Release Notes

MSSP workspace, organizations, sites, and scalability

What’s New

  • MSSPs and large enterprises can be complex. The planner model now enables multiple organizations, each with it's own specific sites, each with its own specific programs. It's layered.
  • Enterprise can be complex, and MSSPs Administrators can lose control when roles, capacity, history, recovery, export, and lifecycle settings are scattered across separate processes. Organization settings bring those controls together at last!
  • For MSSPs, a single portfolio grouping makes it difficult to compare customers, locations, and programs. MSSPs can now review their organizations and their portfolio can now group delivery by organization, site, or program.
  • MSSPs cannot evaluate a multi-customer workflow through a single-organization demo. A separate MSSP demo now covers multiple customer organizations, sites, programs, delegated access, and shared responsibilities.

Fixes & Improvements

  • Program managers had to use a second draft or commit workflow for ordinary changes. Updates now use the standard milestone editor and Save action.
  • Shared plans become unreliable when stale, duplicate, inaccessible, or over-capacity changes are accepted. Multi-site saves now reject those conflicts before replacing saved work.
  • Regular users and MSSPs could enter the wrong demonstration context when demo data and routes overlapped. Each demo now uses separate fixtures and routes.

Security Guidance

  • Enterprise customers cannot rely on permissions enforced only in the browser. Owner, Admin, Editor, and Viewer access is now enforced at the server boundary.
  • Zero trust is important. Tenant isolation fails if a browser-supplied organization or site identifier can grant access. Unknown roles receive no workspace data, and browser-supplied identifiers never authorize records.
  • A lack of multi-tenancy for MSSPs risks exposing one customer’s records while working with another customer. That's all tightened up now.

AI Security Planner and consistent alert actions.

What’s New

  • Security Planner is now AI Security Planner across the application, reports, exports, support pages, and policies. Declared inputs and versioned rules calculate the plan; a model does not generate it.

Fixes & Improvements

  • An alert inspector could present one table recommendation as several Add task actions. It now shows the same single recommendation as the table, lists affected milestones as context, and leaves the row’s plus icon as the only path to a prepopulated draft.

Security Guidance

  • Inspect and Dismiss do not change program work. Add opens a reviewable draft, and only a separate Save changes the program.

OT/ICS planning and live security feeds.

What’s New

  • Improving operational technology and industrial control systems (OT/ICS) without disrupting operations takes more than a standard checklist. The new OT/ICS Security program covers system definition, risk, architecture, access, suppliers, as well as safety. That's important, too.
  • Security alerts are most useful when they are clearly actionbale. Alert feeds brings in a customizable set of alerts from approved government, software ecosystem, and vendor sources, then provides actionable recommendations for milestones and tasks.
  • Thousands of alerts are a lot to review. Some alerts also matter more in specific environments. Alerts are now easy to filter. Machine learning also enables users to identify alerts that matter, then see similar alerts, leverage Naive Bayes and an analyst in the loop model.

Fixes & Improvements

  • Feeds should be easy and timely. Alerts now load when the page opens, refresh every five minutes, and retry a failed source after three minutes. One unavailable publisher no longer holds up the rest.
  • Setup could accept input before saved settings finished loading, or strand a draft when storage failed. It now waits for saved data, preserves entered values, and keeps the draft in place when it cannot save.

Security Guidance

  • Alerts can propose a plan change, but they cannot apply one. Edit opens the existing planning dialog for review; only Save changes the program.
  • A failed or stale source is shown as unavailable or needing attention. AI Security Planner does not replace missing publisher data with sample alerts.

Agile progress, usage evidence, and feedback.

What’s New

  • Percent complete does not show whether work is moving, stuck, or growing. Agile charts now put Burndown, Burnup, Cumulative Flow, and Milestone Velocity in one place.
  • New users should not have to take product claims on faith. Usage shows completed programs and milestones, recommendation scores, reported time saved, and the popular program views. Heat maps for everybody!
  • User feedback is a critical part of understanding adoption (or lack of adoption). Users now have the option to provide NPS feedback and time saved when a program is completed and an explanation of program abandonment. Both will drive continuous improvement.

Fixes & Improvements

  • Burndown, Burnup, the Kanban cards and other views needed some touch ups. Completed work is now continuous, scope steps only when it changes, and ideal progress uses a comparable line. Key facts are surfaced where they should be.

Security Guidance

  • Usage statistics should not expose the program behind them. Analytics exclude titles, dates, notes, files, links, and shared-link tokens; Do Not Track and Global Privacy Control turn collection off. Records expire after 90 days.

Burnup, workload balancing, and safer sharing.

What’s New

  • A busy portfolio does not show where another person-day would make the biggest difference. Portfolio recommendations compare schedule risk with available capacity, then explain which change could improve the forecast. Overbalanced resources, rejoice!

Fixes & Improvements

  • A program can look healthy while one project is blocked, late, or short on capacity. Overview compares projects by health, status, capacity, planned finish, and forecast finish. No one likes surprises.
  • Program schedules were difficult to compare across separate progress summaries. Portfolio puts every program on one calendar and separates delivery from decisions, escalations, and recommendations. The trade-offs have somewhere to stand.
  • List, Kanban, Gantt, PERT, Burndown, and Burnup were buried inside the roadmap. They sit higher in the program navigation, keep project context, and retain the relevant Inspect, Edit, and Delete actions. Fewer treasure hunts, more actual planning.
  • Changing milestone effort could leave the old forecast in place. Effort changes recalculate the milestone, its dependent work, and the program finish. The math has agreed to participate.
  • A completion checkmark could hide unfinished tasks, missing evidence, or an impossible date. Completing a milestone requires finished child work, recorded evidence, and valid chronology; reopening it preserves the status history.
  • A blocker should pause work, not erase its place in the workflow. Clearing a blocker returns the milestone to its prior planned, in-progress, or custom stage.
  • Removing roadmap structure could change dependencies, workload, and finish dates without enough warning. Project and milestone changes preview the effect before saving, and removed work can be restored with its details intact. Delete has acquired an undo button and some judgment.
  • Leaving Setup at the wrong moment could lose changes or make the save result unclear. Setup warns the user before discarding edits, previews the schedule effect, and waits for storage before leaving. Save means saved (but this is not a guarantee).
  • Shared snapshots could be created without a clear review of their contents or relationship to the saved program. Share lists included and excluded fields before publication, identifies stale or ended links, and tells recipients when the snapshot was published, saved, and last reported.
  • Who doesn't do sophisticated program management from their phone these days? Mobile navigation was a squeezed desktop rail, while dense planning views could lose useful controls on smaller screens. Now users can do a lot on the go in a more mobile-specific experience.

Security Guidance

  • Local notes are secrets between the user and their local storage. Shared links, copied text, CSV, Markdown, PowerPoint, and executive reports leave them out. Complete JSON backups still include local notes and users should treat them as sensitive program data If their local notes have sensitive information.
  • A read-only link can still expose program priorities, dates, blockers, roles, and milestone details to anyone holding the address. Users should review the included fields before publication, replace stale snapshots after material changes, and revoke links when review ends.

Projects and person-days.

What’s New

  • Programs often have multiple projects. Now AI Security Planner offers a portfolio, program, project, milestone, and task and subtasks.
  • Programs can now contain multiple projects, each with an outcome, accountable lead, dates, effort, progress, blockers, and critical-path status.

Fixes & Improvements

  • Vague 'planning units' were a bad idea. Effort and weekly capacity now human-readable and use person-days across planner screens and exports.
  • The ransomware response playbook needed some work. It now begins once recovery priorities are approved, and the executive crisis process follows. It's a lot more work now!
  • The Identity roadmap could move into routine operations before third-party access rules were complete. It's better now that it doesn't do this.
  • Thirteen Identity milestones cited sources that did not match the guidance shown in the roadmap. Their source references have been corrected. Just some standard pre-MVP housekeeping.

Roadmaps get flexible. Portfolios get visible.

What’s New

  • Separate roadmaps made the portfolio as a whole hard to follow. Portfolio puts schedules, progress, blockers, critical paths, and next actions into one sortable view. Fewer tabs enable better visibility and questions.
  • A standard package cannot predict every audit, migration, or exception. Milestones can be added with owners, effort, dates, dependencies, and source details, or removed with a warning that explains what will move. The fixed roadmap has made room for reality.
  • A package name rarely survives contact with a steering committee. Program titles can be changed without rebuilding the underlying roadmap. Governance gets its preferred vocabulary; the plan keeps its plumbing.

Fixes & Improvements

  • Adding a task from List required opening the milestone editor first. Add task and Add subtask now sit in the list row with other editing controls and open a draft ready for typing.
  • A status menu inside a Kanban column was explaining the obvious. Cards now spend that space on owners, dates, dependencies, effort, and critical-path signals.
  • One pristine demo program made security delivery look suspiciously tidy. The homepage now shows ransomware, identity, and AI programs at different stages, complete with finished work, blockers, and tasks.
  • An effort estimate of “3” means little when nobody agrees what 3 represents. Settings now stores a planning-unit definition and displays it beside effort fields.
  • My Work repeated portfolio facts in a summary strip and oversized cards. It now condenses each program into Program, Progress, Schedule, and Next action columns.
  • Read-only sharing and file exports had separate controls for the same basic job. One Share dialog now separates snapshot links from JSON, CSV, Markdown, and PowerPoint exports. Fewer menus; the security boundaries stay put.

Burndown, settings, and program lifecycle.

What’s New

  • Percent complete can look reassuring while the remaining work barely moves. Burndown puts the generated baseline, saved reporting snapshots, and remaining planning units on one chart. Flat lines may explain themselves.
  • Re-entering the same setup choices is super tedious and can promote inconsistency. Settings remembers appearance, what one planning unit means, default organization size, and delivery capacity. The browser can fill out its own forms for once.
  • Paused work should not clog the active portfolio, and deleting a program should feel deliberate. My Work adds archive, restore, and confirmed deletion without disturbing other programs. Programs can leave without taking the filing cabinet with them.

Fixes & Improvements

  • A JSON file is a clumsy way to ask for a quick roadmap review. Share now creates a revocable, read-only snapshot link that expires after 30 days. The attachment can sit this one out.
  • Executive updates should not begin with rebuilding the report in PowerPoint. Executive Report now exports a branded, editable 16:9 slide in the selected light or dark appearance. PowerPoint still exists; at least the retyping does not.
  • Tasks and subtasks were easy to add and oddly hard to see in context. List and Gantt now expand the full hierarchy and can hide, show, or sort it. The work breakdown has come out of hiding.
  • My Work had started behaving like a spreadsheet with buttons. Program cards now separate delivery facts from Open, Share, Export, Archive, Restore, and Delete, while active, archived, and available work get their own sections. The spreadsheet impression has been archived.
  • A bookmark should open a page, not a routing mystery. Public pages and workspace views now have stable addresses, and older plan, progress, and report links redirect to the right destination. The browser history can relax.
  • Six text-heavy program choices made scanning feel like homework. Guided and custom programs now have distinct cobalt icons without dropping their accessible labels. Same words, fewer squints.

Security Guidance

  • Shared links can expose program priorities, dates, blockers, accountable roles, and milestone notes to anyone holding the address. Local route comments and report history are omitted. Revoke links when review ends and before clearing the browser data that holds the revocation key.

Four guided programs and custom planning arrive.

What’s New

  • Identity, exposure, AI, and vendor programs require different work, owners, sequencing, and source material. Guided setup now creates a dedicated roadmap for Identity and Access, Exposure Management, AI Governance, and Security Technology Vendor Optimization. One ransomware template has officially stopped trying to do five jobs.
  • Not every security priority fits a packaged program. Custom Program now builds a roadmap from a program name, objective, source, lead role, effort estimate, and milestone list. People who want to create custom programs, rejoice.
  • Comparing saved programs required opening each roadmap. My Work now shows completion, plan dates, and blockers for every saved program on one page. Open, Back, Open, Back is no longer the portfolio workflow.

Fixes & Improvements

  • A target date without a capacity check is a wish upon a star. Overview now compares target and forecast dates, shows overloaded weeks, traces the forecast-driving sequence, and states the decision needed.
  • Dependencies can be hard to see in a flat list and easy to miss on a calendar. PERT now shows the relationships between milestones, while Cards provides a compact view of the work. No funny commentary for this one.
  • A browser is useful storage, but a poor filing cabinet. Programs can now be downloaded as JSON, exported to CSV or Markdown, imported, or shared. No printing, though. It's 2026.
  • People like to fine-tune things, and that's fair. Roadmap editing now covers status, lead role, effort, dates, tasks, and subtasks.
  • Saved programs could briefly appear missing while browser storage loaded. Startup now waits for saved data before rendering My Work. The disappearing act has been cancelled.
  • Executives need the delivery decision, not a tour of the full roadmap. Executive Report now leads with outcome, schedule variance, progress, attention items, and the required decision. The report now opens where the meeting usually ends.
  • Cached site files could load a page that did not match the saved project state. The planner now loads the interface and stored data in the same sequence. The page and project now arrive together.
  • Roadmap diagrams are hard to reuse when they must be rebuilt for every briefing. Gantt and PERT now export directly to PNG. The briefing deck can retire the crop tool.
  • Roadmap actions crowded schedule information in narrower layouts. The controls now reflow instead of covering the plan. They have learned when to make room.

Security Guidance

  • A project file must not replace saved work unless it is complete and intact. JSON imports now enforce file-size, schema, checksum, and stale-write checks before replacing stored program data. Trust, but verify, now applies to imports.

Security programs escape the spreadsheet.

What’s New

  • Guided setup turns ransomware-resilience priorities into a dependency-aware roadmap with dates, lead roles, effort estimates, and critical-path sequencing.
  • Saved programs now survive a refresh or browser restart on the same device. A roadmap should have a longer life than an open tab.
  • Weekly updates capture milestone progress, blockers, decisions, notes, and revised dates. The executive report gets the story across without yet another status meeting.
  • Roadmaps can be viewed as a list, Kanban board, or Gantt chart. Same plan, three useful angles.
  • Executive reports now bring delivery status, schedule movement, critical priorities, blockers, decisions, and next actions into one place. Status updates have officially learned to get to the point.
  • The homepage now demonstrates the working planner instead of decorating around it. Product theatre has left the building.