Change orders got their biggest structural upgrade in months. Required approvers now live in the template itself — you mark them when you build the stage, and the system enforces that they can't be removed from live change orders. This unlocks compliance workflows where certain people must sign off, no exceptions. Under the hood, we shipped CO format 1.2 to carry the new reviewer objects, migrated all seed templates, and rewrote the stage decision logic to respect the new constraints.
Required approvers on change orders. Mark reviewers as required in the template editor. Once a change order is created, those reviewers can't be removed — the UI blocks it and the backend rejects the mutation. The stage won't advance until they submit their review (approve or reject).
Faster CPN permalink lookups. Added an expression index on the permalink column so the database doesn't scan the whole table when you land on a CPN page from a shared link. Users can now quickly access a known component via → /org/@org/libs/<lib>/cpn/<CPN>
Password reset for accounts that never set one. If you were invited but never logged in, the "forgot password" flow now works — it'll let you set your first password without burning the invite link on a failed attempt.
Slow GraphQL operations logged by name. When a query takes too long, the gateway now logs which operation it was (not just the generic endpoint). Makes it trivial to find the offender in the trace.
Change order format 1.2 shipped. New schema stores reviewers as objects with an isRequiredToApprove flag instead of bare IDs. All seed templates migrated. Legacy 1.1 templates still work but can't use the new fields.