Tell it what the machine is
Wegweiser can now be told the one thing it can never collect: what a machine is actually for. Plus bulk user import, so onboarding a customer with real staff no longer means inviting them one at a time.
Every check on a machine can be right and the conclusion still wrong.
Here is the one that started this. A device summary read: a self-hosted Immich server. Every fact behind it was true. Immich was installed, it was running, it was listening, it was the most distinctive thing on the box. The machine is a development desktop that happens to run a photo container for the family.
No amount of further collection fixes that. The missing input is not another log stream, it is a sentence only the person who owns the machine can write.
A machine can now be described
Every device, group and organisation page has a new entry: What this is. Write a paragraph about what the thing is for, what is expected to be running on it, what it is about to become. Up to two thousand characters, attributed and dated.
From then on, every analysis of that machine reads its findings against your description. So does the summary that brings the checks together, and so does any investigation you start from a finding. When you ask about the machine in chat, chat has it too.
It inherits downward the way analysis settings already do. An organisation note reaches every device under it; a group note reaches every device in the group; the machine's own note sits closest. The drawer shows you what a device inherits as well as what you wrote, so if you describe a lab machine under an organisation described as a production estate, you can see the disagreement on the page instead of meeting it in a verdict.
You can also just say it. In chat on a device: "remember that this is my dev box, the Immich container is personal". It records it and quotes back exactly what it saved.
What it will and will not do
This is the part worth being precise about, because a feature like this is one bad decision away from being a mute button.
It qualifies, it does not suppress. Software that looks anomalous but is named in your note as expected stops being reported as a discovery. A note can lower the severity of a finding it genuinely explains.
It will never hide a security finding. Unexpected persistence, credential theft, a live intrusion, malware: full severity, whatever the note says. An attacker on that machine would benefit from exactly the excuse your note provides, so the note does not get to make that call.
The analysis has to show its working. When your note changes the reading, the prose says so, in words: "Given the operator's note that this is a development desktop...". You can see the note was used and judge whether it should have been.
And it gets challenged. The analysis is told when the note was written and asked to say when the collected evidence contradicts it. A description of a machine written eight months ago is a claim, not a fact, and the machine is the one telling the truth.
If what you actually want is for something to stop counting against a score, that is still Analysis policy or accepting the finding. A description is not a silencer, and keeping the two apart is deliberate.
Onboarding a customer with real staff
Separately, and more prosaically: you can import users from a file.
Inviting people one modal at a time is fine for a colleague and absurd for a new client with two hundred employees. Upload a CSV of first name, surname and email, or read the list straight out of Zammad if your helpdesk connector is set up. Either way you land on the same review screen: every row, what will happen to it, and a role selector per person. Nothing is sent until you confirm.
Rows that cannot be imported are listed with the reason rather than stopping the run: already has an account, already invited and not yet accepted, duplicate in the file, not a valid address, not active in the helpdesk. One typo in row 40 no longer means nobody gets invited.
On confirm, the invitations are created and then sent in the background. The record of who was invited is written before the first email goes out, so a mail server having a bad afternoon cannot leave you guessing about who to chase.
Two roles are offered, Master and User, which is what an invitation can actually grant. The platform admin role is not something this screen can hand out, and we would rather say so on the page than fail quietly at the end.