18-08-2026 July 2026 System Release V2
Summary
This release signs users out after 30 minutes of inactivity, works out plant compliance status separately for each client, and speeds up the Online Training Report. It also brings a large set of fixes across Incidents, Sites, Forms, Inspections, Online Training and Live Access.
Authentication
Automatic sign-out after 30 minutes of inactivity - Client staff are now signed out and returned to the login screen after 30 minutes without activity. Previously some parts of the system kept a session open indefinitely, so a browser left unattended stayed logged in. Any activity resets the 30 minutes.
Mobile number verification now uses a code sent by SMS - Confirming a mobile number is now a two-step process: enter the number, then enter the 6-digit code sent to it. The number field also applies tighter checks and shows clearer messages when an entry is not accepted.
Staff
Staff List now hides deactivated staff by default - The Staff List opens with inactive and processing staff filtered out, so large lists are easier to work with. The status filter can be changed or cleared at any time to show everyone.
Filtering and searching the Staff List fixed - Leaving one filter blank no longer cancels the other filters or the search box.
Staff list export shows the correct characters - Downloading the staff list as a spreadsheet now shows characters such as & exactly as they appear on screen. This affects the staff categories, document categories and pending documents columns.
Sites
Bulk export of location QR codes - You can now tick multiple sites in the Sites list and download all their location QR codes at once as a single ZIP file, instead of opening each site and saving each QR code one at a time. Your selection is kept as you move between pages of the list.
Outstanding actions listed in the site finished email - When a site is marked as finished, the notification email now shows how many inspection, risk register and incident investigation actions are still open for that site. The summary is left out when nothing is outstanding.
Site boundary reset now clears the map properly - On the Site Access tab, resetting a location's map boundary now removes it from the map straight away. Previously the boundary could stay on screen after being reset.
Site document fixes - The Save Changes button now activates when you change only a document's owner, and you are warned about unsaved changes if you close without saving. On phones and narrow screens the document details now open straight away when editing a document that is waiting to be uploaded. Staff with view-only site access no longer see a Delete button that never worked for them, and the Delete button on the document category panel now matches the size of the buttons beside it.
Incidents
Restricted incidents now visible and filterable - Incident administrators can now see which incidents are restricted directly from the incident list, sort by it, and filter to show only restricted or only non-restricted incidents. Restricted status is also included in their incident CSV exports. Everyone else sees no change.
Colour-coded due dates in pending action tooltips - Hovering over the Pending Actions status on the Incident list now shows each corrective action and investigation due date in red if it is overdue and blue if it is still upcoming.
Weekly incident report email now shows only recently closed items - The Closed Actions and Investigations section of the weekly email now lists only items closed in the last 7 days, so older items no longer build up. Open and pending actions are unaffected.
Incident photo uploads no longer create broken links - If a photo or file fails to finish uploading to an incident question, the system now rejects it and asks you to try again, instead of saving a link that opens to an error.
Deleted corrective action links no longer show an error page - Opening a link to a corrective action that has since been deleted now shows the standard page not found message instead of a system error.
Safer deleting of incident tags - Removing an incident tag that has already been deleted no longer shows an error page. Tag deletion is now properly restricted to the organisation that owns the tag.
Stronger access checks on incident details - Additional authorisation checks are now applied when incident details are retrieved, bringing this in line with the rest of the module.
Inspections
Clearer attachment and PDF viewer - Opening an attachment now shows a bar fixed to the top of the screen with the file name and simple back, forward and close buttons, so it is always clear which file you are looking at. Multi-page PDFs now show a single Download PDF button in that bar instead of one repeated after every page. This applies wherever attachments are viewed, including Incidents, Plant photos and Risk Register.
Import Inspection now gives a clear message instead of an error page - Importing an inspection from a spreadsheet no longer fails with a server error when no checklist categories have been set up yet. You are told to create a category first, and rows left blank are matched to your own organisation's categories.
Clearer feedback on the Modify Inspection button - When you can view an inspection but not change it, the Modify Inspection button is now greyed out and hovering over it explains why. Previously the button looked available but nothing happened when you clicked it.
Filter buttons now show matching filter tags - The quick-filter buttons on the Inspection Actions, Inspection Checklist Items and Risk Register Actions lists now display a filter tag when switched on, so every active filter is visible in one place. The records shown are unchanged.
Forms
Duplicate permit submissions blocked - Submitting a permit no longer creates the same record twice if the same submission reaches the system more than once. This also stops the duplicate email alerts that followed each repeated submission.
Form and inspection PDF exports no longer fail on unsupported attachments - Printing a form or inspection as a PDF used to fail completely if an attached document was saved in a newer file format the system could not read. The PDF now generates as normal, with a short notice in place of the attachment that could not be included.
Return to the current Forms list after creating a form for someone else - When staff create a form on behalf of another person and save it, they are now taken back to the current Forms Overview page instead of an older version of the list.
Clearer outstanding forms in the compliance reminder email - The compliance reminder email now names each outstanding form at the top of the row and explains what to do next in plain English, such as Not Started - Please complete this form to proceed. The reference number and description now sit underneath in smaller text.
Online Training
Online Training Report loads faster on large organisations - The report now shows its rows straight away, with the total count and summary cards filling in a moment later. Filters chosen in the filter panel are applied once when you close the panel with Done, so the report runs a single time instead of re-running on every change. This report now uses previous and next paging rather than numbered pages.
Deactivated workers now show in Online Training - Workers who have been deactivated are once again included in the Online Training list and its export, so administrators can review the training assigned to them. Filtering by active and deactivated status at the same time now correctly shows both.
Clear message when a training review cannot be opened - When a worker clicks Review on a completed online training and the course records are no longer available, they now see a plain explanation and an OK button, instead of being silently returned to the Dashboard. The message also distinguishes between training content that has been removed and completion records that have been reset.
Trial reminder emails no longer go to paid seat holders - Staff who already hold a paid author seat no longer receive the trial expiry emails, and their courses are no longer transferred or archived when the old trial date passes.
Revoked paid seats now show as Paid Cancelled - When an administrator revokes someone's paid course-author seat, that person's status now clearly reads Paid Cancelled rather than Paid Expired, so it is obvious the seat was withdrawn rather than run out. The affected person sees a matching message and can no longer start a free trial.
Course names no longer change by themselves - Opening an AI-built online course for editing could silently replace its name with the name held in the content editor, and the next save applied that rename for everyone assigned to the course. The name you set in ComplyFlow is now always kept.
Plant
Plant compliance status is now worked out per client - Each client now sees a plant's status based only on their own document requirements, so the plant register and the plant detail page always show the same result. A new grey NA status appears when no plant categories have been set up, and plants with categories set up but none assigned now show as Not Compliant.
Delete photos from plant and vehicle records - Users with edit access can now remove unwanted photos from a plant or vehicle record. Click Edit, use the bin icon on any photo, confirm, then Save to apply the change. Photo uploads now accept JPG, JPEG, PNG, GIF and WebP; HEIC images from Apple devices are no longer accepted.
Suppliers
Deactivating a supplier now deactivates all of its workers - Workers already marked inactive for an expired licence, or not yet registered, were previously skipped when their supplier was deactivated, so they kept their old status and stayed active on sites. All of a supplier's workers are now correctly set to inactive and removed from site access.
Supplier Documents table column alignment - The Status and File Name columns on a supplier's Documents tab no longer overlap when the browser window is narrow.
Workers
Reactivating archived workers is more reliable - Bringing an archived worker back to active no longer fails with a database error when several workers are reactivated at once, or when a worker is archived and immediately reactivated.
Contractor Documents page no longer breaks for contractors with no client links - The Documents list used to fail with an error when a contractor was not connected to any organisation or active project. It now loads correctly.
Correct wording in bulk assign confirmation messages - Assigning a single category or training course to one worker now uses correct singular wording instead of 1 categories or 1 selected workers.
Live Access
Site contact changes no longer remove the previous contact as Area Supervisor - Changing who the site contact is used to quietly remove the outgoing person's Area Supervisor role for that site, so they stopped seeing it and stopped getting permit notifications. Their role is now kept, and is only removed through the normal permission or supervisor-removal options.
The map keeps your zoom when you pick a worker - Selecting a worker from the list now re-centres the map on that person while keeping your current close-up view, instead of zooming back out.
Work order activity now supports emoji and other special characters - Comments and activity entries on work order jobs containing emoji or other four-byte characters previously failed to save. They now save and display correctly.
Risk Register
Safer deletion in Risk Register - Deleting a risk, an action activity, an attached file or a hazard category is now protected against accidental deletion from a saved link, a browser refresh or the back button. Deleting from the screen works as before, and deleting a hazard category now confirms first and updates the list without reloading the page.
Tighter checks on risks and invitations - Staff can no longer view the actions on a risk that belongs to a different organisation. The one-hour wait before an administrator invitation can be sent again is now applied correctly in every region.
Documents
Document approval transfers now recorded in User Actions - When someone transfers a document approval to another person, it is now recorded in the User Actions log, showing who transferred it, which document, and who received it. Any comment added during the transfer is recorded too.
Stronger access checks on document approval - Access checks on the document approval review screen have been strengthened, so document details and files are shown only to users whose permissions allow it. An unused legacy endpoint related to document approval handling has also been removed.
Tax Invoices
Duplicate tax invoices no longer sent from repeat clicks - The Generate and Send button is now disabled as soon as it is clicked and shows Generating, so a second click cannot create another copy of the invoice or send the invoice email again.
Clearer wording on the annual renewal invoice email - The closing paragraph now points suppliers to their account managers at the client organisation, or to the ComplyFlow support team. It no longer displays the client organisation's own contact email address.
Dashboard
Dismissed items now included in dashboard CSV exports - Exporting your dashboard to CSV with dismissed items shown now includes those rows, instead of producing a file with headings only. Client dashboard exports also come out as clean, readable text.
Contractor Portal
New Marketing Tools page - Contractors who are compliant with at least one client can now generate a ComplyFlow Compliant badge from a new Marketing Tools page. They can choose which of their categories to highlight, preview an email-signature or website version, and copy ready-made code to paste into their email signature or website.
Tooltips no longer run off the edge of the screen - Hover tooltips near the right-hand side of the browser window now shift back into view instead of being cut off.
CF Admin
Customisable sign-up pages - The wording, images and options shown on the free-account sign-up pages can now be set up as different versions and managed from an admin settings screen. A version is shown by adding a short tag to the sign-up web address, and how often each version is opened is counted.
General
Filter panel no longer closes when you highlight text - Selecting text inside a filter field by dragging your mouse across it no longer closes the filter panel and loses what you have entered. The panel now closes only when you deliberately click the shaded area beside it.
Reliable staff updates through the access-control integration - Updating a staff member through the access-control system no longer fails when several updates for the same person are sent at the same time. The training system is also now updated with the staff member's new details rather than their previous ones.
Changes to Be Aware Of
The following changes may affect how some features work. Please review these if they apply to your organisation.
You will be signed out after 30 minutes of inactivity - Client staff are now signed out and returned to the login screen after 30 minutes without activity. Some parts of the system previously kept a session open indefinitely. Any activity resets the 30 minutes, and contractor and worker logins are unchanged.
Plant compliance status now reflects only your own requirements - Each client now sees a plant's status based on their own document requirements. Plants at an organisation with no plant categories set up will now show a new grey NA status, and plants with categories set up but none assigned will now show as Not Compliant. Both previously showed as Compliant.
The Staff List now hides inactive staff by default - The Staff List opens with a status filter already applied, so inactive and processing staff are hidden until you change or clear it. CSV exports taken from the list follow whatever filter is applied, so clear the filter first if you need everyone included.
Confirming a mobile number now requires a code sent by SMS - Where your organisation requires a verified mobile number, the person enters their number and then a 6-digit code sent to it. The number must be digits only, between 6 and 15 digits, so numbers typed with spaces or hyphens are no longer accepted.
Deactivating a supplier now deactivates all of its workers - Workers already marked inactive for an expired licence, or not yet registered, were previously skipped and kept their site access. They are now deactivated and removed from site access along with everyone else. Suppliers deactivated before this release are not changed.