> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-august-2026.md).

# Features Introduced in August 2026

Learn what’s new in the Prisma® Cloud August 2026 release. This release includes updates for Prisma Cloud Enterprise Edition version 26.8.1 and Runtime updates for version 34.05.

* [Enhancements](#enhancements)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)
* [Policy Updates - Metadata](#policy-updates---metadata)

## Enhancements

| Enhancement                                                                                                                    | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for Rocky Linux 10.x (Red Quartz)</strong><br><em>Secure the Runtime</em></p>                               | Prisma Cloud now supports Rocky Linux 10.x (Red Quartz) for vulnerability and compliance scanning and for runtime protection.                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Rocky Linux — source-package and epoch support</strong><br><em>Secure the Runtime</em></p>                          | During scanning, Rocky Linux binary packages are now linked to their source package (for example, `expat-devel` and `expat-libs` linked to `expat`). This ensures that CVE matches against the Rocky Linux errata feed are no longer missed. Version comparison also honors the RPM epoch, which eliminates a class of false positives on Rocky Linux images.                                                                                                                                                                            |
| <p><strong>Support for RKE2 v1.35</strong><br><em>Secure the Runtime</em></p>                                                  | Defenders now deploy successfully on RKE2 v1.35 clusters. Previously, defenders failed to connect to Console because CRI-client initialization could not determine the container runtime version on newer RKE2 releases.                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Host defender support on RHEL 10 with nftables</strong><br><em>Secure the Runtime</em></p>                          | Host defenders deployed on RHEL 10 with the `-n` (nftables) install flag no longer log spurious `iptables: executable file not found in $PATH` errors while evaluating the Linux CIS firewall configuration.                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Generic distro-based CVE exclusion via custom feed entries</strong><br><em>Secure the Runtime</em></p>              | Custom CVE exclusions now support any OS distribution — Windows, Ubuntu, Red Hat, Alpine, and others — extending the existing PAN-OS / GKE mechanism. Administrators can upload custom `excludedCve` entries per target distribution through the portal to suppress specific CVEs from vulnerability results.                                                                                                                                                                                                                            |
| <p><strong>False-positive suppression for CVEs on OpenShift nodes</strong><br><em>Secure the Runtime</em></p>                  | OpenShift node scans now filter out CVEs that Red Hat has marked as "not affected" for the OpenShift version in the VEX feed. This eliminates false positives such as `CVE-2025-30204` on OpenShift 4.14 RHCOS nodes.                                                                                                                                                                                                                                                                                                                    |
| <p><strong>Environment variables printed on defender startup</strong><br><em>Secure the Runtime</em></p>                       | On startup, the defender now logs all of its environment variables, making support cases involving env-var configuration significantly faster to triage.                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Defender image — Red Hat Ecosystem Catalog certification</strong><br><em>Secure the Runtime</em></p>                | The defender image now includes the required labels (`name`, `vendor`, `version`, `release`, `summary`, `description`, `maintainer`) and a `/licenses` folder with license files (MIT, Apache, and others), enabling certification in the Red Hat Ecosystem Catalog.                                                                                                                                                                                                                                                                     |
| <p><strong>Agentless OCI — compartment ID support</strong><br><em>Secure the Runtime</em></p>                                  | The Agentless scanner for Oracle Cloud Infrastructure now supports specifying a compartment ID, which allows customers to scope agentless scans to a specific OCI compartment.                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Agentless AWS — expanded fallback instance types</strong><br><em>Secure the Runtime</em></p>                        | The Agentless scanner now uses additional fallback instance types beyond `m5.2xlarge`, `m4.2xlarge`, `m3.2xlarge`, `t2.2xlarge`, and `m6i.2xlarge`. This allows agentless scans to succeed in AWS regions where the current defaults are unavailable (for example, `af-south-1`, `me-central-1`, `il-central-1`, `ap-southeast-4`, `eu-central-2`, and others).                                                                                                                                                                          |
| <p><strong>Registry scan — image deduplication by digest</strong><br><em>Secure the Runtime</em></p>                           | Registry scans configured with a Cap now deduplicate images by digest before enforcing the Cap, so the same image referenced by multiple tags is no longer scanned repeatedly or double-counted against the Cap.                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Vulnerability / Compliance Explorer — daily refresh at very large scale</strong><br><em>Secure the Runtime</em></p> | The daily compliance-stats aggregation in `db.AggregatedComplianceData` is restructured so it no longer accumulates a `$push` array that exceeds MongoDB's hard-coded 100 MiB internal limit. This unblocks daily refresh of the Vulnerability and Compliance Explorer for very large tenants (\~4M+ container compliance hits). A workaround is also available: set the new `MONGO_DB_CUSTOM_CONFIG_PATH` environment variable to mount a custom mongodb configuration that raises `internalQueryMaxPushBytes` from 100 MiB to 500 MiB. |
| <p><strong>LDAP users in multiple groups — access to all assigned collections</strong><br><em>Secure the Runtime</em></p>      | On on-prem consoles using LDAP, when a user belongs to multiple LDAP groups mapped to custom roles, the user is now granted access to every collection associated with those groups instead of only the first collection.                                                                                                                                                                                                                                                                                                                |

## Changes in Existing Behavior

| Feature                                                                                                                   | Description                                                                                                                                                                                                         |
| ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Removal of environment-variable printing from defender failure log</strong><br><em>Secure the Runtime</em></p> | The defender no longer prints its environment variables to the log on failure. This complements the new startup-time env-var dump (see Enhancements) and prevents environment state from appearing in failure logs. |

## API Ingestions

<table><thead><tr><th width="215.60003662109375">Service</th><th>API Details</th></tr></thead><tbody><tr><td><strong>Amazon Bedrock</strong><br></td><td><strong>aws-bedrock-prompt</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListPrompts</code><br>- <code>bedrock:GetPrompt</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include <code>bedrock:GetPrompt</code>. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Bedrock</strong><br></td><td><strong>aws-bedrock-flow</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListFlows</code><br>- <code>bedrock:GetFlow</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include <code>bedrock:GetFlow</code>. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Bedrock</strong><br></td><td><strong>aws-bedrock-flow-alias</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListFlows</code><br>- <code>bedrock:ListFlowAliases</code><br>- <code>bedrock:GetFlowAlias</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role includes the permissions.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Bedrock</strong><br></td><td><strong>aws-bedrock-guardrail</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListGuardrails</code><br>- <code>bedrock:GetGuardrail</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Bedrock AgentCore</strong><br></td><td><strong>aws-bedrock-agentcore-browser-session</strong><br><br>Additional permissions required:<br>- <code>bedrock-agentcore:ListBrowsers</code><br>- <code>bedrock-agentcore:ListBrowserSessions</code><br>- <code>bedrock-agentcore:GetBrowserSession</code><br><br>The Security Audit role includes <code>bedrock-agentcore:ListBrowsers</code>. A custom role is required for <code>bedrock-agentcore:ListBrowserSessions</code> and <code>bedrock-agentcore:GetBrowserSession</code>.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Bedrock AgentCore</strong><br></td><td><strong>aws-bedrock-agentcore-code-interpreter-session</strong><br><br>Additional permissions required:<br>- <code>bedrock-agentcore:ListCodeInterpreters</code><br>- <code>bedrock-agentcore:ListCodeInterpreterSessions</code><br>- <code>bedrock-agentcore:GetCodeInterpreterSession</code><br><br>The Security Audit role includes <code>bedrock-agentcore:ListCodeInterpreters</code>. A custom role is required for <code>bedrock-agentcore:ListCodeInterpreterSessions</code> and <code>bedrock-agentcore:GetCodeInterpreterSession</code>.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon AppFlow</strong><br></td><td><strong>aws-appflow-connector</strong><br><br>Additional permissions required:<br>- <code>appflow:DescribeConnectors</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon CloudFront</strong><br></td><td><strong>aws-cloudfront-vpc-origin</strong><br><br>Additional permissions required:<br>- <code>cloudfront:ListVpcOrigins</code><br><br>The Security Audit role includes the permissions.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Connect</strong><br></td><td><strong>aws-connect-contact-flow</strong><br><br>Additional permissions required:<br>- <code>connect:ListInstances</code><br>- <code>connect:ListContactFlows</code><br>- <code>connect:DescribeContactFlow</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Connect</strong><br></td><td><strong>aws-connect-security-profile-application</strong><br><br>Additional permissions required:<br>- <code>connect:ListInstances</code><br>- <code>connect:ListSecurityProfiles</code><br>- <code>connect:ListSecurityProfileApplications</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Connect</strong><br></td><td><strong>aws-qconnect-assistant</strong><br><br>Additional permissions required:<br>- <code>wisdom:ListAssistants</code><br>- <code>wisdom:GetAssistant</code><br>- <code>wisdom:ListTagsForResource</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Database Migration Service</strong><br></td><td><strong>aws-dms-data-migration</strong><br><br>Additional permissions required:<br>- <code>dms:DescribeDataMigrations</code><br><br>The Security Audit role includes the permissions.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon EC2 Image Builder</strong><br></td><td><strong>aws-imagebuilder-lifecycle-policy</strong><br><br>Additional permissions required:<br>- <code>imagebuilder:ListLifecyclePolicies</code><br>- <code>imagebuilder:GetLifecyclePolicy</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Elastic Load Balancing</strong><br><em>Update</em></td><td><strong>aws-elbv2-describe-load-balancers</strong><br><br>The API now ingests additional listener-level attributes, including routing, mTLS/TLS header routing, CORS, and security-header response attributes.<br><br>Additional permissions required:<br>- <code>elasticloadbalancing:DescribeListenerAttributes</code><br><br>The Security Audit role includes the permissions.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Glue</strong><br></td><td><strong>aws-glue-table</strong><br><br>Additional permissions required:<br>- <code>glue:GetDatabases</code><br>- <code>glue:GetTables</code><br>- <code>glue:GetTable</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Lambda</strong><br></td><td><strong>aws-lambda-get-function-recursion-config</strong><br><br>Additional permissions required:<br>- <code>lambda:ListFunctions</code><br>- <code>lambda:GetFunction</code><br>- <code>lambda:GetFunctionRecursionConfig</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Route53 Resolver</strong><br></td><td><strong>aws-route53resolver-dnssec-config</strong><br><br>Additional permissions required:<br>- <code>route53resolver:ListResolverDnssecConfigs</code><br>- <code>route53resolver:GetResolverDnssecConfig</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon S3</strong><br><em>Update</em></td><td><strong>aws-s3api-get-bucket-acl</strong><br><br>The API now ingests the additional attribute <code>bucketKeyEnabled</code>.</td></tr><tr><td><strong>Amazon SageMaker</strong><br></td><td><strong>aws-sagemaker-mlflow-tracking-server</strong><br><br>Additional permissions required:<br>- <code>sagemaker:ListMlflowTrackingServers</code><br>- <code>sagemaker:DescribeMlflowTrackingServer</code><br>- <code>sagemaker:ListTags</code><br><br>The Security Audit role includes the permissions.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Systems Manager</strong><br></td><td><strong>aws-ssm-command-invocation</strong><br><br>Additional permissions required:<br>- <code>ssm:ListCommandInvocations</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Systems Manager</strong><br></td><td><strong>aws-ssm-ops-item-related-item</strong><br><br>Additional permissions required:<br>- <code>ssm:DescribeOpsItems</code><br>- <code>ssm:ListOpsItemRelatedItems</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Systems Manager</strong><br></td><td><strong>aws-ssm-ops-metadata</strong><br><br>Additional permissions required:<br>- <code>ssm:ListOpsMetadata</code><br>- <code>ssm:GetOpsMetadata</code><br>- <code>ssm:ListTagsForResource</code><br><br>The Security Audit role includes <code>ssm:ListOpsMetadata</code> and <code>ssm:GetOpsMetadata</code>. A custom role is required for <code>ssm:ListTagsForResource</code>.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS Systems Manager</strong><br></td><td><strong>aws-ssm-quicksetup-configuration</strong><br><br>Additional permissions required:<br>- <code>ssm-quicksetup:ListConfigurations</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Amazon Textract</strong><br></td><td><strong>aws-textract-adapter</strong><br><br>Additional permissions required:<br>- <code>textract:ListAdapters</code><br>- <code>textract:GetAdapter</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note</strong>: This API is disabled by default and available upon request.</td></tr><tr><td><strong>Google BigQuery</strong><br></td><td><strong>gcloud-bigquery-model</strong><br><br>Additional permissions required:<br>- <code>bigquery.datasets.get</code><br>- <code>bigquery.models.list</code><br><br>The Viewer role includes the permissions.</td></tr><tr><td><strong>Google Cloud Conversational Insights</strong><br></td><td><strong>gcloud-conversational-insights-conversation-analysis</strong><br><br>Additional permissions required:<br>- <code>contactcenterinsights.conversations.list</code><br>- <code>contactcenterinsights.analyses.list</code><br><br>The Viewer role includes the permissions.</td></tr><tr><td><strong>Google Cloud Customer Engagement Suite</strong><br></td><td><strong>gcloud-ces-app</strong><br><br>Additional permissions required:<br>- <code>ces.locations.list</code><br>- <code>ces.apps.list</code><br>- <code>ces.apps.get</code><br>- <code>ces.tools.list</code><br>- <code>ces.toolsets.list</code><br><br>The Viewer role includes the permissions.</td></tr><tr><td><strong>Google Cloud Customer Engagement Suite</strong><br></td><td><strong>gcloud-ces-app-conversation</strong><br><br>Additional permissions required:<br>- <code>ces.locations.list</code><br>- <code>ces.apps.list</code><br>- <code>ces.conversations.list</code><br>- <code>ces.conversations.get</code><br><br>The Viewer role includes the permissions.</td></tr><tr><td><strong>Amazon S3</strong><br><em>Update</em><br><br></td><td><strong>aws-s3api-get-bucket-acl</strong><br><br><strong>Update:</strong> Added the <code>bucketKeyEnabled</code> attribute to the existing API ingestion</td></tr><tr><td><strong>AWS CodeConnections</strong><br></td><td><strong>aws-codeconnections-connection</strong><br><br>Additional permissions required:<br><br>- <code>codeconnections:ListConnections</code><br>- <code>codeconnections:GetConnection</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note:</strong> This API is disabled by default and available upon request.</td></tr><tr><td><strong>AWS CodeConnections</strong><br><br><br></td><td><strong>aws-codeconnections-host</strong><br><br>Additional permissions required:<br><br>- <code>codeconnections:ListHosts</code><br>- <code>codeconnections:GetHost</code><br><br>The Security Audit role does not include the permissions. A custom role is required.<br><br><strong>Note:</strong> This API is disabled by default and available upon request.</td></tr></tbody></table>

## Policy Updates

| Policy Name                                                                        | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>GCP Vertex AI Workbench User-Managed Notebook Policies</strong><br></p> | <p><strong>Changes:</strong> The following policies are deprecated because GCP deprecated Vertex AI Workbench user-managed notebooks, with support ending January 30, 2025 and final migration of existing resources on March 30, 2026.<br><br>- GCP Vertex AI Workbench user-managed notebook's JupyterLab interface access mode is set to single user<br>- GCP Vertex AI Workbench user-managed notebook is using default service account with the editor role<br>- GCP Vertex AI Workbench user-managed notebook has vTPM disabled<br>- GCP Vertex AI Workbench user-managed notebook auto-upgrade is disabled<br>- GCP Vertex AI Workbench user-managed notebook has Integrity monitoring disabled<br><br><strong>Impact:</strong> Alerts related to these policies resolve when the policies are deleted.</p> |

## Policy Updates - Metadata

| Policy Name                                                                                                        | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>AWS Application Load Balancer (ALB) is not using the latest predefined security policy</strong><br></p> | <p><strong>Severity:</strong> Low<br><br><strong>Changes:</strong> The RQL is updated to include <code>ELBSecurityPolicy-TLS13-1-2-Res-FIPS-PQ-2025-09</code> as an accepted secure policy, replacing the previously listed <code>ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09</code>.<br><br><strong>Current RQL:</strong><br><code>\<br>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners\[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09'))] exists\<br></code><br><br><strong>Updated RQL:</strong><br><code>\<br>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners\[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-Res-FIPS-PQ-2025-09'))] exists\<br></code><br><br><strong>Impact:</strong> Low. This update may re-open existing resolved alerts on AWS ALB resources not using the latest AWS recommended security policy.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-august-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
