Skip to content
OnTrackio

Changelog

What shipped, honestly

A curated record of product changes, newest first. If you are evaluating whether this product is actively built: this page is the answer, and it only lists what is live.

July 2026

Audit log integrity, verified nightly

The tamper-evident audit log now re-verifies its hash chain every night, and any mismatch alerts every administrator through a notice that cannot be muted. Audit retention became a Settings field (30 to 3,650 days) instead of a support request.

Notification preferences with a security floor

Every user gets a channel-by-type matrix: in-app, email, and Slack per notification type. Slack notices now arrive as direct messages to the person concerned when a bot token is configured. Security notices such as breach alerts and offboarding warnings sit on a floor that preferences cannot silence.

Consumables and loaner equipment in the offboarding gate

Stockroom consumables can be reclaimed from holders with a full ledger trail, and offboarding now refuses completion while a leaver still holds consumables or pool checkouts, alongside the existing hardware and license checks.

Audit-readiness export

One click in the compliance hub produces a dated ZIP: hardware register, software register with renewal and legal fields, user access register with roles, and the audit history, ready to hand to an auditor as a data pack.

Finance dashboard, expanded

Book-value-at-risk, warranty expiry queue with values, acquisition and aging views, spend mix by location, manufacturer, and vendor, all FX-normalised per workspace currency.

June 2026

Two-party e-signed transfer agreements

Equipment handover became a real signing flow: the employee reads and signs, IT counter-signs, and the agreement renders as a PDF with evidentiary capture. Wet-signature scans are supported for the paper-first.

Passkey sign-in, end to end

WebAuthn passkeys work through the whole journey: enrolment, the sign-in challenge, and organisation policy enforcement, verified with real authenticators rather than fixtures.

Dual-region readiness

Workspaces carry their own currency, locale, timezone, and compliance jurisdiction. Dashboards FX-normalise mixed-currency estates, scheduled jobs run in workspace-local time, and US workspaces get US-shaped compliance surfaces.

Documents where their people are

Hardware documents became visible to the assignee and license documents to the license owner, behind a strict authorisation gate with confidential-by-default handling.

May 2026

SCIM 2.0 provisioning, live-verified

Joiners, movers, and leavers flow from Okta and Microsoft Entra into the workspace, including group-to-role mapping with automatic grant and revoke. Verified against both providers' real request traffic before release.

Generic SAML 2.0

Bring any SAML identity provider: just-in-time provisioning, attribute-driven role mapping, single logout, and a hardening pass covering replay defense, algorithm allowlists, and MFA policy alignment.

Honest coverage labels on the NIS2 evidence pack

Every Article 21(2) sub-control in the evidence PDF now carries an evidence-class label: native evidence, hygiene floor, proxy metric, or outside ITAM scope, so the pack never claims more than it demonstrates.

Security operations layer

Admin-panel IP allowlists, per-API-token network restrictions, a public status page, and an incident-response runbook with notification templates for the Article 23 timeline.

Setup guides for the pieces above: Slack notifications, agent deployment via Intune, Okta and Entra provisioning, and the full integrations list.

Earlier work, including the identity stack and the multi-workspace foundation, predates this public record. Questions about any entry: ask us directly.

See the current build

Everything above is live in the product today. A 30-minute demo shows it against realistic data.