26.10 Release notes
This release brings a single tracked Document Checker run, organization-wide announcements in My Inbox, richer inventory interdependency views, published inventory segment scopes, My Inbox on your dashboard, and calculated-field filtering with freshness notices.
Feature highlights
Document Checker
Convert larger PDFs into documents
The former 100-page and 20 MB limits on PDF processing are gone. This applies everywhere a PDF is read: converting an uploaded PDF into a document, reading a PDF for a Document Checker run, generating a template outline from a PDF, and uploading regulation documents. As a guideline, keep files under 250 MB; documents of a few hundred pages are supported, and very large documents can take several minutes to process. Figures in converted documents are stored as linked files to keep the result smaller.
Learn more: Manage documents › PDF requirements and limits, Check documents for compliance
Track a document check from start to finish
Document Checker now shows one Checking Document run from the moment you start, including preparation of an uploaded PDF. Follow its stage and question progress in My Inbox or the checker window, return to it after closing the tab, and cancel it while keeping completed answers clearly marked as a partial check. Validation reports use the same checker and previous-run history as other documents; checks read uploaded PDF reports and the authored content of online reports. Large PDFs use far less memory, and a check whose background worker stops now ends as failed instead of appearing to run indefinitely.
Learn more: Check documents for compliance, Document jobs in your inbox
Announcements
Schedule organization-wide announcements in My Inbox
Customer Admins can create announcements under Settings > Announcements, publish them immediately or schedule a start and end time, and choose Info, Warning, or Critical. Notices reach every active member through My Inbox, including its dashboard widget, and members who join while a notice is live receive it too.
Every live announcement is pinned above other updates in My Inbox, Critical ones first. Critical announcements cannot be dismissed until they expire or an admin retires them, an unseen critical notice opens My Inbox after sign-in, and critical notices are emailed to every member when the Critical announcements email event is enabled. Admin actions are recorded in the Settings Activity Log.
SMTP and Amazon SES notification emails also keep readable text in dark mode, and critical announcement emails are clearly marked.
Learn more: Manage announcements
Act on My Inbox tasks from your dashboard
The My Inbox widget brings your updates and tasks to your dashboard with the same filters, selection, bulk actions, and per-item actions as the sidebar inbox. Acting on an item in either place updates the other.
Learn more: Add My Inbox to your dashboard, Customize your dashboard
Inventory
Explore inventory interdependencies with richer views
Existing upstream/downstream interdependencies gain a configurable table of dependent records and artifacts, relationship types, and dependency analytics. Choose core, custom and stakeholder columns, save personal or organization-shared views, and label record relationships with types such as Data Source or Challenger. Use upstream and downstream Record IDs in inventory columns, filters and CSV exports, and chart individual relationships with the Inventory Record - Dependencies Analytics dataset.
Learn more: Configure record interdependencies
Work across record types with published inventory segments
Selecting a published Inventory Segment lets you filter, group, sort, export, and save views across all records in that segment, regardless of inventory record type.
Learn more: Manage inventory segments › View a segment as the inventory scope
Group artifacts across types with published artifact segments
Artifact Segments let you save a set of artifact filters as a named, reusable segment that spans every artifact type, including validation issues. Publish a segment to open it as a scope on the Artifacts page, where you can filter, group, sort, and export the matching artifacts across types, to apply it as a Segment filter rule, and to use it as a dataset in Analytics. Segments use the fields every artifact type shares, and users only see the artifacts they have permission to view.
Learn more: Manage artifact segments
Calculated fields
Filter by calculated values and find calculation errors
You can now filter inventory records and artifacts by calculated values, both in the app and through the API. This was not available before. Formula results have a type: text, number, date, or yes/no. Existing formula fields were assigned a type automatically from the results they had already produced. Aggregation fields use the type of the value they calculate.
Choose a filter that fits the field's type:
- Yes/no, such as Validation Overdue: equals Yes or equals No.
- Number, such as Days Since Last Validation: greater than 365.
- Date, such as Next Review Date: between January 1 and March 31.
- Text, such as Risk Tier: use the same filters as other text fields.
Filters that do not fit the field's type are rejected with a clear message explaining what to change, instead of returning wrong or empty results.
Two new filters help you find calculations that need attention:
- has error finds records where a formula or aggregation failed, shown as
ERR:in the app. - has wrong value type finds type mismatches, such as text returned by a formula with a Number result type. It applies only to formulas with an explicit or automatically inferred result type. It does not apply to aggregation fields; use has error for those.
Use has error to find affected records, fix the formula, and filter again to confirm there are no remaining matches.
A notice next to applied filters shows whether stored values are up to date and, if not, the age of the oldest value and the next automatic refresh. The field editor lets you declare a result type and warns when a formula returns a different type.
Learn more: Working with the inventory › Filter by calculated and aggregation fields, View and filter artifacts, Manage inventory fields › Inventory field types
Enhancements
AI features
Use GPT-5.6 models with AI features
AI features support OpenAI GPT-5.6 models, and self-hosted installations can configure them by setting reasoning_effort to none for each GPT-5.6 LiteLLM entry.
Analytics
Analyze time spent in artifact statuses
The Artifact Statuses Durations Analytics dataset shows how many days each artifact has spent in each status across standard and custom artifact types. Chart average time in status or export the rows through the reporting API and scheduled Data Exports. Scheduled exports also work for Inventory Record Stages Durations. Artifact status history is available from August 2026 onwards.
Calculated fields
Review the impact before deleting a calculated field
The delete confirmation shows how many records hold a calculated or aggregate field's stored value and whether deleting it will remove conditions from saved-view filters, so you can review the impact before confirming.
Use calculated fields in segment conditions
Inventory and artifact segment conditions can now use Calculation and Aggregation fields, with the same operators as the filter builder, including has error and has wrong value type where the field supports them. Segment results show every shared field as a column, and calculated values and dates display correctly. Calculation and Aggregation fields are no longer offered as attestation inventory scope conditions.
Review calculated-field formula changes in the Activity Log
You can compare previous and new formula code and variable changes, identify who made an edit, and read multiline formulas with their formatting preserved.
Document Checker
Manage built-in Document Checker regulations and assessments
Your organization can archive or delete built-in Document Checker regulations and assessments to use its own question sets. Archived items can be restored at any time. These changes apply only to your organization and leave previous runs and artifacts already created intact.
Document templates
Cancel PDF outline parsing from a template
You can stop an in-progress PDF outline from the Parsing PDF… button on the template page or from its progress notification, after confirming the cancellation. Cancelling from My Inbox still works as before.
Inventory
Filter inventory from a table cell
Hover over a supported cell in the Record Inventory and click its filter icon to narrow the list to that cell's value, without building the filter by hand.
My Inbox
Make inbox notifications easier to scan
Distinct titles, context, statuses, action areas, and consistent overdue indicators help you identify tasks and updates that need attention.
Public API
Manage severities and guidelines through the public API
Your tooling can now create artifact severities and delete guidelines without requiring those actions in the UI.
Test results and reports
Style test summary table cells
Tables styled with pandas.Styler now retain cell colors, bold text, and alignment in the documentation UI and HTML and DOCX reports.
Workflows
Filter Global Workflows by workflow name
Select one or more workflows in the new Workflow Name filter to focus the Global Workflows list, timeline, and CSV export on them. Results stay limited to the workflows you are permitted to access.
Use variables in workflow artifact details
Create Artifact steps can fill titles and descriptions from record details and available breached-metric information, so one workflow can create appropriately named artifacts across records.
Bug fixes
Analytics
Findings exports retain analytics filters
Exporting findings from a filtered analytics chart now returns findings matching the filter shown on screen, even more than 15 minutes after you applied it.
Artifacts
Refresh record fields and stage filtering for artifacts
You can filter artifacts by Record: Stage when Stage is a record field, and reopened artifact type details show subsequent record-field changes.
Keep artifact group headers visible when collapsed
Collapse All no longer leaves a grouped Artifacts list blank, so you can still see its group headers and expand the groups again.
Business Units
Reuse deleted Business Unit names
You can create a Business Unit with a previously deleted name, while deleted units no longer appear in the affected filters and assistance results and active names remain protected regardless of capitalization.
Calculated fields
Repair calculated fields affected by the formula migration
Affected formulas are repaired on upgrade and recalculate when you next open their records, replacing a Code execution failed message with the computed value.
Custom fields
Show custom field changes without reloading
Created or edited artifact and inventory custom fields now appear immediately in their fields lists.
Dashboards
Keep dashboard widget artifact type selections
An artifact type selected for a shared widget remains selected after publishing, reloading, or returning to the dashboard and is visible to its viewers.
Show widgets immediately in Add widget
Opening Add widget shortly after a dashboard loads now displays the available widgets instead of an empty list.
Documents
Show Insert Variable options in the document editor
The menu displays its options when toolbar space is limited and explains when organization-wide Track Changes has disabled it.
Restore permitted access to document type details
Non-admin users whose roles allow them to view document type details can now open those details without an incorrect access denial.
Long Text fields embedded in documents keep their content and formatting
A rich-text Long Text field embedded as a variable in a document text block no longer renders blank when the record still shows the field's template. Its tables, lists, and headings keep their formatting, variables inside the field resolve, and a field the reader cannot see shows an Access denied marker instead of raw variable text.
Documents and inventory
Improve loading of template and stakeholder choices
Access checks are faster, and template, Record Owner, and stakeholder selectors show a loading state instead of remaining empty until you refocus the browser tab.
Evidence assessments
Keep approved evidence assessments visible while editing
Clicking an approved assessment's text block no longer makes the assessment disappear or risks replacing it with an empty block.
Findings
Reuse deleted finding status names
You can create a finding status with a previously deleted name, while names still in use remain unavailable regardless of capitalization.
Findings lists and exports with calculated fields no longer time out
Listing or exporting findings that have calculated fields now uses the stored values instead of recalculating every finding, so large CSV exports complete instead of timing out. Values refresh when a finding is opened or edited, when its field is changed, or on the scheduled calculated-field refresh.
Inventory
Use saved layouts in Bulk Edit
Bulk Edit now respects your saved layout instead of ignoring it.
Restore permitted saves of core inventory fields
Record Owners and other authorized non-admin users can again save core fields such as Tier without being denied by an unrelated custom-field permission check.
Show only enabled core fields in inventory filters
Core inventory fields disabled by an administrator no longer appear in inventory filters, attestation scopes, segment conditions or workflow execution filters.
Keep the Intake document default when saving its record type
Editing and saving the Intake inventory record type no longer removes its Development document default or prevents registration of unclassified records.
Prevent crashes while inventory roles load
The Inventory Record overview remains available while your organization's role data is loading.
Use a consistent Inventory Record Stage label
Inventory tables and controls, segment views, and charts now use the same label for the stage field.
Reject unknown stakeholder roles before creating a record
An unknown role name must now be corrected before record creation, preventing a record from being created with incomplete stakeholder assignments.
Inventory fields
Save custom inventory fields with their role permissions
Authorized non-admin users can create or update a custom inventory record field and its role grants together without a 403 error or lost permissions.
My Inbox
Remove assessment tasks when they are no longer assigned
Inbox tasks from assessment workflows now disappear when a step ends, a workflow finishes, or a role or stakeholder change makes you ineligible, while active tasks you can still complete remain.
Notifications
Keep email notification subjects on one line
User-entered titles and names no longer introduce line breaks or formatting markup into notification email subjects.
Show readable failure notifications
Gateway or proxy failures now display a plain-text message with the status code rather than raw HTML in a notification.
Notification emails reach every recipient
Notification emails no longer skip the remaining recipients when one address is inactive or has bounced. Updating a finding through the API with an invalid relationship value now returns a validation error instead of a server error.
Public API
Preserve API client error responses
Affected requests now retain their original 4xx response instead of returning 500, and specified record and artifact field requests identify unknown values with a 400 response rather than a misleading missing-field 404.
Clarify errors for invalid severities and accounts without organizations
Public API finding requests identify an undefined severity with a 400 response, while signed-in accounts without an organization receive a clear 403 instead of an intermittent server error.
Return a clear error for unknown record field keys
Public API requests for a record field key that does not exist now receive a 404 response naming the missing field instead of a server error.
Risk areas and guidelines
Delete risk areas and guidelines that are no longer in use
Deleted artifacts, and artifacts or assessments on records in the Deleted stage, no longer block deleting a risk area or guideline. Only live items count, the dependency check lists only those, and the audit log records what each deletion removed.
Roles and permissions
Enforce configured role-management permissions
Role settings and their controls now follow the corresponding view and action permissions, including for custom organization-admin roles.
Users
Invite users who already sign in with SSO
Inviting a user who already exists through a single sign-on or social connection now succeeds instead of failing.
Validation reports
Include all linked evidence in validation report exports
Evidence linked from a second document of the same type now appears in the export appendix, so its View More link reaches the corresponding evidence.
Fix validation policy checks for reports not yet set up
Policy checks no longer fail silently when a validation report lacks a template or uploaded PDF, and assigning a template no longer leaves the document behaving like an offline PDF.
Workflows
Fix AI-generated workflow field values
A workflow that reports a successful AI-generated field update now writes a newly generated value instead of leaving the field's existing value unchanged.
Stop workflows associated with deleted artifacts or records
In-progress workflows stop when their artifact or record is deleted, and workflows left open by earlier deletions close so they no longer appear open or late.
Send workflow broadcasts only to active recipients
Workflow Broadcast steps no longer send emails or in-app notifications to disabled accounts or users removed from the organization.
Keep workflow editor pickers accessible
Long Insert Variable field lists can be scrolled within the window, and record and artifact preview dropdowns in Broadcast steps can be clicked.
Breaking changes
Public API
Calculated-field API filter compatibility
Before this release, the API accepted filters on calculated fields but ignored the calculated value when applying them. These filters now apply to the calculated value and must match the field's result type. Scripts that previously attempted them may now receive a descriptive HTTP 400 if an operator is incompatible or a value cannot be converted to the field's type. In particular, in and notIn on yes/no (Boolean) calculated fields return HTTP 400.
Action required: If your scripts filter calculated fields, verify that each operator and value fits the field's result type. Replace Boolean in or notIn rules with = and the intended Boolean value. For the new diagnostic filters described in the feature highlight, use hasError or typeMismatch without a filter value. typeMismatch applies only to formulas with an explicit or inferred result type; use hasError for aggregations.
Deprecation notes
Public API
Use record-type-specific lifecycle stage endpoints
Use /inventory/{prt_slug}/stages to manage lifecycle stages for a selected inventory record type. The existing /model-stages endpoints remain supported but are deprecated. Stage creation also works for users with access to multiple record types, and /vm/api/latest preserves typed client-error responses instead of returning a server error.