Log in
On the workspace settings page, Structural now by default collapses the advanced workspace settings that are not configured, and only displays the settings that you did configure. To configure additional settings, you expand the list of unset settings.
PostgreSQL - Fixed subsetting failures that occured when a virtual foreign key column had a different type from its referred primary key. For example, a Rails polymorphic relationship where the text ID column points to integer and UUID keys. Previously, these jobs failed with "operator does not exist: character varying = integer". The pre-job warning about virtual foreign key type mismatches now also covers polymorphic virtual foreign keys.
PostgreSQL - Fixed subsetting failures that occured when a virtual foreign key column had a different type from its referred primary key. For example, a Rails polymorphic relationship where the text ID column points to integer and UUID keys. Previously, these jobs failed with "operator does not exist: character varying = integer". The pre-job warning about virtual foreign key type mismatches now also covers polymorphic virtual foreign keys.
Fixed an issue where when a column was missing from a source database scan and then reappeared within 24 hours with the same name and data type, Structural reported it as a new column. Structural no longer reports these as new columns. When a column reappears that was missing for over 24 hours, or that you already resolved the removal for, Structural still reports it as a new column.
Structural now prevents upgrades when a workspace owner does not belong to your organization. To address this, start the previous version once with a license that includes those users, then upgrade again.
Fixed multiple small issues with the new teams feature.
Comments: Fixed an issue where @mentions were not highlighted in saved comments, and where text that looked like an HTML tag was silently removed from a comment instead of being shown exactly as it was typed.
Oracle - Structural no longer copies Oracle collection columns to the destination database. Collection columns include nested tables and VARRAYs. These columns were never written correctly, and Oracle's data loading tools cannot represent them. Instead, in the destination, Structural sets these columns to NULL. The job includes a warning that names the affected table and columns. Structural returns the same warning for other Oracle column types that Structural cannot write, such as BFILE and the URI types. Previously, Structural emptied these columns without notice. A job that copies a table that contains any of these column types now finishes with the status Completed with warnings.
Fixed an issue that could cause a subsetting job to write rows whose referenced parent rows were missing, so that applying foreign key constraints failed at the end of the job. This happened when a table was reachable from a subset target through paths of different lengths, and it affected all data connectors that support subsetting.
Restored the new teams feature that was released in v1869 but reverted in v1870 because of a data migration issue.
To summarize, all organization users are added to the Default team.
On Structural Settings, the Teams tab displays the Default team. From there, organization administrators can assign team administrators.
The Teams page, displayed from the user menu at the top right, allows team administrators to view the team membership and manage team permission sets.
In addition to team management, team permissions also include the following permissions:
- Create workspaces
- Manage generator presets
- Manage sensitivity rules
- Configure secrets managers
These were previously global permissions. Workspace permission sets are also now managed within the team.
Workspaces that no longer have an owner, usually because the user was removed, are now displayed on the Workspaces Without an Owner page on Team Settings. Team administrators can then assign a new owner.
File groups: Fixed an issue where selecting files in quick succession could leave a file with no data preview and suppress the warning that the selected files do not all have the same columns.
When you delete a user who owns workspaces, you no longer have to immediately transfer those workspaces to a new owner. The workspaces are added to the Workspaces Without an Owner tab on Team Settings. From there, an admin can transfer the workspaces to a new owner or delete the workspaces. Other users that were granted access to the workspaces lose their access until the workspace is transferred.
New team permissions, permission sets, and Team Settings page
Global permissions sets are now separated into global permission sets and new team permission sets. The permissions to create workspaces, manage presets, copy workspaces, enable diagnostic logging, manage sensitivity rules, and manage secrets managers are now team permissions. The existing permissions migrate from global to team automatically.
Every organization now has a default team. Organization administrators automatically become the administrators of the organization’s default team.
The new Team Settings page, which is available to team administrators, allows them to manage team and workspace permission sets.
This is in preparation for a future enhancement to allow Enterprise organizations to create multiple teams and to manage resources separately within those teams.
You can now create custom permission sets on Structural Cloud.
Made the following changes to the Finnish Personal Identity Code generator:
The generator now preserves uniqueness, and can be used on unique and primary-key columns.
The century indicator in each generated code now mirrors the source value instead of being spread evenly across every indicator letter. This ensures that common indicators (+, -, A) remain common, and that rare reform letters only appear when the source uses them.
During data generation, Structural warns when the sampled values fall outside of the chosen birth-date range or use indicators that the range cannot represent. Structural drops those rows instead of writing them to the destination.
Aurora (PostgreSQL data connector) - Fixed an issue where PostgreSQL data generation to an Amazon Aurora destination failed on every run after the first when the source database had Aurora's pg_columnmask dynamic data masking extension installed. Structural no longer copies provider-managed extensions into the destination.
Oracle workspaces now always run on Data Pipeline V2. The option on the Confirm Generation panel to choose between classic flow and Data Pipeline V2 is removed. Existing Oracle workspaces will automatically use the Data Pipeline V2 flow.
Removed the Oracle database-link generation path and the TONIC_ORACLE_DBLINK_ENABLED environment setting. The setting no longer has any effect. You can remove it from your configuration. Database links that exist as objects in your Oracle schema are not affected. Structural still discovers them, and still warns when the destination is missing a link that is referenced by a source synonym.
OAuth for MCP authentication - You can now sign in through your browser to connect supported MCP clients to Structural. Before you approve the access, Structural shows you which application is requesting access. Existing API key connections continue to work and are not changed. To see everything you've authorized, or to revoke access at any time, go to User Settings → Connected applications.
IBAN generator updates:
The IBAN generator now replaces a value that is not a valid IBAN with a generated valid IBAN, instead of failing the row. This is enabled by default.
Added the following options to the IBAN generator: Replace Invalid Values, Country of the generated IBANs, and Also Replace NULL Values.
IBAN validation is now stricter. Values that were previously accepted as valid might now be treated as invalid and replaced.
IBAN columns that are a key, take part in a relationship, or have a unique index now use the masking algorithm that guarantees distinct values. Previously this could produce orphan rows in the destination, duplicate keys, or a failed insert, depending on the column and the type of job.
An IBAN written in lowercase or with spaces no longer fails the row.
Removed the deprecated workspace share “access level" / "role" API, which was superseded by permission sets.
Filtering or sorting workspaces by role now returns a 400. Instead, use permission_set (by name).
The deprecated accessLevel / receivedRole request fields are now inert. Instead, use permissionSetId / receivedPermissionSetId.
Fixed an issue where users with a custom permission set were incorrectly shown as having no access to preset occurrences.
Agent support for document-based data - You can now use the Structural Agent to perform tasks related to document-based data. Document-based data includes JSON columns in relational data and document-based databases (currently MongoDB).
The supported tasks include:
Note that you cannot use the Agent to create or edit generic path generators.
Structural now provides an MCP server to allow you to work with your workspaces directly from an MCP client.
Consistency for many generators, including the Name generator and the Address generator, now ignore whitespace when deciding consistency. This helps when these generators are applied to fixed width columns, such as char(40). This update does not affect other generators, such as the Character Scramble generator and Timestamp Shift generator.
Name generators that are consistent with another column now derive each part of the name (first, middle, and last) from the corresponding part of the source value. Because of this change, the output from the Name generator might differ than the output generated by earlier versions, including for workspaces that have a fixed statistics seed. Within the same version, the output is still deterministic and consistent.
v1806 was not released because of technical issues.
Snowflake - For Snowflake on AWS, you can now use an assumed role for the credentials to connect to the temporary storage location on Amazon S3.
Fixed an issue where users on the same machine and browser shared a Structural Agent chat.
The Finnish Personal Identity Code generator no longer rejects valid Finnish PICs that use the century indicators B–F and U–Y.
The Finnish Personal Identity Code generator no longer rejects codes that contain an individual number in the reserved test/temporary range (900–999). These are now accepted and masked within their own range. A test PIC always maps to another test PIC, and a real PIC always maps to another real PIC.
The Finnish Personal Identity Code generator no longer rejects source PICs that have a date of birth that falls outside the configured date range. The date range now only controls the dates of birth in the generated output. Source values that are outside of the range are accepted and mapped to a date within the range.
The Finnish Personal Identity Code generator is now available for all data connector types. Previously it was only available for PostgreSQL and MySQL workspaces.
For the Alphanumeric String Key generator, added a configuration option to preserve a specified number of characters at the end of the source value.
Spark and Databricks - For the Regex Mask generator, before a job runs, Structural now rejects patterns that mix named and unnamed capture groups, or that use .NET-only syntax such as (?'name'...) or (?#...). This is because the .NET and Spark/Java engines handle these patterns differently. Instead, use only named or only unnamed groups. The validation applies only to jobs that run on the Java/Spark engine, like Spark (Hive SDK) sources and Databricks on Spark 3.3 or later. This limitation does not affect other data connectors.
Azure Key Vault is now supported as a secrets manager.
MySQL - To configure how Structural batches records from a MySQL database, replaced the environment setting TONIC_MYSQL_MIN_ROWS_FOR_RANGE_READ with a new setting TONIC_MYSQL_KEYSET_BATCH_TARGET_MEGABYTES. Instead of basing the batches on a count of rows, the new setting creates batches based on the data volume in megabytes.
AI assistant starter suggestions now adapt to your context, showing workspace-specific prompts inside a workspace and general product questions elsewhere.
On the workspace settings page, when no workspace zones are configured, the Zone dropdown list is now hidden.
Fixed an issue where a workspace created as a copy kept the owner from the original workspace.
Snowflake - The Snowflake data connector now supports Tailscale tunneling.
You can now configure the file connector to import a JSON document that has a single top-level key whose value is an array (for example, { "identifier": [ ... ] }) as a single object, instead of splitting the array into a separate record per element. By default, this behavior is disabled, so that existing workspaces are unaffected. To enable this behavior, set the new workspace setting TONIC_DISABLE_JSON_ARRAY_WITH_KEY to true.
Structural Agent is now available on all application pages. Added chat management functionality to the Structural Agent (New Conversation, Delete Conversation, Rename Conversation). A Structural Agent conversation can be maintained across multiple workspaces or application pages (Note: the agent can only access tools for the workspace that is currently open).
MySQL - Structural now reads large source tables in sequential key-range batches over short-lived connections, to avoid failures from source-side query time limits. To enable this behavior and set the minimum batch size, use the environment setting TONIC_MYSQL_MIN_ROWS_FOR_RANGE_READ. The default is 0, which indicates that the behavior is disabled. You can override this setting within each workspace.