Release v0.120.0
Oct 01, 2026
Backups to S3 are written only through short-lived storage sessions, restores are checked against each snapshot's integrity record, consent prompts report whether they were actually shown, and platform admins get a new AI models page. AI chat usage on multi-turn chats is now counted correctly. Security hardening across backup, restore and remote access. Upgrade recommended.
Backup & Recovery
- Backups to S3 and S3-compatible storage are now written only through a short-lived, write-scoped storage session. No backup command carries your storage keys anymore. Devices need the 0.119 agent or later, and storage endpoints and the agent connection must use HTTPS. Local and NAS destinations are unchanged.
- A new card in each Backup policy's Destination section lists the storage keys your S3 destinations used before this release. Replace each key with your storage provider, disable the old one, then confirm with Check old key or I disabled this key.
- Every restore, verify, test restore, VM restore and bare-metal recovery is checked against the snapshot's integrity record before anything is installed. A snapshot that failed its integrity check is refused; older snapshots without a record still restore and are labelled unattested.
- Windows restores are stricter: file names Windows reserves are refused, and restored permissions that name accounts the machine doesn't recognise are replaced with a locked-down set. The result lists those paths.
- Restore and Recovery views show clear result codes, and advisory warnings no longer show up as failures.
- Recent Windows registry changes are now captured in system-state backups and rebuilt machines.
- A Bare metal rebuild step in a DR plan now waits up to 24 hours by default instead of 4.
- When the agent can't tell which backup features a device supports, it now says unknown and retries, so a brief hiccup no longer makes an up-to-date device look outdated.
Remote Access & Consent
- Consent prompts now report whether they were actually on screen and whether anyone was signed in. Technicians see a specific message for each outcome, and the audit log records it. Under a Require consent policy, a signed-in user who couldn't be shown the prompt is always refused.
- The fallback remote desktop connection now follows the same start rules as the main one: it honours notify mode and the consent prompt, and End stops it immediately. It no longer refuses every start under a notify or consent policy.
- New installs require an agent that supports the remote desktop start check (0.114 or later). Existing installs keep their current setting until they turn it on.
- Breeze Assist on Windows receives its credential only over the agent's local channel and no longer stores it in the agent's config file. For now Assist on Windows runs in the console session only.
- A remote desktop start the server couldn't read now fails with a clear message instead of sitting on connecting.
AI & Automation
- AI chat usage is counted correctly on multi-turn chats. Each turn was being charged the running total of the conversation so far, which inflated session cost, budgets and AI credit use. Each turn is now charged only its own cost.
- The default AI model is now Claude Sonnet 5.5 with adaptive thinking. Existing chats keep their model. Self-hosters routing AI through a gateway alias should update the alias.
- Platform admins get a new Admin → AI models page to manage prices, offered models and the default model. A daily discovery job flags new models for review and never enables or prices anything on its own.
Fixes Across the Console
- The device Patches tab shows each patch's real approval state for its ring instead of Pending approval on everything.
- Built-in alert rules such as Patch job failures and Reboot pending too long can be switched off.
- Recommended → Attach to policy works on a policy that doesn't have a monitors link yet.
- Network topology no longer gets stuck on Building the topology map after you turn it on; each site's first snapshot imports automatically.
- Editing a Text, Number, Boolean or Date custom field saves again.
- Re-running the Windows install one-liner no longer fails when the agent service is already running.
- The Add Device command and its copy button appear only once an enrollment token exists.
This release is mostly about backups you can trust. Backups to S3 storage are now written only through short-lived storage sessions the server hands out, so no backup command ever carries your storage keys. Every restore is checked against the snapshot’s integrity record before a single file is installed, and Windows restores refuse file names and permissions that don’t belong on the machine. A new card in each Backup policy walks you through retiring the storage keys your devices used before.
Remote access gets more honest about consent. Prompts now report whether they were actually shown and whether anyone was signed in, so technicians see exactly why a session didn’t start and the audit log records it. The fallback remote desktop connection now follows the same rules as the main one. On the AI side, multi-turn chats are now charged per turn instead of the running total, the default model moves to Claude Sonnet 5.5, and platform admins get a new AI models page.
Self-hosters, read before you upgrade: backups to S3 now need every backing-up device on agent 0.119 or later and HTTPS for both storage endpoints and the agent connection. Upgrade the server before agents, and update any AI gateway alias for the new default model. The GitHub release notes have the full upgrade detail.