v0.87.5
September 13, 2026
**Activity log, protection of historical data, legal hold, account defence and sessions under control:** administrators see and export who did what, case history and the log can no longer be altered through ordinary means, a case or a process can be put on legal hold with a reason, repeated sign-in attempts lock the account and every web session can be listed and revoked. The same version brings thirty fixes from September testing, a reorganised sidebar and a profile photo.
-
Feature
Activity log you can browse and export
In Settings → Management → Activity log, administrators browse their organisation's operations: who, when, from which channel (browser, automations, assistants) and on which object, with filters by actor, action, object and period and the full detail of every row, where recognised credential names are masked. It exports to CSV or JSON, and the log's retention is set per organisation (from 30 days to 10 years), separately from case retention. The SuperAdmin has the same viewer for each organisation or for the platform. Sign-ins, failed sign-ins, sign-outs, two-factor checks, password recoveries and revocations are recorded too, never with passwords, codes or tokens.
-
Security
Tracked, verifiable history and log
Case history and the activity log are now protected directly in the database: ordinary edits and deletions are rejected. The only exceptions are the planned, tracked operations, such as scheduled retention, the permanent deletion of an organisation and the demo data reset. Evidence therefore stays subject to the retention periods you configure, not to improvised interventions.
-
Feature
Legal hold for processes and cases
An administrator can put a case or a process version on legal hold with a reason: the case is no longer deleted by scheduled retention or by hand, its documents are not removed and the process cannot be deleted until the hold is lifted. A badge shows it in lists and detail, and the case list has a dedicated filter. The feature is premium and is enabled per organisation by the SuperAdmin.
-
Security
Protected accounts and sessions under control
Ten wrong sign-in attempts in a quarter of an hour lock the account for a quarter of an hour; the administrator sees the lock on the Users page and can unlock it right away. The last five passwords cannot be reused. In your profile you find "Active sessions" with device, address and last access of every web session, and you can revoke them one at a time; the administrator has the same list for every user. Signing out closes all sessions as always. After the update, every user will need to sign in again.
-
Design
Reorganised sidebar and profile photo
Implementation Plan and Help are now vertical entries in the sidebar, in the same order whether open or compact; What's new, language and theme sit next to the version number. Notifications open from your photo, with the unread count, and the panel links to your profile. In your profile you can upload or remove your photo (PNG, JPEG or WebP), which also appears in the Users list; without a photo, the initial of your name remains.
-
Improvement
Fixes from September testing
Thirty fixes gathered from testers over the last two weeks. Among the most visible: Library folder permissions also apply to opening, downloading and versions of documents, top-level folder names are unique and a folder with documents in the Trash says so clearly; cases queued by the work-in-progress limit receive the events that arrived while waiting and resume safely even after a restart; Webhook tasks can ignore the response and an inapplicable output closes the task with diagnostics instead of repeating the call; publishing also checks phase forms and nested fields; withdrawing or replacing a version revokes its public links; sharing recognises more forms of credentials and does not expose provenance metadata; deletion confirmations and Kanban drag-and-drop are keyboard accessible; the extension package is verified complete before download.