What changed
Every release of the app and the connected sites. This page is staff-only; customers get release notes when there is something to announce.
28 September 2026
Google Chat alerts; documentation caught up; changelog goes internal
- Google Chat as a comms channel: add a webhook to a space and Avertari posts lifecycle alerts there, alongside Slack and Microsoft Teams.
- Architecture documentation (app, infrastructure, trust centre) now matches what is deployed: single sign-on, API keys, teams, the new sources, the Cloudflare edge design. Every README explains how to clone, branch and push.
- The changelog moved off avertari.io to this staff-only site; /changelog on the public site redirects home.
28 September 2026
Single sign-on, teams, and a developer site
- Single sign-on: an owner points the organisation at its OpenID Connect provider (Okta, Entra ID, Google, anything with discovery) and lists its email domains. People on those domains sign in through the provider; a groups claim decides their role, and optionally their team, on every sign-in. Enforce it and email links for those domains hand over to the provider instead.
- Teams: People services (HR), IT Ops, L&D and Recruitment. A team is a lens, not a rank. HR, L&D and Recruitment read each journey in their own terms: where the person is in the process, which accounts exist, what is still open for IT, and how much of a leaver's access closes by itself. IT Ops and admins decide the access steps. Invite someone straight onto a team, or change any member's role and team on the Members page.
- Every API documented: the OpenAPI description at /api/openapi.json, readable with a session or an organisation API key, and a reference site for it. Member and team changes are on the activity log.
28 September 2026
Pushed logs, API keys, access timing, activity
- SailPoint Identity Security Cloud connector: identities with their lifecycle state and attributes, the roles, access profiles and entitlements they hold, and identity creation and lifecycle-state changes as joiner and leaver events.
- Identity logs pushed to Avertari: a URL and a secret, and any sender that can POST JSON. Google Workspace admin audit through a Cloud Logging sink and Pub/Sub push, Okta or Entra records forwarded by a SIEM, or your own shipper. Nothing to fetch, nothing stored beyond the lifecycle events.
- Organisation API keys: automation (Terraform, CI) connects systems and reads journeys as the admin who made the key, on one organisation only, revocable at any time. The Okta and Google Workspace demo tenants now register themselves.
- Reports > Access timing: accounts still live after leaving, cut off late, live or created before the start date, nobody in the identity provider by the start date, and, explained for everyone, the accounts no HR source knows about.
- Organisation > Activity: who connected, changed or removed what, and when.
- One person is one head: the same email known to HR and to an identity provider counts once, with the HR record winning; an audit log and a directory naming the same account differently is one row.
28 September 2026
Google Workspace without a key
- Google Workspace connects through Avertari's own identity: authorise Avertari's client ID under domain-wide delegation in the Admin console and leave the key blank. Nothing is stored; revoke it in the console at any time. Your own service-account key still works.
- The demo company on this site and in the product's examples now lives on demo.avertari.io, a domain we own.
28 September 2026
Journeys, the offboarding forecast, and click-through reporting
- Journeys: every joiner, mover and leaver, with the accounts the person holds across your systems, what should change, and Approve / Done / Dismiss on each step.
- Offboarding forecast: for a leaver, each account gets a likelihood that it will be shut off without anyone doing it by hand, with the reason: what masters the account, and whether your identity provider deprovisions the app or only fronts its sign-in. A local account nobody deactivates is called out as such.
- Okta: reads app assignments and whether Okta pushes deactivation to each app (okta.apps.read, optional), and whether an account is mastered by Okta or upstream.
- Workforce: every number opens the people behind it. A month opens a calendar with the exact daily joiners and leavers, a day opens the people; a person links to their journeys.
27 September 2026
Edit a connection in place
- Integrations: correct an org URL, client ID or host without disconnecting. The credential and any event-hook secret stay as they are, the row goes back to pending and syncs again; correcting a connection also resets its manual-sync limit.
- Okta: token errors now carry Okta's own reason, and the guide explains the two Okta traps (a JWKS URL isn't used for client authentication; pasted keys need use=sig).
27 September 2026
Status page, website demo, patch notes
- status.avertari.io: live checks of the site, trust centre, app, API and connector identity every five minutes, incident history, email alerts and an RSS feed.
- avertari.io/demo: a fictional company showing live joiner, mover and leaver journeys and the workforce picture behind them.
- Integrations on the website: example tiles that open a step-by-step guide; AI crawlers blocked at the edge.
- Patch notes (this page) with an RSS feed.
27 September 2026
Identity providers as JML sources, Auth0, guides
- Okta, Microsoft Entra ID and Google Workspace now feed the workforce (department, title, hire date, employment type) and produce joiner/leaver events from their audit logs; Okta also in real time via event hooks.
- Auth0 connector.
- A source can be switched off from opening journeys while still keeping the picture current; the same movement seen by two systems is one journey.
- Setup guides for every integration, shown beside the connect form; Okta's shows Avertari's public key inline.
- Sync now / Retry sync; rows update themselves; open tabs offer a reload when a new build is live.
- Invitations can be resent, with an optional personal note.
27 September 2026
One schema per organisation
- Every source maps onto Avertari's person schema; organisations add their own fields once and use them across every source and report.
- Column mapping with a preview for CSV upload, CSV via SFTP and Workday; API connectors map custom attributes to the organisation's fields.
27 September 2026
Workforce model and reporting
- Garden leave, immediate termination, do-not-contact and leave reasons are first-class: access cut-off follows garden leave, immediate terminations are urgent, nobody marked do-not-contact is emailed.
- Employment type (employee, contractor, intern, agency, partner) and org structure (department, division, location, country, cost centre, level, squads and tribes under their own names).
- Workforce page: headcount, joiners, leavers and annualised attrition by any dimension, with a monthly trend.
- Example CSVs for joiners, leavers and full workforce extracts.
27 September 2026
Connectors
- Microsoft Entra ID, Google Workspace, HiBob, Personio, Workday (RaaS), 1Password (SCIM), Google Cloud IAM.
- CSV upload and CSV via SFTP (password or key, host-key pinning).
- Identity logs in Google Cloud Storage or Amazon S3: exported Okta System Log and Entra audit logs, read since the last sync.
- Integrations page with a single connect window for every provider.
25 September 2026
Platform
- Multi-tenant data model with row-level security; per-organisation encryption keys in Cloud KMS (the API encrypts, only the worker decrypts, in memory).
- BambooHR and Okta connectors; JML reconciliation engine (expected vs actual access, over-privilege, time-to-revoke); event-triggered lifecycle comms by email, Slack and Teams.
- Sign-in by email link or passkey; invite-only during early access.
24 September 2026
Launch
- avertari.io, the trust centre at trust.avertari.io with a gated security pack, and the app at app.avertari.io.