What has changed in Prismm lately.
Support in the navigation now opens a form inside the application instead of sending you to our website. Describe what is happening, and the request reaches our support team with a note of the page you were on. Replies come to your email address.
After connecting an institution, its accounts now appear on their own once the connection finishes. Before, they arrived only if you pressed Save, and an account added by hand inside the connection window was lost if you closed the window any other way. Every way of closing it now brings the accounts in.
Reconnecting an institution now repairs the existing connection instead of opening a new one, which had been creating a second copy of each account. Copies made by earlier reconnects are not yet merged. Finishing a reconnect no longer ends on an error page when the reconnect had in fact worked. Each account now shows its own connection status, and an account the institution has stopped reporting is marked as not updating, rather than looking current while its balance goes stale.
Asking for fresh balances on the banks and institutions page failed every time, which could also leave an institution's last-updated time unchanged. It now works. Removing a manually added financial account or an institution, which failed for a few days this month, works again as well.
Every menu now closes when you press Escape, not only the document folder menus. In the checklist editor, indenting a selection no longer pulls in the line above when the selection starts at the end of it.
Pages are now more restricted in what they may run and load. The environment the application runs in carries fewer components and stays current with security updates.
Organization staff could not add a property or a personal property record; every attempt failed. Both work again, and the details entered on the form are saved rather than being dropped. These had been broken for some time, and the account-side equivalents were unaffected throughout.
Adding a trusted person, beneficiary, executor, or legal advisor with an address did not work: the address was left off, or the form failed outright. Both now save as entered.
A fault in the nightly synchronization with our financial data provider could leave a balance quietly out of date. The synchronization no longer disturbs the data it is given, and failures are now reported so they are noticed rather than passing in silence.
A client who has not uploaded anything yet can now be given a checklist. Previously a checklist could only be assigned once at least one document existed.
When something is deleted, the audit log now records what it was, rather than noting only that a deletion took place.
The organization document form now picks a folder the same way the account form does, and the organization edit form uses the same dialog as the rest of the application. Resend and retract prompts name the action they are about to take, and a checklist copied onto an invitation records the firm template it came from.
Third-party scripts are now pinned to fixed versions and checked for integrity when they load, rather than following whatever the provider last published. Libraries that were being loaded on pages that never used them have been removed. Pages carry a content security policy with reporting, and image processing was restricted to the formats the application actually accepts.
Multi-factor verification and password reset now carry tighter rate limits.
The application moved to Ruby 4.0. The container image it runs in was reduced to what production actually needs, and the development and continuous integration environments were brought closer to production. Alongside that, the usual stream of dependency updates.
Firms now receive a weekly email covering the changes across their clients for that week. Each firm sees only its own clients, and the subject line leads with the firm and the week it covers.
The account invitation is now a full page rather than a drawer. A firm can request the access it needs and assign checklists at the same time as inviting the client, instead of arranging both afterwards.
A firm can edit an invitation the client has not answered yet, or retract it. Inviting the same client twice is now refused rather than quietly creating a second invitation. Expired invitations no longer count toward the pending total, and the invites list stopped describing three different states as "pending".
Tapping a field no longer zooms the page on mobile, pages stop drifting sideways, buttons and cards line up, and the logo is clickable again. On desktop, the documents page now fits the width it is given instead of overflowing.
Changing an address on an account is now recorded in that account's audit log, alongside the actions already tracked there.
A pass over copy and labelling on the organization side, including a corrected support address. Renaming a folder that a checklist depends on now warns you first, since the checklist redraws around it.
A subscription still in its trial is treated as active rather than lapsed, subscriptions are always cancelled when an account is deleted, and the billing page no longer errors for customers who have a card on file but no active subscription.
A client who accepts an invitation stays signed in rather than being returned to the login page, and the invitation form submits correctly. Hidden financial accounts no longer appear when associating a document. Email stopped rendering every link in white, and the display font now loads as intended.
Further hardening across the application: stricter transport security and cookie handling, sensitive fields kept out of application logs, correct resolution of client addresses behind our content network, and a state-changing administrative action moved off a form of request that should not have carried it. Base system packages are now refreshed each time the application is built.
The application moved to a newer patch release of its language runtime. Internally, every outgoing email now has a preview for review before release, and routes that pointed at actions which no longer existed were removed.
Organize documents into a nested folder tree of any depth. Create, rename, move, and delete folders, give each one a description, and pick a folder right on the document form. Empty folders stay put and say they are empty rather than disappearing.
Every account now carries the Prismm Document Checklist as a starting point. Firms can write and publish their own checklists to clients, edit them with a live preview, and see at a glance what has been collected and what is still outstanding.
A transition request now carries the account through the full process: the account and its request stay in step, the requester is told where things stand, a transitioned account says so, and the transition is recorded in the audit log.
"Document type" has been retired as a user-facing term. Documents are described by the folder they sit in and the checklist they answer to. Document filtering moved into the search field, and all of an account's checklists are shown at once instead of hidden behind a dropdown.
The documents page and the checklist panel were rebuilt to hold together on small screens, with the panel scrolling on its own rather than taking the page with it.
A round of hardening across sign-in, account verification, and internal administrative access, including stricter rate limiting and additional verification requirements for staff accounts.
Organization users no longer hit an error opening an account dashboard, account invites work for visitors who are already signed in, and several page interactions that had quietly stopped working were restored.
A steady stream of dependency and framework updates, applied continuously so that security patches reach production quickly. No user-facing changes.
Account invites now enforce password requirements when the invite is accepted, and an expired invite explains itself instead of failing silently.
If onboarding is submitted without completing payment details, the problem is now surfaced to the person signing up and reported to our error tracking rather than passing unnoticed.
A multi-stage migration moved sensitive stored fields onto strengthened encryption. The change was rolled out in stages with no interruption to service.
Organizations can set password requirements for their users, applied when a password is created or changed.
The application was moved to the current major version of its framework, keeping it on a supported and actively patched release.
Historical values shown on an account now calculate correctly across the full reporting period.
Accounts now keep an audit log of the actions taken on them, so it is clear who did what and when. Routine per-user events such as sign-ins are kept out of the account view to keep it readable.
A nightly email summarizes activity and outstanding items, backed by improved nightly statistics.
Organizations can put their own logo and colors on the emails their clients receive.
Organizations can remove a client, and an account can be deleted along with its data.
Sessions are handled more strictly, with clearer timeout behavior and tighter permissions on financial account access.
Clearer error messages throughout, the verification code field focuses itself, support links open in a new tab, and an already-used invite explains what happened instead of erroring.
Prismm was redesigned end to end, refreshing navigation, typography, and layout across the application.
Passkeys now work with the authentication built into your device, so you can sign in with a fingerprint, face, or device PIN.
Add a profile photo to your account. Photos are compressed on upload, and an upload that fails now says so rather than leaving an unsaved image on the page.
Institution connections were reworked to identify accounts more accurately, handle institutions that report duplicate account numbers, and clean up accounts that no longer exist at the institution. Institution management was added for our support team.
Email delivery moved to a new provider, fixing routing problems and messages that had failed to send. Forgot-password moved onto the login page, and password entry was made clearer throughout.