Framework settings
The Framework page no longer has its own place in the settings rail. The initialization workflow now lives under Behaviour, alongside the rest of an agent’s behaviour settings.
If a project is still on conversation flow, you can switch it to the agentic framework from the General tab. The switch only goes one way: once a project moves to agentic, it cannot move back.
This only applies to projects still on conversation flow. An agentic project has no framework switch to make.
Global prompt timezone
Your agent’s timezone can now be set from the global prompt editor, right next to the prompt that uses it. Your own timezone is offered first in the list, so the common choice is right there.
Open the Global Prompt tab and use the timezone selector to choose a zone, or clear it if you no longer want one set. Clearing now removes the value instead of requiring you to replace it with another.
Transcript version filter
The Search transcripts endpoint on the Analytics API can now search across several versions in one request.
Pass a list of version IDs to the versionIDs field to pull transcripts from a published version and its past releases together, instead of querying each version separately.
Messages and prompts API
Messages and prompts can now be read, created, edited and deleted by ID through the API, the MCP server and Atlas. This includes a message’s variants and a prompt’s system text and settings, so scripted content can be managed directly rather than only through the builder.
Use the API or MCP server endpoints for messages and prompts to fetch or update them by ID, or work with them in Atlas. The /v2 environment export now nests these under messages and prompts, so exports reflect the same structure.
Tool execution API
You can now run a function, API tool, MCP tool or integration tool on its own, from the API, the MCP server or Atlas, and read what it returned, without starting a conversation.
Call get_schema to read the inputs a tool expects, then call the tool directly to execute it once. Secrets the tool needs are passed by name rather than by value.
This runs the tool by itself, outside of any conversation flow.
Secrets per environment
Secrets have moved from the project level to the environment level, so each environment now keeps its own values.
Every secret has a Default value and can optionally have a Draft value. When you test your agent, Voiceflow uses the draft value if there is one and falls back to the default value. In production, it always uses the default value.
Live agent handoff
Live agent handoff is now available to users on all plans. Users can add the Handoff step to a chat agent and route conversations to a live agent.
Add the Handoff step from the builder and connect it to Ujet, Genesys, Kustomer, Dixa, Sunshine Conversations for Zendesk, or a custom handoff provider.
Notification sound
The chat widget can now play a notification chime when a new message arrives. A visitor who has scrolled away or switched to another tab hears when the agent has replied, instead of only seeing an unread badge on return.
Turn it on in the widget’s settings. No other configuration is needed, and the chime plays automatically whenever a new message comes in while the widget isn’t in focus.
Voiceflow Core 4.2
Voiceflow Core 4.2 has been released as the newest agent model.
Agents running Voiceflow Core 4.1 will move to 4.2 automatically - no action needed. 4.2 is a stronger reasoning and instruction-following model. Conversation quality should improve while remaining at the same cost.
Voiceflow Core 4.1 is deprecated and no longer available for new agents.
Outbound SMS
A phone number assigned for SMS can now start a conversation instead of only receiving one. Your agent sends the first text, and the recipient’s reply continues that same session.
Trigger the outbound message from the phone number API, specifying the number and the recipient. The agent’s first message opens the conversation, and everything that follows, on either side, stays in that thread.
This applies to numbers already assigned for SMS, so no separate setup is needed to enable outbound sending.
Transcript log filtering
You can now filter the logs returned by the transcript endpoint to just the traces you need, instead of downloading the whole log and filtering it yourself.
Pass filterConversation on a request to a transcript to return only conversation traces, or use customTraceTypes to select specific trace types to include. Both are optional parameters on the existing stable transcript endpoint.
This trims what the API returns before it reaches you, rather than requiring you to filter the full log after the fact.
Instruction patching
Agent instructions, global prompts, and playbook instructions can now be read, searched, and patched line by line through the API. You can edit a single line in a 20,000-line prompt without re-sending the entire document, and search instructions to locate specific lines.
Use the new patch endpoints to update individual lines by their line number or search pattern. This applies to instructions at the agent level, global prompt level, and within playbooks.
Full document replacement remains available. Line-by-line patching is an alternative for large instruction sets where targeted edits are more efficient.
Atlas reads your conversations
Atlas can now answer questions about your conversations in bulk. Ask why calls dropped last Tuesday, or which conversations scored badly on an evaluation, and it searches your transcripts, reads the ones that matter, and reports back, instead of you opening them one at a time.
Point it at a date range, an environment, or an evaluation score. It can summarize a single conversation from a link, or run named evaluations across everything it found in one batch. Batches spend your workspace’s evaluation quota and write scores onto the transcripts, so Atlas tells you the cost before it starts.
Reasoning effort
You can now set how hard a Claude model thinks before it answers. Pick a Claude model served through Bedrock and a Reasoning effort slider appears, with stops for Off, Adaptive, Low, Medium and High. Leave it alone and the model keeps its own default.
Set it in Settings → Behaviour → Model & reasoning, or from the Model popover on a playbook or prompt. Thinking tokens are billed as output, so Off is a cost control as much as a speed one.

Phone call audio
We have improved how phone call audio is processed before the agent hears it. There were cases where noise cancellation was stripping parts of what the caller said, so the agent missed some of the utterance and it did not reach the transcript. Callers now come through in full.
Nothing to configure, and this applies to every phone call.
Evaluation run scope
An evaluation can now be scoped to conversations that ran on a published environment, or to draft ones, instead of scoring everything. Resolution rate and Conversion rate are published-only by default, so test traffic no longer skews them.
Set runScope to published, draft or both through the API. It applies to automatic scoring only: a batch run from the Transcripts tab still runs on exactly the transcripts you pick.
Evaluations score what already happened. Tests pin what must happen.
Billing user role
Billing access is now decided by a member’s workspace role alone. Owner, Admin and Billing roles keep it, as do organization admins.
Giving someone edit or admin access to a single project used to carry billing access with it. If you were relying on that, give them the workspace Billing role instead.

Atlas writes your tests
Atlas can now create tests in the Tests tab: scripted turn-by-turn conversations, persona simulations, and checks on what the agent said, where it routed and which tools it called. It can also turn a conversation into a regression test, whether that conversation worked or failed.
After a smoke conversation passes, Atlas offers to pin it as a test. Before a publish or merge to Main, it offers to run the suite first. Atlas writes the test and hands the run back to you to trigger.
Atlas improvements
Atlas now edits prompts in front of you. Ask it to change your global prompt, agent instructions or a playbook’s instructions, and you watch the rewrite happen in the editor rather than waiting for a finished result. In Safe mode the proposal appears as a word-level diff you accept or reject; in Autonomous mode the text is typed straight in.
You can also ask about one part of a prompt instead of the whole thing. Select any text in an editor and choose Ask Atlas from the toolbar above the selection, and that passage is attached to your next question as a chip.
And Atlas can set up credentials with you. When something needs a secret, an integration or an MCP server, it offers a card that opens the normal Voiceflow flow. You fill it in, the card reports back, and Atlas carries on from where it stopped. The credential is entered by you and never passes through the chat or the model.
Secret and integration endpoints
Secrets and third-party integrations can now be listed, created, connected and disconnected through the stable API, the CLI and the Voiceflow MCP server, scoped by project. Secret values are write-only and never returned.
Integrations report whether they can be connected through the API at all. Browser-flow ones such as Zendesk and Salesforce still have to be connected in the builder. A credential value is refused when it arrives from an MCP client.
Safe mode in Atlas
Safe mode is how Atlas works by default: it pauses and asks before anything that changes your project, and runs read-only work such as listing, fetching, exporting, querying analytics and searching transcripts without interrupting you.
It now decides what counts as a change per operation, rather than inferring it from the operation’s name. Anything implemented as a write asks first even if it reads like a lookup, and any newly added operation asks until it is classified. Switch between Safe and Autonomous from the pill in the Atlas composer footer.

Atlas
Meet Atlas, your in-app copilot for building and monitoring agents. Ask how an agent performed this week, how that compares to last week, or where customers are dropping off. Ask for a change to the agent and Atlas makes it.

Atlas holds a single conversation as you move around the product, so you never have to re-explain what you are working on. You can watch it think: a live activity line shows the tools it is calling and the reasoning behind each step.
Anything you find yourself asking repeatedly can become a Skill. Save your own in Settings → Skills, then pick them from Atlas whenever you need them.
Atlas is in Beta, available on agentic projects, and its usage is broken out in your workspace usage charts.
Markdown source view
The fullscreen global prompt and playbook instruction editors can now be switched to their markdown source and edited as plain text, so you can see and change exactly what the agent will read. Use Show markdown source in the floating actions, and Show rendered markdown to switch back.
Source mode has syntax highlighting and tab indentation, and your choice is remembered per editor. The rendered view is still the default, so nothing changes unless you switch. Copying from the rendered view now gives you markdown.

