Skip to content
Changelog

Changelog

Every meaningful change to Sentinel — new capabilities, fixes, and anything that touches the read-only/consent safety model — recorded in the open. We build against real installs, so this is the honest running record. Dates are month-level; the desktop apps are in beta and iOS & Android are in review.

2026-09-08 The desktop app was a tall, half-empty column

  • The Windows and Mac app opened as a narrow vertical strip with everything stacked down it and a large blank area at the bottom that never filled. It now opens as a wider landscape window with the two things you actually do — connecting your system, and deciding what your engineer may see — sitting side by side where both are visible at once, instead of one pushing the other off the screen. Shrink the window and it folds back to a single column, so nothing is lost on a small laptop.
  • The sample-data preview moved below both of those rather than between them, because it is the thing you are least likely to want and it was separating the two things you are most likely to want.
  • Several labels and hints were too faint to read against the dark background. They have been lifted to a contrast you can actually read, and the buttons now show a visible outline when you move through them with the keyboard.

2026-09-08 We were hiding the reason your connection failed

  • When the Windows or Mac app could not reach your inverter, it showed you three words — "Couldn't connect" — and nothing else. The actual reason was being written to the screen every time and then hidden by a styling rule meant for something else entirely, so nobody had ever seen it. You now get the real explanation, which is usually the useful one: another app on your network is holding your inverter's single connection, and closing it fixes the problem in seconds.
  • The two buttons that let your engineer look at your system, or change a setting, no longer appear before there is anything to agree to. They used to sit on screen from the moment the app opened — through startup, through the search for your inverter — offering to share a system that was not connected to anyone. They now appear when a session actually exists, which is what the iPhone and iPad app has always done.
  • "Preview with sample data" is now only offered before you connect. Previously it stayed available during a live call, and pressing it would quietly end the session, close any permission you had granted, and issue a new code — while your engineer sat looking at a screen that had gone blank. The button that ends a preview is of course still there while a preview is running.

2026-09-07 Two controls you should never have been shown

  • The app no longer asks whether to look for an EMS. If your site has one, Sentinel finds it — there is nothing to tick. The old switch was never a search option: the scan always found the EMS, and the switch only decided whether to throw it away afterwards. It was added in June as a safety catch while an EMS reading fault was being chased, that fault was fixed the following day, and the switch simply outlived it. Nobody with a dual AC3 system should have needed to know what an EMS was to see their own equipment.
  • One thing genuinely changed underneath: an EMS on its own no longer ends the search. An EMS answers like an inverter but carries none of an inverter's readings, so if it were treated as the main device you would be looking at a screen of zeros. Sentinel now keeps looking for the actual inverter first and only falls back to showing an EMS alone once it is clear the inverter is switched off.
  • The 48-hour access panel no longer offers to accept a long pasted key. Engineers send a twelve-digit code; the key was the older way of doing the same thing and it had already been removed from the desktop app in August. Keeping the field in one app meant the two could disagree about which key was being approved while the verification code on screen described the other — the exact thing that panel exists to prevent.
  • Three error messages told you to ask your engineer to send a key instead, and one of them named a box to paste it into. That box did not exist in either app. Those messages now point at the six-character code, which is a thing you can actually do.

2026-09-06 Correcting what this site told you about access

  • This page said Sentinel had "no standing access" and that closing the app left nothing behind. That stopped being true when the 48-hour engineer window shipped, and we did not update the page. A 48-hour window is exactly that — a permission that waits for you between sessions. Closing the app still stops everything dead, and nobody can reach your system while it is not running, but reopening it inside those 48 hours resumes the window without asking you again. The page now says so, and explains the difference between that and a live six-character code.
  • The download page named a button, "Allow read access", that the app has not had since August. It is now called "Let your engineer look at your system", and the page says that instead. Being told to look for a control that is not there is the fastest way to make someone doubt the whole thing.
  • Install notes now cover the cases that actually stop people. On Windows: what to do when there is no "Run anyway" button at all (that is Smart App Control, which only allows signed apps), and that the app needs Microsoft's WebView2 runtime. On Mac: the local-network permission is not optional — your inverter is a device on your local network — and how to switch it back on if you declined it by mistake. We also say plainly that the warnings appear because we have not yet bought a code-signing certificate.
  • The example code in the illustration showed five characters. Codes are six.

2026-08-29 Battery readings that admit when they disagree

  • Battery packs are now read on a flat battery. Previously we only looked for packs once the battery reported a charge level above zero — which meant a battery that was deeply discharged, recovering, or simply had not reported yet appeared to have no battery management system at all. That is exactly the state an engineer is called out to look at. Found on a customer's second inverter, where the manufacturer's own portal showed the battery talking normally while Sentinel showed nothing.
  • Where two battery readings contradict each other, the dashboard now says so instead of picking one. A pack showing no current while the inverter measures real power flowing used to be labelled "idle", which is the one thing it definitely was not. It now shows both figures side by side and says which is corroborated.
  • The raw battery-management page now does the detective work itself. Per-pack current has never been documented by the manufacturer, so finding it meant reading fifty-nine unlabelled numbers by eye. Given a current the inverter has already measured, Sentinel now highlights which registers carry that value and at what scale — clearly marked as candidates to confirm, not conclusions.
  • Each pack now shows when it was last read successfully, so a pack whose management system has gone quiet is no longer indistinguishable from a healthy one showing its last known values.

2026-08-17 A longer window for changes, and the iPhone app takes shape

  • The window you open for an engineer to change a setting now lasts one hour instead of fifteen minutes. Fifteen was too short for real work: a diagnosis often means changing something, watching how the system settles, then adjusting again — and being asked to re-approve halfway through teaches people to tap "allow" without reading it. Nothing else changed: the window is still opened by you, on your own device, still closes itself, and no change can be made without it.
  • Solar string current was being reported ten times too low on the dashboard. Fixed, and the reading now shows one decimal place.
  • Replies from the inverter are now checked for corruption before we trust them. On a noisy connection a garbled reply could previously have been shown as a real reading; now it is discarded and re-requested, and the dashboard tells the engineer if the link is unhealthy.
  • Changes sent to AC-coupled inverters were being addressed to the wrong place on the inverter. Corrected.
  • An iPhone and iPad app is in preparation, sharing the same code as the Mac app.

2026-07-05 Mobile navigation, a proper sign-out, and a tighter admin console

  • The site now has a working menu on phones and small screens — tap the menu button to reach every page and the sign-in / apply buttons, instead of the nav vanishing below a certain width.
  • Sign out now fully ends your session: it clears the sign-in cookie so the next visit asks you to sign in again, rather than quietly signing you straight back in.
  • The admin console is now locked to administrators end to end — an engineer who is only pending approval, or who is not an admin, no longer sees the kill switch or the engineer roster at all (previously those were only hidden, not withheld).

2026-07-03 Multi-inverter sites, safer writes, and a simpler way in

  • Sentinel now finds and monitors every inverter on a site, not just the first — it keeps searching the network for more even after it connects to one, so multi-inverter and plant setups are read in full.
  • Writes to an inverter setting are now rate-limited to protect the hardware from wear, and the sleep control changes only the sleep state without touching other flags.
  • New customer page: your installer can send you a single link to download Sentinel, run it and read them the code — with a plain-English explanation of why it stays read-only and in your control.
  • Clearer access for installers: apply and sign in to join the approval queue, with the read window (6 hours) and write window (15 minutes) now spelled out in the app.
  • The engineer dashboard now shows a clear banner the whole time write access is switched on — with a live countdown of the time left — so it is always obvious when changes are possible, mirroring the read-access banner.
  • The desktop and mobile apps now switch straight back to "waiting for an engineer" the moment the engineer disconnects, instead of staying on "engineer connected" until the session ends.
  • Connecting is smoother: live data now appears the instant you open the dashboard — even when the customer allowed access before you connected — and a reconnect after a short break quietly re-authenticates instead of dead-ending on "sign in required".
  • Admin console: an engineer can now be removed from the roster entirely (not just disabled) — their access is revoked immediately and the removal is itself recorded, while their past audit history is preserved. The Approve/Disable actions, which were failing to reach the backend, are fixed too.

2026-07-02 Security hardening + admin console

  • Ran a full security review of the sign-in, audit-log and admin paths and closed everything it found — including making sure hostile data from a paired system can never run code in the engineer dashboard.
  • Sign-in tokens now travel in a request header instead of the URL, so they never land in server logs; sessions have a hard renewal cap, and there is now a Sign out control.
  • Admin console: approve or disable engineers, see connected and recent systems, search the full fleet changelog, and permanently erase all data for one system (for example a test rig) — every erasure is itself recorded.

2026-07-01 Engineer sign-in + permanent audit log of every write

  • Engineers now sign in with their approved work email, secured by Cloudflare Access. There is no open signup — Ron approves each installer and can disable an account at any time from an admin console.
  • Every remote change is now recorded to a permanent, append-only, hash-chained audit log before the command reaches the inverter, keyed to the signed-in engineer and the system it targets.
  • The write path is fail-closed: if a change can't be written to the log, the write is refused. No log, no write.

2026-06 History tab

  • Added a persistent history view to the engineer dashboard: scrub back through power flow, battery, solar and grid over time to see what a system was doing when a fault hit.
  • Per-cell battery voltages retained in the rolling diagnostic window so you can spot cell imbalance without being on the system at the moment it drifts.

2026-06 Multi-inverter discovery

  • The local agent now discovers and lists multiple GivEnergy inverters on the same network automatically, so multi-unit and three-phase sites pair once and surface every unit.
  • Each discovered unit is labelled by model and serial in the dashboard picker.

2026-06 EMS visibility

  • Surfaced Energy Management System state (plant status, per-inverter power/SoC/temperature, site calculated and measured load, grid CT power and total battery power) read-only in the dashboard, so you can confirm how a system is configured before touching anything.

2026-06 Write allowlist + on-device consent

  • Hardened the write path: only an explicit allowlist of registers can ever be written, and only during a customer-armed access window after on-device “Allow”.
  • Every attempted and completed write is now recorded to a permanent, tamper-evident audit log that no engineer can alter or delete.

2026-05 Desktop apps (beta)

  • Shipped ad-hoc-signed Mac (universal) and Windows (64-bit) desktop builds — the current way approved engineers run Sentinel.
  • Six-character ephemeral pairing over a Cloudflare relay: no inbound ports, encrypted outbound only.
  • iOS and Android apps entered development toward App Store / Play Store review.