<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>HRS what's new</title><id>https://docs.humanriskshield.com/whats-new/</id><link href="https://docs.humanriskshield.com/whats-new/feed.xml" rel="self"/><link href="https://docs.humanriskshield.com/whats-new/"/><updated>2026-10-02T00:00:00Z</updated>
<entry><title>HRS Triage: Release 0.85.1</title><id>tag:docs.humanriskshield.com,2026-10-02:triage-2026-10-02-release-0-85-1</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-10-02-release-0-85-1"/><updated>2026-10-02T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.85.1 fixes a What's new entry that pointed analysts to a staff-only article, and the documentation check now catches that in What's new entries.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Learn: A real documentation library</title><id>tag:docs.humanriskshield.com,2026-09-25:learn-2026-09-25-a-real-documentation-library</id><link href="https://docs.humanriskshield.com/whats-new/learn/#2026-09-25-a-real-documentation-library"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;p&gt;The help you are reading now replaced seven placeholder entries. 23 documents
across eight sections, each scoped to the people it is for, cross-linked, and
illustrated with screenshots of the actual product.&lt;/p&gt;
&lt;p&gt;The documentation is version-controlled alongside the code and published with it,
so it always describes the build you are using rather than the build somebody
documented once.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Start here&lt;/strong&gt; promotes the six pages worth reading first.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Filter by who you are&lt;/strong&gt; narrows the whole index to learners, admins or partners.&lt;/li&gt;
&lt;li&gt;Each page opens with a button into the surface it documents.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Learn: The reader renders more</title><id>tag:docs.humanriskshield.com,2026-09-25:learn-2026-09-25-the-reader-renders-more</id><link href="https://docs.humanriskshield.com/whats-new/learn/#2026-09-25-the-reader-renders-more"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;p&gt;Numbered steps render as numbered steps, and screenshots render inline instead of
as their own alt text. External links open in a new tab. Documentation image
sources are restricted to the platform's own assets.&lt;/p&gt;
&lt;p&gt;Sections in the index are now ordered deliberately rather than alphabetically, so
&lt;a href="/learn/what-core-is"&gt;Getting started&lt;/a&gt; is first.&lt;/p&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.85.0</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-release-0-85-0</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-release-0-85-0"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.85.0 protects HumanRisk Shield's own organization and its platform admin account.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: HumanRisk Shield's own organization and admin are protected</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-humanrisk-shield-s-own-organization-and-admin-are-protected</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-humanrisk-shield-s-own-organization-and-admin-are-protected"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Organization 1 is HumanRisk Shield.&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;It's labelled &amp;quot;HumanRisk Shield&amp;quot; and always run by the HRS team.&lt;/li&gt;
&lt;li&gt;Only HRS platform accounts can change its settings, name or industry, or manage its analysts.&lt;/li&gt;
&lt;li&gt;It never belongs to an MSP, even if a sync or an older record says so, and it can't be offboarded or deleted.&lt;/li&gt;
&lt;li&gt;It's left out of what customers see: the organizations HRS protects, industry views, benchmarks, the Portfolio and Campaign spread.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;admin@humanriskshield.com is protected.&lt;/strong&gt; Nobody can deactivate it, remove its admin role or narrow it to one organization. Only an HRS platform admin can unlock it or reset its password or two-factor. Refused attempts are recorded in the audit log.&lt;/li&gt;
&lt;li&gt;See &lt;span class="gated-ref" title="Available when you sign in"&gt;Roles and access&lt;/span&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.84.0</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-release-0-84-0</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-release-0-84-0"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.84.0 carries the HumanRisk Shield name and logo: the console is now &lt;strong&gt;HumanRisk Shield | TRIAGE&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: The HumanRisk Shield logo and name</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-the-humanrisk-shield-logo-and-name</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-the-humanrisk-shield-logo-and-name"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The console now shows the HumanRisk Shield logo (the shield with the pulse line) and the name &lt;strong&gt;HumanRisk Shield | TRIAGE&lt;/strong&gt;, in place of the magnifier logo and &amp;quot;HRS Triage&amp;quot;. It appears in the sidebar, the top bar on small screens, the footer, the sign-in page and the welcome screen. In the sidebar the name sits on two lines.&lt;/li&gt;
&lt;li&gt;Browser tabs read, for example, &amp;quot;Triage · HumanRisk Shield | TRIAGE&amp;quot;, and the footer shows the version under the same name.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.83.0</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-release-0-83-0</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-release-0-83-0"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.83.0 adds industry views: what is hitting each client's industry, in the Phishing Data Centre, the reports, the Portfolio and on campaigns.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: See what is hitting your industry</title><id>tag:docs.humanriskshield.com,2026-09-25:triage-2026-09-25-see-what-is-hitting-your-industry</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-25-see-what-is-hitting-your-industry"/><updated>2026-09-25T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Phishing Data Centre&lt;/strong&gt; has a new &lt;strong&gt;Your industry&lt;/strong&gt; section. It shows each threat category's share across organizations in your industry, next to yours and all of HRS, plus what is rising, the brands impersonated and campaigns seen at several of them. MSP users can switch industries, and HRS staff can pick any. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Your industry&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;Every organization in an industry counts, anonymised:
&lt;ul&gt;
&lt;li&gt;an industry shows only once 5 of its organizations reported a threat in the period;&lt;/li&gt;
&lt;li&gt;a brand or campaign is listed only once 2 of them saw it;&lt;/li&gt;
&lt;li&gt;no organization is ever named.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;threat report&lt;/strong&gt; (download and monthly email) has a &lt;strong&gt;Your industry&lt;/strong&gt; slide, the CSV has an industry section, and the &lt;strong&gt;client report&lt;/strong&gt; has a &lt;strong&gt;Your industry&lt;/strong&gt; page. Each appears only when the industry is large enough.&lt;/li&gt;
&lt;li&gt;A campaign's page shows &lt;strong&gt;Industries this campaign is hitting&lt;/strong&gt;. On &lt;strong&gt;Campaign spread&lt;/strong&gt;, each client shows its industry.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Portfolio&lt;/strong&gt; shows each client's industry and filters by it, including &lt;strong&gt;No industry set&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;MSP and HRS admins can set every client's industry in one save in &lt;strong&gt;Settings → Shared intelligence → Industries&lt;/strong&gt;. The setup checklist has a new optional step, &lt;strong&gt;Set your industry&lt;/strong&gt;. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Shared intelligence&lt;/span&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.82.1: the Phishing Data Centre no longer times out</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-release-0-82-1-the-phishing-data-centre-no-longer-times-out</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-release-0-82-1-the-phishing-data-centre-no-longer-times-out"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Fixed: with every threat feed switched on (&lt;code&gt;PHISH_FEEDS=all&lt;/code&gt;), the &lt;strong&gt;Repository&lt;/strong&gt; (the Phishing Data Centre, including in the demo workspace) could stop with &amp;quot;Maximum execution time exceeded&amp;quot;. Summarising about a million feed entries on every page view took too long. The summary of what the feeds are tracking is now built once an hour by the background worker and shared, and the page reads it. Pages load in well under a second. Apply database migration 0069 after this update.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.82.0</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-release-0-82-0</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-release-0-82-0"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.82.0 puts every printed report in the HumanRisk Shield brand and strengthens protection against password guessing.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Stronger protection against password guessing</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-stronger-protection-against-password-guessing</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-stronger-protection-against-password-guessing"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Accounts lock for longer each time: 15 minutes after 8 wrong passwords or two-factor codes, then 1 hour, 4 hours, and 24 hours. Before, every lock lasted 15 minutes. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Sign in and passwords&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;The owner of a locked account gets an email saying so, with the address of the last attempt, and every lock is in the audit log.&lt;/li&gt;
&lt;li&gt;One network is also limited to 100 failed sign-ins a day, on top of 20 per 15 minutes.&lt;/li&gt;
&lt;li&gt;An email address with no account locks exactly like a real one, so the sign-in page no longer reveals who has an account.&lt;/li&gt;
&lt;li&gt;Re-entering your current password on your profile is limited to 5 wrong tries in 15 minutes.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Every report in the HumanRisk Shield brand</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-every-report-in-the-humanrisk-shield-brand</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-every-report-in-the-humanrisk-shield-brand"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;client report&lt;/strong&gt; (Analytics) and the &lt;strong&gt;campaign write-up&lt;/strong&gt; now follow the HumanRisk Shield brand guide, like the threat report:
&lt;ul&gt;
&lt;li&gt;a deep-violet cover with the HumanRisk Shield logo;&lt;/li&gt;
&lt;li&gt;white A4 pages with the logo, numbered sections and a footer;&lt;/li&gt;
&lt;li&gt;Inter and IBM Plex Mono, built into the page, so it prints the same everywhere.
See &lt;span class="gated-ref" title="Available when you sign in"&gt;Analytics and client reports&lt;/span&gt; and &lt;span class="gated-ref" title="Available when you sign in"&gt;Campaigns&lt;/span&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Fixed: a sender written with a display name showed its domain with a stray &amp;quot;&amp;gt;&amp;quot; in the client report and the campaign write-up.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Release 0.81.0</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-release-0-81-0</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-release-0-81-0"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage 0.81.0 bundles everything from 2026-09-24: the Phishing Data Centre and its monthly threat reports in the HumanRisk Shield brand, more threat feeds, your own time zone, the setup checklist, profile pictures, faster pages, the HRS Labs detection rules, and searchable threat indicators.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: HRS Labs detection rules, and searchable threat indicators</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-hrs-labs-detection-rules-and-searchable-threat-indicators</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-hrs-labs-detection-rules-and-searchable-threat-indicators"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HRS Labs detection rules.&lt;/strong&gt; Automation now comes with over 30 rules written by HRS Labs. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Automation rules&lt;/span&gt;.
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Business email compromise:&lt;/strong&gt; payment changes, executive impersonation, gift cards, payroll diversion and thread hijacking.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scams:&lt;/strong&gt; advance-fee, callback phishing, sextortion and recruitment scams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Brand impersonation:&lt;/strong&gt; fake PayPal, Microsoft 365, DocuSign, parcel carriers, crypto wallets and tax authorities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Delivery tricks:&lt;/strong&gt; BaseStriker, OAuth consent phishing, HTML smuggling and lookalike links.&lt;/li&gt;
&lt;li&gt;They start in shadow and change nothing until you promote them.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Every rule shows its &lt;strong&gt;author&lt;/strong&gt; (HRS Labs, a named HRS SOC analyst, or the analyst of your organization who wrote it), &lt;strong&gt;creation date&lt;/strong&gt;, &lt;strong&gt;priority&lt;/strong&gt;, &lt;strong&gt;tags&lt;/strong&gt;, &lt;strong&gt;matches&lt;/strong&gt; and whether it is &lt;strong&gt;active&lt;/strong&gt;. Open a rule for its description, MITRE ATT&amp;amp;CK techniques and known false positives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Download&lt;/strong&gt; one rule, or every rule, as a JSON file.&lt;/li&gt;
&lt;li&gt;Rules can read the words of an email, the engine's findings, the impersonated brand, a mismatched reply-to, a free-mailbox sender, link hosts, attachment names and an HTML base tag. There are two new condition types: &lt;strong&gt;contains any of&lt;/strong&gt; and &lt;strong&gt;is not on domain&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BaseStriker:&lt;/strong&gt; links hidden behind an HTML base tag are now resolved and checked like any other link.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Threat indicators&lt;/strong&gt; can be searched by value, and filtered by type, disposition and when they were last seen, 50 to a page. &lt;strong&gt;Export CSV&lt;/strong&gt; downloads everything that matches. A &lt;strong&gt;?&lt;/strong&gt; explains where each kind of indicator comes from. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Manage threat indicators&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;Fixed: a rule condition on the sender's domain never matched a sender written with a display name, such as &amp;quot;Dana&amp;quot; &lt;a href="mailto:dana@example.com"&gt;dana@example.com&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: A setup checklist, profile pictures and a faster console</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-a-setup-checklist-profile-pictures-and-a-faster-console</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-a-setup-checklist-profile-pictures-and-a-faster-console"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Setup checklist.&lt;/strong&gt; Admins of an organization that runs its own triage, and MSP admins, get a &lt;strong&gt;Setup&lt;/strong&gt; button in the top bar showing how far setup has got, such as &lt;strong&gt;Setup 4/6&lt;/strong&gt;. It lists each step with a link to where you do it, ticks steps off by itself, and disappears when setup is done. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Set up a new organization&lt;/span&gt;.
&lt;ul&gt;
&lt;li&gt;For an MSP, it shows how many clients have their mail connected, have sent a first report and have a VIP.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hide checklist&lt;/strong&gt; hides it early. Bring it back from the account menu.&lt;/li&gt;
&lt;li&gt;The Command Center's &lt;strong&gt;Getting started&lt;/strong&gt; card links to it.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Profile pictures.&lt;/strong&gt; Add a picture on your &lt;strong&gt;Profile&lt;/strong&gt; (PNG, JPEG or WebP, up to 512 KB). It shows in the top bar, on your profile, on the &lt;strong&gt;Analysts&lt;/strong&gt; list and in the Triage queue's &lt;strong&gt;Assignee&lt;/strong&gt; column. Without one, people see your initials. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Your profile and picture&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;Fixed: every page, the demo workspace included, was slow on a large platform, because the notification bell read the whole audit log on each page and each check for new notifications. Pages and the bell are now several times faster.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: A faster Phishing Data Centre</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-a-faster-phishing-data-centre</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-a-faster-phishing-data-centre"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Fixed: on a large platform, the Phishing Data Centre could stop with a timeout instead of loading. It now loads in seconds, and &lt;strong&gt;Refresh&lt;/strong&gt; rebuilds it with the latest reports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Known indicators&lt;/strong&gt; now counts a link host, domain or file hash already marked malicious at any organization HRS protects, as it says. Before, it only looked within the same organization.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: More threat feeds</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-more-threat-feeds</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-more-threat-feeds"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;HRS Triage now downloads and matches four more public feeds. Your links are never sent to any of them.
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;URLhaus&lt;/strong&gt; and &lt;strong&gt;ThreatFox&lt;/strong&gt; (abuse.ch): links and domains serving malware, with the malware family.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Phishing Army&lt;/strong&gt; and &lt;strong&gt;CERT Polska&lt;/strong&gt;: phishing domain blocklists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Phishing.Database&lt;/strong&gt; (about 400,000 domains) is optional, and HumanRisk Shield decides whether to switch it on.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;A link that serves malware now reads as a &lt;strong&gt;malware link&lt;/strong&gt; on the case and counts toward the malware category, not phishing.&lt;/li&gt;
&lt;li&gt;A domain-list match also catches a link on a subdomain of a listed domain. Like any host-level match, it counts for less than a listed link and never lets the Triage Agent act on its own.&lt;/li&gt;
&lt;li&gt;The Phishing Data Centre's &lt;strong&gt;External intelligence&lt;/strong&gt; shows every feed's size, freshness and health, and how many of your threats each one matched. The threat report and CSV carry the same. See &lt;span class="gated-ref" title="Available when you sign in"&gt;The Phishing Data Centre&lt;/span&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Monthly threat reports by email</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-monthly-threat-reports-by-email</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-monthly-threat-reports-by-email"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The Phishing Data Centre has a new &lt;strong&gt;Reports&lt;/strong&gt; tab. It emails last month's threat report every month, on the day and hour you choose, in your time zone. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Send the threat report every month&lt;/span&gt;.
&lt;ul&gt;
&lt;li&gt;Send one organization's report, or an MSP's report covering all its clients.&lt;/li&gt;
&lt;li&gt;Up to 20 recipients per schedule. They do not need an HRS Triage account.&lt;/li&gt;
&lt;li&gt;Attach PDF, PowerPoint, CSV, or any mix.&lt;/li&gt;
&lt;li&gt;Each email carries the month's headline numbers and a link to stop receiving it.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Every report sent is listed to download again, with the numbers it was sent with.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Send now&lt;/strong&gt; sends last month's report straight away.&lt;/li&gt;
&lt;li&gt;The Phishing Data Centre looks like the Command Center:
&lt;ul&gt;
&lt;li&gt;The numbers are colour-coded tiles that open the reports behind them.&lt;/li&gt;
&lt;li&gt;Each threat category has its own colour in every chart and table.&lt;/li&gt;
&lt;li&gt;Changes on the previous period show as red or lime chips.&lt;/li&gt;
&lt;li&gt;The organization picker applies as soon as you choose.&lt;/li&gt;
&lt;li&gt;Search keeps its less common filters under &lt;strong&gt;More filters&lt;/strong&gt;, and an empty search offers starting points.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: The threat report in the HumanRisk Shield brand</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-the-threat-report-in-the-humanrisk-shield-brand</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-the-threat-report-in-the-humanrisk-shield-brand"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The PowerPoint and PDF threat report now follow the HRS brand guide. See &lt;span class="gated-ref" title="Available when you sign in"&gt;The Phishing Data Centre&lt;/span&gt;.
&lt;ul&gt;
&lt;li&gt;A deep-violet cover and closing page, and white content pages with deep-violet text.&lt;/li&gt;
&lt;li&gt;The original HumanRisk Shield logo on every page.&lt;/li&gt;
&lt;li&gt;Inter for text and IBM Plex Mono for labels, built into the PDF.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;HRS Triage emails carry the HumanRisk Shield logo in their header.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: The Phishing Data Centre, an HRS threat report, and your own time zone</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-the-phishing-data-centre-an-hrs-threat-report-and-your-own-time-zone</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-the-phishing-data-centre-an-hrs-threat-report-and-your-own-time-zone"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Repository&lt;/strong&gt; is now the &lt;strong&gt;Phishing Data Centre&lt;/strong&gt;. Its new &lt;strong&gt;Intelligence&lt;/strong&gt; tab is a briefing. See &lt;span class="gated-ref" title="Available when you sign in"&gt;The Phishing Data Centre&lt;/span&gt;.
&lt;ul&gt;
&lt;li&gt;Threats and categories at each organization, with the malicious rate against everyone HRS protects.&lt;/li&gt;
&lt;li&gt;Time to a decision, known indicators, and quarantines by the agent and by people.&lt;/li&gt;
&lt;li&gt;Top senders with their HRS-wide count, and when people report.&lt;/li&gt;
&lt;li&gt;What HRS sees in the wild, what the public phishing feeds carry, and what to do about it.&lt;/li&gt;
&lt;li&gt;Search is its own tab, unchanged.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Download the report&lt;/strong&gt; as an HRS-branded &lt;strong&gt;PowerPoint&lt;/strong&gt; or &lt;strong&gt;PDF&lt;/strong&gt;, with the numbers as &lt;strong&gt;CSV&lt;/strong&gt;. The report covers:
&lt;ul&gt;
&lt;li&gt;the top threats and a spotlight campaign;&lt;/li&gt;
&lt;li&gt;the headline numbers;&lt;/li&gt;
&lt;li&gt;quarantines, categories month by month, and daily and hourly volume;&lt;/li&gt;
&lt;li&gt;top senders, domains and reporters;&lt;/li&gt;
&lt;li&gt;what was not a threat;&lt;/li&gt;
&lt;li&gt;in the wild, recommendations and a glossary.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Your time zone.&lt;/strong&gt; Times across HRS Triage, reports and downloads are now shown in your time zone. By default it is your device's own zone; choose another in &lt;strong&gt;Profile → Time zone&lt;/strong&gt;. The clock at the top shows it. See &lt;a href="/triage/your-time-zone"&gt;Choose your time zone&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;A welcome screen shows briefly after you sign in, while your workspace opens.&lt;/li&gt;
&lt;li&gt;Other clients are never named in a client's intelligence or report: HRS-wide figures are counts and shares only.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Ask HRS AI prepares actions</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-ask-hrs-ai-prepares-actions</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-ask-hrs-ai-prepares-actions"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Ask &lt;strong&gt;Ask HRS AI&lt;/strong&gt; to do something (&amp;quot;mark #482 malicious and quarantine it&amp;quot;, &amp;quot;assign it to me&amp;quot;, &amp;quot;tell the reporter it was safe&amp;quot;) and it prepares each action as a card. Press &lt;strong&gt;Confirm&lt;/strong&gt; to do it or &lt;strong&gt;Dismiss&lt;/strong&gt; to drop it. Nothing changes until you confirm. See &lt;a href="/triage/ask-hrs-ai"&gt;Ask HRS AI&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Ask &amp;quot;what should I do with #482?&amp;quot; and the case's recommended next step comes as a card you can confirm.&lt;/li&gt;
&lt;li&gt;Confirming runs the same action as the case page, with your permissions, and it is recorded under your name. Quarantines and reporter emails still go to &lt;strong&gt;Approvals&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Actions come only from what you type, never from the AI's reply or from a reported email.&lt;/li&gt;
&lt;li&gt;Admins can set a client's Triage Agent level from the chat: &amp;quot;put Northwind on Autopilot&amp;quot;.&lt;/li&gt;
&lt;li&gt;Fix: MSP and HRS-wide users had to pick a client before asking about the case they had open. The case's client is now used.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: The Triage Agent works ahead of you</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-the-triage-agent-works-ahead-of-you</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-the-triage-agent-works-ahead-of-you"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Campaigns across clients.&lt;/strong&gt; When a message is confirmed malicious at one client, the agent finds the same message at the other clients the same MSP (or the HRS team) runs. It removes it on Autopilot and prepares the quarantine on Assist, within each client's own guardrails. It never overrides a person's verdict. See &lt;span class="gated-ref" title="Available when you sign in"&gt;The Triage Agent&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Response-target watchdog.&lt;/strong&gt; The agent warns the case owner, or whoever runs the client, once, before an unanswered case misses its &lt;span class="gated-ref" title="Available when you sign in"&gt;response target&lt;/span&gt;, then escalates if it is missed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Daily briefing.&lt;/strong&gt; Each morning the people who run each client get one email: what the agent handled overnight and what is waiting for them. The same briefing is on the &lt;strong&gt;Triage Agent&lt;/strong&gt; page.&lt;/li&gt;
&lt;li&gt;New notification choices in &lt;strong&gt;Profile → Notifications&lt;/strong&gt;: &lt;strong&gt;A case is about to miss its response target&lt;/strong&gt;, &lt;strong&gt;A campaign is contained across clients&lt;/strong&gt; and &lt;strong&gt;The agent's daily briefing&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Unowned cases that miss their target now go to the admins of whoever runs the client, so the HRS team hears about the direct clients it runs.&lt;/li&gt;
&lt;li&gt;Fix: the response-target clock stopped when the engine scored a report, seconds after it arrived. So almost no case was ever at risk or escalated, and the Command Center counted them as met. The clock now runs until a person answers.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Every report is categorized, and the agent says when it isn't sure</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-every-report-is-categorized-and-the-agent-says-when-it-isn-t-sure</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-every-report-is-categorized-and-the-agent-says-when-it-isn-t-sure"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Every report now gets a category: &lt;strong&gt;HRS simulation&lt;/strong&gt;, &lt;strong&gt;Business communication&lt;/strong&gt;, &lt;strong&gt;Spam / marketing&lt;/strong&gt;, or an attack family (credential phishing, BEC, malware, QR phishing, callback, scam, extortion, brand impersonation, thread hijacking). See &lt;a href="/triage/how-reports-become-cases"&gt;How a reported email becomes a case&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;When the evidence isn't clear, the report becomes &lt;strong&gt;Needs review&lt;/strong&gt; and goes to a person with the reason, instead of being guessed. A clear attack with a low score is raised to &lt;strong&gt;Suspicious&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;HRS core's phishing simulations are recognized when HRS provably sent them, and on Autopilot the Triage Agent closes them as reported correctly. A fake &amp;quot;simulation&amp;quot; header is now evidence of an attack.&lt;/li&gt;
&lt;li&gt;On Autopilot the agent also closes decided spam and business mail, with one in ten sent for a spot check.&lt;/li&gt;
&lt;li&gt;Fix: the body of plain-text emails was never stored, so the engine and the AI scored most BEC reports on the subject alone.&lt;/li&gt;
&lt;li&gt;Fix: the autonomy checks never saw the engine's evidence codes, so &amp;quot;independent signals&amp;quot; only ever counted campaigns.&lt;/li&gt;
&lt;li&gt;Fix: mail from an email service (SendGrid, Amazon SES and others) no longer scores as a return-path mismatch, and a sender domain built from account and security words now counts against it.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: The Triage Agent</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-the-triage-agent</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-the-triage-agent"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Triage Agent&lt;/strong&gt; now works each report end to end. When every safety gate passes, it:
&lt;ul&gt;
&lt;li&gt;removes the phish from every mailbox that received it;&lt;/li&gt;
&lt;li&gt;confirms the verdict and sends it to your ticketing and chat;&lt;/li&gt;
&lt;li&gt;tells the reporter, and closes the case as &lt;strong&gt;Remediated&lt;/strong&gt; with a written summary.
Anything it should not decide goes to a person with the quarantine already prepared in &lt;strong&gt;Approvals&lt;/strong&gt;. See &lt;span class="gated-ref" title="Available when you sign in"&gt;The Triage Agent&lt;/span&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Every case shows the agent's steps and reasons on its &lt;strong&gt;Summary&lt;/strong&gt; tab. One closed case in ten asks for a &lt;strong&gt;Spot check&lt;/strong&gt;: &lt;strong&gt;Agree&lt;/strong&gt;, or change the verdict. Only people's answers count in calibration.&lt;/li&gt;
&lt;li&gt;Choose how far it goes per client in &lt;strong&gt;Settings → Autonomy&lt;/strong&gt;: &lt;strong&gt;Observe&lt;/strong&gt;, &lt;strong&gt;Assist&lt;/strong&gt;, &lt;strong&gt;Autopilot&lt;/strong&gt; or &lt;strong&gt;Earned autopilot&lt;/strong&gt;. MSP admins can set one default for all their clients.
&lt;ul&gt;
&lt;li&gt;New clients start on Earned autopilot: Assist until their own history proves the engine accurate.&lt;/li&gt;
&lt;li&gt;Clients that had auto-remediation on are on Autopilot; everyone else is on Assist.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed by&lt;/strong&gt; replaces &lt;strong&gt;Operator&lt;/strong&gt;. MSP clients are run by their MSP; direct clients are run by the HRS team unless they run themselves.&lt;/li&gt;
&lt;li&gt;The Microsoft 365 &lt;strong&gt;Auto-remediation threshold&lt;/strong&gt; is now the &lt;strong&gt;Autopilot score floor&lt;/strong&gt; (85 by default). Whether the agent acts is set by its level.&lt;/li&gt;
&lt;li&gt;New &lt;strong&gt;Triage Agent&lt;/strong&gt; page under Operate: what it handled, contained and handed over, spot-check agreement, each client's level, and a live activity feed.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Use your own AI key</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-use-your-own-ai-key</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-use-your-own-ai-key"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Admins can now connect their own Anthropic API key in &lt;strong&gt;Settings → AI &amp;amp; reporters → Use your own AI key&lt;/strong&gt;, for one organization or, for MSP admins, every client at once. AI calls are then billed to your own account, with no HRS daily limit. See &lt;span class="gated-ref" title="Available when you sign in"&gt;AI settings&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;The key is checked with the provider before it is saved, stored encrypted and never shown again. If the provider stops accepting it, AI moves to the next key in line and the panel says so.&lt;/li&gt;
&lt;li&gt;Organizations without their own key use the shared HRS key, now within a daily limit per organization. When the limit is reached, Ask HRS AI and the case copilot say so, and tell admins how to lift it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;System status&lt;/strong&gt; says when AI is available only to organizations with their own key.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Five more Ask HRS AI specialists</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-five-more-ask-hrs-ai-specialists</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-five-more-ask-hrs-ai-specialists"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Campaigns&lt;/strong&gt;: &amp;quot;Any campaigns running?&amp;quot; gets each wave's reports, mailboxes, decisions and open cases, and how many of your other clients got the same message.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Indicator lookup&lt;/strong&gt;: type a domain, link or file hash (&amp;quot;Have we seen evil.example?&amp;quot;) for its history here, the team's disposition, other clients' reports and the phishing lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reporter history&lt;/strong&gt;: &amp;quot;Is jane@contoso.com a reliable reporter?&amp;quot; gets their score, tier and recent reports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deadlines &amp;amp; approvals&lt;/strong&gt;: &amp;quot;What's about to breach?&amp;quot; and &amp;quot;What's waiting for approval?&amp;quot; in one answer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Client health&lt;/strong&gt; (MSP and HRS users): &amp;quot;Which clients need attention?&amp;quot; lists clients that have gone quiet or are missing a roster, a mailbox connection or AI. See &lt;a href="/triage/ask-hrs-ai"&gt;Ask HRS AI&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Ask HRS AI brings in specialists</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-ask-hrs-ai-brings-in-specialists</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-ask-hrs-ai-brings-in-specialists"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;&amp;quot;What should I work on next?&amp;quot; now gets your open cases ranked, each with its reasons: time left before the response target, severity, VIP, campaign, no verdict yet.&lt;/li&gt;
&lt;li&gt;Name a case and Ask HRS AI brings its full picture (evidence, phishing-list hits, campaign, blast radius, deadline, approvals) and the recommended next step.&lt;/li&gt;
&lt;li&gt;&amp;quot;How do I ...?&amp;quot; questions are answered from the help center, with a link to the article.&lt;/li&gt;
&lt;li&gt;The line under each answer shows which specialists helped. See &lt;a href="/triage/ask-hrs-ai"&gt;Ask HRS AI&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Tickets in ConnectWise, Autotask and HaloPSA</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-tickets-in-connectwise-autotask-and-halopsa</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-tickets-in-connectwise-autotask-and-halopsa"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Connect each client to your PSA in &lt;strong&gt;Settings → Integrations → Connect your PSA&lt;/strong&gt;. A confirmed threat opens one ticket on that client's company; quarantines, removals and missed response targets add internal notes. See &lt;span class="gated-ref" title="Available when you sign in"&gt;Open tickets in ConnectWise, Autotask or HaloPSA&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Test&lt;/strong&gt; now says why a connection failed: the keys were refused, the client wasn't found, or the site couldn't be reached.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
<entry><title>HRS Triage: Free phishing lists check every link</title><id>tag:docs.humanriskshield.com,2026-09-24:triage-2026-09-24-free-phishing-lists-check-every-link</id><link href="https://docs.humanriskshield.com/whats-new/triage/#2026-09-24-free-phishing-lists-check-every-link"/><updated>2026-09-24T00:00:00Z</updated><content type="html">&lt;ul&gt;
&lt;li&gt;Every link in a reported email is now checked against &lt;strong&gt;OpenPhish&lt;/strong&gt;, &lt;strong&gt;PhishTank&lt;/strong&gt;, &lt;strong&gt;Google Safe Browsing&lt;/strong&gt; and &lt;strong&gt;ThreatFox&lt;/strong&gt;; ThreatFox also checks sender domains and attachments. A hit shows on the case's &lt;strong&gt;External intel&lt;/strong&gt; tab and in its reasons, and raises the score even when the sender passes SPF, DKIM and DMARC.&lt;/li&gt;
&lt;li&gt;OpenPhish and PhishTank are downloaded and compared inside HRS Triage, so your links are never sent to them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;System status&lt;/strong&gt; shows a &lt;strong&gt;Phishing lists&lt;/strong&gt; row with how fresh each list is.&lt;/li&gt;
&lt;/ul&gt;
</content></entry>
</feed>
