Skip to main content

Changelog

Updates, changes, and improvements at Retool.

Refer to the stable and edge release notes for detailed information about self-hosted releases.

note

The object permissions feature is currently rolling out to cloud instances. It is not yet available on self-hosted instances.

Retool now supports object roles—a new role type that grants groups Use, Edit, or Own access to specific apps, workflows, resources, and agents. Object roles are separate from organization roles, which control access to admin settings like billing and SSO.

When you create an object role, you set an access level for each object type and choose how the role applies:

  • Universal access—The role applies to all current and future objects of that type across the organization.
  • Individual access—Access is scoped to specific objects or folders, which you define when assigning the role to a group.

Object roles are assigned to groups from the Groups page. Once assigned, all members of the group inherit the role's permissions. You can view a group's or user's full object-level access from the Object permissions tab on their detail page in Settings.

Updates to organization roles

As part of this launch, organization roles have been updated to cleanly separate admin settings access from object-level access. The Create Role button on the Roles & Permissions page is now a dropdown where you choose between creating an object role or an organization role. A filter control on the roles list lets you view all roles, object roles only, or organization roles only.

To get started:

  • Object roles—Understand how object roles work, including universal vs. individual access and folder inheritance.
  • Create an object role—Step-by-step instructions for creating and managing object roles.
  • Organization roles—Updated UI for managing organization roles, including a new role type selector and filter controls on the Roles & Permissions page.
  • Assign roles to groups—Assign object or organization roles to groups.

You can now trigger workflows from functions in the new app builder. Converting classic apps that trigger workflows is now supported as a result.

To trigger a workflow from your app, open the Chat tab and prompt your agent with the workflow's name.

Update my app so that the Customer Feedback table retrieves data using the Retrieve Survey Feedback workflow.
Create a new app that tracks our quarterly sales KPIs. For the data, use the Calculate Conversion Rate workflow as well as the lifetime_value and quota_attainment tables in @Retool Database.

The triggered workflow is run on behalf of the app's authenticated user.

Retool now blocks Microsoft SQL Server resources that use Windows Authentication with custom ODBC connection parameters outside an approved allowlist. Previously, unsupported parameters were logged as warnings but still applied. They now cause resource setup to fail.

Who is affected

Self-hosted deployments using Microsoft SQL Server resources with Connect using Windows Auth enabled and one or more custom entries in Connection options (or equivalent resource JSON) whose keys are not on the allowlist. Windows Authentication is not available on Retool Cloud.

How to check if you are affected before upgrading

Search your Retool deployment logs (dbconnector / backend) for this exact string from the prior log-only release:

MSSQL Windows Auth ODBC connection string parameter not on allowlist

Each matching log line includes the parameter key (parameterKey in structured logs). Resources that logged this message will fail to connect or save after upgrading until those parameters are removed or replaced.

What you will see after upgrading

Resource setup or test connection fails with an error like:

Unsupported MSSQL ODBC connection string parameter "<key>". Only a fixed set of ODBC attributes may be supplied via connection params.

Remediation

  1. Open each affected MSSQL Windows Auth resource.
  2. Remove unsupported keys from paramsFromConnectionString.
  3. Use Retool's built-in resource fields where possible. For example, use SSL/TLS for encryption and certificate verification.
  4. If you need an ODBC attribute that is not listed below, contact Retool Support before upgrading.

Allowed paramsFromConnectionString keys

ODBC attributeAlternate spellings accepted
APPapp
ApplicationIntentapplicationintent
ColumnEncryptioncolumnencryption
ConnectRetryCountconnectretrycount
ConnectRetryIntervalconnectretryinterval
Connect TimeoutConnectTimeout, connecttimeout
Failover_Partnerfailoverpartner
FailoverPartnerSPNfailoverpartnerspn
HostnameInCertificatehostnameincertificate
IpAddressPreferenceipaddresspreference
KeepAlivekeepalive
Languagelanguage
LoginTimeoutlogintimeout
MARS_Connectionmarsconnection
MultiSubnetFailovermultisubnetfailover
Packet SizePacketSize, packetsize
QueryLog_Onquerylogon
QueryLogTimequerylogtime
Regionalregional
ServerSPNserverspn, Server_SPN
Workstation IDWorkstationID, workstationid
WSIDwsid

Security-sensitive attributes (Driver, Encrypt, Trusted_Connection, credentials, Server, Database, and similar) are set by Retool and cannot be supplied via connection params.

Common parameters that are blocked

  • Encryption and certificate trust settings such as Encrypt and TrustServerCertificate — use the resource SSL/TLS settings instead.
  • LoginRetryCount / LoginRetryInterval — use ConnectRetryCount / ConnectRetryInterval.
  • Credential keys such as Uid, Pwd, User, or Password.
  • Keys containing ; or crafted to inject additional ODBC attributes.