Skip to content

Release Notes

Version 17.0.2

  • Removed the redirect URL field from the LexisNexis RiskNarrative integration.

Version 17.0.1

  • Fixed an issue where wide Markdown tables in a case were squeezed to the field width instead of scrolling horizontally.

Version 17.0.0

Version 17 is faster throughout, puts AI to work on real compliance questions, and refreshes the interface. It introduces the compliance CRM: Atfinity can now be used as a CRM in its own right, one built around compliance rather than around sales. Alongside that come many improvements, large and small.

Highlights

Instance Tree pages, the compliance CRM

Client data no longer has to be read one case at a time. An Instance Tree page shows a client, everyone and everything connected to them, and the history of your dealings with them, so you can work from the relationship instead of from whichever case happens to be open. It gives you a CRM built around compliance rather than around sales, without a second system to keep in step.

AI Case Checks

Not every concern can be written as a rule. An AI Case Check lets you describe in plain language what would make a case worth a second look, and reports for every case whether that pattern is there, how serious it is and how sure it is. Reviewers see the judgement calls they would otherwise only find by reading the whole file, and a wizard can hold a case back until one is settled.

Atfinity Intelligence works on the case and the configuration

Atfinity Intelligence now does the work rather than describing it. In a case it reads what is there and fills values in. In the configuration it builds and changes ontologies, informations, rules, documents and pages, so a new configuration starts from something instead of from nothing. A tenant decides whether the AI may write at all, and each chat is then set to read only or to read and write, so it proposes where you want a proposal and acts where you want action. You can see how many tokens it has used.

Document text extraction

What a document says is available without anyone reading it first. Uploaded documents can be searched, compared against what was entered, and handed to the AI, so a case no longer waits on someone retyping what is already on the page.

Passport and identity card data extraction

Identity documents fill the case in themselves. Upload a passport or an identity card and the name, date of birth, nationality, document number and expiry date arrive in the fields you mapped, which removes the slowest and most error-prone step of onboarding. A value someone corrected by hand is never overwritten by a later upload.

Rules can see what changed and where a value came from

A rule can now compare a value against what it was, and tell a value a client supplied from one an integration or a document wrote. That makes it possible to react to a change rather than to a state, to treat evidence differently by its source, and to show in a document how each answer arrived.

A more compact, refreshed interface

More fits on the screen and less competes for attention. People working long cases scroll less, find things faster, and can size the panels around the task in front of them.

Case manager

  • Owner and assignee can be changed in bulk, from a case overview and from an insights widget, including to nobody. Bulk actions follow the permissions of the user, and the delete button says on hover why it is disabled.
  • Case list columns are chosen per user through the cogwheel.
  • Date ranges are one relative window across column filters and widgets. A metric over a window in the past can compare it with the window of the same length before it.
  • The case navigation can be hidden with the button beside the CaseID, and the browser remembers the choice for every case opened after it.
  • The case history holds one entry per move when several rules transition a case in one evaluation, and every state the case passed through counts as entered. The case_state_changed webhook reports the last move, and is also sent when such a chain brings the case back to the state it started in.

Case wizard

  • An AI Case Check evaluates a case against a description written in plain language and reports whether the problem is present, how severe it is from Very low to Very high, and how confident it is. The minimum confidence is configurable, a check is placed in a process tab, an instance page or a wizard step and belongs to the identifier it sits on, and a wizard step can be blocked while a check is still running or still needs attention.
  • An Identification element reads a passport or an identity card, including its machine readable zone, and fills the fields mapped to given names, surname, birth date, sex, nationality, document type, document number, issuing country and expiry date. A value a person entered by hand is never overwritten by a later upload, and @provided_by reports one the element wrote as Document extraction.
  • The text of an uploaded document is extracted and kept with the case, shown in the case manager and available to the AI, and is deleted together with the case. Reading a file blocks nothing by itself, and a transition that has to wait for the text says so in its condition through CASE.files_being_read.
  • Manual Instance Actions let a user run a configured action on an instance from the case: send an email, assign values, or create a lifecycle case. An action takes typed input parameters, respects the permissions of the user running it, and warns ongoing cases about the changed instance.
  • A Button layout element runs rule actions from a process layout, an instance page or a structure shown as a table.
  • A structure can be shown as an editable table, with configurable columns and widths.
  • An instance used by more than one case reports the other cases that use it, warns about it, and keeps its values in step between them.
  • A relationship information can offer instances belonging to other cases, and you choose which columns identify them in the picker.
  • A tab can be limited to the instances that match its condition, and all instances on a tab collapse at once.
  • Uploaded files show a thumbnail and open in a full screen preview, and HEIC uploads are read.
  • The case information side panel shows the Case ID, the process and the case roles.
  • Comments render markdown and open links in a new tab.
  • Saving a field with the value it already holds no longer adds an entry to the activity log, and a change inside a structure names the occurrence it happened in.
  • A case is locked while an integration runs.
  • A multi-line Text or Rich Text field never shows more lines than its maximum, and scrolls instead.

Instance pages

  • Instance Tree pages walk role, structure and relationship branches out of an instance, forwards or backwards, for one or many instances, and can be an ontology's default detail view.
  • Card List, Info List and Interaction Log are new page widgets alongside tables, charts and text. A Card List has filters and a link destination, an Info List downloads all files of an item as one archive, and an Interaction Log records calls, emails and meetings.
  • Only the author of an interaction log entry can change or delete it, and administrators can change and delete an entry whose author is deactivated or that has no author.

End user wizard

  • A New Case (Lifecycle Process) wizard starts a case from an instance page, and can also be started from another system over the API. The other system names the instance by its Atfinity id or by an identifier of its own, such as a customer number, held in an information whose value is unique among the instances. Started from an instance page, the wizard asks the person to confirm the email address it was started for before the form opens. Another system can instead vouch for the person, and the link it receives then works once and expires ten minutes after it was created unless opened, see Start wizards.
  • Wizard templates have a type: New Case, New Case (Lifecycle Process), Ongoing (instances) and Ongoing (whole case). A template offers only the New Case type that matches the kind of its process.
  • Documents and booklets are rendered, previewed and downloaded in the wizard, including ones hidden in the case manager.
  • Super categories group categories, and a super category's name can be a translated field value.
  • Field descriptions are shown as bubble text, render markdown, and collapse behind Read more. A validation error replaces the description while it applies.
  • A back button returns to the previous step, including when the condition of a step stops matching.
  • An AI Case Check can block the next step while it is still checking or needs attention.
  • The email address is filled from the first instance field that provides one, and is not reset when the template changes after someone set it by hand.
  • The case colour is shown in the wizard header.
  • The fonts are configurable and no longer come from Google Fonts, so text does not reflow while a font loads.
  • Fields of a locked instance stay read-only.
  • Numbers use the number format configured on the tenant, and dates use its date and time format whenever the visitor's browser language has no date format of its own in Atfinity.
  • A step places its fields where its layout shows them, moved up as far as they fit, so the layout no longer has a Clean up button.

Insights

  • Line charts are new, a pie chart can be drawn as a full pie instead of a donut, and a bar chart can be horizontal.
  • Charts can limit which groups they show. Grouped by State or Time Spent in State, a chart can leave out the final states, show only them, or show a chosen set; grouped by Owner, Assignee, Initiator or Process, it can leave out deactivated users and disabled processes.
  • Charts grouped by State or Time Spent in State can be sorted in workflow order.
  • Time Spent in State charts show days, hours or minutes, whichever fits, and collect the states beyond the maximum number of groups into an Other group holding the average a case spends in any of them.
  • A chart can use a reference date chosen from the widget's date and date-time attributes instead of the creation date, and a chart grouped Over time shows a Last and a Next number of intervals, so it can show cases whose date lies ahead. An existing chart keeps its maximum number of intervals as its Last count.
  • A stacked bar chart grouped over time draws every interval in its range, including an empty one, and chooses the values that get their own segment from their totals across the whole range.
  • The tooltip of a stacked bar chart shows every segment with its share of the bar, except on a Time Spent in State chart.
  • Charts are drawn at once instead of growing into place, and widgets take their new size immediately when the window is resized.
  • Cases can be deleted, their owner or assignee changed in bulk, and the selected rows exported, from a widget.
  • Boolean widget buckets are named Yes and No.

Documents, booklets and e-signatures

  • Proofs and file informations are included in booklets and can be signed, with grouped proofs shown under a Group column.
  • ADX has pie, bar, stacked bar and line charts, an OLD wrapper, @metadata references and AI prompt functions, and returns the typed free text of a List information when a template translates its free text key.
  • A booklet aligns its pages for duplex printing, and one booklet is marked as the default with a chosen action.
  • Booklet upload attaches only the documents selected in the analysis step, matches group documents that print no information values and documents holding more pages than the case expects, and names the missing pages it found.
  • In the document editor the zoom percentage describes the page on screen, boxes scroll into view when a link navigates to them, the boxes panel is resizable, and hyperlinks survive being placed on an editable field layer.
  • A booklet warns when a proof or file information cannot be printed.
  • The e-signature integration is set to None when the one in use is deleted, and the documents a booklet sends for signing match what it renders.
  • Code boxes are hidden rather than deleted when matching is turned off, and checkboxes and charboxes report an inconsistency when the taxonomy or maximum length behind them changes.
  • An option without a translation in the language being rendered no longer replaces the whole text it sits in.

Rule language

  • OLD. reads the value an information held at the previous evaluation, in rules and in ADX templates.
  • @provided_by and @provided_at report who or what wrote a value and when, has_changed reports whether it changed, and same_object compares two instances by identity.
  • Number with unit is a data type. A calculated information can produce one, a rule can assign one of its keys, and SAME_UNIT and SAME_NUMBER_WITH_UNIT compare two of them by unit and item, and by amount as well.
  • A rule can assign into a structure, including into an occurrence chosen by an index expression.
  • New arrow methods every(), some(), find(), count(), sort() and reduce(). Two arrow functions side by side in one rule can use the same argument name.
  • New case attributes CASE.documents_by_key, CASE.booklets_by_key, CASE.signature_links, CASE.cross_case_usage_by_instance_id, CASE.number_of_instance_warnings, CASE.is_first_rule_engine_run, CASE.num_active_wizards, CASE.wizards, CASE.files_being_read and CASE.number_of_files_being_read, and the WIZARD constant for the wizard being evaluated for.
  • AI Case Check results are available on CASE and on the instances they were raised for.
  • A new [API] Create Signature Request rule action sends a booklet to one signatory and makes the signing link available through CASE.signature_links.
  • New dictionary support: to_dict, pick, merge_dicts (also written |), and a bare identifier in a dictionary literal as shorthand for key: 'key'.
  • New list operators RANGE, SORT, COUNT and CUSTOM_MAX.
  • New validation operators TIN_VALID, LEI_VALID, BIC_VALID, ISIN_VALID and VAT_VALID.
  • New boolean operators truthy and falsy, and conversion operators TO_INT, TO_DECIMAL and TO_STRING.
  • New string operators CHAR_CODE and CHARS.
  • A RuLa function can take an instance as an argument, and a manual instance action's input parameters are offered in the editor.
  • The and operator, equality against unknown, LIST and the _OF_ANY operators follow three-valued logic consistently.
  • sort() and SORT order an unknown value after every known value instead of failing.
  • A transition rule action is applied at most once per evaluation, keeps its destination, and has the same side effects as a manual transition.
  • Date functions resolve against the evaluation's own clock, so a long evaluation cannot straddle midnight.
  • Comparisons suggest the possible values of the information on the other side.

Configuration

  • JSON is a new information type that holds a whole JSON object or array in one field.
  • Every configuration item shows its own history in its side panel, so you can see what changed on an information, a rule or a document, including its boxes and sections, without leaving it.
  • A rule decides which sub-taxonomy a taxonomy information takes its values from.
  • A category or a tab can be moved or copied between processes.
  • A configuration rule can be marked to run only once per case.
  • Platform notifications announce a message to every user for a week, a month, a year or indefinitely.
  • RuLa has an autoformatter and a Format all action that reports what it could not cover.
  • Renaming an information key also rewrites the layout item conditions that read it through self, the filters that reference it, and the remaining RuLa fields that held the old key.
  • Export and import cover linking information, widget items, branch keys, page title line information, the Button element's label, priority and icon, the identification mapping, AI prompt settings, the empty state text of an information, the dashboard greeting, and which translations are marked outdated.
  • New inconsistencies cover AI prompts referencing a field their instance does not have, two Identification elements reading the same file information, a registration step without email authentication, a creation wizard in a lifecycle process, a sub-taxonomy rule returning a key the taxonomy does not offer, and button elements placed where they are not allowed.
  • Configuration changes are detected by content, so the version advances only when something actually changed.
  • Deleting a workflow state or transition warns which rules lose an action.
  • A text information can carry a regular expression, and the error it produces is shown inline in the case.
  • Keys are validated for length, and have to be unique between meta and ontology informations.
  • The rules overview has reworked filters and marks the active quick filter.
  • The icon chooser has been rebuilt, and there are ontology icons for groups of people and companies.
  • The endpoint change log shows changes as a leaf level diff.
  • The configuration search finds the names, labels, descriptions and other translated texts of the configuration in every language, and every piece of RuLa, and shows the text each result matched. It no longer matches settings chosen from a fixed list, such as the chart type of a widget.
  • A wizard template that starts a case has a Test wizard button, which runs the wizard on the draft configuration and creates a draft case, see Configuring a Wizard.
  • Scheduled rules and the rule test are hidden without the permission.
  • Deleting an information no longer leaves a gap in the layout.

Atfinity Intelligence

  • The case and the configuration are open to Atfinity Intelligence and to external MCP clients. The AI tools are switched on per tenant, which also decides whether writing is allowed at all, and each conversation is then set to read only or to read and write. MCP client registration is set to off, per tenant, or on for all. The calls made and the tokens they consumed are recorded per feature and per day.
  • The AI settings and what the AI has used sit on one page instead of two.

Integrations

  • New integrations: Finastra Essence and ComplyAdvantage Mesh.
  • The AI backend can be any OpenAI-compatible service.
  • Integration credentials are encrypted at rest under a key that can be rotated with the rotate_encryption_keys management command, and the value of a secret admin parameter is withheld from the integrations API.
  • The Run LLM action of the OpenAI ChatGPT integration works with the default Azure deployment, gpt-5-chat.
  • The Actico Name Matching integration screens companies as well as people.
  • The Avaloq CLM integration can send an open date when it creates a person, and the World-Check ZFS Extended screening can send the registered country of an organisation.
  • The Gemini integration accepts files.
  • The Debug integration log is a list of expandable rows, and shows the raw response when it is not JSON.
  • An integration can upload a file under a custom filename.
  • Sending an SMS, a World-Check or ComplyAdvantage screening, an IDnow identification, the custom API, a data source lookup, a webhook, and the OAuth token and file download requests of a marketplace integration are attempted again for a few seconds when their connection could not be established, as the HTTP requests of a marketplace integration already were. A request through the configured proxy is attempted again as well, when the proxy cannot be reached or cannot reach the host.
  • Integration logs describe a saved list by its items, say what actually happened, and quote text values safely.
  • The API requests that create something name what they created in a Location header.

Administration

  • Users can reset their own password from the login page.
  • Meta admins have a report of approved cases per process and quarter.
  • The User Access Log records refused SAML logins, logins refused for missing permissions, an expired 2FA code, a missing 2FA setup and a refused password change, each with an action naming the reason, and always shows the client IP.

Performance

  • Opening, saving and recalculating a case is faster, including a case with complex documents.
  • Large information tabs open faster and keep up with typing, and the process layout and the document editor respond faster to every interaction.
  • Booklets are generated and downloaded faster.
  • DAYS_BETWEEN, HOURS_BETWEEN, DAYS_SPENT_IN_STATE and HOURS_SPENT_IN_STATE take the same time whatever the length of the period they measure, so a case that stays open no longer evaluates more slowly each day.
  • Exporting and importing a configuration is faster.
  • The configuration and administration screens, the case list and the activity log load faster.
  • Putting a configuration live is faster, and its progress bar reflects the work still to do.
  • The case manager and the end user wizard load less on first open, so both start faster.

Security

  • An authenticated automated security scan now runs on every build, and its findings are addressed before the build is accepted.
  • As with every release, version 17 is marked stable only once our external security team has penetration tested the release candidate and the findings are fixed.
  • Dependencies and container base images were updated, and the containers run as a non-root user.
  • The case manager and the end user wizard load an image only when it is embedded in the text or served from the page's own address.
  • A configuration item is read or changed only through the parent it belongs to, and a Documents page downloads only the documents placed on it.

Operations

  • The API serves Prometheus metrics on /metrics: request counts by endpoint, method and status code, and request latencies by endpoint. It is reachable only from inside the installation, and the Helm chart annotates the api pod for scraping by default.
  • Next to /api/1/health, health is reported by /health/live, /health/ready and /health, which are reachable only from inside the installation, with startup, liveness and readiness probes declared against them and tunable under api.probes.
  • Every response carries an X-Request-ID header, and a caller can send its own, so a request can be followed from a gateway into the application logs. Every request ends with a line naming its method, path, status and duration, and background work it starts keeps the same id.
  • The user action log is written regardless of the log level.
  • The Helm chart is pushed to the registry, deployments upgrade the release and deploy image digests, and the ingress controller's compression and proxy limits are set through the release.
  • The Kerberos ticket manager is published and tested like the rest of the deployment.
  • The public documentation is published at docs.atfinity.io, restructured around guides, with every old URL still served.

Various improvements

  • The interface is more compact: smaller default controls, a new border radius, and tighter navigation, tables, modals and side panels, with a consistent icon set throughout.
  • Change counts, the progress of a running task and AI answers update as they happen instead of on the next refresh.
  • Side panels and the admin, case and configuration navigations are resizable.
  • The German, French, Italian, Spanish and Serbian interface texts are corrected throughout, for spelling, grammar and consistent terms.

Fixes

These were present in 16.x and are corrected in 17.

Rule language

  • A dictionary with a number or a boolean key can be saved, where it previously put the case into recovery mode.
  • A quoted string literal, a taxonomy option and a dictionary key are no longer replaced by a variable or an argument that happens to have the same name.
  • A variable holding unknown reads as unknown rather than as its own name, and an is known check on a number or a boolean compiles.
  • An arrow function argument resolves to its own element rather than to the one of an arrow function it is nested in.
  • A value a rule assigns is checked against the information's constraints, and one that cannot be saved reports a field error instead of leaving the field silently empty.
  • today() returns the date in the configured time zone instead of the date of the machine.
  • Renaming an information, ontology, role or taxonomy key updates the RuLa fields that held it.
  • max_results and roles are applied by the Query Existing Instances action.
  • ROUND no longer returns nothing for a zero.
  • MARKDOWN_TABLE renders a table with a single row of values instead of one character per column.
  • self can be used in the condition of a text item.
  • The unknown literal is an unknown value, so unknown is unknown is true and unknown is known is false, where each was answered as if the literal were the text unknown.
  • A Decimal information compares equal to the same number written in a rule, so p.amount = 1.1 is true when the field holds 1.1.
  • CASE.last_transition_by and CASE.last_transition_by_name return api when no user performed the last transition, where they returned nothing.

Case manager

  • A bulk delete of cases no longer fails silently.
  • A bulk delete of cases checks the workflow state permissions of the user deleting, where it checked those of another user, and deletes nothing from a process the user can only read.
  • A case overview, an instance overview and a widget detail view export the rows that are selected rather than all of them, export the State column values, and no longer fail on a title holding a character such as *, /, : or ?.
  • Cases in a read-only process can be selected, so a selection can be exported.
  • Copying or duplicating a row on an overview shows the result without a refresh, and a search no longer shows the results of the query before it.
  • An overview search finds a value holding punctuation, such as Mueller-Luedenscheidt, and a search term without a letter or a digit, such as the & in Smith & Jones, no longer empties the result.
  • A case overview shows the colour and calculated name a rule gives a case, where it showed the previous ones until the case changed state.
  • A case holding a very large number is listed, sorted and filtered correctly, and a case table shows every digit of it, where such a case could be missing from the case list and its number was rounded.
  • Dates and times in an Excel export use your date and time format, where they were shown year first.
  • A user watching a case is no longer notified about a transition, an assignment or an owner change they made themselves.
  • Closing a case opened from the Reason column of an instance's history returns to that history, where it returned to the dashboard.
  • A case that is completed while its rules are still being evaluated keeps its final state, where the running evaluation could still save values and move it on.

Case wizard

  • A comment longer than the limit reports the limit instead of erroring and discarding what was written.
  • A file provided in a creation case can be previewed and downloaded in the lifecycle case.
  • A tab with the role matrix switched off no longer shows roles under the instance headers, and the matrix appears when Show All Instances is off and the instances share the outcome ontology.
  • A text item is shown when its condition holds for any instance, not only when it holds for every one.
  • The activity log names the structure a changed component belongs to instead of reporting a deleted document.
  • A category holding a line break as its first element is no longer reported as empty.
  • A date typed with a different separator or without leading zeros, such as 02/04/2024 for a day first date format, is read in the order of your date format, where it could be read month first.
  • A link written without https://, such as www.example.com, in a description or a rich text value is a clickable link, where it showed as plain text.
  • An open issue on a structure component counts towards the badge of the tab that shows the structure.
  • The Run for button of a Click to run rule runs the rule for the instance it names, where it could run for another instance once the offered runs had shifted, and on a draft case it runs the draft rule.
  • Creating a wizard from the wizards tab can be confirmed after switching from a template that asks for instances to one that does not, where the dialog stayed blocked until the page was reloaded.

End user wizard

  • The wizard recovers from a network interruption instead of stopping until it is reloaded, and a render error in one field no longer blanks the whole wizard.
  • A wizard can no longer be continued with an invalid date.
  • An email authentication step that has been switched off is no longer offered.
  • A text item in a structure is shown only in the occurrences its condition holds for, where it was shown in every occurrence.
  • A replaced cover image or logo shows straight away, where the wizard kept showing the previous file.

Documents and booklets

  • An ADX template that reads a structure information without iterating it renders instead of crashing, and a preview iterates a structure the same way a render does.
  • A booklet that mixes pages from two downloads of one smart document attaches the up to date pages.
  • Uploading an outdated or wrong document on its own reports what is actually wrong instead of the same message twice.
  • A document counts as completely filled once every field it prints is filled, where printing the name or another built-in attribute of a structure occurrence or a related instance kept it incomplete.
  • A document with Remove PDF fields switched on keeps the links in its PDF, where they were removed with the fields.
  • A PDF with an empty entry among a page's annotations can be uploaded to a document and rendered, where both failed.
  • A copied document keeps the PDF fields its checkbox options and charbox characters fill, where the copy lost them.

Insights

  • A widget no longer crashes the page when This month is combined with Compare to previous period.
  • A stacked chart names its largest subgroups rather than its smallest.
  • A pie or donut chart in a narrow widget is drawn in full and shortens its legend instead of being cut off.
  • Changing a widget's data source or grouping clears the settings that no longer apply.
  • A chart grouped by calendar quarter and a widget limited to the current calendar quarter count quarters from January, April, July and October, where they counted three months from the start of the current month.
  • A page whose date page filter was saved without dates opens unfiltered on that date, where it showed an invalid date range error.

Configuration

  • Renaming an information key saves instead of returning a server error.
  • Changing an enum information that has a default value and restricted options to take its values from a taxonomy no longer breaks the information.
  • An unforced rule no longer overwrites a value a user entered, including a free text value and a value on an instance the rule reaches through a relationship, such as p.employer.name.
  • The Create New Information in Structure dialog opens empty rather than pre-filled with the previous component, and stays open when a key is rejected.
  • A long key, tab key or translation key is readable wherever the configuration shows one.
  • Creating a tab in a process layout opens it.
  • Putting a configuration live with Skip reindexing cases and instances after importing a configuration from another environment keeps case and instance search working, where it could fail or leave the search on outdated data.
  • The references of an information include a lifecycle scheduled rule whose actions read or assign it through self, where only the rule's condition was found.
  • The draft cases overview sorts by State, Process, Owner and Assignee by name, where sorting by State failed.
  • The suggestions of a code editor in a dialog open next to the text being typed, where they opened away from it.
  • Apple Mail shows the email logo once, where it repeated it below the message, and an SVG email logo no longer stops an email from being sent.

Login

  • A SAML login opens the identity provider's sign-in page on its own, and so does the Log in button on the page that redirects to it, where the login stopped on that page.
  • A SAML login of a user locked by an administrator is refused, where it opened a session.
  • A refused login is recorded in the User Access Log under the tenant of the user it names, or under the tenant of the login page when no user has that email address, where it was recorded without a tenant and shown to the admins of every other tenant.

Integrations

  • A data source retrieve request no longer puts the raw source identifier in the URL path.
  • The description of an integration's admin parameters is shown on the form.
  • A text value placed into the body of a Custom API request has its quotes and backslashes escaped, where a value holding one produced a body that was not valid JSON.
  • A JSON request body of an integration sends values such as 012345 or NO as written, where a leading zero changed the number and NO was sent as false.
  • A CIFAS search sends every line of a block address.
  • A SmartSearch with the High Risk Search Option set to false runs a normal search, where it ran a high risk search.
  • Adding an integration that has not been activated for the tenant is refused, where the API could add it.
  • force_update on an instance writes a value the instance does not hold yet into the instance, where it could overwrite the copy an ongoing case held instead.
  • Values sent through the API together with a new structure occurrence are stored the same way as values set on their own, where a yes/no, an option or a list was read back wrong.

Operations

  • zip_export, zip_import and the database dump of the backup hook complete when a row is larger than about 24 MB, where the dump aborted with a lost connection.
  • Reloading the case manager or the configuration after an update loads the new version, where for up to an hour it could load the previous one and show an empty page.

Potentially breaking changes

Some of the improvements and bug fixes in this release mean you may have to adapt a configuration or the way you operate Atfinity. Here is a list of things to check. Read them carefully and contact us if you need help.

Configuration and operations

  • /api/1/health also reports Elasticsearch and the Celery workers, and answers with an error status when either is down, so a monitor polling it now alerts on those too.
  • Every log line now carries the id of the request that caused it after the log level, so a line that read [INFO] - message now reads [INFO] [<id>] - message. Anything that parses Atfinity log lines by position has to be adjusted.
  • :=! is reported as an inconsistency everywhere it has no effect, which is everywhere outside the actions of a rule. It was previously accepted and then silently dropped, so nothing was written. A configuration that carries one has to change it to := before it can be put live.
  • FLATTEN without a key always returns a list. It previously joined a list of texts into one text and failed on a list of numbers.
  • Comparing the result of FLATTEN with a single value using =, !=, <, >, <= or >= is reported as an inconsistency and has to be corrected before the configuration can be put live. Reduce the list to one value first, or use CONTAINS or IN to test whether it holds a value.
  • The Run LLM action of the OpenAI ChatGPT integration no longer takes Temperature, Top P, Frequency Penalty or Presence Penalty, and ignores an input assignment that still sets one. A request to public OpenAI no longer sends a Temperature of 0.7 and a Top P of 0.95, so its model answers with its own defaults.
  • An image in a rich text value, a text item or a markdown description that points at another address is no longer loaded, including an end user wizard pointing at an image on the address of the case manager. Embed such an image, or serve it from the page's own address.
  • A wizard step places its fields where its layout shows them, moved up as far as they fit, so a step that used empty rows or cells as spacing renders without them, and the Clean up button is gone.
  • A SAML login of a user locked only by failed password attempts is let in, while a user locked by an administrator is refused.
  • The input and output assignments of an integration or custom API rule action are checked like those of every other rule action, so one that refers to something the rule does not declare is reported as an inconsistency and has to be corrected before the configuration can be put live.
  • A rule that assigns to a document's key, __name, __hidden, __disabled, __before_toc, __to_be_signed, __create_missing_values or __document_type is reported as an inconsistency and has to be removed before the configuration can be put live. Such an assignment had no effect on the document.
  • The file types, size and number of files a File information allows hold wherever a file is written into it: an upload in the case manager or over the API, a proof assigned to the field, and a rule assignment. In 16.x only the end user wizard checked the size and the number, so an upload that does not fit is now refused with the restriction it crossed, and a rule leaves the field untouched and records a case error. Check the restrictions of fields an integration or another system writes files into.
  • MIN, MAX, AVG and CUSTOM_MAX return unknown for an empty list, and MIN, MAX and AVG return unknown for a list holding an unknown value, where they previously failed or read that value as a zero. Use MIN_OF_ANY, MAX_OF_ANY or AVG_OF_ANY to skip the unknown values instead.
  • GET_ATTR returns its default, or unknown when none was given, for a key missing from a dictionary, and HAS_ATTR returns false. Both previously failed.
  • DAYS_BETWEEN, HOURS_BETWEEN, DAYS_SPENT_IN_STATE and HOURS_SPENT_IN_STATE reject a named argument they do not know, and the two hour operators also reject day_length, which they previously accepted and ignored. All four now apply exclude_days, exclude_before_time and exclude_after_time when passed positionally.
  • A new workflow no longer grants Delete Cases on its entry state, and grants it only where you configure it. Existing workflows keep the permissions they were configured with.
  • Integration credentials are stored encrypted under a key supplied through the new DATA_ENCRYPTION_KEYS environment variable. An installation that does not set it keeps working with a key derived from SECRET_KEY, so losing or regenerating SECRET_KEY then loses the stored credentials, and existing values are encrypted on upgrade. See Encryption at Rest.
  • A Number (with unit) field is a composite value in the rule language rather than a plain number. Reading the field still gives you the amount, but arithmetic on it now carries the unit and the item, and a calculated Number (with unit) produces one instead of a decimal. A rule that fed such a result into a plain number field, or into something that expects a number, has to read ["decimal_number"] off it. See Number with unit.
  • A data source retrieve request sends the source identifier encoded, as a single part of the URL path. An identifier containing a /, such as persons/123, previously extended the path, one containing a ?, such as 42?type=person, previously added to the query, and one that was already encoded, such as x%20y, was sent as it was.
  • The api, mariadb and web containers run as a non-root user, and the Kubernetes pods enforce it.
  • Page previews, file thumbnails and document previews are rendered with pdfium instead of MuPDF. Rendering is faster and uses less CPU, and a page image can differ very slightly from the same page in 16.x. pdfium does not repair a damaged cross-reference table, so a PDF that 16.x previewed by salvaging one now fails to render and has to be repaired or exported again.

Public API

Renamed and removed:

  • The workflow state action delete_uploaded_pdfs is now called delete_uploaded_files. Existing permissions are renamed on upgrade, and a caller that matched the old name has to match the new one.
  • A Document in a Case reports its type as document in place of booklet, so a caller that matched booklet has to match document.
  • An Ontology reports signatory_first_name_information_id and signatory_last_name_information_id in place of signatory_name_information_id, so a caller that read the one field now reads the two.
  • A comment no longer carries is_assigned_to_user. It still carries assigned_user, so a caller compares that user against its own.
  • The case list reports in_state_since next to in_state_for. Both carry the moment the case entered its state, and in_state_since is the name to read.
  • The decimal_number of a Number (with unit) field is a number however the value was saved, where a value entered in the case manager was reported as text.
  • Setting an information that belongs to a structure directly on an instance, through a case update or case creation, is refused with structure_component_outside_structure_occurrence, where it was accepted and stored a value outside any occurrence. Set it on one of the structure's occurrences instead.

Added:

  • A case reports its AI Case Checks. A field of type ai_case_check carries an ai_case_check object with all_clear_message, pending_message, problem_message and states_by_instance_id, whose states report is_pending, has_result, has_failed, has_dismissed_problem and the problems found. The case reports ai_case_problems and the counts num_ai_case_problems_high_severity, num_ai_case_problems_medium_severity and num_ai_case_problems_low_severity.
  • A field an Identification reads into carries an identification object with the item_id and label of the item and, under mapped_information_ids_by_attribute, the information each of given_names, surname, birth_date, sex, nationality, document_type, document_number, issuing_country and expiry_date is mapped to.
  • A document and a requested proof report the signed file as esigned_file_id, esigned_file_uuid and esigned_filename, a file proof as esigned_file_id and esigned_filename, all of them report signatory_requests_ratio, and an instance reports signatory_name, signatory_email and signatory_phone_number. A requested proof also reports allow_esignatures, signatory_instance_ids, filled_fields_ratio and is_completely_filled, as a document already did.
  • An information reports allow_external_instances and allow_esignatures, a Text and a Rich Text field report regex and regex_example, an option of an instance relationship field reports is_external, instance_id_label and page_id, and a case reports cross_case_instance_usage.
  • A tab reports default_collapsed, use_instance_condition, matched_instances, instance_ids, show_instances_in_navigation and num_missing_fields_by_instance_id, and an instance reports manual_instance_actions and is_outcome_instance.
  • An instance reports the page it is shown on as page_id and page_type: the one requested with page_id, or the default detail page of its ontology.
  • The case list reports case_status, user_has_case_write_access, earliest_comment_deadline, in_state_since, and workflow_state next to state with the same content.
  • An instance overview reports num_interactions, last_interaction_time, last_interaction_type, owner_user_group_names, initiator_user_group_names and _updated.
  • A file proof reports information_value_file_id and value_ordering, and the case reports is_reading_an_uploaded_file while a file is still being read. A file proof also reports its type as information_file, the instance_id and description of its field, the accepted_file_types and max_file_size_mb the field allows, allow_esignatures, signatory_instance_ids, filled_fields_ratio and is_completely_filled.
  • The upload history of a case, uploaded, also lists every file uploaded into a file information, and each entry reports its type: provided for an uploaded document or proof, information for a file in a file information. The id of an information entry is the id of the information value the file belongs to.
  • A booklet reports its proofs and information, duplex_page_alignment and default_primary_action. A structure field reports display_as_table and, when shown as a table, columns with a name, an information_key and a width each. A text or line break item reports is_structure_item and text_style, which is NONE, INFO, WARNING or ERROR, and a text item reports instance_ids, the instances its condition is true for.
  • An occurrence of a structure field reports is_not_necessary.
  • End user wizards can be started over the API, on a creation process or for an instance of a lifecycle process named by instance_id or by instance_identifier. The lifecycle call takes either skip_authentication or the email the person confirms before the form opens. The answer carries case_id, wizard_uuid, link and url.
  • A PATCH carrying a name for a requested proof is refused before the file is read, where it previously replaced the file first and then refused the rename. Only a custom proof can be renamed.