Customer Release Notes
Release notes explain what changed for administrators and operational users. They should focus on behavior, workflows, labels, reports, permissions, and actions that users may notice.
Current Release Summary
| Area | Customer Impact |
|---|---|
| Documentation | Expanded customer-admin documentation with role guides, playbooks, workflow references, page references, troubleshooting, glossary, and quick-start scenarios. |
| Screenshots | Documentation uses screenshots that match the current customer portal. |
| Administration | Added practical guidance for onboarding, offboarding, role assignment, ownership, approvals, overdue work, and monthly health checks. |
| Reporting | Added deeper explanation of dashboard metrics, KPI formulas, scheduled reports, and management report packs. |
| GRC Workflows | Added cross-module guidance for assessments, risks, policies, vendors, audits, issues, and evidence. |
2026-06 Release
This release adds enterprise identity controls, governance records, signatures, and several risk, compliance, and operations capabilities. A second product brand was also introduced; documentation and behavior are identical across brands.
| What Changed | Who Is Affected | Admin Action Required | Reporting / Workflow Impact |
|---|---|---|---|
| Enterprise Identity and Access: single sign-on (SAML, OIDC, Azure AD, Okta, Google), SCIM 2.0 provisioning, LDAP directory sync, service accounts, and access reviews with CSV export. | Tenant admins, security and identity teams. | Configure the identity provider, verify provisioning and directory mappings, and schedule periodic access reviews. | New audit entries for sign-in, provisioning, and access-review activity. |
| Segregation-of-duties (SoD) enforcement and lifecycle provisioning/deprovisioning. | Tenant admins, control owners. | Confirm SoD rules and joiner/mover/leaver handling before relying on automated access. | Conflicting access can be blocked or flagged during approvals. |
| Governance Documents module for official governance records (charters, appointment and delegation letters, minutes, decisions), distinct from policies. | Governance owners, executives, secretaries. | Identify which records belong as governance documents versus policies and assign owners. | New record type with its own lifecycle and audit trail. |
| Digital Signatures, including an external-signer token flow. | Document owners, approvers, external signers. | Confirm signer lists and external-signer access before sending for signature. | Signature steps are tracked in workflow and history. |
| Statement of Applicability (SOA) under Compliance. | Compliance managers, auditors. | Maintain applicability decisions and justifications per control. | SOA status feeds compliance reporting. |
| Workflows engine with a builder/wizard and configurable approvals. | Tenant admins, process owners. | Review workflow definitions and approver coverage. | Approval routing and statuses follow the configured workflow. |
| Per-category risk appetite and a Risk Scale Criteria editor; risk templates and a create-risk wizard. | Risk managers, risk owners. | Set appetite per category and confirm the scale criteria before scoring. | Risk thresholds and ratings depend on the configured scale and appetite. |
| Assessment evidence-pack ZIP export. | Assessment owners, auditors. | Use the export to package assessment evidence for review or audit. | Provides a downloadable evidence bundle per assessment. |
| Comprehensive audit logging across modules. | Admins, auditors. | Review audit logs during investigations and periodic checks. | Expanded, searchable activity history. |
| Background Jobs operations dashboard. | Tenant admins. | Monitor scheduled and queued processing and follow up on failures. | Visibility into long-running and recurring jobs. |
| Configurable session idle-timeout. | Tenant admins, all users. | Set the idle-timeout value to match your security policy. | Users are signed out automatically after inactivity. |
| SLA monitoring and webhooks with automatic retries. | Admins, integration owners. | Review SLA targets and webhook endpoints. | More reliable outbound notifications and SLA tracking. |
| NCA ECC-2:2024 seeded framework. | Compliance managers. | Scope the framework and assign controls where applicable. | New framework available for assessments and reporting. |
What Administrators Should Review After an Update
- Review changed module pages for new workflow or status behavior.
- Check role and permission guidance when new actions are introduced.
- Review release notes before management reporting.
- Validate scheduled reports if report filters or metrics changed.
- Communicate user-facing changes to control owners, risk owners, policy owners, and auditors.
Release Note Format
Each future release should include:
| Section | Purpose |
|---|---|
| What Changed | Short business explanation of the change. |
| Who Is Affected | Roles or modules impacted. |
| Admin Action Required | What administrators should check or update. |
| Reporting Impact | Whether dashboards, KPIs, exports, or scheduled reports may change. |
| Workflow Impact | Whether statuses, approvals, ownership, or evidence expectations changed. |
Example Entry
| Field | Example |
|---|---|
| What Changed | Assessment compliance reporting now explains how non-assessed controls affect KPI interpretation. |
| Who Is Affected | Compliance managers, assessment owners, control owners, executives. |
| Admin Action Required | Review active assessments and confirm control statuses are complete before reporting. |
| Reporting Impact | Assessment compliance KPI may differ from overall compliance score when many controls are not assessed. |
| Workflow Impact | Control owners should complete responses before assessment closure. |
Customer Communication Checklist
- Explain the change in business language.
- Mention only actions users need to take.
- Avoid technical implementation details.
- Identify affected roles.
- Include screenshots when the page layout changed.
- Update playbooks and troubleshooting pages when behavior changes.