changelog.exe

Changelog

Microsoft Teams intake, API tokens, and identity checks on every PSA

Date pill, the entry title, and the five highlights with pixel glyphs

August was about meeting requesters where they already are and locking down who Rallied will act for. Microsoft Teams intake, an API for your own tooling, identity checks on every PSA, and every integration now holding its own credentials.

Microsoft Teams intake and per-ticket chat

Requesters can open a ticket by messaging your MSP's bot in Teams. The bot gathers the essentials, files the ticket in your PSA, and opens a group chat for that ticket with the requester in it. Technicians keep working in the PSA, the requester keeps talking in Teams, and notes flow both ways. Each MSP gets its own white-labeled bot.

API tokens and a talk endpoint

Settings has an API Tokens page. Create a token, show the secret once, and call the talk endpoint with a ticket id and a prompt to ask the agent about that ticket from your own scripts or tooling. The reply comes back in the same request, and tokens can be revoked at any time.

Identity verification on HaloPSA, Autotask, and Jira

ConnectWise has had Traceless identity verification for a while. HaloPSA, Autotask, and Jira now get the same flow: a sensitive ticket in execute mode, such as an MFA reset, waits for the requester to verify before the agent does anything. If there is no email to verify against, the agent stays parked and the ticket gets a note saying why.

Every integration holds its own credentials

The Pipedream proxy is gone. Each of the 21 integrations that used to run through it now has its own connect form, checks the credentials against the vendor before saving, and stores the secret encrypted in Rallied. Atera, Huntress, SentinelOne, KnowBe4, Mimecast, Syncro, and HubSpot are among them.

ConnectWise status gate per board

The accepted-status setting for ConnectWise is now scoped by board and matched on status id instead of name, so two boards that both use a status called New are no longer confused and a status rename no longer breaks the gate.

The agent can search the web

Agents have web search, fetch, and map tools, so a vendor review or a licensing question that needs a page from the open web no longer stalls on a CAPTCHA.

Also shipped

  • Rallied learns from closed tickets. After a ticket closes, it proposes a memory such as a client access rule, and a person accepts or dismisses it before anything is used again.
  • Outcome reporting shows which tickets Rallied resolved and what that was worth, on a per-client ROI page that now loads in one query.
  • HaloPSA imports every company, not just the first 50.
  • ConnectWise imports skip soft-deleted companies and keep any-board coverage when part of a sync fails.
  • The agent checks the details of an action before asking for approval, so the approval you see matches what will run.
  • Teams relays every client-facing ConnectWise note, not only the latest, and no longer echoes the requester's own message back.
  • Outbound email can send from a different mailbox on your verified domain, such as alerts@ or billing@, and never from any other domain.
  • Production now has memory and restart alerts, a per-MSP silence heartbeat, and an external uptime check after the August 9 outage.
  • Baseline security response headers on every API response.

CIPP connects on its own, without a Microsoft 365 connection

Date pill, the entry title, and a pixel cloud-server glyph

If your shop manages Microsoft 365 tenants through CIPP, Rallied no longer needs its own Microsoft 365 connection before it can talk to CIPP. CIPP connects, edits, and disconnects on its own from the integrations tab.

What changed

CIPP has been a standalone integration since July, with its own card in the integrations tab and the same dialog reachable from the Microsoft 365 page. Until this week, opening that dialog on an MSP without Microsoft 365 connected returned an error, so the connect, edit, and disconnect buttons did nothing. That check is gone. CIPP now resolves its own credentials and works whether or not Microsoft 365 is connected.

Why it matters

Some MSPs run CIPP for tenant administration and never connect Rallied to Microsoft 365 directly. On those accounts the integrations tab showed an error toast on every visit and CIPP could not be configured at all, which meant no tenant list and no CIPP-backed actions. Those accounts can now set CIPP up in one visit.

What it does not do

It does not change who can do what. Token, role, and MSP access checks run exactly as before. Actions that read Microsoft 365 settings directly still need that integration connected.

Also in CIPP

The CIPP page has a read-only Companies tab that lists every tenant CIPP manages and flags the ones not yet onboarded in Rallied, so you can see the gap without opening CIPP. Because MSPs self-host CIPP and update it on their own schedule, Rallied also detects the CIPP version and shapes each request to match, with one retry when an install answers differently than expected.

How to turn it on

Nothing to switch on. Open Integrations, choose CIPP, and enter your CIPP URL and credentials. Setup details are in the docs at https://docs.rallied.ai.

Rallied now has a public changelog

changelog.exe window with the entry title and a pixel commit glyph

Rallied ships to production several times a week. Until now, the only way to find out was to notice something new in your PSA or ask on a call.

This page fixes that. Each entry is dated, links to its own page, and covers what changed for the MSPs using Rallied: new integrations, changes to how tickets get resolved, and fixes.

How entries work

Ship notes cover a short stretch of production releases. Roundups summarise a month for people evaluating Rallied. Feature posts go deeper on one change that deserves the space.

Entries are written from the pull requests that reached production, then edited by a person before they go live. If something is listed here, it is running for customers today.

See Rallied in Action

Rallied resolves L1 tickets end-to-end. Password resets, account unlocks, onboarding — handled in minutes, not hours.