Release v0.84.0
Jun 26, 2026
Enforce USB blocking on Windows, auto-fill catalog items with AI, work quotes and contracts in bulk with Pax8 and TD SYNNEX lookups built in, surface SentinelOne and Huntress activity in the console, connect the Network Proxy that never worked, and customize ticket auto-replies — on top of a broad security-hardening and reliability pass.
Security & Compliance
- USB blocking that actually blocks on Windows. Peripheral Control's Block and Read-only actions now genuinely enforce on Windows devices — previously they only logged and alerted while the device stayed fully usable. Enforcement needs no kernel driver, reverts cleanly when you remove the policy, and honestly reports 'alert only' if it can't confirm the block instead of falsely claiming success. macOS and Linux remain alert-only and are reported as such.
- Encrypted webhook secrets. Integration webhook URLs are now encrypted at rest and masked when displayed, so the secret tokens embedded in them are no longer stored or shown in the clear.
- Broad access-control hardening. A sweep of authorization fixes closes cross-organization and cross-partner data-access gaps, blocks a cross-tenant destructive-command path, enforces site-level scoping on reads and PAM rule changes, fails session access closed the moment access is revoked mid-session, and adds missing role, step-up, and signing-permission checks.
- UAC interception is now opt-in. Windows User Account Control interception now defaults to off for new organizations, with already-active organizations grandfathered in, so the feature only intercepts elevations where it's been deliberately enabled.
- Verified tunnel connections. The network tunnel now verifies TLS per session with an explicit scheme, tightening the security of proxied connections to discovered devices.
Billing, Quoting & Catalog
- AI auto-fill for catalog items. Type a product name or SKU and Breeze drafts a catalog item for you — descriptive fields filled in and a typical price range shown as guidance — for the one-off purchases that don't come from a distributor feed. You always review and enter the real price before saving.
- Per-organization Stripe in a Payments tab. Stripe key entry has moved into Integrations as its own Payments tab, making it clearer where to connect a customer's Stripe account for invoicing.
- Bulk actions on quotes, invoices, and contracts. Act on many quotes, invoices, or contracts at once, and delete a draft directly from its detail page.
- Pax8 subscriptions linked to contract lines. A new picker lets you link, change, pause, or unlink a Pax8 subscription against a contract line, keeping distributor subscriptions and your recurring billing in sync.
- TD SYNNEX lookups inside the quote editor. Look up TD SYNNEX EC Express pricing and availability inline while building a quote, without leaving the editor.
- Catalog refinements. The product catalog now works correctly in All-Orgs scope, AI enrichment records its spend against the org budget, and several catalog edge cases are handled gracefully instead of erroring.
Visibility & Monitoring
- SentinelOne and Huntress activity surfaced in the console. A new EDR operations view (initial rollout) brings SentinelOne threats and Huntress incidents out of the background and into the places you work — on a device's Security tab with inline isolate, kill, quarantine, and rollback actions; on partner-wide fleet lists; and as summary cards on the Security dashboard — with one-click escalation of any threat or incident into a tracked Breeze incident.
- Per-device policy compliance. Each device now has a configuration-policy compliance section showing how that specific device measures up against its assigned policies.
Remote Management & Network
- The Network Proxy now works. Connecting to a discovered device's web interface from Network Discovery previously hung on 'Connecting…' forever — the tunnel never actually opened. It now establishes a real, authenticated reverse-proxy connection so you can reach a LAN device's web UI through Breeze, with SSRF protections and the same allowlist guards as other tunnels. The discovery asset view is reworked to make linking versus proxying clearer.
- Better Remote Tools. The Remote Tools panel now lists all services and gives you a reliable Close/Back, so you no longer get stuck in the view.
- Friendlier viewer updates. The remote desktop viewer now shows an interactive update prompt instead of silently closing itself when an update is available.
Ticketing
- Customizable auto-replies and canned responses. Partners can now customize the acknowledgement email sent when a ticket is created from inbound email — with merge variables — and build a shared library of reusable reply templates that technicians insert into the reply composer with the ticket's details filled in automatically. Leaving the auto-reply blank keeps the existing default, so nothing changes unless you customize it.
Platform & Reliability
- Smoother upgrades for self-hosted servers. The partner-scope database migrations introduced in 0.83 are now safe to re-run, so self-hosted installations upgrade cleanly regardless of which prior version they're coming from.
- Windows installer parity. The MSI installer can now enroll using a bootstrap token embedded in its filename, matching the direct-executable enrollment flow.
- Sharper reliability scoring. Reliability now caps alarming-event counts, uses age-aware time windows so newly-enrolled devices aren't misjudged, and adds an offender drill-down; a separate fix removes a double-counting bug that inflated event counts by roughly a third, and the agent now keeps its reporting cadence across restarts.
- Lighter Windows agent. The agent batches Windows hardware collection and runs hardware and patch scans daily instead of every few minutes, cutting redundant work on monitored Windows machines.
- Reduced database pressure during sync and patching. SentinelOne sync and the patch scheduler no longer hold a database connection open across slow background work, continuing the connection-handling improvements from the 0.83 line.
- Patching fixes. Default update rings are de-duplicated, and selecting a ring no longer collapses the patch list to just 50 items.
- Smaller fixes. Peripheral policy syncs no longer briefly ship an empty policy set during a save, the Network Changes empty state explains that Alerting is a prerequisite, and a nested-button glitch in configuration-policy monitoring is cleaned up.
Version 0.84.0 is a wide-ranging feature release with a strong security and reliability backbone. The headline for endpoint control is real USB blocking on Windows — Peripheral Control’s Block and Read-only actions, previously alert-only everywhere, now genuinely enforce on Windows with no kernel driver and clean reversion. Alongside it ships a broad access-control hardening pass closing cross-tenant data-access gaps, encrypted-at-rest webhook secrets, verified tunnel connections, and opt-in UAC interception.
Billing and sales get a lot of attention. AI can now auto-fill a catalog item from just a product name or SKU for those off-the-shelf purchases that don’t come from a distributor, Pax8 subscriptions and TD SYNNEX pricing are wired directly into contracts and the quote editor, and you can now act on quotes, invoices, and contracts in bulk. Security visibility takes a step forward too: SentinelOne and Huntress activity is surfaced throughout the console — on devices, on fleet-wide lists, and on the dashboard — with one-click escalation into a tracked incident.
Rounding it out, the Network Proxy finally works end to end so you can reach a discovered device’s web UI through Breeze, ticket auto-replies and canned responses become customizable, and a deep reliability pass sharpens reliability scoring, lightens the Windows agent, and further reduces database pressure during sync and patching. Self-hosted servers also upgrade more smoothly thanks to re-runnable partner-scope migrations. It’s a recommended upgrade across the board.