Skip to main content

Release Notes — September 2026

Spans 2026-09-15 → 2026-10-05. 26 commits across five themes: sign-in (no more logout an hour after login), RBAC enforcement (module permissions and record access applied consistently, record-team access levels), scheduling and tasks (free/busy, schedule-aware task creation, task type durations, new filters), calendar coverage (admins see who has connected Google Calendar), and fixes across forms, email, contacts, dashboards and Customer 360.

Migrations to apply

Three tenant migrations ship in this period. Run them on every environment with:

npx ts-node apps/api/src/scripts/run-tenant-migrations.ts
MigrationAdds
085Gives every user who has dashboards the default tabs, and fills default-named tabs that are still completely empty. Customised tabs are untouched.
086Adds the automation (Workflows) permission: full access for roles at level ≥ 90 or named Admin / Super Admin, explicitly off for every other role so it can be toggled in the Roles screen.
087Seeds task type durations where blank — Call 30 min; Meeting, Demo, Onboarding 60 min — so schedule checks run.

Migrations now run only from the command line; the admin-panel migration endpoints refuse.

Read-only collaborators after deploy

Record-team members now get the access level they were added with. Existing memberships are read-only: collaborators who are outside the record owner's scope can still open and find the record, but can no longer edit it until someone switches them to Read/Write on the record's team panel.


Sign-in: No More Hourly Logouts​

Users were being logged out an hour after signing in. The web app now uses one shared HTTP client with a single-flight token refresh: the 1-hour access token renews silently in the background, and the session lasts as long as the 7-day refresh token. A follow-up fixed screens that still loaded the old client.

See Logging In.


RBAC: Permissions and Record Access Enforced Everywhere​

  • Module permissions are now enforced on contacts, accounts, opportunities, projects, targets, gamification and workflows. Opportunities check the opportunities module (not deals). Admin settings writes and sensitive reads are admin-only.
  • Opening a record directly (/leads/:id, /opportunities/:id, …) is checked against record access — users get a clear "no access" instead of seeing records outside their scope.
  • Record access now applies to lead, opportunity and task lists, Kanban, export and bulk select-all, and to global search and projects. Team scope uses team membership; reporting-line scope works in reports and dashboards; dashboard scope is clamped to the role.
  • Record teams:
    • Members can find records they collaborate on in list views.
    • Each member has an access level — Read or Read/Write — enforced on edits.
    • People added to a record team get a notification with the reason they were added, and the record's activity timeline shows it. The opportunity team panel gains role and access controls.

See Record Access and Roles & Permissions.


Scheduling, Tasks and Calendar​

  • Schedule-aware task creation — when you assign a task with a time to someone, the form shows their busy blocks, warns about clashes (without blocking the save), suggests free slots, and flags assignees who haven't connected a calendar.
  • Internal free/busy across users powers this (GET /scheduling/free-busy).
  • Task type durations — each task type has a default duration (editable in Task Settings) used when a task has no estimate.
  • Record team prompt — assigning a task on a record to someone who can't see that record offers to add them to the record team (with role, access and reason) before saving.
  • New task filters — Team, Department, and any active user as assignee.
  • Calendar Connections — a new admin page shows which users have connected Google Calendar, who hasn't, and connections that haven't synced in 24 hours. Users without a connection see a Connect your Google Calendar banner on the Tasks page.

See Managing Tasks, Task Views, Scheduling, Task Settings and Calendar Connections.


Forms, Email, Contacts, Dashboards and Customer 360​

  • Forms — hidden-field defaults are applied to API submissions; booking pages honour field visibility and width; public form, landing and booking pages always render in light mode.
  • Email — system emails no longer fail with "Greeting never received" (port 465 is treated as TLS, longer timeouts, quotes stripped from env values).
  • Contacts — the main email, phone and mobile are derived from the contact's email and phone lists; save errors show the server's message.
  • Dashboards — every user gets the default dashboard widgets.
  • Imports — CSV files are parsed with a faster parser (large uploads no longer time out; leading zeros are kept). Opportunities imported straight into Won/Lost get their won/lost dates stamped.
  • Customer 360 — account engagement counts activity on the account, its opportunities and its contacts, ignoring bookkeeping events; Recalculate reports failures.
  • Smaller fixes — the convert modal shows the lead's owner; Opportunity Settings saves a pipeline rename on blur/Enter; the subscription product picker searches the whole catalogue; the record team prompt scrolls into view; the service worker no longer intercepts Google / Gmail / Xero OAuth callbacks.
Legacy .xls files

Since the CSV parser change, legacy .xls (Excel 97–2003) uploads are not read correctly. Save the file as .xlsx or .csv before importing.


Index of changes​

  • a6ab6b9 parse CSV with fast-csv to stop upload 504s
  • 2b2cac8 contacts: derive email/phone/mobile from emails[]/phones[]
  • 3e8178f opportunity settings: save pipeline rename on blur/Enter
  • 3766f8e contacts: show the server's error message on save
  • bc515dd auth: stop logging users out an hour after login
  • 22d8c6d auth: repoint dynamic imports missed by the http client consolidation
  • d1c81f8 forms: apply hidden-field defaults to API submissions
  • 996e216 leads: show the lead's owner in the convert modal
  • 3dc5cd4 customer 360: meaningful account score recalculation
  • 93f7645 migration 085 — default dashboard widgets; stamp won/lost on import
  • 64dafd8 migration 086 — enforce module permissions and record access across modules
  • 232da87 email: stop "Greeting never received"
  • b7747f1 forms: honour field visibility and width on booking pages
  • 2fdd86e forms: public pages always in light mode
  • ea67b0c rbac: record team members find records in list views
  • 4a382ab scheduling: internal free/busy across users
  • ff9d1db calendar sync: connection coverage for admins
  • b02b6d7 accounts: subscription product picker search
  • 7cb3755 rbac: enforce record team access_level on writes
  • c9d3ef8 tasks: schedule-aware task creation and record team prompt
  • 4fd0869 record team: notify collaborators when added, with a reason
  • 24876f1 calendar sync: coverage page + connect prompt
  • abdbb1e migration 087 — task type durations
  • e775dda tasks: scroll the record team prompt into view
  • 9e60ded tasks: filter by team, department and any assignee
  • 6e36926 web: keep the service worker from intercepting /api OAuth callbacks