Breeze RMM v0.84.0 — a feature release: catalog/quoting gets distributor + Pax8 + AI assists, billing gains bulk actions, an EDR operations surface (SentinelOne + Huntress) lands behind a flag, native ticket auto-replies & canned responses, a working HTTP network proxy, plus reliability, patching, and broad API security hardening.
Summary
- Quoting & catalog — inline TD SYNNEX EC Express price/availability lookup in the quote editor (#1922), a Pax8 subscription → contract-line picker (#1924), and AI auto-fill for new catalog items from a product name or SKU (#1942).
- Billing — bulk actions across quotes, invoices, and contracts, plus draft delete from the detail view (#1926).
- EDR operations (preview) — SentinelOne + Huntress threat/incident surfacing across the fleet, behind a feature flag (#1946).
- Ticketing — customizable auto-reply and reusable canned responses (#1931).
- Networking — a working HTTP reverse Network Proxy with a reworked discovery asset modal (#1913), and per-session TLS verification for the tunnel proxy (#1916).
- Endpoint management — Windows USB blocking enforcement with no kernel driver (#1871), MSI filename-bootstrap enrollment for Windows parity (#1902), and per-device config-policy compliance shown on the device detail page (#1895).
- Reliability & patching — saner reliability scoring (capped counts, age-aware windows, offender drill-down, de-duplicated events) and patch-list/update-ring fixes.
- Security hardening — a cluster of API authorization, session-revocation, and secrets-at-rest improvements.
Added
- Inline TD SYNNEX EC Express price & availability lookup by SKU inside the quote editor (#1922)
- Pax8 subscription → contract-line picker: link, change, pause, and unlink (#1924)
- AI catalog auto-fill — draft a new catalog item's fields from a product name or SKU (#1942)
- Stripe payment keys now live in Integrations → Payments instead of buried in billing settings (#1954)
- Billing bulk actions on quotes / invoices / contracts, plus draft delete on the detail view (#1926)
- EDR operations (preview) — SentinelOne + Huntress threats/incidents across the fleet, behind a feature flag (#1946)
- Ticket auto-reply + canned responses — customizable templated replies with merge variables (#1931)
- Network Proxy — working HTTP reverse proxy, with a reworked discovery asset modal (#1913)
- Windows USB blocking enforcement — no kernel driver required (#1871)
- Per-device config-policy compliance section on the device detail page (#1895)
- MSI filename-bootstrap enrollment for Windows installer parity (#1902)
- Reliability card: offender drill-down with age-aware windows and capped alarming counts (#1907, #1921)
- Viewer: interactive update prompt instead of a silent auto-close (#1909)
Improved
- PAM: UAC interception now defaults to opt-in for new orgs; existing active orgs are grandfathered to their current behavior (#1914) — see upgrade notes
- Remote Tools shows all services and has reliable Close / Back navigation (#1911)
- Tunnel proxy now does per-session TLS verification with an explicit scheme (#1916)
- Software Library loads correctly in "All Orgs" mode (aggregates across accessible orgs) (#1938)
- Network Changes has a clearer empty state that points to creating a discovery profile (#1940)
- Background sync/scheduler work split out of DB transactions to reduce connection pressure during S1 sync and patch scheduling (#1919)
Fixed
- Patches: selecting an update ring no longer collapses the patch list to 50 items (#1897)
- Patches: duplicate identical "Default" update rings are de-duplicated (#1939)
- Reliability: stopped ~1.37× count inflation from events double-counted across the window (#1904, #1905); agent now persists its reliability send cadence across restarts (#1912)
- Config Policy: Monitoring tab rendering fixed (no more invalid nested controls) (#1937)
- Catalog: the item drawer blocks saving a bundle when the detail load fails (prevents wiping components) (#1944, #1947); enrichment attributes are shape-validated on create (#1945, #1948)
- Peripherals: stop shipping an empty policy set on an enqueue-before-commit race (#1882)
- Database: partner-scope ring/approval migrations are now safe to re-run (#1941)
Security
- Hardening across the API: additional authorization/authentication gates (RBAC, step-up, signing capabilities), fail-closed mid-session revocation for the tunnel and event WebSockets, tighter cross-org/partner access boundaries, and webhook URLs encrypted at rest and masked on read (#1887, #1888, #1890, #1891, #1892, #1893). Self-hosters are encouraged to upgrade.
Self-Hosting / Upgrade Notes
Standard upgrade — bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d (run pnpm install if you build from source).
- Database — nothing required. 7 new idempotent migrations apply automatically on boot (
autoMigrate, unlessAUTO_MIGRATE=false): ticket response templates, tunnel per-session TLS verification, the partner-scope update-ring/approval guards + default-ring de-dup, installer bootstrap-token platform column, and the PAM UAC opt-in grandfathering. No large-table rewrites or backfills. - Behavior change — PAM UAC interception (#1914): new organizations default to opt-in for UAC interception. Organizations already active keep their existing behavior (grandfathered). If you rely on UAC interception for a newly-created org, enable it explicitly.
- EDR operations is a preview behind a flag. It's gated by the web build-time flag
PUBLIC_ENABLE_EDR_INTEGRATIONS(off by default). With it off, the fleet EDR pages and dashboard summary are hidden. No server env vars are required for the rest of the release. - No new required environment variables.
Full Changelog: v0.83.3...v0.84.0
What's Changed
- fix(api): block cross-tenant destructive DR command injection by @ToddHebebrand in #1888
- fix(api): close cross-org/partner app-layer allowlist gaps by @ToddHebebrand in #1887
- fix(api): add missing authz/authn gates (security RBAC, step-up, signing caps) by @ToddHebebrand in #1890
- fix(api): fail-closed mid-session revocation for tunnel + event WS by @ToddHebebrand in #1891
- fix(api,secrets): encrypt webhook URLs at rest + mask on read by @ToddHebebrand in #1893
- fix(api,ai): AI approval arg-match, device-memory site auth/injection, notif encryption by @ToddHebebrand in #1892
- fix(api): enforce app-layer site axis on reads + PAM rule writes by @ToddHebebrand in #1889
- feat(policies): per-device config-policy compliance route + device-detail section (#1876) by @ToddHebebrand in #1895
- test(api): raise timeout on flaky mcpServer effectiveTier site-axis test by @ToddHebebrand in #1900
- fix(test): treat file-level use('*', requirePermission) as a live perms source by @ToddHebebrand in #1901
- fix(patches): stop ring selection collapsing the patch list to 50 by @ToddHebebrand in #1897
- test(api): raise timeout on flaky mcpServer C4 site-axis alerts test by @ToddHebebrand in #1903
- fix(reliability): dedup events across window to stop ~1.37× count inflation (#1904) by @ToddHebebrand in #1905
- feat(viewer): interactive update prompt instead of silent auto-close by @ToddHebebrand in #1909
- fix(agent): persist reliability send cadence across restarts (#1906) by @ToddHebebrand in #1912
- fix(peripheral): stop shipping empty policies[] on enqueue-before-commit race (#1879) by @ToddHebebrand in #1882
- docs(billing): spec QuickBooks Online accounting integration (Xero follow-on) by @ToddHebebrand in #1885
- feat(agent): Windows USB blocking enforcement (no kernel driver) by @ToddHebebrand in #1871
- test(api): fix userDeleteResurrect 403 after #1887 partner-mgmt gate by @ToddHebebrand in #1915
- fix(pam): default UAC interception to opt-in; grandfather active orgs by @ToddHebebrand in #1914
- perf(agent): cut redundant Windows collection — batch hardware WMI, daily hardware/patch scans by @ToddHebebrand in #1910
- fix(web): show all services + reliable Close/Back in Remote Tools by @ToddHebebrand in #1911
- feat: working Network Proxy (HTTP reverse proxy) + discovery asset-modal UX rework by @ToddHebebrand in #1913
- fix(api): phase-split s1Sync + patchScheduler conn-holds (#1896) by @ToddHebebrand in #1919
- docs(issue-to-pr): prevent duplicate PRs when fanning out issue-fixers by @ToddHebebrand in #1920
- docs: sync technical docs for v0.83.1–v0.83.3 by @ToddHebebrand in #1899
- feat(installer): MSI filename-bootstrap enrollment (Windows parity) by @ToddHebebrand in #1902
- feat(reliability): cap alarming counts, age-aware windows, offender drill-down (#1907) by @ToddHebebrand in #1921
- feat(tunnel-proxy): per-session TLS verification + explicit scheme (#1916) by @ToddHebebrand in #1925
- feat(web): inline TD SYNNEX EC Express lookup in the quote editor by @ToddHebebrand in #1922
- feat: Pax8 subscription → contract-line picker (link/change/pause/unlink) by @ToddHebebrand in #1924
- feat(billing): bulk actions on quotes/invoices/contracts + draft delete on detail by @ToddHebebrand in #1926
- test(web): fix UserRiskPage fetch-order-race flake on Test Web by @ToddHebebrand in #1928
- chore(ci): Windows runtime smoke for agent startup (#1000) by @ToddHebebrand in #1930
- fix(db): guard partner-scope migration reruns (#1936) by @ToddHebebrand in #1941
- fix(patches): dedupe default update rings (#1934) by @ToddHebebrand in #1939
- fix(config-policy): avoid nested monitoring buttons (#1932) by @ToddHebebrand in #1937
- feat(tickets): customizable auto-reply + canned responses by @ToddHebebrand in #1931
- fix(software): support catalog all-orgs scope (#1933) by @ToddHebebrand in #1938
- fix(discovery): clarify network changes empty state (#1935) by @ToddHebebrand in #1940
- feat(catalog): AI auto-fill new catalog items from a product name/SKU by @ToddHebebrand in #1942
- feat(web): EDR operations surfacing (SentinelOne + Huntress) — Pillars 1–4a by @ToddHebebrand in #1946
- fix(catalog): validate attributes.enrichment shape on create (#1945) by @ToddHebebrand in #1948
- fix(catalog): block bundle save when detail load fails (#1944) by @ToddHebebrand in #1947
- docs(testing): UI QA sweep logs + test lists (v0.82.1 → 6c880e0) by @ToddHebebrand in #1951
- fix(catalog): record AI enrich spend to org budget (#1949) by @ToddHebebrand in #1953
- fix(catalog): coerce AI enrich output to schema instead of 502 (#1950) by @ToddHebebrand in #1952
- feat(web): move Stripe key entry into Integrations as a Payments tab by @ToddHebebrand in #1954
Full Changelog: v0.83.3...v0.84.0