Release notes
What changed in each Tagaris release, newest first.
Upgrading is a pull of the new image tag; database migrations apply themselves at
start. Take a backup before a major upgrade. Install and upgrade guides are in the
documentation.
Tagaris for iOS 1.0
September 2026
The companion app
- Tagaris for iOS (iPhone and iPad) is on
the App Store. It pairs with your own server and signs in the same way as the
browser, including two-factor and single sign-on, so your security policy
applies unchanged.
- Scan a QR label to open the asset, change its whereabouts or status, log
maintenance, open attachments and raise a linked ticket. Scan an unknown serial
or tag to create the asset on the spot.
- Audit mode walks a room label by label. Stock, accessories, components and
consumables are on the phone too, and an optional Face ID or Touch ID lock
guards the app.
- Works with the free tier and needs Tagaris 2.3.0 or later on the server.
Android is in development.

2.4.1
11 September 2026
Security and mobile
- Seven dependency vulnerabilities patched across all published images, which scan
clean again with no critical or high findings. Pull the image again; there is no
migration.
- Mobile app: an optional app lock in the Account tab. Opening or returning to the
app asks for Face ID or Touch ID, with the device passcode as fallback. The sign-in
session is unaffected.
- Mobile app: a failed keychain read on launch no longer leaves the app on the splash
screen; it starts unpaired instead.
2.4.0
4 September 2026
Specifications, custom fields and status shortcuts
- Hardware specification on assets: CPU, RAM, storage and GPU are fields on every
asset. Device sync fills them from Intune and Jamf where available, only where you
have not set them yourself, and they appear in the discovered-devices review and
the data export.
- Custom fields can be limited to one or more categories, can be a yes/no or a
dropdown as well as text, number or date, and can be marked required. A starter set
of specification fields can be added per category for switches, servers, access
points, UPS, NAS and more.
- Per-asset replacement age: an asset can override its category's rule. The asset
page shows the computed due date, and the replacement-due flag, daily digest and
calendar feed honour it.
- Status quick actions: one-tap next steps from the current status on the asset
page, web and app, plus a Change status menu listing every built-in status and
your custom labels. Disposal keeps its own flow.
- Mobile app: an appearance setting (match the device, light or dark), and custom
status labels on the change-status screen.
- Fixed: changing status from the app or the bulk action now detaches a custom
status label, so the change shows.
- Security: two high-severity advisories patched and the images rebuilt for
advisories in the base image. Pull the image again; no migration.
2.3.0
14 August 2026
Tickets, and the groundwork for the app
- Tickets on assets: link any service desk ticket to an asset by URL, or connect a
Jira Cloud site under Settings, Integrations to raise tickets from the asset page
with the details filled in, link by issue key and see each ticket's status. Tagaris
only creates issues and reads their status. Ticket links appear in the asset
history and the data export.
- The daily digest can raise a Jira ticket carrying the same items, so devices
needing attention land in the service desk queue as well as inboxes.
- Credential expiry warnings: API keys with an expiry date appear in the daily
digest, and each integration (Jira, Intune, Jamf) can carry a credential expiry
date that warns 30, 7 and 1 days before it lapses.
- Stock item images: accessories, components and consumables can carry a product
image, from the web or the app's camera. Stored with photos, so existing backups
cover it.
- The server side of the mobile app: the app signs in like a browser, password with
two-factor or single sign-on, so the same security policy applies, and it works on
the free tier.
- The API's asset list now honours the documented filters.
- Security: two high-severity dependency advisories patched; the image scans
clean.
2.2.0
27 July 2026
Licensing and security
- Licensing tightened: purchased keys activate once through the Goodhall
Solutions licensing service and are then verified offline on your own server.
Air-gapped servers apply a licence file instead, with no internet access at
all.
- Routine hardening of the Docker image: development and build tooling no longer
ships in the runtime image.
2.1.0
21 July 2026
Added
- Asset attachments: receipts, invoices, warranty certificates and manuals on an
asset, alongside photos. Attachments appear in the asset history, the data export
and existing backups.
- Scheduled backups with restore: one archive holding the database and, optionally,
photos and attachments. Run by hand or on a daily or weekly schedule with a
retention count, optionally encrypted with a passphrase, and optionally copied to
S3-compatible storage. Restore asks for a typed confirmation, and an archive from
another install can be uploaded, so moving servers is download, upload, restore.
- Search on every list page, shareable in the URL.
- Deeper location trees: breadcrumb paths, sub-location rollups, full paths in
every picker, and an include-sub-locations filter on the asset list and export.
- Searchable popup pickers for people, locations and assets.
- Personal API keys, created in My account and capped at the holder's role, next to
organisation keys for integrations. Every key has a chosen expiry, and the API can
be switched off install-wide.
Security and fixes
- The Docker image scans clean, with no critical or high findings.
- Photo uploads over 1 MB no longer fail, and the setup account always opens its
own organisation first.
2.0.0
16 July 2026
Teams, security and integrations
- Roles and access: an install-owner tier above Admin, Editor and Viewer, one
central permission check behind everything, and settings split into Organisation
and Application areas. Cross-organisation groups grant one role across several
organisations, and an access overview lists every account and how it signs in.
- Single sign-on with Microsoft Entra ID, including directory role mapping, a
"require single sign-on" option with the owner as the break-glass account, and
client-secret expiry warnings.
- Two-factor authentication for password sign-in: authenticator app, email code or
backup codes, with a per-install policy.
- Email through Microsoft 365 or Google Workspace as well as SMTP, ahead of
providers retiring basic authentication.
- Full stock and lifecycle management: check-out and check-in, accessories,
components and consumables with low-stock alerts, maintenance records,
straight-line depreciation, a physical audit workflow, per-organisation custom
fields, custom status labels and bulk status changes.
- Financial lifecycle: any ISO 4217 currency, a dispose and reinstate workflow with
a book-value snapshot, and Disposals and Value-by-location reports.
- Device sync: pull managed devices from Microsoft Intune and Jamf into a review
queue, with per-connector filters, schedule and policy.
- Migrating made practical: asset import presets for Snipe-IT and Halo, flexible
people imports, and a people pull from Microsoft Entra ID.
- A built-in reports page with eight ready-made reports and a custom report
builder, a getting-started checklist, and a full organisation data export, free on
every tier.
Before 2.0
Tagaris began as an internal service, built and used in day-to-day work before it
was offered to anyone else. Version 2.0 is the first generally available release.