Plenix 2026.09.1 — Clickable dashboards, a live knowledge graph and a security overhaul

Every dashboard number now opens the records behind it. Documents get version history and trash, LMS gets real quizzes and certificates, accounting goes multi-entity, and we shipped over 30 security fixes. Covers 21–25 September 2026.

T
The Plenix Team·25 September 2026·9 min read

This is the first of our versioned release notes. From now on, after every major round of work we publish a numbered release (year.month.number) listing what's new, what's better, what changed, what we fixed and what we tightened on security. This one covers 21 to 25 September 2026.

New features

Dashboards you can click into

  • Every widget drills down. Click any number, bar, slice or point on the main, CRM, HR, field service, accounting, projects and monitoring dashboards and you get the exact records behind it, in a drawer with links to each one. The totals and the records now come from the same query, so they always match.
  • 67 data sources for custom widgets, up from a handful. That covers tickets and ticket time, contacts, companies, proposals, contracts, backups, inventory, purchase orders, patches, SSL certificates, software, printers, security events, payroll, shifts, training, recruitment, LMS, campaigns, NPS, appointments, OKRs, e-signatures, compliance, legal, property and production.
  • Over 100 ready-made widgets: by engineer, by queue, SLA breach rate, average resolution, first response, CSAT, win rate, days to pay, and more. New chart styles include stacked, horizontal stacked, leaderboard and record list. KPI tiles can compare against the previous period and show a target.
  • Donut charts are easier to read, and every chart has hover tooltips. We also added quick-build presets and "today" timeframes.

Reports for every module

  • Every module now has a reports page with live, clickable report boards. That includes new pages for ticketing (13 canned reports), field service, compliance, customer success, security, legal, property, production, calendar, OKRs, LMS and e-signatures.
  • In accounting, click any line of the P&L, balance sheet or trial balance to see the journal lines behind it. Aged debtor and creditor buckets filter the table.
  • Ticketing adds a per-page selector, 5 pre-built reports and 20 canned reports.

Documents

  • Version history. Edits, re-uploads and restores keep the previous file as a numbered version you can download or restore.
  • Named milestones are never pruned. You can compare any two versions with a line-by-line diff for text and Word files.
  • Retention policy. Admins set how many versions to keep, and optionally a maximum age.
  • Trash. Deleted files and folders stay restorable for 30 days.
  • New views: Starred, Recent and Shared.
  • Moving files: a Move dialog and drag-and-drop between folders, in both the list and the tree.
  • Folder templates: 5 presets, or save any folder structure as a template.
  • Activity and comments: a folder and file activity log, plus file comments you can resolve.
  • Share-link permissions. Links can be viewer, commenter or editor. Guests can comment and upload, every access is logged, and you can be notified when a link is opened.

Learning (LMS)

  • Quizzes with single-choice, multiple-choice, true/false and written-answer questions. Pass marks, explanations and graded attempts.
  • Marking queue for written answers. Reviewers score each answer and leave feedback, and the learner is notified.
  • Attempt rules. Set attempt limits, a wait between attempts, random question draws and shuffled answers. Admins can reset attempts.
  • My Learning: assigned courses, a catalogue to enrol yourself, a course player and a quiz taker.
  • Enrolment and reminders. Bulk-enrol by person, department or everyone. Reminders go out when training is due soon or overdue.
  • PDF certificates with certificate numbers. Completing a course can grant a skill, you get expiry reminders, and people are re-enrolled automatically when a certificate lapses.
  • Markdown lessons and module attachments.

Accounting: multiple entities

  • Run several legal entities in one workspace. Each entity has its own invoice numbering and can be limited to its own chart of accounts.
  • Intercompany charges post a matched pair of journals and can be settled.
  • A consolidated P&L and balance sheet, with per-entity, eliminations and group columns.

Knowledge graph

  • Plenix now links records across CRM, ticketing, RMM, accounting, projects and field service every hour.
  • Explorer at Graph: search for a record, see what it's connected to, and check its history on any date.
  • Impact analysis: what depends on this device or company, which tickets are open, which contracts and how much monthly revenue are at risk. You also get a warning before you dispose of an asset that other records depend on.
  • The graph only shows records your role and plan allow you to open.

Threat intelligence

  • Your own feed of IOCs (indicators of compromise). Paste in a threat report and defanged values are handled for you.
  • An admin approves each IOC before it counts. You can retire old IOCs and set an expiry.
  • Look up any value on demand. SIEM events are checked against active IOCs automatically, and matches are escalated.

Automation

  • Date triggers: "30 days before a contract ends", "on the day an invoice falls due" and so on. There are 6 ready-made date templates.
  • Nested AND/OR condition groups and more operators.
  • Signed webhooks (HTTPS only, HMAC-signed) and a Slack/Teams/Discord/Google Chat action.

Search and security

  • Semantic search now uses real embeddings. Results are ranked by meaning, respect document permissions, and fall back to keywords if needed.
  • Security module: per-device EDR controls, device and event views, and richer triage.

Remote support (RMM)

  • One toolbar for both remote viewers (WebRTC and VNC). It includes observer mode, session notes, zoom, stats, a live terminal (PowerShell or CMD, admin or user), a process manager and system info.
  • Live chat with the end user pops up on their desktop. It's shared between every engineer on the session and stored encrypted.

Platform

  • Platform settings now work: company name, timezone and date format. Ticket list columns can be laid out as you like.
  • Contract renewal reminders. Contracts move from active to expiring to expired automatically, with a 90-day window.

Improvements

  • Remote sessions look sharper. Text is sharp, full screen really is full screen, the VNC cursor stays visible in full screen, and the toolbar slides in over the picture instead of shrinking it.
  • Toner stock waits for approval near the reorder level, so a small customer can't take the last cartridge ahead of a large one.
  • Sign-in on your phone is faster. The authenticator code field shows alongside the push prompt, so you never wait for your phone. Old sign-in notifications are replaced instead of stacking up.
  • The blog moved from docs.plenix.cloud to plenix.cloud/blog. Old links redirect.
  • New homepage with an interactive module star map, a flow explorer, a product carousel and a comparison against general business platforms as well as MSP tools.

Changes

  • The plenix.cloud, docs and app sites use cookieless, self-hosted analytics. The privacy and cookie policy has been updated to explain it.
  • Tenant data retention is now explicit. When an account closes, the data can be exported for 90 days and is then permanently deleted, with a deletion certificate. Billing records are kept for 7 years, as the law requires.

Fixes

  • Remote sessions: fixed "ghost monitors" appearing in remote sessions after someone had used Remote Desktop on the machine.
  • Trend widgets: all-time trend widgets (monthly trend, daily volume) no longer error.
  • Toner emails: supplier orders are always emailed, even when a supplier has API details on file.
  • Scroll-snap: the homepage no longer skips content on tall sections.
  • Blog cover images: fixed images missing on the blog.
  • Push sign-in devices: a brief notification outage no longer silently removes your push sign-in device.
  • Scheduled reports: these re-check plan access before sending. After a downgrade, they no longer email data from modules you no longer have.
  • Backups: backups retry automatically after a temporary storage error.
  • Reactivation: accounts can be reactivated right up until their data is actually deleted.

Security

This window included a full A–Z security review. We fixed more than 30 issues. None were known to have been exploited. We don't publish exploit details, but here is what changed:

  • Script protection. A strict, nonce-based script policy (CSP) is now enforced on the app, the docs and the marketing site.
  • Sign-in protection.
    • Each account locks after repeated failed MFA attempts.
    • A second-factor check can no longer be replayed.
    • Customer portal accounts lock after repeated failures.
    • Sign-in takes the same time whether or not an email address exists.
  • Suspended accounts. Sessions end as soon as a tenant is suspended or closed.
  • Access checks by module.
    • Dashboard widgets and global search now respect your role and your plan for every module.
    • A company's invoices, tickets, projects and contracts need the matching module.
    • Toner fulfilment records are limited to managers and finance roles.
  • One-time actions can't be repeated. Burn-after-read vault links, download limits, e-signature signing and portal proposal approvals now happen exactly once, even when requests arrive at the same moment.
  • Other hardening:
    • Exports are protected against spreadsheet formula injection.
    • Mail server settings are protected against internal-network requests.
    • Campaign links can't redirect to other sites.
    • Share passwords are no longer accepted in URLs.
    • Stored credentials in historical audit logs are redacted.
    • RMM sessions are bound to the signed-in engineer.
    • Payment webhooks are authenticated before they're processed.
  • Infrastructure.
    • Agent releases are signed, and canary updates are kept separate from normal ones.
    • Identity-server admin calls use a dedicated service account.
    • API logs are restricted.
    • Deploys no longer leave temporary copies of configuration behind.
  • Monitoring. There are 56 no-code platform health and security checks: sign-in anomalies, admins without MFA, disk forecasts, certificate and domain expiry, backup and restore-test failures, file integrity, and more. Each can be tuned or muted with a reason.
  • AI usage. AI usage limits can no longer be exceeded by sending requests in parallel, and AI inputs are validated.