Skip to content

Release notes

Written for somebody deciding whether to take an upgrade: what changed, whether it touches the database, and what to do first.

The full technical record is the changelog, which lists every change in every release. Your deployment carries the notes for the version it is being offered: the status panel and Admin, Licence both show them, along with whether that release carries a migration. CHANGELOG.md ships with the software.

Deployment status, 29 September 2026: 0.22.1 is available on the beta channel and runs on staging and the public demo. The stable channel still recommends 0.21.0 while the 0.22 release completes its soak. Check your deployment’s status panel for the version it is actually running and the update it is offered.

⚠ Migration: this update records the first reuse detection on a retired refresh token. Take a verified backup before upgrading.

A stale browser presenting the same retired token repeatedly now creates one security event and cannot sign out a later, unrelated session. A dropped live update stream no longer rotates a healthy refresh token on each retry; stream tickets reject sessions that have ended so the browser returns to sign-in.

An initial reuse alert still ends live sessions for that account. Investigate an unexpected first alert as a possible credential replay; repeated alerts with “no live sessions” on earlier versions may have come from the same stale browser retrying.

0.22.0: decision-provider release and reliability fixes

Section titled “0.22.0: decision-provider release and reliability fixes”

⚠ Migration: this full release includes the additive 0.22 release-candidate changes for decision provenance, school criteria, tags, history and mail delivery. Take a verified backup before upgrading.

The release includes the 0.22.0-rc.1 features below: optional reviewed decision providers, school criteria and AI tags, and Microsoft 365 shared mailbox intake and sending. Jev starts off, Laya has no trained Plugboard checkpoint, and identity approvals remain manual.

Repair lodging and ticket visibility in the portals, worker status sync, support backup restore and Teams follow-ups now use the intended department scope. Failed repair lodging cleans up the unlinked submission and releases its loan. Repair and parent-portal status labels wrap beneath titles on phones.

Structured AI answers now work with the tested Ollama 0.32.14 image, llama.cpp-backed OpenAI-compatible servers and Anthropic schemas. Current OpenAI models receive their supported token-limit field. Hosted deployments no longer offer new Ollama or Laya configurations; existing local-model records remain visible. Loan pagination and failed-device-erase confirmation also retain the user’s action when an update arrives late. This release also updates three dependencies flagged by the release audit.

Before relying on AI, confirm your chosen provider is configured and enabled, and review its suggestions on your own data. Provider setup and automatic-action accuracy remain school-specific checks.

Staging release candidate, 28 September 2026. This preview combines optional self-hosted Laya and hosted Jev behind the same decision engine. Jev is off by default and inputs are pseudonymised before leaving Plugboard. Existing chat connectors can provide uncalibrated answers; rules and manual work remain usable with AI disabled. Changing the model starts a separate human accuracy record.

The decision engine supports ticket triage, repair type, sentiment and welfare, message intake, conversation checks, same-issue matching, routing, assistant intent, portal help and catalogue requests. Suggestions use the school’s own choices, show model details and allow human review. Welfare, department transfers, identity approvals and resolution remain subject to their staff controls.

Schools can describe their decision criteria, preview samples and configure up to ten optional AI tags. Triage can link authorised resolved-ticket history; history-only suggestions remain manual. Assistant commands retain fast paths, exact action reviews and readable ticket status labels such as In Progress.

Microsoft 365 mailbox sending, polling and incoming attachments are included, with scoped worker credentials and replay handling. Email replies keep unverified sender labels; verified Teams requester replies retain their waiting-ticket behaviour. Ticket merge, timer and conversation concurrency fixes are included.

Migration: additive decision provenance, criteria, tags and history changes, plus mail delivery and attachment replay keys. Take a verified backup first.

No trained Plugboard checkpoint or calibrated automatic-action defaults are released. Training remains paused for human review of the proposed golden set. Live Jev validation requires an explicitly configured provider key. This candidate updates staging only; it does not update the public demo or promote stable.

0.21.0: Teams intake, a visitor register, network IP addresses and the mobile app

Section titled “0.21.0: Teams intake, a visitor register, network IP addresses and the mobile app”

⚠ Migration: three additive migrations. One adds three tables for network IP addresses and configuration snapshots; one adds two tables and a Teams ticket source for Teams intake, and extends the database function that finds which school an unauthenticated request belongs to; one adds two tables for the visitor register and a per-kiosk visitor sign-in setting, off by default. None removes or rewrites customer records. Take a verified backup first, and use the normal update procedure. This release follows the normal beta and staging rings; stable promotion is separate.

None of the four new features has yet been run against real vendor systems. Teams intake has not met a school’s Teams tenant or Azure Bot, the network additions have not met a live Meraki organisation, UniFi console or SNMP device, and the visitor register has not run on kiosk hardware or sent a real email. Each is tested against the vendors’ documented formats. If you turn one on, check the first results against the source, and tell us what does not match.

Microsoft Teams ticket intake. Staff message the school’s IT bot in Teams, or @mention it in a channel, and a ticket opens through the same intake as email: the requester is identified by their Entra object ID, never a display name, and routing and auditing are unchanged. A channel thread stays on one ticket; a chat joins its open ticket unless the message starts with new:. Public replies and closures are posted back, but channels and group chats get a pointer, never the reply itself, and internal notes never go. Attachments are recorded by name only. The bot uses the school’s existing Entra connector app registration and accepts nothing until an administrator’s Test has passed. Public cloud only; Slack is not included. See Microsoft Teams intake.

Visitor and contractor register, part of the campus operations add-on (Facilities module), with no new plan or price. Visitors and contractors sign in and out on a reserved kiosk with the new visitor sign-in option, or at the office, and the register keeps the on-site list for an evacuation. The person being visited is emailed by default; turning that off is an audited setting, and every sign-in records whether it was on. A contractor’s Working With Children Check is recorded as sighted by staff, with expiry reminders; Plugboard does not check a registry. A contractor with an expired or missing check is signed in and held at the office rather than turned away. See visitors and contractors.

Network IP addresses and configuration history. The Network pane gains an IP addresses tab: subnets and VLANs from Meraki, UniFi (local) and SNMP, plus subnets and reservations recorded by hand, with utilisation and address conflicts. Client addresses appear only with client tracking on and network.clients.view. A Configuration tab keeps read-only, versioned snapshots of Meraki and UniFi (local) configuration with a comparison between versions. Secrets are removed before anything is stored, no new device credentials are asked for, and nothing is pushed, restored or exported.

New permissions. network.config.view (read configuration snapshots), visitor.view, visitor.manage and visitor.configure. No built-in role other than Owner holds them; grant them to the roles that need them. visitor.view, visitor.manage and network.config.view are free Participant permissions; visitor.configure is Technical. See the permissions reference.

Reviewed CSV import for devices and stock. Device and stock imports now show every row’s outcome before anything is written, and apply exactly that review. All three imports, people included, skip invalid rows instead of failing the file and return them as a file to fix. A stock count imported during a kiosk sale does not overwrite the sale. See devices and stock.

The assistant filters the page you are on. On tickets, devices, people, loans, repairs, stock, AV rooms, printers and monitors, a request such as unassigned tickets or low stock sets that page’s own filters. See the assistant. Known errors reach their incidents: a document bound to a problem ticket is listed first on every incident caused by it. See documentation.

The mobile app is not yet available. Version 0.21.0 of the iPhone, iPad and Android app for technicians, the client portal, parents and kiosks is prepared for the App Store and Google Play but has not been published in either. See the mobile app.

Also fixed: confirming a managed-hosting onboarding now creates the administrator named at confirmation on the new deployment. New managed deployments have the hosting provider’s weekly server backup switched on. Custom domains on managed hosting no longer fail with Cloudflare error 1456. LDAP and Active Directory agent jobs no longer fail on binary identifiers. The account page no longer requests signed-in devices in demo mode. The retention purge’s audit entry now counts the network client sightings, Teams messages and visitor records it removed.

0.20.1: stop legacy AI calls when school settings cannot be read

Section titled “0.20.1: stop legacy AI calls when school settings cannot be read”

This patch follows the 0.20.0 feature release. It adds no database migration; schools upgrading from an earlier version still need the 0.20.0 migration and upgrade checks.

Legacy AI calls now stop if the school’s AI settings cannot be read. The ticket classifier and ticket-from-description path could previously continue to provider selection after a settings lookup failed, without confirming the school’s AI policy. They now return no AI result before selecting or calling a provider. A successful read of the school’s disabled setting still disables AI; a successful read with no saved setting retains the existing on-demand defaults. The newer AI service already stopped on a settings-read failure.

The issue was reproduced with a synthetic database-read failure and covered by a regression test. No live disclosure was observed.

The 0.20.0 notes remain the feature, migration and scale-test reference. OneRoster remains a preview requiring a school-provider pilot; this patch adds no provider validation or certification. Use the normal update procedure.

0.20.0: safer sign-in, larger registers and a OneRoster preview

Section titled “0.20.0: safer sign-in, larger registers and a OneRoster preview”

⚠ Migration: one additive migration creates three database indexes: two for ordered people lists and one for device assignments. It does not remove or rewrite customer records. Take a verified backup first, allow time for index creation on large databases, and use the normal update procedure.

Review connector-agent trust when upgrading. Creating an agent or rotating its token now requires an unrestricted whole-school administrator and fresh authentication confirmation. An agent can answer LDAP sign-in jobs, so delegated connector-management access alone is insufficient. Review existing enrolments, revoke unknown or untrusted agents, and enrol approved replacements. Rotation keeps the old token valid for seven days and is not immediate containment. See connector-agent security.

SAML sign-in must start in Plugboard. Responses are bound to the request and intended recipient, and reused assertions are refused. Unsolicited sign-in from an identity-provider launcher is not accepted. Test the school’s IdP after the upgrade. Multiple API replicas need the start and callback to reach the same process; an API restart invalidates unfinished sign-ins. See SAML setup and routing.

Larger registers load in pages. The loan desk and repair loan picker fetch 50 records at a time, with search and filters applied across the authorised pool. Totals and new-number suggestions cover the whole pool, and borrower warnings include loans outside the visible page. Bulk actions apply to the current page. Custom console clients should use /loans/inventory; the legacy /loans list now rejects a result above 1,000 records instead of returning an unbounded register. See loans and the loan API transition.

People and device CSV imports do less repeated database work. Device location filters use database grouping, and the new indexes support people paging and assignment lookups. Ticket configuration options refresh within 30 seconds after a change made through another API process. API responses and browser API requests now explicitly prevent caching sensitive data. Live updates continue to respect an open edit, and changing a ticket filter clears hidden selections.

OneRoster is available as a read-only preview. It supports the OAuth 2 REST bindings for OneRoster 1.1 and 1.2 and imports student/staff people records. It does not provision accounts, import family relationships or write back to the SIS. Synthetic tests include 100,000 users; no live school-provider validation or 1EdTech certification is claimed. Pilot it with independently checked counts before scheduling a school sync. See OneRoster setup. Sentral also removes its former silent 20,000-record cutoff and refuses an incomplete pull. See Sentral roster limits.

Also fixed: campus technicians can use an authorised local device’s shared district MDM for wipe requests and LAPS without needing permission to manage the connector. Device scope, MFA, approval and source-binding checks remain. Failed configuration reads now show unavailable states and retry controls rather than empty catalogues or default policy values. Native embedded-database starts apply row-level security and run application processes as a restricted database role; externally managed databases still require the operator’s separate migration-owner and application-role configuration. The default container release does not publish native installers; check the download centre for the versions actually available for your platform.

A dedicated staging tenant held 100,000 each of people, devices, tickets, repairs, loans, ticket comments and synthetic audit entries. Separately executed patched services reduced the median loan read from 2,819 ms and about 49 MB to 103 ms and about 25 KB for a 50-row page. In single import runs, creating 1,000 people took 204 ms and creating 1,000 devices took 1,587 ms; repeat imports were also checked.

These measurements used fictional data against the staging database. The patched services ran separately from the deployed application, without applying the new indexes to staging. Read medians used five sequential samples; import timings used one run each. They are not browser timings or a sustained multi-user capacity guarantee. The CSV request limit remains 5,000 rows, and this release does not introduce a resumable 100,000-row import job.

0.19.3: sentiment on tickets, staff experience, and replacing a device on a repair

Section titled “0.19.3: sentiment on tickets, staff experience, and replacing a device on a repair”

⚠ Migration: three — repair replacement, the portal device snapshot and text-message delivery status, and sentiment. Take a verified backup first.

Sentiment on tickets. Every requester message is read for tone (calm, concerned, frustrated, angry, distressed), urgency and signals such as chasing or being blocked from class. The queue gets a Tone column and a “Frustrated requesters” filter, and Briefing lists them. Suggest mode proposes a one-step priority bump; auto mode applies it, never to the top priority, and it can always be undone. With no AI, a rules pass still gives a coarse level from facts the desk already holds, labelled Rules rather than AI. A student ticket using a safeguarding word, or read as distressed, is flagged to staff alongside the school’s safeguarding contact.

Staff experience. A nightly 90-day summary for each staff member — waits, reopens, chases, satisfaction and how often their tickets read as frustrated — shown on the person page, in Briefing and on a new Experience report. It needs report.view and client.view.

No per-person score is ever calculated or stored for a student or parent. They appear on the Experience report only as school-level totals, such as the share of student tickets that read as frustrated — never as a row, a name or a score. See sentiment & staff experience.

Replace device on a repair. Choose the new device from stock or a loan already out, or record one on its way, and say what happens to the old one: back to the vendor with an RMA, kept as a spare, kept for parts, e-waste, or held for a data wipe. A covered repair never asks the family to pay for the replacement. See replacing a device on a repair.

Also in this release: the person page now answers questions about a person’s loans, devices, repairs and tickets straight from the records, with no model call; portal-lodged tickets carry the same MDM device snapshot portal repairs already did; parent portal status lines and loan notices can be translated, with only approved translations reaching families; and the Sent tab shows Twilio delivery status (needs PUBLIC_URL on HTTPS). The AI value card moved from the dashboard to Briefing, retitled “What the assistant saved you”. See what we process.

0.19.2: managed AI moves off OpenAI and Anthropic, and quieter monitor alerts

Section titled “0.19.2: managed AI moves off OpenAI and Anthropic, and quieter monitor alerts”

No database migration. This includes 0.19.1, whose release was cancelled before it deployed.

Managed AI now runs entirely on open models that DigitalOcean serves itself: gpt-oss-120b for fast work, NVIDIA Nemotron 3 Ultra for capable work, and BGE-M3 for embeddings. OpenAI and Anthropic are no longer sub-processors — the text never reaches a model’s creator, so DigitalOcean is the only AI sub-processor for managed AI, still processing in the United States. Calls are still pseudonymised before they leave. The managed connector moves over by itself on start-up, and the move is audited. Cost per call is lower too: about US$0.0005 for a triage call and US$0.006 for a capable one.

0.19.0’s plan of GPT-5 mini and Claude Sonnet 5 needed a higher DigitalOcean account tier than managed AI runs on, so on a deployment that took 0.19.0 every call to them was refused and AI suggestions stopped until this release. If you skipped straight from 0.18.2 to 0.19.2, this never affected you.

  • A monitor that stays down no longer piles up alerts. A Critical monitor re-alerts every ten minutes, and each repeat used to add another sticky card with the same text. Repeats now replace the card on screen with the latest duration, the bell keeps one entry per monitor, and the alert clears itself when the monitor recovers.

See the assistant and AI features and what we process.

0.19.0: the assistant becomes the desk’s background brain

Section titled “0.19.0: the assistant becomes the desk’s background brain”

⚠ Migration: eight migrations — the AI engine, notices, the fix catalogue, repair outcome and cover, known issues, API-key write approvals, identity runbooks and the portal device snapshot. Take a verified backup first.

Work is prepared before anyone opens it, every AI value is labelled and can be undone, and with no AI connector configured the desk behaves exactly as 0.18.2 did. Managed AI runs on DigitalOcean; names, emails, phone numbers and IDs are masked before every call leaves. Each AI feature has its own mode (off, shadow, suggest, auto) under Admin, AI settings; auto unlocks only after a proven accuracy record, and never for identity work.

If you take this release, read 0.19.2’s notes above before you rely on AI suggestions. 0.19.0 shipped planning to use GPT-5 mini and Claude Sonnet 5 through DigitalOcean; that never worked on the account tier managed AI runs on, so every managed AI call failed until 0.19.2’s model change. OpenAI and Anthropic were briefly listed as sub-processors behind DigitalOcean for this reason; as of 0.19.2 they are not.

Ticket brain. A brief, triage suggestions and a reply draft are prepared in the background when a ticket arrives and after each requester reply, so opening a ticket never waits on a model. Triage shows as ghost values with one-click accept, dismiss or undo; drafts appear greyed in the reply box (Tab takes it) and are never sent without a person. Resolving offers a wrap-up note, time worked and a knowledge-base draft.

Same issue. Duplicates are found by similarity. A same-person duplicate within 48 hours can merge automatically, with one-click unmerge. Outage clusters at a site are proposed as an incident that groups the reports, posts a known issue and tells each requester once.

Briefing replaces the old assistant page: what needs you, what was done overnight (with undo) and what was spotted. The page assistant now knows which record you are on, so “what does this person have on loan” answers for that person rather than every loan issued.

Joiners, movers and leavers. SIS changes plan runbooks — disable, revoke sessions, licences, groups, mailbox delegation, device and loan recovery — that are previewed, approved with step-up, staged and undoable; nothing is deleted. Access requests on a ticket get a one-button card that already knows the groups, licences and seats available. New Licences & access reports.

Device fixes on staff devices: a catalogue of fixes the AI can suggest and a person runs through the MDM. Never on a student device.

Repairs get a likely-outcome card at lodgement (result, days, cost range) and cover agreements, so a repair covered by a school’s insurance with its vendor never asks a family to approve or pay.

Notices gain approved translations of loan and repair notices, text messages with quiet hours, and family contact preferences.

Portal, kiosk and parents: “Which device?” on lodging with an MDM snapshot, help articles and known issues while typing, known issues on the kiosk tap, and plain Now / Next / When repair status for parents. No generated text reaches a student or parent; safeguarding words show the school’s configured contact instead.

Admin gains AI settings, AI activity (every model call and suggestion, with export), and a value card on the dashboard (moved to Briefing in 0.19.3, retitled “What the assistant saved you”). The people page is reworked around a details rail and a grouped menu, and its assistant box now asks about that person.

Changed: API-key writes now wait for a person. MCP and /v1/actions writes no longer run on the key’s word alone. A write tool called with an API key is held as a pending approval, audited as mcp.write.pendingApproval, until somebody with integration.manage who also holds that tool’s own permission approves it (with a step-up) or declines it, under Admin, API & webhooks, Approvals. Requests lapse after seven days. Anything scripting writes against /api/mcp or /api/v1/actions must now wait for, or poll, the approval — POST /v1/actions/:name answers 202 with a { "status": "pending_approval", "approvalId" } body, pollable at GET /v1/actions/approvals/:id. Reads are unchanged. API keys also gain an AI switch: keys made before 0.19 keep AI access, new keys start without it.

See AI features, AI settings, AI activity, access & runbooks, cover agreements, translations & text messages and what we process.

No database migration. A small follow-up to 0.18.1.

  • Notifications about something going wrong elsewhere, such as a monitor going down, a failed backup or device sync, a breached SLA or a monitor alert, now arrive as warnings. They used to show a green success tick.
  • The dashboard opens on its title. The desk setup and repair outcome reminders sit below “Dashboard” rather than above it. Desk-wide notices, such as the licence banner, stay at the top of every page.

0.18.1: one plan, a trial and read-only mode, and interactive reports

Section titled “0.18.1: one plan, a trial and read-only mode, and interactive reports”

This is the first 0.18 release to ship; 0.18.0 stopped at its final checks and was never offered to any deployment.

⚠ Migration: one application migration, 20260925090000_licence_one_plan, adds a trial start date, device blocks, campus operations and Business seats to the licence record, and a Business seat count to usage reports. No existing data is changed. The control plane has its own migration, 20260924000000_one_plan_licence_pricing, which only Plugboard runs; a self-hosted school does not. Verify a backup before upgrading. No new permissions.

Licensing behaviour changes on upgrade. Before 0.18.1, a school without a licence had every module with no end date, and removing a licence did the same. From 0.18.1:

  • An unlicensed school is on a 30-day trial with every base module and no add-ons. The clock starts the first time 0.18.1 runs, so a school that is unlicensed today gets the full 30 days from its upgrade. After that the desk becomes read-only until a licence is added.
  • Removing a licence no longer unlocks everything. The school goes back to what is left of its trial, or becomes read-only straight away if the trial has been used.
  • A licence that expires past its grace days, or is cancelled, also makes the desk read-only. Before, it switched modules off and hid their records; they now stay readable.
  • If your school is licensed and current, nothing changes.

Read-only means staff can still sign in, read everything, back up, restore and export, look after their own account, take access away from people, and add or renew the licence. Every other change is refused with a message saying how to fix it, including changes through API keys, REST actions and MCP. The portals, kiosk, inbound email and webhooks keep taking requests, and sync with other systems pauses. A banner tells everyone, and warns in the trial’s last week.

There is now one Plugboard plan: A$250 a month billed annually, with every base module, 2 Technical seats, 2,000 managed devices and, on managed hosting, 5,000 hosted AI calls a month. Extra Technical seats, Business seats, 1,000-device blocks and the campus operations add-on (Facilities, Administration, Other departments and School operations) are added on top. Each staff account is a Technical seat, a Business seat or a free Participant, set by its roles and shown on the Users page; viewers, requesters and approvers are free, where before every active account counted. Going over shows a warning and is settled at renewal. Licences on the earlier tiers keep their terms. Admin, Licence shows seats, devices, device blocks, campus operations and hosted AI against what the licence includes.

Admin, Campuses could fail to load once a school had a campus, because two parts of the server both answered for campuses. That is fixed. Creating and deleting a campus now needs site.manage and is written to the audit log; before, it went through connector.manage and was not audited. Campus pickers elsewhere list the campuses of the person using them.

Reports and Cost breakdown are rebuilt to match the dashboard, with charts you can hover, or focus and step through with the arrow keys, for exact values. Legend keys switch series on and off, report tables sort by any column, and report summaries show as a row of figures. On Cost breakdown, Manage periods lines up with the filters, and Share shows the breakdown as a donut. CSV exports are unchanged.

Admin, Roles groups each role’s grants by area, with readable names beside the permission keys. Admin, Security and Admin, SSO open on a summary of what is set, with each area or sign-in method one click away; every setting and check is unchanged. Admin, Features groups modules by area with their icons, says why a module is off and shows what depends on what. Admin, Backups lists run history last.

Anything that opens or closes because you pressed something now grows or shrinks smoothly, tabs and sub-pages slide in from the side you moved towards, and pages load in from top to bottom. Alert notifications show their full text on amber and no longer shake. The page assistant is on Tickets, AV and Documentation, and fits its space on every page. AV, Printers and Network headers and empty states match the rest of the desk, and the ticket timer’s … menu opens again.

See licence and plan, plans, modules, reports, costs, roles, single sign-on, campuses and moving around a page.

0.17.1: time tracking on tickets, and People and Directory as one screen

Section titled “0.17.1: time tracking on tickets, and People and Directory as one screen”

This is the first 0.17 release to ship; 0.17.0 stopped at its final checks and was never offered to any deployment.

⚠ Migration: one application migration, 20260924090000_ticket_time_tracking, adds work type, start and end, billable and linked-message fields to time entries, server-side timers, quick time without a ticket, and an estimate on each ticket. Verify a backup before upgrading. Time tracking switches on for every school that has Tickets; you can switch it off on Admin, Features. No new permissions.

Tickets now track time properly. A timer starts when you begin writing a reply or note, or from Start timer if your school prefers, and only one of yours runs at a time. Timers are kept on the server, and a tray beside the bell lets you pause, resume, log or discard them from any page. A timer left running for hours asks whether to keep or trim it before it is logged. The composer has a time field that fills from the timer and takes 25, 1.5h or 1h30, with quick-add chips and a work type, and the time is linked to the reply or note it went with. The Time chip shows logged time against the ticket’s estimate, which can come from its category. The Work tab lists every entry by day, split by work type and person. Resolving a ticket you have logged nothing on offers to add time first, or requires it if your school says so.

My time (/time) shows your week against a daily target, with quick time for walk-ups, meetings and travel that have no ticket; a quick entry can be turned into a ticket later. Leads with report.view get a Team view. Schools choose the timer mode, daily target, backdating window, resolve rule, long-timer threshold, report rounding, billable time, work types, and estimates and work types by category under Admin, Tickets, Time tracking. Editing somebody else’s time, and changing these settings, needs workflow.manage. Reports gain Estimate vs actual, and Ticket effort can group by work type, campus, department or requester, with report rounding applied to each entry. A report whose module is switched off is now refused by the server, including scheduled emails.

People and Directory are one screen. People is in the navigation for anyone with client.view or directory.view, with a Roster view and an Accounts view that searches every directory connection. Old /directory links, including those on tickets, open the Accounts view with their search and ticket. A person’s Account tab now lists their groups, and people with identity.license.manage can assign and remove licences there with a typed name, a reason and fresh authentication. For live accounts, inbox delegates in the Accounts view are read-only; manage delegation from the person’s Account tab. Search all accounts replaces Manage in Directory.

The reminder about closed repairs that need an outcome is now a banner on the dashboard and the Submissions list, instead of a notification that came back on every page. The ticket’s Files chip is gone; use the Files tab. On a repair, Repair context has moved to the left column, above Vendor & communications.

See time tracking, ticket settings, people, reports, submissions and the audit log.

0.16.0: one way of moving, rebuilt screens and staying signed in

Section titled “0.16.0: one way of moving, rebuilt screens and staying signed in”

⚠ Migration: one application migration adds the optional repair outcome Result; there is no control-plane migration. Verify a backup before upgrading. Existing outcomes have no Result until somebody edits them. No permissions change. Product photos are stored with the product, and the portal photo address is public in the same way the portal catalogue already is.

Staff are no longer signed out of every device without warning, which usually happened first thing in the morning. Opening the desk with an expired sign-in could renew it on a page that was about to be replaced, and the next refresh then looked like a stolen token. The server now hands the same renewed sign-in to any page that asks within the short grace window. When a retired token genuinely comes back, the forced sign-out is recorded in Logs as Refresh token reuse detected.

Classic and Modern now move the same way. Buttons press and spring back, a record opened from a list grows out of the row you clicked, in-page links scroll clear of the navigation and briefly outline where you landed, and tabs slide. Notifications are compact, pause while you point at them, show failures in red without the alert chime, and at most four show at once. The Assistant is back in the bottom-right corner on tablets and computers; phones keep the header button. Each page’s own assistant sits at the top of the page.

Dashboard metrics form one balanced panel. Needs attention is colour-coded by urgency, Service health leads with a one-line verdict, and Recent activity is grouped by day. Tickets bring ThreatLocker Approve and Deny back to the top of the ticket, add a Connected systems card and show time, watchers, checklist and files as compact chips. Repairs show a six-stage progress strip and keep status changes in a Move to menu. Recording an outcome, for one repair or for several closed repairs at once, uses one form with a new Result: repaired, replaced, no fault found or beyond repair.

Devices put privileged actions before the records and History & logs last, show every remote command as a labelled, coloured button, show warranty coverage at a glance and show missing compliance information in red. Each person has a full page, which every person link now opens; the People screen keeps a quick preview with common actions. Products can have a photo or an icon, shown on the desk, the student portal and kiosk, and the parent portal, and buyers in purchase history link to their person page.

See the dashboard, tickets, submissions, devices, people and stock.

0.15.1: one consistent desk, saved dashboards and clearer portals

Section titled “0.15.1: one consistent desk, saved dashboards and clearer portals”

This is the first 0.15 release to ship; 0.15.0 stopped at its final checks and was never offered to any deployment.

No database migration. Every staff area now follows one working language: labelled local tabs, a single primary action, aligned rows and 44px controls, with honest loading, partial, stale and unavailable states. The Assistant launcher moves into the staff header. The dashboard becomes saved views of configurable widgets; people with the new dashboard.manage permission (wildcard administrators already hold it) can publish team templates, and each publish, update and removal is recorded in Logs.

Integrations show the permission behind each webhook event, and remote support previews its targets before launch. Branding previews light and dark before saving, Features explain why a module is unavailable, kiosks show their setup status, and email messages edit beside their preview. Security requests show who decided and when; backups lead with recovery evidence; compliance sections load and fail independently.

Inductions show programme progress and collect returns from the Issued view; the card checker keeps manual entry beside the reader. Reports name their data source and warn when an export no longer matches the chosen dates.

The client portal puts repairs and overdue loans first, and a kiosk that cannot reach the server offers a retry. Parents see each child’s open repairs and what they owe, with charges split into To pay and Paid and the school’s own repair spend marked as not billed to them. A sign-in link that hits a server hiccup can be tried again. Repair tracking shows the next stage and when it was last checked, and ratings work from the keyboard and cannot be sent twice.

Account separates Sign-in & security from Preferences, lists where you are signed in and lets you end a session you do not recognise. Staff sign-in no longer reports a server outage as a wrong password, and first-time setup says when your password was set even if the automatic sign-in after it fails.

AV, printers, network and monitors now put faults and their impact first, with clearer source, freshness and unknown-state information. Public status keeps internal details private and identifies retained results as stale when refreshing fails.

Documentation separates internal runbooks from public help, with ownership/review attention and a reviewed public-copy workflow. New requester articles start as drafts; publishing remains deliberate. Help preserves searches through retry, article deep links and browser history. The connector catalogue describes capabilities, not live services.

Access administration adds clearer user recovery, reviewed role grants and security-policy changes, visible unassigned campus work and separate SSO method setup. Existing permissions and identity checks remain. Configuration acceptance does not prove provider sign-in. These refinements require no database migration.

Automation rules now show execution order, scope, conditions, intended actions, historical previews and recorded outcomes. New drafts start disabled and changes have an explicit review before saving. Existing hourly limits and device-lock approvals remain in place. Assistant advice does not yet populate or apply rule drafts.

Stock adds product search and purchase evidence. Stocktake retains failed scans for retry; Field capture distinguishes local, pending, failed and synced records. Disposals reviews serials and sanitisation evidence before retirement and retains blocked serials. Recording sanitisation does not perform a device wipe.

Charge approvals, cost reports, software contracts and licence administration have clearer layouts, mobile forms and error recovery. Cost reports distinguish approved recovery from paid amounts; software keeps manual and provider counts separate. Missing update diagnostics stay unknown. These refinements require no database migration.

Service-desk settings now separate ticket configuration, repair workflows, departments, SLA targets and staffed hours into focused workspaces. Parts and repair-status edits use explicit save/cancel controls. New submission fields, exact custom colours and configurable repair stages are not included yet.

Repairs keep the next action, vendor conversation, temporary loan and outcome context visible. The loan desk has clearer filters, due states and short-lived Undo actions. Undo refuses to overwrite a newer loan change, and closing a repair still works when its loan has already been returned. These refinements require no database migration.

Operations has clearer project, list, board, timeline, resource, booking, maintenance and workload views, with recoverable errors and retained drafts. Roster lifecycle review shows new or changed records as signals to confirm, rather than claiming verified arrivals or departures. Local checks do not establish real calendar, finance or provider side effects.

Assistant now has clearer overview, recommendations, health, activity, settings and conversation views. Conversation shows progress and supports cancellation; administrator changes retain an exact review and outcome receipt. Operational health remains available independently of AI.

Connector setup guides you through service, access, validation and activation review. Recorded checks, demo data and private-network agent requirements are explicit. One-time agent tokens are hidden immediately when their dialog closes. Combined provider connections and shared credentials are not included yet.

Device inventory, device detail, Fleet and device jobs have clearer source and permission information, exact management targets and recoverable outcomes. Device jobs include serial selection. Missing observations stay unknown; a connection check does not prove a completed sync. These refinements require no database migration.

Dialogs now open and resize with a gentle spring and close smoothly, in both Modern and Classic themes. Save feedback preserves draft controls. Reduced-motion preferences use immediate transitions. This change requires no database migration.

Ticket detail keeps its AI summary visible above Activity, Work, Context and Files. Clearer classification, labels, watcher and time details make the record easier to scan. Technicians can include optional time with a reply or internal note. Those saves remain separate operations: a saved reply is retained during attachment recovery, and an uncertain time result asks for review before another attempt.

People has a clearer roster and linked-work profile. Directory searches authorised directory connections and identifies each account’s source, including incomplete search results. Same-name accounts stay separate. Cross-source person aggregation and new group/calendar tools are not included. Navigation section icons are restored and AI workspace is labelled Assistant. Identity actions retain the directory connection selected by the technician.

Assistant backend improvements bound inference and fallback work, strengthen source grounding, and support the progress/cancellation and reviewed-action interface above. Health remains independent of model responses. Real-provider performance has not been established by local verification. These refinements require no database migration.

Logs now carries the richer activity design through to the full history, with coloured icons, linked records, day groups and expandable event details. Search the Action dropdown for readable choices such as Ticket created. It includes the full catalogue of recognised audit actions across the application, even before your desk has recorded one, and retains older or custom actions from your history. Select several actions to show events matching any of them, then combine them with person, record type and date filters. Remove selections individually or clear them together. CSV exports respect those selections. Loading, retry and empty states make the current result clear.

The Modern dashboard has clearer tile faces, softer floating shadows and distinct coloured icons with restrained accents. Tiles sit directly above the page background, with a subtle glass highlight and gentle spring on hover and press. Reduced-motion preferences are respected. Navigation, Classic and your saved tile layout remain intact.

Recent activity now has coloured event icons, linked records, clearer timestamps and a refresh control. It starts with five updates and can expand to show the remaining recent entries. Full history remains available only to authorised users, and empty demo history is explained clearly.

The public demo no longer shows first-run setup prompts or redirects. Ticket AI availability also correctly recognises an enabled AI connection when another connection in the same category is disabled.

These changes are pending release.

0.14.6: an operational assistant and clearer school workflows

Section titled “0.14.6: an operational assistant and clearer school workflows”

The new Assistant workspace brings together operational health, recommendations, activity and conversation. It reads the sources your role and enabled modules permit, including services, connections, site agents, devices, loans and repairs. The overview uses recorded information without waiting for a model, and remains useful with built-in ticketing switched off. Missing, stale, unavailable and demo observations are labelled separately.

Recommendations link to supporting records and can be dismissed, reopened or snoozed for a day. Native conversation history is shared with the floating assistant, expires after seven days and follows your current access. Ticket searches are no longer mistaken for people searches.

The assistant can prepare an exact review for supported cloud connection tests, non-authentication connector display names, the product name and default Classic/Modern styles. Passwords, keys and routing stay in secure setup; agent-backed and finance tests also use that flow. This release does not add unrestricted administration, scheduled autonomous remediation, streaming or model-generation cancellation. Cancel applies to pending action reviews.

People now combines a searchable, filtered roster with the selected person’s permitted equipment and work. CSV import previews supported column mapping, matches, skipped rows and errors before applying; existing identifiers remain unchanged. Year, tutor group and campus use recorded data. The page does not invent classes, departments or successful source-sync dates.

Admin, Connectors guides setup through Service, Access, Validate and Review. Saving leaves a connection disabled until you explicitly enable it. This also applies when editing an enabled connection: saving pauses it while you test the changed settings, then review and enable it to resume use. Failed tests preserve your draft, and a passed connection test is shown separately from sync completion. Admin sections, permission choices, labels and retry states are clearer.

Client and parent portals put equipment, current repairs, loans, requests and linked children into a clearer overview. Parents have an explicit Sign out control. Public pages offer recovery from temporary read failures. Retrying a failed photo upload does not resend a reply, and temporary kiosk verification errors keep the device’s registration.

Modern surfaces have stronger frosted depth. Existing navigation choices and the ticket’s visible AI summary, checklists, subtasks, approvals and related context are retained.

Upgrade: no new database migration. Update API and web together. Existing permissions and module choices remain authoritative. Check the status panel or Admin, Licence for deployment availability; stable promotion and native installer publication remain separate.

0.14.5: faster answers with better ticket context

Section titled “0.14.5: faster answers with better ticket context”

The assistant returns direct answers for supported desk lookups without waiting for a model to rewrite them. Counts, dates, links and approval wording stay as the application produced them.

AI ticket summaries and reply drafts use linked device and repair details, category, queue, the latest public conversation and relevant published knowledge articles. Device models and serial numbers are labelled separately. The instructions distinguish physical keyboard faults from accessibility settings and account for work already booked. Internal notes and restricted documentation are excluded. Cached summaries refresh when their supporting facts or instructions change.

The public demo can use managed inference instead of its seeded CPU model, with that configuration preserved across hourly resets. Customer connector choices are unchanged.

Upgrade: no new database migration or customer setup step. Check the status panel or Admin, Licence for deployment availability. Stable promotion and native installer publication remain separate.

Ticket detail now has Activity, Work, Context and Files views. Activity keeps the original report, visible AI summary and conversation together, with explicit Reply to requester and Internal note controls. Status, priority, assignee, queue and SLA details stay alongside the workspace on desktop. On phones, use Ticket details to reach them.

Work retains checklists, assigned subtasks, evidence, dependencies, templates, approvals, security approvals and time tracking. A notice above the tabs shows pending approvals and work or child tickets that block completion. Context keeps linked records, requester information, labels, related tickets and watchers. Files collects accessible message attachments. Configured actions, transfer, merge and history remain available from Actions.

Unsaved inputs survive tab changes. A failed reply retains its draft and audience; interrupted attachments can be retried without sending the message again. Existing themes, navigation choices and permissions are preserved.

Upgrade: no new database migration or setup step. Check the status panel or Admin, Licence for deployment availability. Stable promotion and native installer publication remain separate.

Dashboard tiles now use their existing icon colors as colored backgrounds by default, with dark text and icons in light mode and light text and icons in dark mode. The dashboard keeps its existing grouping, links and activity feed.

Under Dashboard, Customise, turn Colored tiles off to restore neutral cards. This preference is saved to your account and follows you across devices. Existing tile visibility and ordering are preserved. Reset restores the default layout with colors enabled.

No new database migration. Stable promotion and native installer publication remain separate.

Admin, Connectors now uses a stable setup order. Sign-in and directory services come first, followed by device management and enrolment, student information and ticketing. Communication, infrastructure and operational integrations follow. New connectors appear in their relevant category instead of being promoted simply because they were added most recently.

AV and room monitoring has a dedicated section below core infrastructure. Configured instances, permissions and background collection keep their existing behaviour. Providers within a category also have a stable order.

Dialogs take keyboard focus as they appear. Pressing Escape immediately after switching from connector configuration to a confirmation reliably returns to the configuration form without submitting another change.

This release includes the 0.14.1 button and form-control fixes. Container images also omit build-only web caches, reducing download and scanner disk usage.

Upgrade: no new database migration beyond 0.14.0. An upgrade from 0.13.0 still applies the district connector migration. Check the status panel or Admin, Licence for deployment availability; native installers and stable promotion remain separate.

Issue, Return, Mark unavailable and Edit on Loans now share the same sizing. The same action styles apply across administration, stock, security, dialogs and account setup, with consistent labels, corners, spacing and keyboard focus. Primary, secondary and destructive actions remain visually distinct.

Tables retain readable columns on phones and scroll horizontally when needed. The Loans action labels stay intact. Form fields and icon buttons also use shared minimum sizes, and selected actions no longer change size when toggled.

Upgrade: no new database migration. This patch includes all 0.14.0 district connector and identity-provider setup improvements. Check the status panel or Admin, Licence for the version available to your deployment.

0.14.0: multiple connections for districts

Section titled “0.14.0: multiple connections for districts”

Release channel: 0.14.0 is tagged for beta publication. Check your status panel or Admin, Licence for availability after image and deployment verification; a version tag alone does not confirm that your deployment has updated. Stable-channel promotion and native installers remain separate.

Add several named Jamf, Entra, Google Workspace or other connector instances in one organisation, with independent credentials and state. Choose organisation-wide or selected-campus coverage independently of the agent site. This supports a district using shared systems alongside individual schools’ connections.

Select the source for directory reads and account actions. Campus-scoped account access requires a confirmed link to a local person; device commands retain their recorded MDM source. SIS sync keeps equal external IDs and leaver detection separate by source, and identifies partial failures. Interactive tiles and buttons also regain spring feedback, respecting reduced-motion and pointer preferences. All 0.13.0 school operations, assistant and regional billing updates are included.

Admin now opens settings instead of reopening completed onboarding. Connectors and desk setup explicitly offer Entra, Google Workspace, custom OIDC and SAML sign-in configuration. Provider instructions preserve existing settings; LDAP password sign-in remains a separate option.

Person privacy exports include their connector-source links, and erasure removes those links alongside the person’s identifying fields. Confirmed directory links also have a readable entry in the audit log.

⚠ Migration: one additional application migration since 0.13.0, 20260913180000_multiple_connector_instances; no additional control-plane migration. Verify a backup and update API, web and site agents together. Existing IDs, credentials, enabled state and agent bindings are preserved. Review the backfilled campus coverage. Agent secrets for additional connections must use instance IDs, and older agents cannot claim their work.

Do not downgrade to the previous application after creating additional instances. Prefer a forward fix, or restore the verified pre-upgrade database with matching application and agent versions. Shared imports without a clear campus require local assignment. Workflows without source pickers refuse ambiguous connections. Multi-issuer sign-in and SCIM are separate work; provider capabilities and live/demo limitations have not changed. Representative live-provider validation is still required before a customer rollout.

See Configuring a connector, Directory accounts and Connector agents. Upgrades from 0.12.0 also need the migrations listed under 0.13.0 below.

0.13.0 — school operations and assistant reviews ⚠ migration

Section titled “0.13.0 — school operations and assistant reviews ⚠ migration”

Deployment status: 0.13.0 is published to the beta channel and running on staging and the public demo after release verification. The stable release remains 0.12.0 during the documented soak process. Native installer publication remains disabled.

Plan school projects, maintenance, purchases and events with shared approvals, dependencies, milestones, resources and bookings. Review synced roster changes and create lifecycle work; capture stocktake observations offline and resolve conflicts when synchronizing. Supported AV/room integrations and TeamViewer status mapping help identify equipment needing attention.

Purchasing can connect to Xero or MYOB after provider setup and authorization. Review the supplier, account and tax mapping before exporting an approved purchase. Interrupted deliveries have an explicit reconciliation path. Issue insights compare ticket and repair patterns, recurring categories and repeat devices across periods.

The native assistant can cite published knowledge, summarize tickets and draft responses. Changes require an expiring review of the recorded action. The optional Salesforce Agentforce advisory pilot is disabled until an administrator verifies its configuration and grants staff access. Live Salesforce sandbox validation remains outstanding; this is not a general availability claim.

The app uses clearer shared controls and calmer surfaces across workflows, sign-in and the assistant, with existing theme and navigation preferences. Guided setup and the dependency fixes from 0.13.0-rc.1 are included.

Fixed annual billing is available in AUD, USD, GBP, EUR, NZD and CAD. The website suggests a currency from your country and lets you choose another. Quotes, licences and invoices use that currency; existing AUD contracts are unchanged. See Plans for the fixed price table.

Before updating: verify a backup. There are five new application migrations since 0.12.0 and 0.13.0-rc.1, covering assistant controls, school operations and finance integrations, trusted database-owner maintenance and subscription currency. Update API, web and site agents together. The separate control plane has one new currency migration. It preserves existing amounts and defaults older contracts to AUD. The vendor mail service retains Resend until both Cloudflare Email Sending credentials are configured. Native installer and mobile-store publication remain separate from this release.

Deployment status: this candidate passed CI, image verification and live health/version checks. It is superseded by 0.13.0 on staging and the public demo. The stable release remains 0.12.0 during the 0.13 rollout.

This candidate introduces a guided setup for the first administrator: choose built-in ticketing, an existing ticketing system or no ticketing; select licensed workflows and portals; configure access, connections and backups; then review the desk before launch. Progress is saved across sessions. Existing desks can open Admin → Desk setup without being forced through setup again.

The release also updates dependencies to address known security advisories and reduces temporary build-artifact storage. There are no additional application or control-plane database migrations since 0.12.0.

0.12.0 — department desks and navigation refresh ⚠ migration

Section titled “0.12.0 — department desks and navigation refresh ⚠ migration”

Deployment status: 0.12.0 has passed final staging verification and is available on the stable channel. Each school’s deployment still needs its own upgrade; publication does not automatically update it.

This release includes the RC1–RC5 changes below: department desks with explicit activation and department/campus access boundaries; grouped navigation, hover submenus and school-default preferences; corrected identity and authenticator feedback; in-app Documentation search alignment; Iru connection compatibility; application inventory; and scoped Full Access delegation with fresh identity checks and audit records. Send As grants remain disabled and deferred.

Upgrading from 0.11.1 includes 17 migrations. Back up and verify recovery before updating. No additional application or control-plane migrations were added after RC5; the functional source is unchanged from that accepted candidate.

Live Jamf/Intune validation and formal human usability/assistive-technology assessment remain follow-ups. The Expo technician/requester development preview is separate; native installers and mobile store distribution remain unpublished. Earlier references in these guides to 0.12 candidate features describe the features now included in this final release, subject to permissions and explicit department entitlement/activation.

0.12.0-rc.5 — in-app Documentation search alignment ⚠ migration

Section titled “0.12.0-rc.5 — in-app Documentation search alignment ⚠ migration”

This candidate passed staging acceptance before final 0.12.0 publication.

The magnifying glass in Plugboard’s Documentation page (/docs) is centred within the Search everything written down input. The live-document hint stays below it and is associated with the field for screen readers. There are no additional migrations since rc.4.

0.12.0-rc.4 — account preference synchronization ⚠ migration

Section titled “0.12.0-rc.4 — account preference synchronization ⚠ migration”

Returning your appearance or navigation position to the school’s setting also clears an older choice on another device when it next loads your account. Account controls reflect the saved preference. There are no additional migrations since rc.3; upgrading from 0.11.1 still includes the 17 migrations below.

0.12.0-rc.3 — navigation and acceptance fixes ⚠ migration

Section titled “0.12.0-rc.3 — navigation and acceptance fixes ⚠ migration”

This candidate passed image verification and staging rollout. Deployed checks confirmed the changes below; the cross-device school-default reset correction is in rc.4.

The follow-up adds desktop hover submenus, restores Modern navigation glass and spring motion, and aligns account visibility settings with workspace groups. Returning from a custom order to groups preserves hidden pages. Touch, keyboard and reduced-motion support remain. Backup verification now describes integrity checks without claiming that every archive supports in-app restore; department feature switches have readable labels and configuration links.

Microsoft licence and authentication-method lookups use the query options their APIs support. If an identity section cannot load, it shows an error instead of remaining on “Loading”. Switching profiles clears the previous identity data. Authenticator enrollment retains the refreshed sign-in session. An incorrect or expired setup/removal code can be corrected without being sent back to sign-in. Users administration shows an access message instead of an unusable creation form when the signed-in account cannot manage users.

The Expo development preview supports technician and requester ticket workflows. Both modes passed the reported physical login, ticket, rotation and resume checks. Advanced actions and school SSO/passkeys use browser handoffs. App-store distribution is not part of this server release.

No additional migrations since rc.2. Upgrades from 0.11.1 still include the 17 migrations below and require a verified backup. Native installers remain unpublished.

0.12.0-rc.2 — staged beta and Iru update ⚠ migration

Section titled “0.12.0-rc.2 — staged beta and Iru update ⚠ migration”

This image passed CI, image scanning, signing and staging rollout. Signed-in ticket, department, device, loan, automation and Full Access acceptance completed; the final navigation, identity-read and account display corrections are in rc.3.

This candidate includes the 0.12.0-rc.1 changes below and renames the visible Kandji connector to Iru (formerly Kandji). Existing saved connections keep their identifier, credentials and API origin. The connector guide explains both supported API domains and the older UI labels.

This candidate also removes test TLS fixtures and build caches from the runtime image. The rc.1 image scan stopped publication before staging was updated.

An upgrade from 0.11.1 includes 17 database migrations, including department access policies. Back up and verify recovery before updating. There are no additional migrations beyond the unpublished 0.12.0-rc.1 source. The connector remains read-only Apple device lookup and fleet inventory; the rebrand does not add remote commands or Iru’s other platform products. Native installers remain unpublished.

0.12.0-rc.1 — source changes included in rc.2 ⚠ migration

Section titled “0.12.0-rc.1 — source changes included in rc.2 ⚠ migration”

This tag did not publish an image or update staging: its image scan rejected test TLS fixtures in the runtime package. The rc.2 candidate contains the following changes and the packaging correction.

  • Jamf computer/mobile and optional Intune application inventory on device MDM records, with source/timestamps, search and pagination. Large fixture checks passed; live test tenants were unavailable. Inventory does not establish installation or VPP/licence entitlement.
  • Wipe queues reserve capacity across campuses, coordinate concurrent workers, and stop automatic replay after uncertain results, including retry rows from older versions. Requesters can see limited state and must acknowledge an uncertain previous outcome before a new request. Typed serial, MFA, approval and cooling-off controls remain.
  • Credential and authentication-configuration authority checks, stricter API-key department access, formula-safe exports and conditional charge/loan updates. Staff session replacement clears private page state and kiosk repair details stay within the current sitting.
  • Private native panel access and administrator recovery, capability-link log redaction and consistent pre-update database snapshots. Native installer publication remains disabled.
  • Printer freshness records the latest observation independently of historical changes. Source demo seeding requires explicit DEMO_MODE=1.

Three additional additive migrations record refresh-token logout, printer observation time and API-key legacy access. Back up before upgrading. Send As is deferred from this release; its grants remain disabled.

These changes are included in the rc.2 beta candidate. This is not a stable-release announcement. Back up and verify recovery before applying its additive migrations.

Check the version and explicit add-on entitlements on the instance you use. Validate its runtime, staff/requester workflows and audit outcomes before school use. The generated capability reference distinguishes live handlers, demo simulation, blocked actions and unsupported operations.

  • Optional Facilities, Administration and other school departments, with service forms, department membership, explicit transfers, email routing and recurring maintenance. Add-ons require explicit activation and entitlement. Paused departments retain history and require schedules to be explicitly restarted.

  • Grouped workspace navigation in modern and classic, including phone search, keyboard navigation, preserved personal arrangements and clearer loading, retry and stale-data feedback on key staff pages.

  • Whole-school backup protection: unrestricted campus access is required, with departments.manage when any active or paused department exists. New v3 logical archives preserve paused history and validate the complete table/count/link manifest before restore. Older unmarked archives require operator validation and a maintenance restore; this also applies to ICT-only schools. Keep old archives and their encryption keys.

  • Device CSV export uses the current filters across all matching devices within its size limits. Report CSV uses the range of the displayed result.

  • Department boundaries extend to rules, reports, notifications and queued work. Shared workflow settings require school-wide department administration after a department is configured. Department webhooks and external API-key access remain withheld pending explicit integration scopes.

  • Automation audit history, school and rule hourly caps, OBSERVE mode, campus conditions, previews and guarded approvals. Bundled connectors do not yet implement unattended device.lock.

  • Software contract register with free-text owners, renewal reminders and compute-on-read licence positions. No identity inventory is persisted.

  • Durable bulk device-location jobs, with progress, cancellation and bounded retries. Remote command fanout is not included.

  • Scoped REST action catalogue and invocation, using the same tools as MCP.

  • Source-aware connector links and kind-specific remote URL template validation. Remote launch screens remain device-based.

  • Opt-in Exchange Full Access and delegation revocation. The corrected Full Access pilot passed grant, repeated grant, revoke and outside-scope refusal using a five-command role. Send As grants remain blocked after two outside-scope grants succeeded in live testing; the app’s outside-scope removal was refused and independent administration cleaned up. Add-RecipientPermission is excluded from the role. Each deployment still needs runtime, scoped-operation, UI and audit acceptance before enabling use.

  • Node 24 and Nest 11 runtime updates. Container installs include the pinned PowerShell/Exchange module; source/native installs need those dependencies installed separately if using delegation.

  • The platform source toolchain pins pnpm 10.34.5, including reviewed lifecycle-script allowlisting. Use that version and the committed lockfile when building the platform; the documentation site retains its own npm workflow.

  • Help → Connector capabilities and the public reference are generated from the same reviewed runtime registry. A build guard detects reference drift; an available handler still requires that school’s credentials, permissions, entitlements and provider setup.

  • API keys retain their issuer’s permission and campus limits. Tenant-wide SCIM requires an unrestricted campus grant; older unbounded keys need rotation. Public reads and tool calls enforce their required scopes.

  • Closing tickets or submissions requires the relevant close permission across edits, actions, bulk work and tools. Concurrent refresh-token use has one rotation winner. Connector/OIDC outbound requests retain destination checks across DNS resolution and redirects, including dual-stack fallback.

  • Docker application archives use persistent API storage. The updater checks existing storage before migration; native updates preserve default archives across bundle replacement. See backup storage and update limits.

Additional identity and support hardening has merged into source: active person checks on portal sessions and inductions, durable per-device kiosk mode, atomic setup/claim consumption, complete support opt-out checks and customer ownership checks on deployment telemetry. Staging acceptance is still pending.

Content boundary changes are in review: moving a document into a restricted library retracts its public copy atomically, and email headers reject line breaks before delivery. The generated connector reference includes the stricter Gmail sender schema. These remain candidate behavior until deployed and accepted.

Plugboard follows semantic versioning: MAJOR.MINOR.PATCH.

Patch, 0.6.1 to 0.6.2 Fixes only. Nothing new to learn, nothing to reconfigure
Minor, 0.5.3 to 0.6.1 New modules, connectors or features. Existing behaviour is preserved
Major Something that changes behaviour you may be relying on. There has not been one yet

A version number is a git tag, and a tag is only ever used once. If a release is withdrawn, the next attempt takes the next number rather than reusing the old one, so what you have installed is unambiguous.

Channel What it is Who should be on it
Stable The default. Every published release Everybody, unless you have a reason
Beta Pre-release builds, ahead of stable A test instance, never a live desk

Set the channel in your .env. If you have never set one, you are on stable.

Managed hosting is on stable, and update windows are covered under releases and update windows.

A release marked ⚠ migration in the changelog changes the shape of the database. A release without it does not.

Take a verified backup before applying a marked release. Not a backup: a backup you have confirmed exists and is not empty. See backups and restore.

Two things are worth understanding before you upgrade into one:

Migrations are forward-only. Rolling the program back does not roll the database back. If a migration itself is the problem, the fix is restoring the pre-update dump, and everything written since it is lost.

The installer already does most of this for you. A release carrying a migration takes a dump into backups/ before the schema changes, and checks the dump is not empty or truncated before allowing the migration to run, because an empty dump is worse than no dump: it looks like a backup. That safety net is real, and it is not a reason to skip your own. See updating.

Plugboard’s migrations are additive as a matter of policy: new tables start empty, new columns are nullable or defaulted, and a school that opens none of the new modules sees exactly what it saw before.


Three migrations, all additive — a connector and deep-link reference on Ticket, stock and reorder tracking on repair parts, a consecutive-failure counter on connectors. Nothing is backfilled and no existing query changes behaviour.

What’s new

  • The device register can hold a device no MDM ever enrolled — add one by hand, or import a CSV.
  • A device’s assigned owner can be set directly from induction check-in, loan issue, or the admin panel.
  • Fleet health now shows devices no MDM manages, not only the ones it does.
  • A ticket remembers which connector filed it and links back to it on the vendor’s own site.
  • Closing a repair against parts on hand now decrements stock, with a desk alert once a part crosses its reorder point.
  • Client portal requesters can attach a photo when lodging a ticket.
  • Bulk loan issue and return report which rows failed, not just a count.

Fixed

  • A printer connector that can’t be reached now backs off and disables itself after five failures, instead of retrying every ten minutes forever.

Security

  • A related-tickets panel could return another campus’s ticket subject and status to a site-scoped admin — fixed, along with the same missing check on unlinking tickets.
  • The feedback delivery webhook’s token could reach the error log on a non-standard failure response — redaction now targets the specific path.
  • An unhandled error in the feedback delivery sweep could restart the control plane — it now handles per-row failures without crashing.

What you should do. Take a verified backup and upgrade normally.


Six migrations, all additive — new tables for repair-submission attachments, printer status history and feedback board delivery; a generated full-text search column for tickets; MDM and loan-archive columns on Loans, Loan groups and Stock; and an ownership flag on repair submissions. Nothing is backfilled destructively and no existing query changes behaviour. Take a verified backup first.

A broad feature push: loan and stock data-model gaps, kiosk and induction safety, ticket search and dashboard query cost, device and fleet security, repairs correctness, printer reliability, control-plane recovery tooling, identity/SCIM and retention sweeps, sign-in ergonomics, mobile navigation, and a new pipeline that delivers in-app feedback straight to the Multica board. The full record, with root cause for every item, is in the changelog.

  • Loan groups own their own MDM sync, so two loan pools can sync from two different device groups instead of one overwriting the other, and a device that leaves its MDM group is flagged as departed automatically. The loans list can also be filtered by device kind, user group and free text.
  • A repair submission can carry an intake photo.
  • Printer status and toner are tracked over time, with an alert when a printer goes down, runs low, or a monitoring sweep itself stalls.
  • Fleet sync can be triggered on demand from Admin → Connectors → Fleet, with a full summary written to the audit log every run.
  • A stuck managed onboarding can be retried, and a yanked release un-yanked, both from the control-plane panel — previously either meant editing the database by hand.
  • The identity panel shows licence spend, including licences still assigned to disabled accounts.
  • MFA enrolment shows a QR code, not just a text secret to type in.
  • In-app feedback now reaches the Multica board on its own, with retry and backoff if delivery fails, instead of sitting in the control plane until someone reads the inbox.
  • Stock, loans, printers, the admin Kiosks panel and the welcome page show real loading, empty and error states now, instead of one shell for all three — a failed request no longer looks like an empty list.
  • Induction check-in enforces required fields, and a bulk student import now reports which names it couldn’t match instead of dropping them silently.
  • The induction kiosk no longer sticks on the previous student’s result, and resets itself after 90 seconds idle.
  • Card lookup and registration now match card numbers regardless of case.
  • Cost charts read the calendar in Sydney time rather than UTC — you may see a repair or purchase move to a different month the first time you view a chart after upgrading; totals for the year are unaffected.
  • A repair’s recorded coverage (warranty or insurance) now reaches the cost reports, and repair history names who acted, not just their role.
  • SCIM discovery routes now answer correctly for an identity provider’s setup wizard.
  • Expired parent sign-in links and portal session revocations are swept automatically instead of growing forever.
  • Feedback submitted in-app is now attributed to its actual author.
  • The mobile top navigation no longer grows to cover the screen — it scrolls sideways instead.
  • A repair claim of device ownership made through the client portal is now flagged when it can’t be verified against a device assigned to that person.
  • A retired or disposed device can no longer receive a remote command, and wipe and remote-action controls are gated on the permissions and settings that actually apply, instead of being hidden only after a refused request.

Known issue. The Loans page still shows an old Sync from MDM button that calls endpoints this release removes; it fails until you use the new per-group Sync now control under Admin → Loan groups instead. A follow-up fix is tracked.

What to do first. Take a verified backup and upgrade normally.

Two migrations, both data repair rather than schema change. One clears a connector field that may hold a credential; the other disables a small number of remote-access targets left misconfigured. Take a verified backup first.

This closes the last of the August security audit — fourteen smaller findings that were real but not urgent. Nothing here changes how the desk is used. Highlights: a blocked outbound request could once put an API key into an error message; a portal streaming link is now single-use instead of working for its whole sixty-second life however many times it was presented; an idle session now actually expires, instead of the setting being accepted and ignored; and plugboard-agent install-service — instructed since the agent shipped — now exists, rather than silently starting a foreground poll loop instead. The full record is in the changelog.

What to do first. Take a verified backup and upgrade normally. Nothing else is required.

One migration, additive — two nullable columns and an index on Loan; nothing is backfilled and no existing query reads either. Take a verified backup anyway.

This closes the rest of the August audit findings, alongside the launch blockers and should-fix items that went out in 0.7.0 through 0.7.2.

  • A loan can have a due date. The desk can say when a device is expected back, derive it from a per-pool loan period, and list what is late.
  • The assistant can see the ticket queue. Until now it had tools for repairs and nothing for tickets, so “show me open tickets” confidently returned repair submissions instead.
  • Where a device was last seen is now its own permission, network.clients.view, rather than riding on the broad device.view every technician holds. Client sightings are location data about children, so a school now grants it deliberately. See permissions.
  • The public demo carries documentation. The module shipped in 0.6.1 with an empty seed, so the one deployment every buyer is pointed at showed an empty product until now.
  • /api/health no longer names the build commit, only the version.
  • HSTS is set on every served surface.
  • The control plane’s routes are now checked by an authorisation test rather than relying on every handler remembering to guard itself.

Everything in 0.7.1, plus a fix to the public demo seed. Customer instances are not affected by the bug or the fix — the seed refuses to run outside the public demo — so if you are upgrading, 0.7.2 and 0.7.1 are the same product, and the 0.7.1 and 0.7.0 notes below are your release notes.

  • The public demo now comes back up cleanly after a deploy, instead of occasionally failing to restart behind a numbering clash in its sample data.
  • The assistant no longer disappears for the rest of your sitting when a single permission check is slow to answer.
  • Reordering or hiding a tab under Account → Appearance now updates the page in front of you immediately, instead of waiting for a reload.

Everything in 0.7.0, which never shipped. The 0.7.0 tag failed its own release gate over a dependency vulnerability in a build tool, so no image was ever built, signed or deployed. If you are on 0.6.2, this is your 0.7 release, and the 0.7.0 notes below are part of it.

Five control-plane migrations and seven customer-instance migrations — all additive: new columns, mostly nullable and backfilling nothing, plus one that numbers every repair already in your database, oldest to newest, so the numbering reads as a history. Take a verified backup first; see updating.

Upgrading the panel requires rebuilding every region host.

  • Repairs have a number now, the same way tickets always have, and search finds a job by number whether it was logged as a ticket or a repair — the two answer as one list, newest first.
  • The search box can search your own external helpdesk too, if you run Zendesk or Web Help Desk alongside Plugboard — off until an administrator turns it on per connector in Admin → Connectors, because it searches as the one credential Plugboard holds rather than as the person searching.
  • You can set up your own navigation under Account → Appearance — hide tabs you never use and reorder the rest, for yourself only. The search box also finds pages now, not just records, and understands the words people actually use rather than only what is on the tab.
  • Network client tracking has a switch, in Admin → Security: off until a school turns it on, one sighting kept per device rather than a history, and a retention window between 1 and 90 days. It existed in the database from the day the network module shipped and was unreachable until now.
  • An on-premises connector can be assigned to a site in Admin → Connectors, which is what makes Active Directory, Synergetic, PaperCut, Web Help Desk and SNMP printers actually work on a managed deployment.
  • Ticket comments now say who wrote them — a technician’s name, or Automatic triage — instead of “Someone” for anything not typed by a signed-in person.
  • A URL Plugboard does not recognise now opens inside the desk frame, with navigation and a way back, instead of a bare unstyled 404.
  • Several screens — moving between pages, opening a ticket, the submissions list — got faster by asking the server once for things that do not change while you are working, instead of on every click.

Highlights, not the complete list — see the changelog for the rest:

  • A portal request’s status can no longer be read by anyone the request does not belong to.
  • A restricted documentation library can no longer be renamed, moved, unrestricted or deleted by someone who is not allowed to read it.
  • A connector agent’s token now expires and can be rotated without an outage.
  • The assistant now requires a permission to open.
  • Twelve actions that decide who can read what now write an audit row.
  • Revoking a kiosk now actually stops it working.
  • The build toolchain for the ticket classifier’s regex engine no longer pulls in a vulnerable archive library — a build-time dependency fix with no runtime effect, and the reason 0.7.0 itself does not exist as a release.

Never published. The release gate stopped it and no artefact was ever built. There is no upgrade path from it because it was never installable. Its changes shipped, unaltered, as part of 0.7.1 above.


No migrations. Upgrade from 0.6.1 without ceremony.

Three things 0.6.1 shipped broken, all inside the features it added:

  • The Network page never loaded. It asked the API for the estate without signing the request, and had no way to show the error, so it looked like it was still loading rather than like it had failed.
  • The Meraki, UniFi and SNMP connectors could not run. They installed, they tested green, and the first real call answered “connector not registered”. A test now refuses to let a connector ship unreachable.
  • The Documentation page rendered outside the desk frame, with no navigation and no way back.

What to do first. If you configured a network connector on 0.6.1 and saw an empty pane, this is why. After upgrading, open Network and press Refresh from every connector once.

Four migrations. Take a verified backup first.

There is nothing to upgrade from 0.6.0. 0.6.0 was tagged and never published: the release gate stopped it on two failures and skipped every job downstream, so no image was built or signed, no release was created, and nothing was deployed anywhere. 0.6.1 is the first published release of this work. If you are on 0.5.3, 0.6.1 is your next version.

A minor release: it adds two sellable modules, three provider categories and three connectors.

Documentation. The desk’s own runbooks, kept apart from the public knowledge base. Spaces with their own access rule, version history on every save, a named owner per document, and a review cycle so a stale page says so. Documents bind to a device model, a ticket category, a campus, a monitored service or a connector, so a ticket about a Chromebook shows the Chromebook runbook before anybody searches, and says why. Sold from Standard.

Remote access. A button on the device page that opens whatever remote support tool you already run, with the machine selected. Configured as a link, so it works with tools we have never heard of and needs no connector. Plugboard never carries the session and never holds a credential that could control a machine.

The network estate. Wireless, switching, gateways and the filter across Meraki, UniFi and SNMP, merged rather than resolved. Network devices match ticket text, and a device going down raises an event on the monitor board you have already configured alerting on. Sold from Standard.

A kiosk is a device rather than one shared key. Name a counter, say which campus it stands on, decide whether it offers card tap, and revoke one iPad without un-enrolling the library.

Global search also began reading article bodies rather than titles and summaries only.

PaperCut never worked on a hosted deployment. A connector whose base URL carried a path requested the wrong URL. Decommissioned network hardware was never forgotten. And the portal returned to the sign-in screen while still holding the last student’s session token for the length of a round trip. On a kiosk in a corridor, a reload in that gap landed on the previous student’s records.

  • Internal documentation is served only to signed-in staff, never from public routes, enforced by a test rather than a convention. A restricted space withholds its documents, including their titles, from search, from ticket suggestions and from anyone without the extra permission.
  • Client sightings on the network pane are location data about children, so they are off by default, keep seven days (ninety at most), are never exposed to a portal, and are stored one row per device rather than as a history.
  • Starting a remote session is its own permission, separate from managing devices, and every session is recorded against the person the device belongs to.
  1. Take a verified backup. Four migrations.
  2. Upgrade, then go straight to 0.6.2. Three of the features this release adds do not work until then.
  3. Expect the two new modules to appear on their own. Modules are on unless a school switches them off, so a Standard licence or better gets Documentation and Network in the navigation on first sign-in. Turn either off under Admin, Features if you do not want it.
  4. If you enable Network, read client sightings before turning tracking on. It is off, and it should stay off unless you have decided you want it.
  5. Kiosks: claiming your first kiosk device switches the old shared key off for the whole tenant, and any remaining old-style device stops tapping at that moment. Do the rollout in one sitting, not over a week.

Never published. The release gate stopped it and no artefact was ever built. There is no upgrade path from it because it was never installable. See 0.6.1.


Everything before 0.6 and everything after it is in the changelog, in the same format, with the ⚠ migration marker on the releases that carry one. The notes for whichever version you are being offered are shown in the status panel and under Admin, Licence before you apply it.

If you are several versions behind, upgrade through them in order rather than jumping. Migrations are applied in sequence, and the notes for each release tell you what changed for your people.