Skip to content

Release notes

Written for somebody deciding whether to take an upgrade: what changed, whether it touches the database, and what to do first.

The full technical record is the changelog, which lists every change in every release. Your deployment carries the notes for the version it is being offered: the status panel and Admin, Licence both show them, along with whether that release carries a migration. CHANGELOG.md ships with the software.

Admin, Connectors now uses a stable setup order. Sign-in and directory services come first, followed by device management and enrolment, student information and ticketing. Communication, infrastructure and operational integrations follow. New connectors appear in their relevant category instead of being promoted simply because they were added most recently.

AV and room monitoring has a dedicated section below core infrastructure. Configured instances, permissions and background collection keep their existing behaviour. Providers within a category also have a stable order.

This release includes the 0.14.1 button and form-control fixes. Container images also omit build-only web caches, reducing download and scanner disk usage.

Upgrade: no new database migration beyond 0.14.0. An upgrade from 0.13.0 still applies the district connector migration. Check the status panel or Admin, Licence for deployment availability; native installers and stable promotion remain separate.

Issue, Return, Mark unavailable and Edit on Loans now share the same sizing. The same action styles apply across administration, stock, security, dialogs and account setup, with consistent labels, corners, spacing and keyboard focus. Primary, secondary and destructive actions remain visually distinct.

Tables retain readable columns on phones and scroll horizontally when needed. The Loans action labels stay intact. Form fields and icon buttons also use shared minimum sizes, and selected actions no longer change size when toggled.

Upgrade: no new database migration. This patch includes all 0.14.0 district connector and identity-provider setup improvements. Check the status panel or Admin, Licence for the version available to your deployment.

0.14.0: multiple connections for districts

Section titled “0.14.0: multiple connections for districts”

Release channel: 0.14.0 is tagged for beta publication. Check your status panel or Admin, Licence for availability after image and deployment verification; a version tag alone does not confirm that your deployment has updated. Stable-channel promotion and native installers remain separate.

Add several named Jamf, Entra, Google Workspace or other connector instances in one organisation, with independent credentials and state. Choose organisation-wide or selected-campus coverage independently of the agent site. This supports a district using shared systems alongside individual schools’ connections.

Select the source for directory reads and account actions. Campus-scoped account access requires a confirmed link to a local person; device commands retain their recorded MDM source. SIS sync keeps equal external IDs and leaver detection separate by source, and identifies partial failures. Interactive tiles and buttons also regain spring feedback, respecting reduced-motion and pointer preferences. All 0.13.0 school operations, assistant and regional billing updates are included.

Admin now opens settings instead of reopening completed onboarding. Connectors and desk setup explicitly offer Entra, Google Workspace, custom OIDC and SAML sign-in configuration. Provider instructions preserve existing settings; LDAP password sign-in remains a separate option.

Person privacy exports include their connector-source links, and erasure removes those links alongside the person’s identifying fields. Confirmed directory links also have a readable entry in the audit log.

⚠ Migration: one additional application migration since 0.13.0, 20260913180000_multiple_connector_instances; no additional control-plane migration. Verify a backup and update API, web and site agents together. Existing IDs, credentials, enabled state and agent bindings are preserved. Review the backfilled campus coverage. Agent secrets for additional connections must use instance IDs, and older agents cannot claim their work.

Do not downgrade to the previous application after creating additional instances. Prefer a forward fix, or restore the verified pre-upgrade database with matching application and agent versions. Shared imports without a clear campus require local assignment. Workflows without source pickers refuse ambiguous connections. Multi-issuer sign-in and SCIM are separate work; provider capabilities and live/demo limitations have not changed. Representative live-provider validation is still required before a customer rollout.

See Configuring a connector, Directory accounts and Connector agents. Upgrades from 0.12.0 also need the migrations listed under 0.13.0 below.

0.13.0 — school operations and assistant reviews ⚠ migration

Section titled “0.13.0 — school operations and assistant reviews ⚠ migration”

Deployment status: 0.13.0 is published to the beta channel and running on staging and the public demo after release verification. The stable release remains 0.12.0 during the documented soak process. Native installer publication remains disabled.

Plan school projects, maintenance, purchases and events with shared approvals, dependencies, milestones, resources and bookings. Review synced roster changes and create lifecycle work; capture stocktake observations offline and resolve conflicts when synchronizing. Supported AV/room integrations and TeamViewer status mapping help identify equipment needing attention.

Purchasing can connect to Xero or MYOB after provider setup and authorization. Review the supplier, account and tax mapping before exporting an approved purchase. Interrupted deliveries have an explicit reconciliation path. Issue insights compare ticket and repair patterns, recurring categories and repeat devices across periods.

The native assistant can cite published knowledge, summarize tickets and draft responses. Changes require an expiring review of the recorded action. The optional Salesforce Agentforce advisory pilot is disabled until an administrator verifies its configuration and grants staff access. Live Salesforce sandbox validation remains outstanding; this is not a general availability claim.

The app uses clearer shared controls and calmer surfaces across workflows, sign-in and the assistant, with existing theme and navigation preferences. Guided setup and the dependency fixes from 0.13.0-rc.1 are included.

Fixed annual billing is available in AUD, USD, GBP, EUR, NZD and CAD. The website suggests a currency from your country and lets you choose another. Quotes, licences and invoices use that currency; existing AUD contracts are unchanged. See Plans for the fixed price table.

Before updating: verify a backup. There are five new application migrations since 0.12.0 and 0.13.0-rc.1, covering assistant controls, school operations and finance integrations, trusted database-owner maintenance and subscription currency. Update API, web and site agents together. The separate control plane has one new currency migration. It preserves existing amounts and defaults older contracts to AUD. The vendor mail service retains Resend until both Cloudflare Email Sending credentials are configured. Native installer and mobile-store publication remain separate from this release.

Deployment status: this candidate passed CI, image verification and live health/version checks. It is superseded by 0.13.0 on staging and the public demo. The stable release remains 0.12.0 during the 0.13 rollout.

This candidate introduces a guided setup for the first administrator: choose built-in ticketing, an existing ticketing system or no ticketing; select licensed workflows and portals; configure access, connections and backups; then review the desk before launch. Progress is saved across sessions. Existing desks can open Admin → Desk setup without being forced through setup again.

The release also updates dependencies to address known security advisories and reduces temporary build-artifact storage. There are no additional application or control-plane database migrations since 0.12.0.

0.12.0 — department desks and navigation refresh ⚠ migration

Section titled “0.12.0 — department desks and navigation refresh ⚠ migration”

Deployment status: 0.12.0 has passed final staging verification and is available on the stable channel. Each school’s deployment still needs its own upgrade; publication does not automatically update it.

This release includes the RC1–RC5 changes below: department desks with explicit activation and department/campus access boundaries; grouped navigation, hover submenus and school-default preferences; corrected identity and authenticator feedback; in-app Documentation search alignment; Iru connection compatibility; application inventory; and scoped Full Access delegation with fresh identity checks and audit records. Send As grants remain disabled and deferred.

Upgrading from 0.11.1 includes 17 migrations. Back up and verify recovery before updating. No additional application or control-plane migrations were added after RC5; the functional source is unchanged from that accepted candidate.

Live Jamf/Intune validation and formal human usability/assistive-technology assessment remain follow-ups. The Expo technician/requester development preview is separate; native installers and mobile store distribution remain unpublished. Earlier references in these guides to 0.12 candidate features describe the features now included in this final release, subject to permissions and explicit department entitlement/activation.

0.12.0-rc.5 — in-app Documentation search alignment ⚠ migration

Section titled “0.12.0-rc.5 — in-app Documentation search alignment ⚠ migration”

This candidate passed staging acceptance before final 0.12.0 publication.

The magnifying glass in Plugboard’s Documentation page (/docs) is centred within the Search everything written down input. The live-document hint stays below it and is associated with the field for screen readers. There are no additional migrations since rc.4.

0.12.0-rc.4 — account preference synchronization ⚠ migration

Section titled “0.12.0-rc.4 — account preference synchronization ⚠ migration”

Returning your appearance or navigation position to the school’s setting also clears an older choice on another device when it next loads your account. Account controls reflect the saved preference. There are no additional migrations since rc.3; upgrading from 0.11.1 still includes the 17 migrations below.

0.12.0-rc.3 — navigation and acceptance fixes ⚠ migration

Section titled “0.12.0-rc.3 — navigation and acceptance fixes ⚠ migration”

This candidate passed image verification and staging rollout. Deployed checks confirmed the changes below; the cross-device school-default reset correction is in rc.4.

The follow-up adds desktop hover submenus, restores Modern navigation glass and spring motion, and aligns account visibility settings with workspace groups. Returning from a custom order to groups preserves hidden pages. Touch, keyboard and reduced-motion support remain. Backup verification now describes integrity checks without claiming that every archive supports in-app restore; department feature switches have readable labels and configuration links.

Microsoft licence and authentication-method lookups use the query options their APIs support. If an identity section cannot load, it shows an error instead of remaining on “Loading”. Switching profiles clears the previous identity data. Authenticator enrollment retains the refreshed sign-in session. An incorrect or expired setup/removal code can be corrected without being sent back to sign-in. Users administration shows an access message instead of an unusable creation form when the signed-in account cannot manage users.

The Expo development preview supports technician and requester ticket workflows. Both modes passed the reported physical login, ticket, rotation and resume checks. Advanced actions and school SSO/passkeys use browser handoffs. App-store distribution is not part of this server release.

No additional migrations since rc.2. Upgrades from 0.11.1 still include the 17 migrations below and require a verified backup. Native installers remain unpublished.

0.12.0-rc.2 — staged beta and Iru update ⚠ migration

Section titled “0.12.0-rc.2 — staged beta and Iru update ⚠ migration”

This image passed CI, image scanning, signing and staging rollout. Signed-in ticket, department, device, loan, automation and Full Access acceptance completed; the final navigation, identity-read and account display corrections are in rc.3.

This candidate includes the 0.12.0-rc.1 changes below and renames the visible Kandji connector to Iru (formerly Kandji). Existing saved connections keep their identifier, credentials and API origin. The connector guide explains both supported API domains and the older UI labels.

This candidate also removes test TLS fixtures and build caches from the runtime image. The rc.1 image scan stopped publication before staging was updated.

An upgrade from 0.11.1 includes 17 database migrations, including department access policies. Back up and verify recovery before updating. There are no additional migrations beyond the unpublished 0.12.0-rc.1 source. The connector remains read-only Apple device lookup and fleet inventory; the rebrand does not add remote commands or Iru’s other platform products. Native installers remain unpublished.

0.12.0-rc.1 — source changes included in rc.2 ⚠ migration

Section titled “0.12.0-rc.1 — source changes included in rc.2 ⚠ migration”

This tag did not publish an image or update staging: its image scan rejected test TLS fixtures in the runtime package. The rc.2 candidate contains the following changes and the packaging correction.

  • Jamf computer/mobile and optional Intune application inventory on device MDM records, with source/timestamps, search and pagination. Large fixture checks passed; live test tenants were unavailable. Inventory does not establish installation or VPP/licence entitlement.
  • Wipe queues reserve capacity across campuses, coordinate concurrent workers, and stop automatic replay after uncertain results, including retry rows from older versions. Requesters can see limited state and must acknowledge an uncertain previous outcome before a new request. Typed serial, MFA, approval and cooling-off controls remain.
  • Credential and authentication-configuration authority checks, stricter API-key department access, formula-safe exports and conditional charge/loan updates. Staff session replacement clears private page state and kiosk repair details stay within the current sitting.
  • Private native panel access and administrator recovery, capability-link log redaction and consistent pre-update database snapshots. Native installer publication remains disabled.
  • Printer freshness records the latest observation independently of historical changes. Source demo seeding requires explicit DEMO_MODE=1.

Three additional additive migrations record refresh-token logout, printer observation time and API-key legacy access. Back up before upgrading. Send As is deferred from this release; its grants remain disabled.

These changes are included in the rc.2 beta candidate. This is not a stable-release announcement. Back up and verify recovery before applying its additive migrations.

Check the version and explicit add-on entitlements on the instance you use. Validate its runtime, staff/requester workflows and audit outcomes before school use. The generated capability reference distinguishes live handlers, demo simulation, blocked actions and unsupported operations.

  • Optional Facilities, Administration and other school departments, with service forms, department membership, explicit transfers, email routing and recurring maintenance. Add-ons require explicit activation and entitlement. Paused departments retain history and require schedules to be explicitly restarted.

  • Grouped workspace navigation in modern and classic, including phone search, keyboard navigation, preserved personal arrangements and clearer loading, retry and stale-data feedback on key staff pages.

  • Whole-school backup protection: unrestricted campus access is required, with departments.manage when any active or paused department exists. New v3 logical archives preserve paused history and validate the complete table/count/link manifest before restore. Older unmarked archives require operator validation and a maintenance restore; this also applies to ICT-only schools. Keep old archives and their encryption keys.

  • Device CSV export uses the current filters across all matching devices within its size limits. Report CSV uses the range of the displayed result.

  • Department boundaries extend to rules, reports, notifications and queued work. Shared workflow settings require school-wide department administration after a department is configured. Department webhooks and external API-key access remain withheld pending explicit integration scopes.

  • Automation audit history, school and rule hourly caps, OBSERVE mode, campus conditions, previews and guarded approvals. Bundled connectors do not yet implement unattended device.lock.

  • Software contract register with free-text owners, renewal reminders and compute-on-read licence positions. No identity inventory is persisted.

  • Durable bulk device-location jobs, with progress, cancellation and bounded retries. Remote command fanout is not included.

  • Scoped REST action catalogue and invocation, using the same tools as MCP.

  • Source-aware connector links and kind-specific remote URL template validation. Remote launch screens remain device-based.

  • Opt-in Exchange Full Access and delegation revocation. The corrected Full Access pilot passed grant, repeated grant, revoke and outside-scope refusal using a five-command role. Send As grants remain blocked after two outside-scope grants succeeded in live testing; the app’s outside-scope removal was refused and independent administration cleaned up. Add-RecipientPermission is excluded from the role. Each deployment still needs runtime, scoped-operation, UI and audit acceptance before enabling use.

  • Node 24 and Nest 11 runtime updates. Container installs include the pinned PowerShell/Exchange module; source/native installs need those dependencies installed separately if using delegation.

  • The platform source toolchain pins pnpm 10.34.5, including reviewed lifecycle-script allowlisting. Use that version and the committed lockfile when building the platform; the documentation site retains its own npm workflow.

  • Help → Connector capabilities and the public reference are generated from the same reviewed runtime registry. A build guard detects reference drift; an available handler still requires that school’s credentials, permissions, entitlements and provider setup.

  • API keys retain their issuer’s permission and campus limits. Tenant-wide SCIM requires an unrestricted campus grant; older unbounded keys need rotation. Public reads and tool calls enforce their required scopes.

  • Closing tickets or submissions requires the relevant close permission across edits, actions, bulk work and tools. Concurrent refresh-token use has one rotation winner. Connector/OIDC outbound requests retain destination checks across DNS resolution and redirects, including dual-stack fallback.

  • Docker application archives use persistent API storage. The updater checks existing storage before migration; native updates preserve default archives across bundle replacement. See backup storage and update limits.

Additional identity and support hardening has merged into source: active person checks on portal sessions and inductions, durable per-device kiosk mode, atomic setup/claim consumption, complete support opt-out checks and customer ownership checks on deployment telemetry. Staging acceptance is still pending.

Content boundary changes are in review: moving a document into a restricted library retracts its public copy atomically, and email headers reject line breaks before delivery. The generated connector reference includes the stricter Gmail sender schema. These remain candidate behavior until deployed and accepted.

Plugboard follows semantic versioning: MAJOR.MINOR.PATCH.

Patch, 0.6.1 to 0.6.2 Fixes only. Nothing new to learn, nothing to reconfigure
Minor, 0.5.3 to 0.6.1 New modules, connectors or features. Existing behaviour is preserved
Major Something that changes behaviour you may be relying on. There has not been one yet

A version number is a git tag, and a tag is only ever used once. If a release is withdrawn, the next attempt takes the next number rather than reusing the old one, so what you have installed is unambiguous.

Channel What it is Who should be on it
Stable The default. Every published release Everybody, unless you have a reason
Beta Pre-release builds, ahead of stable A test instance, never a live desk

Set the channel in your .env. If you have never set one, you are on stable.

Managed hosting is on stable, and update windows are covered under releases and update windows.

A release marked ⚠ migration in the changelog changes the shape of the database. A release without it does not.

Take a verified backup before applying a marked release. Not a backup: a backup you have confirmed exists and is not empty. See backups and restore.

Two things are worth understanding before you upgrade into one:

Migrations are forward-only. Rolling the program back does not roll the database back. If a migration itself is the problem, the fix is restoring the pre-update dump, and everything written since it is lost.

The installer already does most of this for you. A release carrying a migration takes a dump into backups/ before the schema changes, and checks the dump is not empty or truncated before allowing the migration to run, because an empty dump is worse than no dump: it looks like a backup. That safety net is real, and it is not a reason to skip your own. See updating.

Plugboard’s migrations are additive as a matter of policy: new tables start empty, new columns are nullable or defaulted, and a school that opens none of the new modules sees exactly what it saw before.


Three migrations, all additive — a connector and deep-link reference on Ticket, stock and reorder tracking on repair parts, a consecutive-failure counter on connectors. Nothing is backfilled and no existing query changes behaviour.

What’s new

  • The device register can hold a device no MDM ever enrolled — add one by hand, or import a CSV.
  • A device’s assigned owner can be set directly from induction check-in, loan issue, or the admin panel.
  • Fleet health now shows devices no MDM manages, not only the ones it does.
  • A ticket remembers which connector filed it and links back to it on the vendor’s own site.
  • Closing a repair against parts on hand now decrements stock, with a desk alert once a part crosses its reorder point.
  • Client portal requesters can attach a photo when lodging a ticket.
  • Bulk loan issue and return report which rows failed, not just a count.

Fixed

  • A printer connector that can’t be reached now backs off and disables itself after five failures, instead of retrying every ten minutes forever.

Security

  • A related-tickets panel could return another campus’s ticket subject and status to a site-scoped admin — fixed, along with the same missing check on unlinking tickets.
  • The feedback delivery webhook’s token could reach the error log on a non-standard failure response — redaction now targets the specific path.
  • An unhandled error in the feedback delivery sweep could restart the control plane — it now handles per-row failures without crashing.

What you should do. Take a verified backup and upgrade normally.


Six migrations, all additive — new tables for repair-submission attachments, printer status history and feedback board delivery; a generated full-text search column for tickets; MDM and loan-archive columns on Loans, Loan groups and Stock; and an ownership flag on repair submissions. Nothing is backfilled destructively and no existing query changes behaviour. Take a verified backup first.

A broad feature push: loan and stock data-model gaps, kiosk and induction safety, ticket search and dashboard query cost, device and fleet security, repairs correctness, printer reliability, control-plane recovery tooling, identity/SCIM and retention sweeps, sign-in ergonomics, mobile navigation, and a new pipeline that delivers in-app feedback straight to the Multica board. The full record, with root cause for every item, is in the changelog.

  • Loan groups own their own MDM sync, so two loan pools can sync from two different device groups instead of one overwriting the other, and a device that leaves its MDM group is flagged as departed automatically. The loans list can also be filtered by device kind, user group and free text.
  • A repair submission can carry an intake photo.
  • Printer status and toner are tracked over time, with an alert when a printer goes down, runs low, or a monitoring sweep itself stalls.
  • Fleet sync can be triggered on demand from Admin → Connectors → Fleet, with a full summary written to the audit log every run.
  • A stuck managed onboarding can be retried, and a yanked release un-yanked, both from the control-plane panel — previously either meant editing the database by hand.
  • The identity panel shows licence spend, including licences still assigned to disabled accounts.
  • MFA enrolment shows a QR code, not just a text secret to type in.
  • In-app feedback now reaches the Multica board on its own, with retry and backoff if delivery fails, instead of sitting in the control plane until someone reads the inbox.
  • Stock, loans, printers, the admin Kiosks panel and the welcome page show real loading, empty and error states now, instead of one shell for all three — a failed request no longer looks like an empty list.
  • Induction check-in enforces required fields, and a bulk student import now reports which names it couldn’t match instead of dropping them silently.
  • The induction kiosk no longer sticks on the previous student’s result, and resets itself after 90 seconds idle.
  • Card lookup and registration now match card numbers regardless of case.
  • Cost charts read the calendar in Sydney time rather than UTC — you may see a repair or purchase move to a different month the first time you view a chart after upgrading; totals for the year are unaffected.
  • A repair’s recorded coverage (warranty or insurance) now reaches the cost reports, and repair history names who acted, not just their role.
  • SCIM discovery routes now answer correctly for an identity provider’s setup wizard.
  • Expired parent sign-in links and portal session revocations are swept automatically instead of growing forever.
  • Feedback submitted in-app is now attributed to its actual author.
  • The mobile top navigation no longer grows to cover the screen — it scrolls sideways instead.
  • A repair claim of device ownership made through the client portal is now flagged when it can’t be verified against a device assigned to that person.
  • A retired or disposed device can no longer receive a remote command, and wipe and remote-action controls are gated on the permissions and settings that actually apply, instead of being hidden only after a refused request.

Known issue. The Loans page still shows an old Sync from MDM button that calls endpoints this release removes; it fails until you use the new per-group Sync now control under Admin → Loan groups instead. A follow-up fix is tracked.

What to do first. Take a verified backup and upgrade normally.

Two migrations, both data repair rather than schema change. One clears a connector field that may hold a credential; the other disables a small number of remote-access targets left misconfigured. Take a verified backup first.

This closes the last of the August security audit — fourteen smaller findings that were real but not urgent. Nothing here changes how the desk is used. Highlights: a blocked outbound request could once put an API key into an error message; a portal streaming link is now single-use instead of working for its whole sixty-second life however many times it was presented; an idle session now actually expires, instead of the setting being accepted and ignored; and plugboard-agent install-service — instructed since the agent shipped — now exists, rather than silently starting a foreground poll loop instead. The full record is in the changelog.

What to do first. Take a verified backup and upgrade normally. Nothing else is required.

One migration, additive — two nullable columns and an index on Loan; nothing is backfilled and no existing query reads either. Take a verified backup anyway.

This closes the rest of the August audit findings, alongside the launch blockers and should-fix items that went out in 0.7.0 through 0.7.2.

  • A loan can have a due date. The desk can say when a device is expected back, derive it from a per-pool loan period, and list what is late.
  • The assistant can see the ticket queue. Until now it had tools for repairs and nothing for tickets, so “show me open tickets” confidently returned repair submissions instead.
  • Where a device was last seen is now its own permission, network.clients.view, rather than riding on the broad device.view every technician holds. Client sightings are location data about children, so a school now grants it deliberately. See permissions.
  • The public demo carries documentation. The module shipped in 0.6.1 with an empty seed, so the one deployment every buyer is pointed at showed an empty product until now.
  • /api/health no longer names the build commit, only the version.
  • HSTS is set on every served surface.
  • The control plane’s routes are now checked by an authorisation test rather than relying on every handler remembering to guard itself.

Everything in 0.7.1, plus a fix to the public demo seed. Customer instances are not affected by the bug or the fix — the seed refuses to run outside the public demo — so if you are upgrading, 0.7.2 and 0.7.1 are the same product, and the 0.7.1 and 0.7.0 notes below are your release notes.

  • The public demo now comes back up cleanly after a deploy, instead of occasionally failing to restart behind a numbering clash in its sample data.
  • The assistant no longer disappears for the rest of your sitting when a single permission check is slow to answer.
  • Reordering or hiding a tab under Account → Appearance now updates the page in front of you immediately, instead of waiting for a reload.

Everything in 0.7.0, which never shipped. The 0.7.0 tag failed its own release gate over a dependency vulnerability in a build tool, so no image was ever built, signed or deployed. If you are on 0.6.2, this is your 0.7 release, and the 0.7.0 notes below are part of it.

Five control-plane migrations and seven customer-instance migrations — all additive: new columns, mostly nullable and backfilling nothing, plus one that numbers every repair already in your database, oldest to newest, so the numbering reads as a history. Take a verified backup first; see updating.

Upgrading the panel requires rebuilding every region host.

  • Repairs have a number now, the same way tickets always have, and search finds a job by number whether it was logged as a ticket or a repair — the two answer as one list, newest first.
  • The search box can search your own external helpdesk too, if you run Zendesk or Web Help Desk alongside Plugboard — off until an administrator turns it on per connector in Admin → Connectors, because it searches as the one credential Plugboard holds rather than as the person searching.
  • You can set up your own navigation under Account → Appearance — hide tabs you never use and reorder the rest, for yourself only. The search box also finds pages now, not just records, and understands the words people actually use rather than only what is on the tab.
  • Network client tracking has a switch, in Admin → Security: off until a school turns it on, one sighting kept per device rather than a history, and a retention window between 1 and 90 days. It existed in the database from the day the network module shipped and was unreachable until now.
  • An on-premises connector can be assigned to a site in Admin → Connectors, which is what makes Active Directory, Synergetic, PaperCut, Web Help Desk and SNMP printers actually work on a managed deployment.
  • Ticket comments now say who wrote them — a technician’s name, or Automatic triage — instead of “Someone” for anything not typed by a signed-in person.
  • A URL Plugboard does not recognise now opens inside the desk frame, with navigation and a way back, instead of a bare unstyled 404.
  • Several screens — moving between pages, opening a ticket, the submissions list — got faster by asking the server once for things that do not change while you are working, instead of on every click.

Highlights, not the complete list — see the changelog for the rest:

  • A portal request’s status can no longer be read by anyone the request does not belong to.
  • A restricted documentation library can no longer be renamed, moved, unrestricted or deleted by someone who is not allowed to read it.
  • A connector agent’s token now expires and can be rotated without an outage.
  • The assistant now requires a permission to open.
  • Twelve actions that decide who can read what now write an audit row.
  • Revoking a kiosk now actually stops it working.
  • The build toolchain for the ticket classifier’s regex engine no longer pulls in a vulnerable archive library — a build-time dependency fix with no runtime effect, and the reason 0.7.0 itself does not exist as a release.

Never published. The release gate stopped it and no artefact was ever built. There is no upgrade path from it because it was never installable. Its changes shipped, unaltered, as part of 0.7.1 above.


No migrations. Upgrade from 0.6.1 without ceremony.

Three things 0.6.1 shipped broken, all inside the features it added:

  • The Network page never loaded. It asked the API for the estate without signing the request, and had no way to show the error, so it looked like it was still loading rather than like it had failed.
  • The Meraki, UniFi and SNMP connectors could not run. They installed, they tested green, and the first real call answered “connector not registered”. A test now refuses to let a connector ship unreachable.
  • The Documentation page rendered outside the desk frame, with no navigation and no way back.

What to do first. If you configured a network connector on 0.6.1 and saw an empty pane, this is why. After upgrading, open Network and press Refresh from every connector once.

Four migrations. Take a verified backup first.

There is nothing to upgrade from 0.6.0. 0.6.0 was tagged and never published: the release gate stopped it on two failures and skipped every job downstream, so no image was built or signed, no release was created, and nothing was deployed anywhere. 0.6.1 is the first published release of this work. If you are on 0.5.3, 0.6.1 is your next version.

A minor release: it adds two sellable modules, three provider categories and three connectors.

Documentation. The desk’s own runbooks, kept apart from the public knowledge base. Spaces with their own access rule, version history on every save, a named owner per document, and a review cycle so a stale page says so. Documents bind to a device model, a ticket category, a campus, a monitored service or a connector, so a ticket about a Chromebook shows the Chromebook runbook before anybody searches, and says why. Sold from Standard.

Remote access. A button on the device page that opens whatever remote support tool you already run, with the machine selected. Configured as a link, so it works with tools we have never heard of and needs no connector. Plugboard never carries the session and never holds a credential that could control a machine.

The network estate. Wireless, switching, gateways and the filter across Meraki, UniFi and SNMP, merged rather than resolved. Network devices match ticket text, and a device going down raises an event on the monitor board you have already configured alerting on. Sold from Standard.

A kiosk is a device rather than one shared key. Name a counter, say which campus it stands on, decide whether it offers card tap, and revoke one iPad without un-enrolling the library.

Global search also began reading article bodies rather than titles and summaries only.

PaperCut never worked on a hosted deployment. A connector whose base URL carried a path requested the wrong URL. Decommissioned network hardware was never forgotten. And the portal returned to the sign-in screen while still holding the last student’s session token for the length of a round trip. On a kiosk in a corridor, a reload in that gap landed on the previous student’s records.

  • Internal documentation is served only to signed-in staff, never from public routes, enforced by a test rather than a convention. A restricted space withholds its documents, including their titles, from search, from ticket suggestions and from anyone without the extra permission.
  • Client sightings on the network pane are location data about children, so they are off by default, keep seven days (ninety at most), are never exposed to a portal, and are stored one row per device rather than as a history.
  • Starting a remote session is its own permission, separate from managing devices, and every session is recorded against the person the device belongs to.
  1. Take a verified backup. Four migrations.
  2. Upgrade, then go straight to 0.6.2. Three of the features this release adds do not work until then.
  3. Expect the two new modules to appear on their own. Modules are on unless a school switches them off, so a Standard licence or better gets Documentation and Network in the navigation on first sign-in. Turn either off under Admin, Features if you do not want it.
  4. If you enable Network, read client sightings before turning tracking on. It is off, and it should stay off unless you have decided you want it.
  5. Kiosks: claiming your first kiosk device switches the old shared key off for the whole tenant, and any remaining old-style device stops tapping at that moment. Do the rollout in one sitting, not over a week.

Never published. The release gate stopped it and no artefact was ever built. There is no upgrade path from it because it was never installable. See 0.6.1.


Everything before 0.6 and everything after it is in the changelog, in the same format, with the ⚠ migration marker on the releases that carry one. The notes for whichever version you are being offered are shown in the status panel and under Admin, Licence before you apply it.

If you are several versions behind, upgrade through them in order rather than jumping. Migrations are applied in sequence, and the notes for each release tell you what changed for your people.