HRS Triage · October 2, 2026
Release 0.85.1
- HRS Triage 0.85.1 fixes a What's new entry that pointed analysts to a staff-only article, and the documentation check now catches that in What's new entries.
HRS Learn · September 25, 2026
A real documentation library
The help you are reading now replaced seven placeholder entries. 23 documents
across eight sections, each scoped to the people it is for, cross-linked, and
illustrated with screenshots of the actual product.
The documentation is version-controlled alongside the code and published with it,
so it always describes the build you are using rather than the build somebody
documented once.
- Start here promotes the six pages worth reading first.
- Filter by who you are narrows the whole index to learners, admins or partners.
- Each page opens with a button into the surface it documents.
HRS Learn · September 25, 2026
The reader renders more
Numbered steps render as numbered steps, and screenshots render inline instead of
as their own alt text. External links open in a new tab. Documentation image
sources are restricted to the platform's own assets.
Sections in the index are now ordered deliberately rather than alphabetically, so
Getting started is first.
HRS Triage · September 25, 2026
Release 0.85.0
- HRS Triage 0.85.0 protects HumanRisk Shield's own organization and its platform admin account.
HRS Triage · September 25, 2026
HumanRisk Shield's own organization and admin are protected
- Organization 1 is HumanRisk Shield.
- It's labelled "HumanRisk Shield" and always run by the HRS team.
- Only HRS platform accounts can change its settings, name or industry, or manage its analysts.
- It never belongs to an MSP, even if a sync or an older record says so, and it can't be offboarded or deleted.
- It's left out of what customers see: the organizations HRS protects, industry views, benchmarks, the Portfolio and Campaign spread.
- admin@humanriskshield.com is protected. Nobody can deactivate it, remove its admin role or narrow it to one organization. Only an HRS platform admin can unlock it or reset its password or two-factor. Refused attempts are recorded in the audit log.
- See Roles and access.
HRS Triage · September 25, 2026
Release 0.84.0
- HRS Triage 0.84.0 carries the HumanRisk Shield name and logo: the console is now HumanRisk Shield | TRIAGE.
HRS Triage · September 25, 2026
The HumanRisk Shield logo and name
- The console now shows the HumanRisk Shield logo (the shield with the pulse line) and the name HumanRisk Shield | TRIAGE, in place of the magnifier logo and "HRS Triage". It appears in the sidebar, the top bar on small screens, the footer, the sign-in page and the welcome screen. In the sidebar the name sits on two lines.
- Browser tabs read, for example, "Triage · HumanRisk Shield | TRIAGE", and the footer shows the version under the same name.
HRS Triage · September 25, 2026
Release 0.83.0
- HRS Triage 0.83.0 adds industry views: what is hitting each client's industry, in the Phishing Data Centre, the reports, the Portfolio and on campaigns.
HRS Triage · September 25, 2026
See what is hitting your industry
- The Phishing Data Centre has a new Your industry section. It shows each threat category's share across organizations in your industry, next to yours and all of HRS, plus what is rising, the brands impersonated and campaigns seen at several of them. MSP users can switch industries, and HRS staff can pick any. See Your industry.
- Every organization in an industry counts, anonymised:
- an industry shows only once 5 of its organizations reported a threat in the period;
- a brand or campaign is listed only once 2 of them saw it;
- no organization is ever named.
- The threat report (download and monthly email) has a Your industry slide, the CSV has an industry section, and the client report has a Your industry page. Each appears only when the industry is large enough.
- A campaign's page shows Industries this campaign is hitting. On Campaign spread, each client shows its industry.
- The Portfolio shows each client's industry and filters by it, including No industry set.
- MSP and HRS admins can set every client's industry in one save in Settings → Shared intelligence → Industries. The setup checklist has a new optional step, Set your industry. See Shared intelligence.
HRS Triage · September 24, 2026
Release 0.82.1: the Phishing Data Centre no longer times out
- Fixed: with every threat feed switched on (
PHISH_FEEDS=all), the Repository (the Phishing Data Centre, including in the demo workspace) could stop with "Maximum execution time exceeded". Summarising about a million feed entries on every page view took too long. The summary of what the feeds are tracking is now built once an hour by the background worker and shared, and the page reads it. Pages load in well under a second. Apply database migration 0069 after this update.
HRS Triage · September 24, 2026
Release 0.82.0
- HRS Triage 0.82.0 puts every printed report in the HumanRisk Shield brand and strengthens protection against password guessing.
HRS Triage · September 24, 2026
Stronger protection against password guessing
- Accounts lock for longer each time: 15 minutes after 8 wrong passwords or two-factor codes, then 1 hour, 4 hours, and 24 hours. Before, every lock lasted 15 minutes. See Sign in and passwords.
- The owner of a locked account gets an email saying so, with the address of the last attempt, and every lock is in the audit log.
- One network is also limited to 100 failed sign-ins a day, on top of 20 per 15 minutes.
- An email address with no account locks exactly like a real one, so the sign-in page no longer reveals who has an account.
- Re-entering your current password on your profile is limited to 5 wrong tries in 15 minutes.
HRS Triage · September 24, 2026
Every report in the HumanRisk Shield brand
- The client report (Analytics) and the campaign write-up now follow the HumanRisk Shield brand guide, like the threat report:
- a deep-violet cover with the HumanRisk Shield logo;
- white A4 pages with the logo, numbered sections and a footer;
- Inter and IBM Plex Mono, built into the page, so it prints the same everywhere.
See Analytics and client reports and Campaigns.
- Fixed: a sender written with a display name showed its domain with a stray ">" in the client report and the campaign write-up.
HRS Triage · September 24, 2026
Release 0.81.0
- HRS Triage 0.81.0 bundles everything from 2026-09-24: the Phishing Data Centre and its monthly threat reports in the HumanRisk Shield brand, more threat feeds, your own time zone, the setup checklist, profile pictures, faster pages, the HRS Labs detection rules, and searchable threat indicators.
HRS Triage · September 24, 2026
HRS Labs detection rules, and searchable threat indicators
- HRS Labs detection rules. Automation now comes with over 30 rules written by HRS Labs. See Automation rules.
- Business email compromise: payment changes, executive impersonation, gift cards, payroll diversion and thread hijacking.
- Scams: advance-fee, callback phishing, sextortion and recruitment scams.
- Brand impersonation: fake PayPal, Microsoft 365, DocuSign, parcel carriers, crypto wallets and tax authorities.
- Delivery tricks: BaseStriker, OAuth consent phishing, HTML smuggling and lookalike links.
- They start in shadow and change nothing until you promote them.
- Every rule shows its author (HRS Labs, a named HRS SOC analyst, or the analyst of your organization who wrote it), creation date, priority, tags, matches and whether it is active. Open a rule for its description, MITRE ATT&CK techniques and known false positives.
- Download one rule, or every rule, as a JSON file.
- Rules can read the words of an email, the engine's findings, the impersonated brand, a mismatched reply-to, a free-mailbox sender, link hosts, attachment names and an HTML base tag. There are two new condition types: contains any of and is not on domain.
- BaseStriker: links hidden behind an HTML base tag are now resolved and checked like any other link.
- Threat indicators can be searched by value, and filtered by type, disposition and when they were last seen, 50 to a page. Export CSV downloads everything that matches. A ? explains where each kind of indicator comes from. See Manage threat indicators.
- Fixed: a rule condition on the sender's domain never matched a sender written with a display name, such as "Dana" dana@example.com.
HRS Triage · September 24, 2026
A setup checklist, profile pictures and a faster console
- Setup checklist. Admins of an organization that runs its own triage, and MSP admins, get a Setup button in the top bar showing how far setup has got, such as Setup 4/6. It lists each step with a link to where you do it, ticks steps off by itself, and disappears when setup is done. See Set up a new organization.
- For an MSP, it shows how many clients have their mail connected, have sent a first report and have a VIP.
- Hide checklist hides it early. Bring it back from the account menu.
- The Command Center's Getting started card links to it.
- Profile pictures. Add a picture on your Profile (PNG, JPEG or WebP, up to 512 KB). It shows in the top bar, on your profile, on the Analysts list and in the Triage queue's Assignee column. Without one, people see your initials. See Your profile and picture.
- Fixed: every page, the demo workspace included, was slow on a large platform, because the notification bell read the whole audit log on each page and each check for new notifications. Pages and the bell are now several times faster.
HRS Triage · September 24, 2026
A faster Phishing Data Centre
- Fixed: on a large platform, the Phishing Data Centre could stop with a timeout instead of loading. It now loads in seconds, and Refresh rebuilds it with the latest reports.
- Known indicators now counts a link host, domain or file hash already marked malicious at any organization HRS protects, as it says. Before, it only looked within the same organization.
HRS Triage · September 24, 2026
More threat feeds
- HRS Triage now downloads and matches four more public feeds. Your links are never sent to any of them.
- URLhaus and ThreatFox (abuse.ch): links and domains serving malware, with the malware family.
- Phishing Army and CERT Polska: phishing domain blocklists.
- Phishing.Database (about 400,000 domains) is optional, and HumanRisk Shield decides whether to switch it on.
- A link that serves malware now reads as a malware link on the case and counts toward the malware category, not phishing.
- A domain-list match also catches a link on a subdomain of a listed domain. Like any host-level match, it counts for less than a listed link and never lets the Triage Agent act on its own.
- The Phishing Data Centre's External intelligence shows every feed's size, freshness and health, and how many of your threats each one matched. The threat report and CSV carry the same. See The Phishing Data Centre.
HRS Triage · September 24, 2026
Monthly threat reports by email
- The Phishing Data Centre has a new Reports tab. It emails last month's threat report every month, on the day and hour you choose, in your time zone. See Send the threat report every month.
- Send one organization's report, or an MSP's report covering all its clients.
- Up to 20 recipients per schedule. They do not need an HRS Triage account.
- Attach PDF, PowerPoint, CSV, or any mix.
- Each email carries the month's headline numbers and a link to stop receiving it.
- Every report sent is listed to download again, with the numbers it was sent with.
- Send now sends last month's report straight away.
- The Phishing Data Centre looks like the Command Center:
- The numbers are colour-coded tiles that open the reports behind them.
- Each threat category has its own colour in every chart and table.
- Changes on the previous period show as red or lime chips.
- The organization picker applies as soon as you choose.
- Search keeps its less common filters under More filters, and an empty search offers starting points.
HRS Triage · September 24, 2026
The threat report in the HumanRisk Shield brand
- The PowerPoint and PDF threat report now follow the HRS brand guide. See The Phishing Data Centre.
- A deep-violet cover and closing page, and white content pages with deep-violet text.
- The original HumanRisk Shield logo on every page.
- Inter for text and IBM Plex Mono for labels, built into the PDF.
- HRS Triage emails carry the HumanRisk Shield logo in their header.
HRS Triage · September 24, 2026
The Phishing Data Centre, an HRS threat report, and your own time zone
- Repository is now the Phishing Data Centre. Its new Intelligence tab is a briefing. See The Phishing Data Centre.
- Threats and categories at each organization, with the malicious rate against everyone HRS protects.
- Time to a decision, known indicators, and quarantines by the agent and by people.
- Top senders with their HRS-wide count, and when people report.
- What HRS sees in the wild, what the public phishing feeds carry, and what to do about it.
- Search is its own tab, unchanged.
- Download the report as an HRS-branded PowerPoint or PDF, with the numbers as CSV. The report covers:
- the top threats and a spotlight campaign;
- the headline numbers;
- quarantines, categories month by month, and daily and hourly volume;
- top senders, domains and reporters;
- what was not a threat;
- in the wild, recommendations and a glossary.
- Your time zone. Times across HRS Triage, reports and downloads are now shown in your time zone. By default it is your device's own zone; choose another in Profile → Time zone. The clock at the top shows it. See Choose your time zone.
- A welcome screen shows briefly after you sign in, while your workspace opens.
- Other clients are never named in a client's intelligence or report: HRS-wide figures are counts and shares only.
HRS Triage · September 24, 2026
Ask HRS AI prepares actions
- Ask Ask HRS AI to do something ("mark #482 malicious and quarantine it", "assign it to me", "tell the reporter it was safe") and it prepares each action as a card. Press Confirm to do it or Dismiss to drop it. Nothing changes until you confirm. See Ask HRS AI.
- Ask "what should I do with #482?" and the case's recommended next step comes as a card you can confirm.
- Confirming runs the same action as the case page, with your permissions, and it is recorded under your name. Quarantines and reporter emails still go to Approvals.
- Actions come only from what you type, never from the AI's reply or from a reported email.
- Admins can set a client's Triage Agent level from the chat: "put Northwind on Autopilot".
- Fix: MSP and HRS-wide users had to pick a client before asking about the case they had open. The case's client is now used.
HRS Triage · September 24, 2026
The Triage Agent works ahead of you
- Campaigns across clients. When a message is confirmed malicious at one client, the agent finds the same message at the other clients the same MSP (or the HRS team) runs. It removes it on Autopilot and prepares the quarantine on Assist, within each client's own guardrails. It never overrides a person's verdict. See The Triage Agent.
- Response-target watchdog. The agent warns the case owner, or whoever runs the client, once, before an unanswered case misses its response target, then escalates if it is missed.
- Daily briefing. Each morning the people who run each client get one email: what the agent handled overnight and what is waiting for them. The same briefing is on the Triage Agent page.
- New notification choices in Profile → Notifications: A case is about to miss its response target, A campaign is contained across clients and The agent's daily briefing.
- Unowned cases that miss their target now go to the admins of whoever runs the client, so the HRS team hears about the direct clients it runs.
- Fix: the response-target clock stopped when the engine scored a report, seconds after it arrived. So almost no case was ever at risk or escalated, and the Command Center counted them as met. The clock now runs until a person answers.
HRS Triage · September 24, 2026
Every report is categorized, and the agent says when it isn't sure
- Every report now gets a category: HRS simulation, Business communication, Spam / marketing, or an attack family (credential phishing, BEC, malware, QR phishing, callback, scam, extortion, brand impersonation, thread hijacking). See How a reported email becomes a case.
- When the evidence isn't clear, the report becomes Needs review and goes to a person with the reason, instead of being guessed. A clear attack with a low score is raised to Suspicious.
- HRS core's phishing simulations are recognized when HRS provably sent them, and on Autopilot the Triage Agent closes them as reported correctly. A fake "simulation" header is now evidence of an attack.
- On Autopilot the agent also closes decided spam and business mail, with one in ten sent for a spot check.
- Fix: the body of plain-text emails was never stored, so the engine and the AI scored most BEC reports on the subject alone.
- Fix: the autonomy checks never saw the engine's evidence codes, so "independent signals" only ever counted campaigns.
- Fix: mail from an email service (SendGrid, Amazon SES and others) no longer scores as a return-path mismatch, and a sender domain built from account and security words now counts against it.
HRS Triage · September 24, 2026
The Triage Agent
- The Triage Agent now works each report end to end. When every safety gate passes, it:
- removes the phish from every mailbox that received it;
- confirms the verdict and sends it to your ticketing and chat;
- tells the reporter, and closes the case as Remediated with a written summary.
Anything it should not decide goes to a person with the quarantine already prepared in Approvals. See The Triage Agent.
- Every case shows the agent's steps and reasons on its Summary tab. One closed case in ten asks for a Spot check: Agree, or change the verdict. Only people's answers count in calibration.
- Choose how far it goes per client in Settings → Autonomy: Observe, Assist, Autopilot or Earned autopilot. MSP admins can set one default for all their clients.
- New clients start on Earned autopilot: Assist until their own history proves the engine accurate.
- Clients that had auto-remediation on are on Autopilot; everyone else is on Assist.
- Managed by replaces Operator. MSP clients are run by their MSP; direct clients are run by the HRS team unless they run themselves.
- The Microsoft 365 Auto-remediation threshold is now the Autopilot score floor (85 by default). Whether the agent acts is set by its level.
- New Triage Agent page under Operate: what it handled, contained and handed over, spot-check agreement, each client's level, and a live activity feed.
HRS Triage · September 24, 2026
Use your own AI key
- Admins can now connect their own Anthropic API key in Settings → AI & reporters → Use your own AI key, for one organization or, for MSP admins, every client at once. AI calls are then billed to your own account, with no HRS daily limit. See AI settings.
- The key is checked with the provider before it is saved, stored encrypted and never shown again. If the provider stops accepting it, AI moves to the next key in line and the panel says so.
- Organizations without their own key use the shared HRS key, now within a daily limit per organization. When the limit is reached, Ask HRS AI and the case copilot say so, and tell admins how to lift it.
- System status says when AI is available only to organizations with their own key.
HRS Triage · September 24, 2026
Five more Ask HRS AI specialists
- Campaigns: "Any campaigns running?" gets each wave's reports, mailboxes, decisions and open cases, and how many of your other clients got the same message.
- Indicator lookup: type a domain, link or file hash ("Have we seen evil.example?") for its history here, the team's disposition, other clients' reports and the phishing lists.
- Reporter history: "Is jane@contoso.com a reliable reporter?" gets their score, tier and recent reports.
- Deadlines & approvals: "What's about to breach?" and "What's waiting for approval?" in one answer.
- Client health (MSP and HRS users): "Which clients need attention?" lists clients that have gone quiet or are missing a roster, a mailbox connection or AI. See Ask HRS AI.
HRS Triage · September 24, 2026
Ask HRS AI brings in specialists
- "What should I work on next?" now gets your open cases ranked, each with its reasons: time left before the response target, severity, VIP, campaign, no verdict yet.
- Name a case and Ask HRS AI brings its full picture (evidence, phishing-list hits, campaign, blast radius, deadline, approvals) and the recommended next step.
- "How do I ...?" questions are answered from the help center, with a link to the article.
- The line under each answer shows which specialists helped. See Ask HRS AI.
HRS Triage · September 24, 2026
Tickets in ConnectWise, Autotask and HaloPSA
- Connect each client to your PSA in Settings → Integrations → Connect your PSA. A confirmed threat opens one ticket on that client's company; quarantines, removals and missed response targets add internal notes. See Open tickets in ConnectWise, Autotask or HaloPSA.
- Test now says why a connection failed: the keys were refused, the client wasn't found, or the site couldn't be reached.
HRS Triage · September 24, 2026
Free phishing lists check every link
- Every link in a reported email is now checked against OpenPhish, PhishTank, Google Safe Browsing and ThreatFox; ThreatFox also checks sender domains and attachments. A hit shows on the case's External intel tab and in its reasons, and raises the score even when the sender passes SPF, DKIM and DMARC.
- OpenPhish and PhishTank are downloaded and compared inside HRS Triage, so your links are never sent to them.
- System status shows a Phishing lists row with how fresh each list is.
HRS Triage · September 24, 2026
From first invite to offboarding
- Invite people instead of sharing passwords: new analysts get an email to choose their own password (valid 3 days). Pick who they can see by organization or MSP name, not by id.
- Tell reporters what happened without a connected mailbox: switch on External actions in Settings and the case's Actions tab offers reporter emails, including a new confirmed threat email that tells them to delete it and speak up if they clicked.
- Change a case's status from the case: Investigating, Escalated, Remediated or Closed, with a note, and reopen a closed case.
- Fix: a second action on the same case (a reporter email after a quarantine, say) was refused, and a failed or rejected action could never be tried again.
- Fix: opening a case or campaign you can't see now returns "not found" with the right status.
HRS Triage · September 24, 2026
Organizations known by name
- Organizations now show by name everywhere, including the scope pill at the top of every page, instead of "Org 12". The name comes from the one set in Settings, then the name HRS core sends, then the organization's mail domain.
- An MSP HRS core hasn't named yet shows its clients, for example "MSP 91 (Adatum, Wingtip)".
- A name an administrator set in Settings is no longer replaced when reports arrive.
HRS Triage · September 24, 2026
See and resend failed webhook deliveries
- Settings → Integrations now shows each webhook, chat and ticketing destination's recent deliveries, with the error when one failed, and Resend for one or all failed deliveries.
- Fix: on some servers, webhook events could wait hours before their first send.
- Problems the app recovers from on its own now reach the HRS team's error monitor, so they get fixed.
HRS Triage · September 24, 2026
Help that stays on screen
- Fix: the ? help on the Command Center could open off the edge of the screen (Engine trust opened under the sidebar). Help now always opens fully visible, above the button when there is no room below.
- Tap ? to open help on a phone or tablet; Esc or a tap elsewhere closes it.
- More ? help on the Command Center (false alarms, missed threats, auto-remediation, severity mix, campaigns, operating tempo, the work queue, live activity, peer benchmark) and on the Calibration figures.
HRS Triage · September 24, 2026
Notifications that reach you
- Email and push when a case is assigned to you, an action needs approval, a case misses its response target, or a high or critical threat is reported. Choose per event in Profile → Notifications, and send yourself a test email. See Notifications.
- The bell now shows missed response targets and new high and critical threats, and one line for what's waiting in Approvals, which clears as they're decided.
- Webhooks, Slack and Teams now also hear about engine-detected threats, quarantines and missed response targets.
- Fix: emails to reporters failed to send. Fix: MSP admins could not see or decide approvals.
HRS Triage · September 23, 2026
Security: hostile email stays contained
- Reported emails are cleaned with a stricter, structure-aware filter before you see them, and the preview is sealed off even if opened on its own.
- Remote images in a reported email now stay off until you choose Load them, so opening a case never tells the sender it was read.
- Images in reported mail are only scanned for QR codes when they are genuine PNG, JPEG or GIF files of a sensible size.
- Sign-in pauses for a network after 20 failed attempts in 15 minutes, and password-reset links always point to HRS Triage.
- Other websites can no longer frame HRS Triage, submit its sign-in forms, or sign you out without a click.
HRS Triage · September 23, 2026
Resources, with pictures
- Guides now show the page they describe: real screenshots with captions (click to enlarge), and diagrams for how a report becomes a case, quarantine and restore, and the SLA clock.
- Shorter articles, with keyboard shortcuts shown as keys, and tips and notes that stand out.
- The Resources home adds popular searches, a filter for analyst or admin guides, and a live system status card.
- Guides meant for HRS staff are never shown to organization or MSP users.
HRS Triage · September 23, 2026
Fix: no sign-out on a network blip
- A failed connection check when a page loaded could sign you out a second later. The idle countdown now only starts once the server has confirmed your session.
HRS Triage · September 23, 2026
Product tour
- A guided two-minute tour of HRS Triage. It highlights the sidebar, search, the Command Center, the triage queue and each main page in turn, and links to each page's guide. It only shows the pages your role can use.
- It's offered once, at your first sign-in. Replay it from the account menu (Take the tour), the command palette, or Tour this page in the footer.