Must Not Match' are now both available on Phrase and Regex Rules and can be used individually, or combined.

What's coming next to 6.0

  • Rule library: Define rules once and use them in multiple policies. Each instance is linked to the library rule, and matches any changes made to the library rule.

  • Pre-built policies and rules: Industry standard policies and rules, like CIS Benchmarks and DISA STIGs, will be available as re-usable instances in the library. If you have any policies or rules you want us to consider, please submit via Nexus Ideas Hub and select Idea and product area as Skylar Compliance.

  • Domains on compliance variables: Define a Compliance variable with Domain specific values, and a Global fallback value, allowing you to define a rule once and use it across devices in multiple Domains.

What's coming later to 6.0

Further out, we're also planning a governed approval workflow for auto-remediation, a Compliance Hub for at-a-glance health reporting, improvements to device list filtering and global searches, and expanded device control capabilities, including staged device firmware upload and upgrades, and a reusable function library. Additionally, we're exploring better support for SD-WAN devices like Meraki, and public cloud providers like Azure and AWS, enabling change detection and compliance checks across multi-cloud and hybrid environments.

What the 6.0 Preview means, and breaking API changes

The 6.0 Preview contains a new v3 API, replacing the v2 API that's available currently in 5.6 (see the 5.6 API documentation). Some endpoints already have breaking changes in v3, and any request to the v2 API will be transparently rewritten to the corresponding v3 API in 6.0, but may return errors if your request doesn't fit the new schema.

Breaking changes have already landed on the v3 endpoints tied to the Compliance feature, and we anticipate further changes to the Device, Device Control, Discovery, Global Search, and old Reports endpoints, as well as any endpoint that supports filter parameters, like the Log endpoint.

The new v3 API and the 6.0 Preview application are both fully supported, though the API can still change before 6.0 reaches general availability, and the old v1 API will also be removed by that time. Until then, we'd recommend holding off on building new integrations against the v3 API, and we'll confirm once the API is locked for GA. If your integrations touch any of the endpoints above, or if you use the Skylar Compliance SyncPack in Skylar Automation, we recommend waiting to upgrade your Production appliances; otherwise, it's fine to request an upgrade if you want to try the new features.

How to get access

New trial requests will still use the 5.6 appliance. The 6.0 Preview is available as an opt-in update to your existing appliance, but you'll need to request access from us first. To do so, open a support case and provide the relevant RP serial, and we'll enable the 6.0 upgrade for your appliance.

Recently shipped

  • Lua Functions: A new function type for Device Controls, available for both ad hoc and scheduled commands. Lua Functions let you manually return errors if an output is unexpected, return early using standard Lua syntax, and accept typed variable inputs rather than simple string substitution, giving you clearer feedback when a command fails and a more reliable foundation for device automation. Note: New Lua Applets can no longer be created. Existing ones continue to work, but we recommend migrating to Lua Functions.

  • Better details in compliance violations and reports: File, line number, and line are automatically shown in the Details field for any Phrase or Regex based rule, so you can find the source of a violation faster.

  • Compliance transcripts: Enable transcripts on compliance policies, making it easier to debug unexpected behaviour in rules.

  • Compliance Lua documentation: A new popout accessible directly from the rule editor with markdown formatted documentation and examples.

  • Appliance performance improvements: Appliance performance and UI responsiveness are now improved when using high numbers of agents (300+), and with high frequency backups (like once every hour).

Reminders

  • Plugin requests: If there's a device plugin you need that we don't currently support, you can request a new plugin or an update to an existing one at any time. Providing details upfront, including manufacturer, device OS/model, firmware version, and any relevant vendor documentation, helps our engineering team move faster. For full instructions, visit this page and follow the steps to open an Incident case with Support.

  • Device software upgrades: Plugins that already support software upgrades are listed below. If yours isn't on the list, you can open a support case at any time to request it be added, ideally with a non-production device available for testing.

    • Accedian VCX

    • Accedian Skylight Flex 100

    • Arista EOS - recently added

    • Aruba ArubaOS-CX - recently added

    • Check Point Gaia

    • Check Point VSX

    • Cisco ASA

    • Cisco IOS - now also supports IOS-XE devices in Bundle and Install mode

    • F5 Big IP

    • Fortinet FortiGate

    • HP ProCurve

    • Juniper ScreenOS

    • Palo Alto Firewall

  • Compliance policy and rule ideas: If there's a policy or rule you'd like to see in our pre-built library, or anything else on your compliance wishlist, submit it via the Nexus Ideas Hub, selecting Idea and Skylar Compliance as the product area.

Have questions or something you'd like to discuss? Reply in the thread below, or reach out to your engagement manager or customer success manager.