Release v0.119.0
Sep 30, 2026
Network topology is complete, Windows time sync monitoring and enforcement arrive, Xero joins QuickBooks for accounting, one report definition now covers many organizations, and backups upload through server-issued links. Security fixes and hardening land across the server, agent and Breeze Helper. Upgrade recommended.
Network & Monitoring
- Network topology is complete. Breeze builds each site's physical map from switch neighbor and address tables and from UniFi, and marks a connection as ambiguous when the evidence doesn't settle it. You can hide or restore a link per view. Turn topology on per partner under Settings → Partner → Modules.
- Topology operations: interface history and link health, site monitoring policies (arming one asks for an MFA check), on-demand traceroute, and views of what an outage would affect and what changed recently.
- Windows time sync monitoring: each device reports its time source, sync settings, domain role, timezone and time-service events on a new Time panel. A fleet Time page keeps 400 days of history with CSV export, and new time sync monitors are ready to attach. Needs the 0.119 agent.
- Time sync enforcement: a Time sync tab in Configuration Policies sets NTP servers, poll interval and the expected timezone, and knows the difference between domain members and standalone machines. Resync, Set timezone and Apply policy are one-click commands.
- Compliance alerts fire on the first failing check, stay open until the device is actually compliant, and close on their own when the rule no longer applies.
- Anomaly detection is much quieter. New persistence and novelty checks cut anomaly episode noise by about 87%, and the device badge and fleet findings count open episodes.
- Devices that check in but send no logs can now be found with a Logs silent filter.
Billing & Reporting
- Xero accounting: connect a Xero organisation, map contacts and items, import customers, push and void invoices, and sync payments both ways. It appears once the server has Xero app credentials configured.
- Multi-org report series: one report definition produces a report for every organization, or just the ones you pick, with recipient rules and an internal CC. Combine merges the near-identical per-org reports you already have into a series.
- Every saved report and every run shows which organization it covered and whether it was delivered. A scheduled run that reached nobody says so.
- New Backup status report.
- Invoices and quotes now go to the organization's contact with the Billing role. Editing the billing contact no longer overwrites the org's primary contact.
Backup & Recovery
- Brokered backup writes: with the 0.119 agent, backups to S3 storage over HTTPS upload through short-lived links issued by the server. The server then checks each snapshot against the backup's own record and marks it attested, usually within half an hour of the upload finishing.
- Windows rebuild hosts: rebuild a whole-machine Windows backup into a virtual disk on a Windows host, and optionally create a Hyper-V VM from it.
- Devices protected by Cove backup now count in the customer portal's backup tile, posture report and organization summary.
- Restores from S3 storage always go through a short-lived storage session. They need HTTPS end to end and an agent on 0.118 or later.
- Backup traffic has its own usage limits, so a busy backup never delays device check-ins.
- Restore and verification screens show device names and plain-language reasons instead of raw IDs.
AI & Automation
- Explain this: ask the AI to investigate a topology problem at a site. Every claim it makes has to cite its evidence, and the one diagnostic it can propose runs only after you approve it with a passkey.
- 42 more read-only tools are available to AI chat and AI agents, and monitors can be managed from chat.
- AI chat looks tools up as it needs them instead of loading every tool up front, which makes the first request about 71% smaller.
- An early version of AI Suggested Fixes remembers fixes that worked across your organizations, with Proven fix badges and votes. It is off by default.
- When no AI model is available, AI screens say 'AI isn't configured' instead of looking ready.
Remote Access & Devices
- macOS remote desktop keeps a persistent capture stream, for a much higher frame rate on macOS 14 and later.
- Remote desktop clicks land on target on Windows machines with monitors at different scaling levels. Needs the 0.119 agent.
- Breeze Assist on macOS and Linux no longer gets stuck on 'agent is still setting up'. The fix ships as a Breeze Helper update.
- macOS agents keep Full Disk Access through the upgrade.
- Software installs show Sent to agent, Downloading or Installing, and warn when an install goes stale, instead of sitting on Pending.
- A Patch jobs tab lists patch jobs created by AI or the API, with per-device results.
- Mobile app: a Reboot now button on reboot-pending alerts.
Security & Platform
- Security fixes and hardening across the server, the agent and Breeze Helper, including fixes for published security advisories. Upgrade recommended, and let agents and Breeze Helper update to 0.119.
- Live device inspection (processes, services, scheduled tasks, event logs, files, registry and live sessions) now needs the device execute permission. Viewer roles and the built-in approver roles lose it.
- Remote consent is enforced more strictly: on devices whose remote access policy requires consent, VNC and the AI screen tools are refused, and desktop sessions need an agent that can show the consent prompt.
- Approval Security: choose whether approvers need a registered approver device for high- and critical-risk approvals, per partner or per organization. It becomes the platform default on November 5, 2026.
- Notification channel and settings secrets are stored encrypted and shown masked.
- Users limited to certain sites see only those sites in fleet security posture, threats, the executive summary and OS distribution.
- Force MFA can be edited in Settings → Roles and is copied when you clone a role.
- Self-hosters can upgrade a digest-pinned install in one step with guided-setup.sh --upgrade, and Administration → System warns when the running version doesn't match.
This release finishes network topology. Breeze now builds the physical map of each site from switch and UniFi data, tracks interface history and link health, runs traceroutes, and shows what an outage would affect. Explain this hands a site to the AI, which has to cite its evidence for every claim. Windows time sync gets full coverage too: every device reports where it gets its time, a fleet page keeps 400 days of history, and a Time sync tab in Configuration Policies sets NTP servers and timezones for you.
On the business side, Xero joins QuickBooks for invoices and payments, and one report definition can now cover every organization with delivery status on each run. Backups upload through short-lived links the server issues, and the server checks each snapshot after upload. A Windows rebuild host can turn a whole-machine backup into a virtual disk and a Hyper-V VM.
This release includes security fixes and hardening across the server, the agent and Breeze Helper, including fixes for published security advisories. Upgrading is recommended, and let agents and Breeze Helper update to 0.119. Live device inspection now needs the device execute permission, so check custom roles that should keep it. Self-hosters on 0.118.x, read before you upgrade: relayed remote connections have failed since 0.118.0 until you remove one line from your coturn configuration, and restores from S3 storage now need HTTPS end to end. The GitHub release notes have the full upgrade detail.