Release highlights

This update strengthens account security controls, rebuilds the General analytics workspace around a flexible multi-dimensional table, and makes task and reporter notifications more reliable. It also includes a substantial set of fixes across email intake, search, and user role management.

  • Mandatory two-factor authentication policy and admin-led 2FA reset
  • Redesigned General analytics with parent/child breakdowns across eight dimensions
  • Task notifications now reach task authors as well as assignees
  • Customisable one-time password emails for the whistleblowing portal
  • Conditional logic in dynamic forms
  • Eight bug fixes, including email attachment handling and regional role retention


What's new in this release

1. Stronger two-factor authentication controls

Following the introduction of authenticator-app 2FA in the 2026-04 release, this update gives administrators direct control over how two-factor authentication is applied across their organisation.

Mandatory 2FA. A new toggle lets administrators require two-factor authentication for all users, rather than leaving it optional. The setting applies immediately, and affected users are prompted to complete 2FA setup at their next sign-in.

Admin-led reset. Administrators can now reset a user's two-factor authentication from the admin console. This provides a secure recovery path when a device is lost or an authenticator app becomes unavailable. The action is permission-gated and fully audited, with optional notification to the user, and existing security policies continue to apply — including re-enrolment at the next sign-in.

Together these changes let organisations enforce a consistent security baseline without creating a support burden when users lose access to their devices.


2. Redesigned General analytics

General analytics has been rebuilt around a structured breakdown table that replaces the previous pie chart view.

The table now supports parent and child selectors, so you can construct multi-dimensional views of your case data. Both levels can be set to any of the following:

  • Categories
  • Units / departments
  • Priorities
  • Channels
  • Statuses
  • Routes / procedures
  • Assignees
  • Regions

Parent rows are visually distinguished to make the hierarchy easier to read at a glance. This lets you answer questions that previously required exporting data — for example, comparing case volume by channel within each region, or reviewing how priorities are distributed across assignees.


3. Task notifications for authors and assignees

Task-related notifications have been reworked so that the right people are informed at the right time.

  • Task authors now receive notifications when their task is assigned, alongside the assignee. Duplicate emails are suppressed when the author and assignee are the same person.
  • Task completion and task expiry notifications now reach task executors correctly. These previously did not trigger.

The underlying notification mechanism has been rebuilt on an event-driven model, which makes task notifications more reliable and easier to extend in future releases.


4. Customisable one-time password emails

The one-time password email used in the whistleblowing portal can now be tailored to your organisation. Administrators can adjust the subject, body, and branding to match their own tone of voice, with support for placeholders and localisation.

A preview and test-send option is included, so changes can be verified before they reach reporters. No development work is required.


5. Conditional logic in dynamic forms

Dynamic forms now support a new match key class, which allows conditions to be built from combinations of values in the options column.

The syntax works as follows:

  • Each line forms a separate OR group
  • Within a line, spaces denote AND
  • Within a line, commas denote OR

This makes it possible to show or hide form elements based on compound conditions rather than single values.


Improvements

Default notification opt-in for new reporters

A new configurable setting controls whether reporters are automatically opted in to notifications through their confirmed registration channel. When enabled, this removes a step from the reporter onboarding flow. Teams that prefer explicit opt-in can leave it switched off.

Shorter one-time password validity

One-time passwords in the feedback flow now expire after 10 minutes, bringing the validity window into line with standard verification practice.

Substantiation filter in the Groups report

The Groups report now includes a substantiation filter, allowing results to be narrowed by substantiation status. The filter works alongside search, sorting, and export, so refined result sets carry through to your reports.

Faster filter dropdowns

Filter selectors now load their options automatically as needed rather than all at once. This noticeably reduces initial load time and improves responsiveness when working with large datasets.


Bug fixes

  • Fixed an issue where incoming emails with large attachments could be dropped and never registered. The attachment size limit has been raised to 25 MB and handling of larger files improved.
  • Fixed an issue where reporters using a confirmed phone number as their primary channel did not receive new report notifications, despite templates being configured.
  • Fixed an issue where saving changes or assigning new roles to a user in the Users tab removed all of their assigned regional roles, such as Regional Coordinator or Regional Manager. Regional roles are now retained correctly.
  • Fixed a server error that caused search to fail for certain queries. Query parsing and validation now handle these edge cases reliably.
  • Fixed the autocomplete in the Responsible user field, which sourced its data from counterparties rather than from active system users.
  • Fixed an issue where a full dossier was not generated automatically when a personage was created. Personage entries are now created as part of dossier assembly, producing faster and more complete dossier builds.
  • Fixed case author assignment on ticket creation. When the personage case involvement option is selected, membership is now checked against the personage, and the case author is assigned to reporters and displayed in the dossier.
  • Fixed alignment, spacing, and accessibility issues in the status dropdown, and ensured consistent behaviour across browsers and devices.


Why this release matters

This release addresses three practical needs. Security teams get the ability to enforce two-factor authentication as policy rather than encourage it as an option, with a recovery path that does not require compromising on that policy. Case managers and analysts get a genuinely flexible reporting surface in General analytics, reducing the need to export data for routine questions. And the notification fixes close several gaps where people who should have been informed about a task or a new report simply were not.


Recommended next steps

  1. Decide whether mandatory two-factor authentication is appropriate for your organisation, and review who holds the permission to reset 2FA for other users.
  2. Explore the new parent and child selectors in General analytics to see which breakdowns are most useful for your regular reporting.
  3. Review your one-time password email template and adjust the wording and branding to match your organisation.
  4. If you use tasks, confirm that the notification behaviour now matches your expectations for both authors and assignees.