Manus 2.0 lets an incoming email, Slack message or calendar event start an agent run with no human in the loop. It shipped days after researchers disclosed that a single email could hijack a Manus agent and reach the user's connected accounts. If your teams already expense Manus seats, the useful move this month is a Team plan pilot with read-only connectors and no inbox triggers, and a block on the new Cue app for anything tied to a corporate identity.
Manus announced 2.0 on Monday, September 28, 2026, alongside Cue, a separate app that gives each personal agent "its own email, phone number, wallet" and a computer. The headline number is a 32% cost cut. The security detail that matters more is in a Salt Labs report covered on September 25: an email carrying obfuscated JavaScript got a Manus agent to execute code during a routine task. Salt says the research was done earlier in 2026 and the flaw has since been fixed.
What Manus Actually Shipped on September 28
Manus 2.0 is four products under one name: a new agent harness called Cascade, a redesigned desktop app called Studio, event-triggered automations, and a paid hosting tier called Cloud Computer. Cue ships beside them as its own app.
Per the Manus announcement, automations can fire on email arrivals, ad performance changes, calendar events, Slack messages and Notion updates. Studio adds Video Editor and Game Dev environments to the documents, spreadsheets, slides, websites and code the product already produced. Cloud Computer is described as a dedicated environment for projects that need always-on hosting, including multiplayer game servers and 24/7 automations. TestingCatalog's launch write-up confirms Cloud Computer is paid and lists no price for it, and neither does the announcement.
If the name sounds familiar, the persistent-VM idea is older than 2.0. We covered the original Manus Cloud Computer in May. What changed is the trigger. A Manus task used to start when a person typed a prompt or a schedule they set came due. Now it can also start when someone outside your company sends you an email.
How Much Weight the 32% Cost Claim Can Carry
Very little, because Manus measured it against an unnamed baseline in a single configuration. The announcement says Cascade used "23.2% fewer tokens," finished tasks in "28.2% less time" and cost "32% less to run" than the previous system in "one tested configuration." It does not name the task set, the model behind each run, or the configuration.
That matters for budgeting because Manus bills in credits, and credit burn varies by an order of magnitude per task. NoCode MBA's September 2026 pricing breakdown reports simple queries using 10 to 50 credits and deep multi-source research using 500 to 900. A 32% cut on a workload you have not measured tells you nothing about your own bill. Treat it as a vendor claim and price your pilot from your own credit logs.
What the Team Plan Costs, Including the SSO Line
The Team plan starts at $20 per seat per month, and SSO costs extra below 30 seats. Manus's own help center lists Team at "Starting from $20 per seat/month," with SSO, a data training opt-out, team usage analytics, internal access control and shared slide templates on top of the Pro features. Annual billing takes 17% off.
The catch is in a separate help article on SSO pricing: teams below 30 seats pay "a flat fee of 150 USD + tax" for SSO, and it becomes free only at 30 seats or more, starting with the next billing cycle. For a 10-seat pilot at $20 a seat, or $200 a month, that is a large addition, and the help page does not say how often the fee recurs, so ask. Budget it; a pilot without SSO is a pilot nobody can offboard cleanly.
The Team page also lists an admin dashboard with usage tracking and access control, audit logs, and a statement that Manus "explicitly prohibits model providers from training on our Team/Enterprise Plan customers' data." The security page lists SOC 2 Type 2, ISO 27001:2022 and ISO 27701:2019. It does not say where customer data is stored, so ask for that in writing before anyone in a regulated unit signs up.
Why Email-Triggered Agents Are the Real Risk
An event-triggered automation is an agent run that starts when a message or update arrives in a connected app. That design turns every sender who can reach a trigger into someone who can hand your agent instructions.
Salt Labs showed what that looks like on Manus specifically. Researchers sent a Manus user an email with a hidden payload; Manus blocked plaintext execution requests, but the team bypassed the guardrails with JSFuck JavaScript obfuscation and got remote code execution. Salt's October 1 release says the security warning fired only after the code had run, and that connected email, cloud storage and code repositories were within reach.
To be fair to Manus: the flaw is fixed. Salt says it reported the bug to Manus and got no response, then went through Meta's bug bounty program, which confirmed and remediated it, and later reproduction attempts failed. Implicator also reports that Manus did not reply to the report. What should worry you is what the report shows about the process: detection that trails execution, and a fix that came through Meta's bug bounty after Manus's own channel went quiet. In that test the agent was reading an email a user asked about. With 2.0 automations, an email can start the run on its own.
We have seen the same failure class when SalesBleed turned a public web form into an Agentforce data leak, and when Claude's Slack integration began reading whole channels. In each case outside text reached an agent holding live credentials, and no person approved the step in between.
Why Cue Stays Off Corporate Accounts for Now
Cue gives an agent its own identity, a way to contact people outside your company, and a budget to spend. Per The Next Web, each Cue agent gets its own email address, phone number, wallet and computer, can take calls and leave summaries, and spends inside a budget the user sets. Agents can also work together in group chats and delegate tasks.
What Manus has not published is any administrator control for it. The announcement names a user-set budget, and Implicator reports that Manus has not said what Cue will cost after early access. Cue is in early access behind an invite code, which means an employee can sign up with a work address this afternoon and you would see it only in expense reports or email logs.
An agent with its own phone number and wallet is a non-human identity your IAM program did not issue. If you have started on agent identity in Okta or Entra, Cue agents sit outside all of it.
Whether the Ownership Story Changes the Vendor Read
It removes one uncertainty and adds another. Implicator reports that after Beijing blocked Meta's $2 billion deal, Manus's founders and backers bought back Meta's shares at the original valuation, Tencent is now the largest external investor, and Manus is seeking $500 million at a $4 billion valuation in a round that has not closed. The Next Web says the company is now Singapore-based and is building a separate team for the Chinese market.
If you paused a Manus decision in April because of the Meta deal and China's block, the acquirer question is settled. The investor and data-location questions now need answers from Manus directly, and your third-party risk team will want them before renewal.
What to Do Before Your Next Manus Renewal
The safe path is a narrow pilot with read-only connectors and human-started tasks, plus a written list of answers you need from Manus before you widen it.
This Week:
- Search expense and SSO logs for Manus and Cue sign-ups on corporate addresses, so you know how many seats already exist outside procurement.
- Tell staff in writing that Cue is not approved for any work account, phone number or payment card until Manus publishes admin controls for it.
- On any existing Manus workspace, disconnect write-scoped connectors to email, Slack, cloud storage and code repositories that no current project needs.
This Month:
- Run a Team plan pilot of 10 to 20 seats with SSO turned on, and budget the $150 SSO fee. Keep automations limited to scheduled triggers you control, and keep email and Slack triggers off.
- Log credits per task for two weeks and build your own cost baseline before you believe the 32% figure.
- Red-team one automation with a crafted inbound email before any trigger touches an external sender. Our Zapier and n8n alternatives guide covers where a deterministic step belongs in front of an agent.
Before Renewal:
- Get written answers on data residency, audit log retention and export, Cloud Computer pricing, and a named security contact with a response commitment.
- Compare the admin surface with the one OpenAI shipped for Dots, which has its own gaps on data residency and audit export.
The Bottom Line
Manus 2.0 moves the product from a tool someone prompts to a process that runs when the outside world pokes it, which is the same shift Microsoft made with Scout on its own identity stack. Manus is asking you to trust a 32% cost claim from one unnamed configuration, a security process that left an outside report unanswered, and a consumer agent app with a wallet and no published admin controls.
You can still buy it. Turn on SSO first, then read-only connectors, then inbox triggers once a red-team email fails against them, and allow Cue only after Manus publishes controls an administrator can enforce.
Continue Reading
- OpenAI's Dots Beta Skips Data Residency and Your OTel Collector
- Manus Cloud Computer: The Persistent Agent State Bet
- China Blocks Meta's $2B Manus Deal: Agentic AI Sovereignty
- SalesBleed Turned a Public Web Form Into an Agentforce Data Leak
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- Zapier and n8n Alternatives Once Workflows Become Agents
