v0.76.0
August 1, 2026
Confidential data stays confidential everywhere, and everyone sees only what is theirs. A safeguard is worth as much as its least guarded exit: a field could be hidden on the item's page and appear in the clear in the indicator computed from that very field, and a read-only role could see no flow in its own list yet still learn names and volumes from another screen. Confidentiality now follows the data wherever it is recomputed, visibility is the same from whichever direction you arrive, and connections with external assistants work the way the standard expects.
-
Security
Confidential data stays confidential everywhere
A field marked as confidential was correctly hidden on the item's page, yet the indicator built from that very field showed the exact number in the same response: the safeguard could be bypassed with no effort at all. Confidentiality now follows the data wherever it is recomputed — single-item values, flow totals, label breakdowns, trends over time and goals — and propagates along the whole chain, including when one indicator aggregates another. Indirect traces are closed too: a goal's outcome, read next to its threshold, told you on its own whether the real value had crossed it, and even the closing date gave it away. Threshold, due date and notes stay visible: they are choices made by whoever runs the process, not measurements. The same safeguards apply on the channel used by conversational assistants.
-
Security
Everyone sees only what is theirs
An integration key with read-only permission, created without stating which flows it could read, reached all of them — while the same role in the interface saw none: the permission's name limited writes but not the breadth of reads. Now, if you state nothing, the key sees what that role would see; naming flows explicitly remains a grant and holds as given. Analysis screens respect visibility too: the overview, automation plan, saturated phases and detail pages used to show names, identifiers and volumes of flows you could not open, and the totals let you infer the size of the organisation. Finally a flow's indicators, views, fields and linked procedures follow the visibility of the flow itself: someone who cannot open it no longer reads its configuration by knowing its address.
-
Integration
External assistants and credentials
Connecting an external assistant failed with a baffling message asking for credentials that do not exist: the key was accepted only in non-standard forms, and the automatic settings lookup received a web page instead of an answer. The standard form is now accepted and anything else gets a clear error — and the key no longer has to travel inside the address, where it ends up in logs and browsing history. Integration keys can finally carry an expiry date: it was shown in the list but no screen let you set it, so no key ever had one. Extension linking now truly checks the browser identifier: the check lived only in the page, so credentials valid for three months could be minted with an invented identifier and the active connections list no longer told a real link from a fabricated one. And the assistant chosen for anonymisation must actually exist, and cannot be the assistant itself.
-
Improvement
Searches and long fields no longer bring the server down
A disallowed character in a search field produced an internal error on procedures, items and events: it now gets an explained refusal. And overly long values are refused clearly instead of reaching the database and returning a technical error — this affected the external object reference, where the internal message travelled all the way back to the caller, the organisation's registered name, and the code of a flow created by an agent.