When the user calls, open a case
A problem you were told about on the phone now gets the same depth of investigation as one Wegweiser found itself: describe it in the device chat, attach the log, and the cause comes back into the thread. Plus remote control that reaches a locked machine, agents that keep themselves current, and investigations charged for what they cost.
Most of what Wegweiser does starts with the data. An analysis reads a machine, flags what is wrong, and an investigation works out why. That covers the problems a machine can tell you about.
It does not cover the phone call. This morning an MSP trialling Wegweiser wrote about a client whose practice software crashed once a day, until the vendor reinstalled it, after which it crashed ten times a day. There was no finding to click on. There was only what the end user had said, and a technician who wanted to know whether to blame the software, the graphics driver, or the remote-access tool that kept appearing in the crash list.
Open a case
The device chat now has two modes. Ask is the chat you know. Open a case turns the same box into a brief: describe the problem in your own words, say roughly when it started, point at a log file on the machine or attach one, add a screenshot of the error if you have it. Then send it and get on with the day.
A case is investigated in the background on our strongest model, at the highest effort we offer, for as long as the question needs. It reads the machine: crash reports, the Windows reliability timeline, event logs, services, installed software, and now SQL Server's own error log and memory state. It correlates what it finds on a timeline, follows a lead to the end, and posts the cause, its confidence and the next action back into the chat you opened it from. The one this morning took about a minute of evidence to separate two problems the technician had assumed were one: the practice software was failing in its own graphics layer, and the remote-access tool was crashing the Windows sign-in screen, a different fault on a different screen.
A case is read-only, always. It can look at everything and change nothing. If the answer needs something changed, it says so to you in words.
It tells you the cost first. Before a case starts you see the ceiling, 150 wegcoins by default, and your balance. It is charged for what it actually used, and it stops asking questions and writes up what it has before it gets near the ceiling. The cases run so far have cost between 4 and 47. If you have your own Anthropic key configured, it runs on that key instead.
The chat can suggest one. Ask an ordinary question about a device and, if the answer did not settle the problem, the suggestions under it may include Open a case on this, with the brief already drafted from the conversation. It fills in the case for you to read and edit. Nothing starts until you send it.
It can open the ticket. With Zammad connected, tick one box and the case files a ticket for your client. What your client sees is a plain statement: the investigation is under way and you will be in touch. What your team sees, as internal notes, is your original description and then the findings. The ticket ends up waiting for you in "pending reminder", because the conclusion is ours and the decision about what to tell the client is yours.
Remote control reaches a locked machine
The same MSP mentioned, almost in passing, that remote control had shown the welcome screen and then refused every click. It turned out not to be their machine. On a locked Windows computer our capture helper was running as the signed-in user, and Windows does not let a user's process see the lock screen. It gave up, and the picture froze.
The helper now runs with the agent's own system rights and follows the screen wherever Windows moves it: the desktop, the lock screen, the sign-in prompt, a UAC dialog. Ctrl+Alt+Del works and you can sign in. It shipped in agent 0.3.103 today.
Agents that keep themselves current
That MSP's machines were several agent versions behind, which is why a fix they needed had not arrived. Updates used to wait for each MSP to switch them on, and a setting nobody knows about is a setting nobody changes.
So updates are now on by default, on a deliberately cautious schedule. Every release goes to our own machines first. Yours receive it a day later, and only once it has run on ours without a failure, spread over six hours so a bad build could be stopped before it reached everyone. Each machine proves the new version works before it counts, and puts the old one back by itself if it cannot. You can still pin a version or pause updates for your tenant, and a single machine can refuse. And we now have a brake of our own: one switch that halts every rollout at once if we ever need it.
Investigations are charged for what they cost
While building cases we found that the one-click root-cause investigation had been charging for the last step of its work only. A run that took thirteen steps was billed as one. From today every investigation is priced on what it actually used, the same way a case is. Most will cost a few wegcoins more than they did. We would rather say so here than have you notice it on a statement.
What cases are asking for next
Every case ends by listing what it wished it could measure, and that list is how the new diagnostics above were chosen: the reliability timeline, crash reports, performance counters, a service's recovery settings, the Windows licence and its expiry, SQL Server's error log and memory. They are fixed, read-only commands built into agent 0.3.104, which reaches your machines tomorrow. The next list is already growing.