Version 1.5 is the largest single expansion of the method set the platform has had. Nine tools arrive, taking ErgoSphere from 43 to 52, and eight of them are canonical published methods implemented under their own names. FRAM, SNA and EAST open a new Systems shelf on Method Tools, EAST composing task, social and information networks of one scenario over a single shared entity model. CDM brings the Critical Decision Method interview to a native, interactive incident timeline. GDTA and SAGAT arrive as a pair, one eliciting situation awareness requirements and the other measuring situation awareness against simulator ground truth. SWAT completes the workload shelf, and HE-HAZOP puts a configurable, team-run guideword walkthrough beside SHERPA on the reliability shelf. The ninth is an ErgoSphere original: a rebuilt ErgoCompass that helps you choose the right method, assures the foundational work has not been skipped, and records a justification defensible enough to survive an audit - written straight into the HF Integration Plan rather than kept beside it. Sharing the headline is ErgoBow, which stops being a bowtie editor and becomes a critical control management platform: a governed enterprise control library with structured performance standards, applicability and deployment across a configurable context hierarchy, multi-level assurance planning with an evidence registry behind it, dependency and common-mode analysis that ends the false defence-in-depth claim, an accountable route from a failed control through temporary controls to restoration, and portfolio views that aggregate without losing the thread back to the evidence. Its central position is that reported health, calculated health and accepted health are three different things and are never collapsed into one number. Underneath all of it, the catalogue is reorganised under a naming rule that is now written down rather than assumed, and the assurance layer takes a decisive step: a saved project can prove it has not been altered, there is one governance chain across the platform instead of two, and a single mutation gate now stands at every one of the forty-five save seams. The report preview finally matches the Word document it previews, across roughly forty tools. Your existing projects open unchanged.
Hollnagel's method for modelling everyday work as it is actually done, built as the flagship canvas of the platform. Functions are hexagons carrying six aspects in their canonical positions - Time, Control, Output, Resources, Preconditions, Input - and couplings run from one function's Output into another's non-Output aspect, which is the only direction the method permits and the only direction the tool will draw. What separates a FRAM tool from a hexagon editor is the instantiation, and it is first class here: a named, stored selection of which functions and couplings are active under a stated set of conditions, with per-function variability characterised on timing (too early, on time, too late, not at all) and precision (precise, acceptable, imprecise). Upstream output variability propagates downstream through the couplings and the tool highlights the propagation paths. It does not compute a resonance score, because no such canonical calculation exists and inventing one would be a fidelity failure. Analysis is the comparison of instantiations, plus the analyst's own narrative.
A team or organisation as a network of agents - people, roles, teams or technological agents - connected by communication, information flow, task dependency or command. The analysis is the metrics, and the full standard set is implemented in the domain layer with tests rather than in the canvas: degree centrality with in, out and total for directed networks; sociometric status, the weighted measure the HF literature actually uses, normalised by the node count less one; betweenness, closeness and eigenvector centrality; and at network level density, cohesion, Freeman centralisation, diameter, component count, isolates and reciprocity. Derived findings name the key agents, the brokers who hold high betweenness on low degree, and the isolates. The study declares whether it is directed or undirected and the tool respects that declaration: it will not silently symmetrise a directed network, and where a metric is meaningful in only one mode it is hidden rather than shown as a misleading number. On an undirected network it says plainly that cohesion and density coincide rather than presenting one number twice as though it were two findings.
The largest tool build to date. EAST models one scenario as three linked networks - task, social and information - and the method is the composition, not the three networks. They are built over a single shared entity model, so the agent you see as a node in the social network is the same object that performs a task in the task network and holds information in the information network. Same identity, three roles. That is what makes the flagship interaction possible: select anything in any network and its related entities light up in the other two, which is how EAST answers the questions no single network can - where information exists in the system but not with the agent who needs it, which communications carry which tasks, and where distributed situation awareness is strong or broken. Two view modes are both first class and switch from the ribbon, the choice persisting with the document: three panels side by side kept in visual sync, or a single canvas with a network toggle and the cross-highlight surfacing related entities from the inactive networks. Per-network metrics are reported for all three, with the social network reusing SNA's tested calculator rather than a copy of it. Cross-network reporting is kept to descriptive counts - how many tasks an agent performs, how many information items a task uses - because a composite index the method does not define would be an invention, not a measure.
Klein's structured retrospective interview for eliciting expert decision making from a single non-routine incident, built as a capture instrument rather than a calculator, because that is what the method is. The four sweeps are the shape of the tool: the incident and the expert's unstructured account, then the verified timeline with decision points marked, then the twelve-probe deepening that is the analytical heart, then the "what if" hypotheticals. The probe set ships as the canonical twelve and is yours to edit per study - add, rename, reorder, disable, restore - with deletion blocked while responses reference a probe and disabling preserving what has already been captured. The timeline is the centrepiece and is drawn natively rather than through a graph engine: decision points are visibly focal against ordinary connective events, verified events read differently from unverified ones, each decision point carries a quiet indicator of how many probes and summary fields are filled so you can see which points are thin without opening them, and selecting one drives the probe grid straight to it. The probe surface works both ways round, one decision point across all probes or one probe across all decision points, because both interview styles happen in real rooms. The Situation Assessment Record is a first-class output with one-click carry-across from the probe responses, offered rather than applied - the analyst owns the synthesis. There is no score anywhere, and no sentiment or confidence colouring on responses, because the method does not license either. Completion coverage is the only quantitative thing CDM legitimately produces.
Endsley's subject-matter-expert elicitation method, decomposing a role into the goals an operator is trying to achieve, the decisions each goal demands, and the information required to make each decision - with every requirement tagged to one of the three levels of situation awareness: perception of elements, comprehension of the situation, projection of future states. GDTA is deliberately not a task sequence and the tool does not pretend otherwise; it is goal-oriented, descriptive, and produces no score and no timing. What it produces is the hierarchy, which is what drives display and information design, and which now also seeds SAGAT.
The objective counterpart to the SART tool that already ships, and a deliberate pair with it on the cognitive shelf. SAGAT scores an operator's answers against simulator ground truth and reports percentage correct broken down by SA level, by participant, by freeze and by condition, because comparison across conditions is the whole point of running it. One thing is deliberately absent: the freeze itself. That happens inside someone else's simulator, and ErgoSphere is the instrument-design and analysis platform around the trial, not a trial runtime. There is no simulator integration, no freeze scheduling, no display blanking. The tool builds the query bank before the trial, captures responses and ground truth after each freeze - live at the freeze or transcribed afterwards from paper - and does the scoring and comparison after it. The query bank can be entered directly, or seeded from a GDTA study, in which case each seeded query keeps a reference to its source requirement and a snapshot of the source text, so a later change upstream raises a stale-link indicator instead of silently rewriting your query bank.
Reid and Nygren's three-dimension workload method - time load, mental effort load and psychological stress load, three levels each - completing the workload shelf beside NASA-TLX, IWS and ATWIT. Both stages are supported. The card sort now shows all twenty-seven combinations at once in three columns, with click-to-place alongside drag and a descriptor viewer beneath, so the ranking is a task you can actually finish rather than a scroll. Two fidelity positions are stated openly rather than buried: the interval scale is derived by linear rank mapping rather than full conjoint scaling, which is a documented simplification recorded in the Library Guide with its reason, and if you skip the card sort entirely - as many practitioners do - the tool reports the dimension levels separately and produces no 0 to 100 score, rather than inventing one. Group scales are derived by averaging participant ranks and re-ranking, alongside the per-participant scales.
A guideword-driven, team-based walkthrough of a task decomposition, applied to human actions rather than process parameters. It sits beside SHERPA on the reliability shelf and takes SHERPA's structure, but three things are genuinely different and all three are built. The guideword set is configurable, shipping nine defaults - not done, repeated, less than, more than, wrong sequence, too early, too late, wrong object, wrong action - and editable per study, because guideword sets vary by industry in a way SHERPA's closed taxonomy deliberately does not. The worksheet carries session metadata for the chair, the scribe, the attendees, the date and the node or scope statement, because a facilitated session is what makes the output admissible in a safety case, and entry is built to keep up with a room that is talking. And recommendations have a lifecycle rather than being terminal text: an owner, a target date and a status tracked to closure. The risk matrix is not hardcoded - likelihood bands, severity bands and the band-to-rating mapping are all editable, with a sensible five by five default, and the matrix definition is stored inside the document so a saved study always reproduces its own scale. This is the human-action variant and it stays there: no process parameters, no P&ID nodes, no plant lines.
A practitioner picks methods constantly and is rarely asked to write down why. ErgoCompass makes that decision an artefact. It takes you through a short on-ramp about the problem, matches the cognitive and systems method family by complexity and the physical family by purpose fit, surfaces the methods native to your industry, and recognises composite stacks such as SCTA and EAST for what they are. Alongside the recommendation runs an assurance layer for the foundational work that gets skipped under time pressure - hierarchical task analysis, data gathering, task decomposition, triangulation - so a method set that rests on nothing is visibly a method set that rests on nothing. What it captures is a positive justification, not merely a record of what was excluded, and that justification is written into the HF Integration Plan's method record in Section 7, where the HFIP previously had a home for exclusion rationale and none at all for the reason a method was chosen. The relationship runs both ways: the HFIP prompts ErgoCompass from the method card, and ErgoCompass's output updates the HFIP's method set. It is deliberately not registered as a required method in the compliance catalogues, because that would make "choosing your methods" appear in the Close-Out Report as an analysis you failed to perform. Ratings and guidance are ErgoSphere's own, informed by Stanton and Young (1999) and Holman et al. (2021), both cited in the Library Guide.
A bowtie drawn in a project file describes controls. It does not govern them. ErgoBow now carries an enterprise control library: canonical control records with a stable code, purpose, type and taxonomy, an accountable owner role, a lifecycle running Draft, In Review, Approved, Withdrawn and Superseded, effective dates, revision history and change rationale, along with the applicability constraints and prohibited uses that say where a control must not be relied upon. Each carries a structured performance standard rather than a paragraph of prose - control objective, required functionality, availability, reliability, survivability, operating limits and tolerances, response time, independence requirements, competencies and authorisations, inspection, test and maintenance requirements, failure criteria, evidence requirements, and the degradation response and restoration criteria. Every requirement carries its own identifier, which is what makes the rest of this section possible: evidence and findings target an individual requirement rather than a whole control.
A barrier can now be instantiated from the library as a version-pinned reference, so the bowtie states which revision of the control it relies on. Local implementation detail is recorded against that reference instead of copying the definition and letting the two drift. The tool shows whether a bowtie is using the current approved revision, and when the library moves, you get an explicit review, adopt or retain-current decision rather than a silent update underneath a published diagram. Near-duplicate local controls are surfaced, because the failure mode of every control library is the same one: three slightly different versions of the same control, each maintained by someone who does not know about the other two.
Completeness is now tested rather than eyeballed. The engine flags a material threat with no preventive control, a catastrophic consequence with no mitigation, a critical control with no owner, no performance standard, no verification or no evidence requirement, a free-text local control that was never linked to a canonical one, and any reference to an expired or withdrawn revision. The rules are configurable rather than fixed, because the threshold for "adequate" belongs to the duty holder, not to us.
A configurable context hierarchy models where controls apply - enterprise, business unit, corridor, route or section, site, asset - configurable rather than hard-coded to rail geography, with stable identifiers, effective dates, and proper handling of commissioned, retired and temporary contexts. Controls are assigned by explicit context or by rule, and the applicability states are distinct and meaningful: required, applicable but not deployed, deployed, exempted, and not applicable. Exclusions, variations and alternate controls carry a justification and an approval. When the hierarchy or its source attributes change, applicability is re-evaluated without silently overturning a decision somebody approved. The implementation register is kept deliberately separate from the definition - owner, local procedure and asset references, status, effective period, local variation, compensating controls and commissioning evidence - because a corporate control definition and its implementation at one site are two different records with two different owners. Competency and authorisation requirements attach at both control and assurance-activity level, with independence and segregation-of-duty rules for verifiers and approvers, contractor and delegated-role support, and point-in-time validation that answers the question that actually matters in an investigation: was this person competent and authorised at the moment they performed this verification.
Assurance runs at configurable levels - frontline verification, supervisory, functional and technical, independent, and governance review - with each plan item naming the requirement it tests, the method, the frequency or trigger, the sampling strategy, the responsible role, the independence requirement, the evidence required, the acceptance criteria and what happens on failure. Results are recorded as Pass, Pass with Observation, Fail, Inconclusive, Not Performed or Not Applicable, and a corrected result supersedes rather than overwrites, so the original is never destroyed. Evidence is a registry in its own right: what it proves, which requirement, which contexts and period, who performed it and whether they were a competent person, the performed, received, reviewed and expiry dates, an integrity hash or immutable reference where one exists, classification and retention, and the states that matter most - missing, expired, rejected, superseded and conflicted.
This is the design position the whole module is built on. The accountable owner's declaration of a control's health, the deterministic projection computed from governed rules and evidence, and the disposition governance has formally accepted are held separately and never collapsed into one number. Where they differ, the difference is the finding. Every status is traceable to the inputs, rules, dates and accountable decisions that produced it, so "why is this amber" has an answer rather than a colour. And the rule that governs the whole projection is that missing data cannot produce a good result: unknown, stale, incomplete and conflicted states stay visible as themselves and cannot be coerced to green by an absence of evidence.
A failed or uncertain control signal now has a route from detection to restoration. Findings carry their source, a classification that distinguishes an asset defect from an implementation failure, a control-design weakness, an assurance weakness or a systemic failure, the affected controls, requirements and contexts, the immediate action taken, and causes where they were investigated. Corrective actions carry owners and due dates, extensions require approval and keep their full history, and close-out takes completion evidence and independent verification. Repeat findings and cross-context patterns are detected rather than left to be noticed. Declaring a control degraded records the degradation type, when it started and when it was detected, the scope including what is not yet known, which performance requirements have failed, the operating restrictions imposed and who had the authority to impose them, and the restoration owner, plan, target and return-to-service verification. Temporary and compensating controls are first class and, critically, they expire: a mandatory expiry and maximum duration, a named authoriser, an extension workflow that cannot erase the original expiry date, and closure only once restoration evidence has been accepted. Escalation is rules-driven, on triggers including a safety-critical control going ineffective or unassured, multiple controls degraded on one pathway, a temporary control nearing expiry or failing, and an overdue high-severity action.
Five barriers on a pathway are five barriers only if they can fail independently. ErgoBow now models what controls actually depend on, as typed directional dependencies - power supply, telecommunications and data networks, detection and monitoring platforms, shared assets, source datasets and configuration, a person, role, team or contractor, a procedure or competency, an inspection or test capability, an environmental sensor, an access window, an external organisation, or another control - each with its criticality, redundancy, independence claim, failure effect and supporting evidence. From that, the common-mode analysis identifies barriers relying on the same dependency, propagates an active dependency degradation through to the health of everything downstream, and shows exposure concentrated by owner, technology, contractor or evidence source. It specifically detects controls described as independent that share a critical dependency, and reports pathway defence count twice: raw, and adjusted for independence. Redundant dependencies can be modelled without redundancy being assumed to work. A scenario mode explores failure impact without ever writing over actual recorded health.
Bowties and control records become controlled safety artefacts, moving through a configurable lifecycle from Draft to Technical Review, Control-Owner Acceptance, Independent Review, Approved and Published, then Periodic Review and Superseded or Archived, with rejection, withdrawal, scheduled revalidation and an emergency-change path that mandates a retrospective review rather than quietly skipping one. Published revisions are immutable and work continues on a working copy. Revisions are compared semantically rather than textually - what changed about hazards, threats, consequences, controls, standards, owners, assurance requirements and risk ratings - and the impact of a change is traced across library controls, bowties, implementations, assurance plans and reports, flagging evidence that needs revalidation where the assumption behind it has moved. Sign-off is electronic with meaning, timestamp and identity, self-approval can be prohibited, delegation and contractor restrictions are supported, and conditions, dissent and accepted residual issues are recorded rather than smoothed away. Comments anchor to a specific object at a specific revision. This lifecycle now runs on the one platform governance chain described above, rather than ErgoBow's former private one.
The point of aggregation is usually where traceability dies. Here the portfolio read model aggregates by control, bowtie, context, owner, control type and consequence while keeping effectiveness, assurance coverage, evidence confidence and action status as four separate measures rather than one blended score, and every aggregate drills through to the underlying implementation, assurance result and evidence item. Point-in-time and trend views read from governed historical state, and data latency and source quality are shown rather than assumed. The dashboards answer the questions a governance committee actually asks: which safety-critical controls are ineffective, degraded or not assured; which pathways carry multiple degraded or non-independent controls; where controls are required but not deployed or not verified; what is overdue; which controls fail repeatedly across contexts; where health rests on weak, stale or incomplete evidence; which temporary controls are about to expire; and what changed since the last governance period. Governance packs export as documents: the bowtie and performance standard report, the critical-control register, the control-owner assurance statement, the corridor assurance report, and the degraded-control and overdue report.
Two packages in this programme were deliberately not undertaken and are stated here rather than implied. There is no enterprise integration API in 1.5: ErgoBow does not yet synchronise with an external asset, maintenance, incident, document or competency system, so where the model references those records it references them as identifiers you enter or import rather than as a live connection. And the enterprise security, deployment and pilot-hardening package has not been run. ErgoBow remains local-first, holding its records inside the project file, which is the supported boundary for this release. The domain model was built so that neither of those is a rewrite when it comes, but neither is in your hands today.
The platform has always split its tools across two pages - canonical methods under their published names on Method Tools, ErgoSphere's own work under the Ergo prefix on ErgoTools - but the rule behind the split had never been written, so it was applied by instinct and had drifted. It is now stated: a tool implementing one canonical published method belongs on Method Tools, named as the literature names it, because building a better instrument for a published method is not invention. The Ergo prefix is earned only where ErgoSphere supplies the method itself, composes two or more canonical methods into something with its own identity, or extends a method with constructs its source does not define. Where a tool implements a canonical method only partially it keeps the prefix and the description says so.
Applying that rule created a column that should always have existed. Method Tools gains a Systems shelf, and the canonical systems methods move onto it: ErgoFRAM becomes FRAM, ErgoCWA becomes CWA, ErgoLink becomes Link Analysis, ErgoStrata becomes AcciMap, and SNA - which was already unprefixed and sitting awkwardly among the ErgoTools - joins them, alongside the new EAST. ErgoACT deliberately keeps its prefix: it is a simplification of ACT-R rather than the ACT-R architecture, and the prefix signals that honestly. These are full renames rather than the display-only relabel used for SCTA in an earlier release - route, registry key, localisation key, page folder, namespace, icon, splash key, guide filename and persisted identity all move together - and SCTA's own rename is completed properly here too.
The ten key performance area assessment introduced in 1.4 as ErgoCompass is renamed ErgoRadar, which better describes what the radial picture actually shows and frees the ErgoCompass name for the method-selection tool above. The rename is name and icon only: the KPA set, the acceptability bands, the radial logic, the evidence model and the report content are all unchanged, and the Stroeve, Kirwan and Everdij citation stands. Both now sit together in a new Direction group under ErgoTools, which also gives ErgoRadar the left-hand navigation and File menu entries it had been missing since it shipped.
"Tool Library & Guides" in the Help ribbon took you to the Library index, from which you then found your way back to the tool you were already in. It is now "Tool Guide", and it opens the guide for the tool you have open, directly. On the handful of tools with no guide the button is hidden rather than shown as a dead control. No tool page was edited to achieve it: the button lives in two shared controls, and the resolution from tool to guide is now a single shared catalogue.
Triggered by FRAM being absent from the Library Guides page, every surface that enumerates the tool set by grouping was audited against the catalogue pages: the tiles, the registry, the Tools menu, the left-hand navigation, both guide manifests, the Library buckets and the cross-tool link picker. Two real gaps were found and closed - six method tools missing from the Library's method buckets, and a tool missing from the cross-tool link catalogue - and both surfaces are now guarded by tests, so a tool that ships without appearing everywhere it should will fail the build rather than quietly go missing. The stale System column count on the ErgoTools page, which had not been updated since two tools shipped, is fixed, and the ErgoCompass method catalogue no longer recommends methods it cannot open.
If ErgoSphere is to hold critical control and bowtie records for a safety duty holder, the file stops being a drawing and becomes evidence, and the first question an auditor asks is whether it can be altered without anyone knowing. Until now it could: a default project is an unencrypted archive, and it could be unzipped, edited, re-zipped and reopened with no complaint. Every save now computes an integrity digest over the content and the control files together, and every load verifies it and reports a mismatch through the load report you already see. The compliance sign-off hashes that existed but were only ever checked on demand inside the compliance pages are now verified at load as well. For encrypted projects, each entry is now bound to its own name, closing a gap where entries could be deleted, reordered or spliced between projects under the same key without detection. A project saved before this release still opens, with an honest note that it carries no integrity data rather than a false alarm.
ErgoBow had grown its own revision, approval and audit chain, duplicating what the compliance subsystem already provided. Two chains means two answers to "is this approved", which is worse than either one alone. They are now one. A schema migration folds ErgoBow's governance store into the platform chain, merges its electronic sign-offs into their compliance twins, and collapses its eleven states onto the platform's seven without destroying the original value, so nothing is lost in translation. Frozen governance packs are verified and never re-signed. ErgoBow is rewired onto the platform service and its retired types are deleted rather than left as a second path. The control library keeps its own simpler lifecycle deliberately - it is versioned reference data, not a project document - but its approvals now write into the one compliance ledger, so a canonical control approval appears alongside every other governance approval.
A governed document at a published revision opened fully editable. You could work in it, the session list updated as you went, and only when you saved did a dialog appear to tell you the document was read-only - and then tell you to "create a working revision" without saying where. An editor must never present as editable and then discard. The mutation gate is now consulted when a document opens and again whenever lock or governance state changes, at a shared seam rather than in forty-five editors. A blocked document opens with its editing surfaces disabled and an information bar naming the actual reason, carrying a "Create working revision" button that does the thing rather than describing it. Session and home lists now show which documents are locked before you open them.
The save guard sat on each tool's own save. It was not the only way a document reached disk. Editors work on the same object the service store holds, so an edit is in the store the moment it is made, and a File > Save serialised the whole store without consulting the gate at all. That path is closed. A governance-blocked document is now written from its governed snapshot rather than from memory, and substituted rather than omitted - omitting it would delete the document from the archive, which is a worse outcome than the one being prevented.
That substitution decided whether a governed document had been modified by re-serialising it and comparing the text against the stored snapshot. It is the wrong question, and it fails in a way that gets worse over time: any change to the serialiser, and any new field on a model, makes every previously published document compare as modified permanently - and the substitution is not harmless when it fires, because it overwrites the in-memory document with the older snapshot and strips the newer fields on every save. A diagnostic on a real project found one hundred and ninety-four differences on a document nobody had opened, every one of them a formatting or schema artefact and not one of them a change to any recorded value. The comparison now runs against a baseline taken when the document was loaded, and answers the question that was always meant: did the user change this document. Untouched documents are no longer named, no longer rewritten, and the notification you see is scoped to what you actually lost.
Placing a document under the governance chain is now a pattern rather than a bespoke build, with a shared "place under governance" idiom, published-revision stamping into report front matter, and audit event capture at the same save seam every tool already has. It is proven on HTA and SCTA alongside ErgoBow, and the shape is what every future tool copies. The mutation gate and event capture reached the remaining tool editors in the same pass, so a blocked mutation tells you what happened everywhere, not only in the three tools that had governance switched on.
Locks are advisory and are only taken when you open a session in an editor, so there are ordinary situations where nobody holds one - working from the project pages, or renaming and deleting from a list. In those cases a save rebuilt every entry from memory, and on a shared file that meant whoever saved last silently destroyed everything the other person had saved since. A save that would overwrite a file changed since you loaded it now stops and offers you the choice: save a copy, overwrite deliberately, or cancel. It uses the same integrity digest introduced above to tell whether the file really changed, falling back to the modified timestamp on older files.
The test for "somebody else is in this file" was the existence of a lock sidecar next to it - which you create yourself simply by opening one editor. So a solo user spent the rest of their session on the shared-file save path, and that path cannot express a deletion: a deleted session, assessment or link came back on the next load. The test now asks whether another instance genuinely holds a lock right now. Both save paths and every merge rule are otherwise untouched.
Lock ownership is identified by user, machine and process, so after a crash the leftover locks carried a dead process's identity and your own documents read as somebody else's - and for the five minutes it takes a lock to go stale you were offered read-only access to your own work. A restarted instance now reclaims locks that are unambiguously its own user's, on its own machine, from a process that is no longer running. Separately, editors now release the document lock when they close rather than holding it until the project does, so a colleague no longer sees documents you stopped looking at half an hour ago as being in active use. Seventeen single-page editors adopt this; the multi-page and pop-out tools follow.
A project written by a newer build carries entries an older build knows nothing about. The partial save preserved them; the full save dropped them. Worse, an unrecognised entry was reported as a load error, which disabled regular save and pushed you towards Save As - and Save As is a full save, so the application's own recovery advice was what destroyed the data. Unrecognised entries are now held and re-emitted through every save path, and they are no longer treated as a load failure.
The keyboard and menu paths had drifted apart in both directions: Ctrl+S no longer reached the save path although the File menu still worked, and Ctrl+Shift+S reached Save As even where the menu item was correctly disabled under a read-only licence. Both are fixed together, at the shared cause rather than symptom by symptom.
Reports began as PDF, gained an in-app preview, then moved to Word. The Word builders were developed into the detailed reports we wanted and the preview was left where it stood, so the thing you looked at before exporting increasingly was not the thing you exported. Across roughly forty tools the preview now carries every section, table, chart and diagram that the tool's Word builder emits inside its findings. The visual rule is absolute: if the Word document embeds a chart, graph or diagram, the preview shows it, and "the numbers are already in a table" is not an exemption. The Word skeleton around the findings - the abstract, introduction, method and conclusion you fill in yourself - deliberately stays out, because those are placeholders for you to complete, not report content.
The bowtie diagram itself now appears in the ErgoBow preview, rendered on demand exactly as the Word export renders it. ErgoLoop shows its causal loop diagram, ErgoEvac its floor plan, AcciMap its factors by level, Link Analysis its element-type breakdown and top links, ErgoTrace its findings by type, ErgoNeuro its workload timeline, and ErgoLens its per-capture RULA and REBA derivation graphs. ErgoSense previously reported only the active recording, so a multi-take session looked like a single capture; it now carries the full sessions table and a per-session breakdown. ErgoDesign gains an executive summary, compliance bands and a standards breakdown, and now quotes the same compliance percentage as its Word report rather than a second figure computed a different way.
An ErgoGlare indoor assessment previewed as an outdoor report with every section empty, because the preview had no indoor arm at all. The whole indoor body is new: scene overview, instant glare metrics with the DGP band chart, illuminance, render evidence, annual daylight metrics and mitigation priorities, with the fisheye and falsecolour render artefacts pulled straight through. Outdoor gains the three sections it was short of. ErgoACT went from one chart to five, adding the model-flow diagram, the module timeline of the median run, the completion-time histogram and the parameter sweep, plus the baseline comparison and the generated productions appendix. MAC, RAPP and ART had minimal preview renderers that ended with "see the full report for detail"; all three now carry that detail.
Where the fix was to copy the Word builder's recommendation text into the preview, it was shared instead, so the two surfaces are now structurally incapable of recommending different things - copying would have drifted at the first edit. A standing test counts the visuals each side emits, per tool, and fails the build when a Word builder gains a chart the preview never got, which is precisely the failure that had accumulated across some twenty tools. Three exemptions are recorded with their reasons rather than left implied. Nine tools that shipped a full Word report had no preview content at all and fell through to a cover page; all nine now have one, along with the proper tool name, reference and methodology card that a generic fallback had been leaving blank.
Bringing NASA-TLX to parity exposed two genuine errors. An unweighted session previewed as 0.0 and "Low Workload" while its Word report scored it correctly, because the preview read only the weighted score where the Word builder falls back to the unweighted one. And the headline badge banded at 30 and 60 while the interpretation chart on the same page banded at 40, 60 and 80, so the badge could contradict the chart beside it. Both are corrected, and the bands are now 40, 60 and 80 everywhere. One divergence was found and deliberately left alone: SUS grades against two different published curves on one page, and retuning one method's thresholds to match another's silently is exactly what we do not do - it is flagged for a decision rather than quietly resolved.
The tools built before the two-row header stepped through their stages with a Continue button on the page, so you could only see the stage you were on and could only reach an earlier one by walking backwards. The tools built since put their stages in the header tab row, which shows every step up front and lets you jump straight to the one you want. RULA, REBA, NIOSH, Snook, SUS, Nielsen and NASA-TLX now do the same. Every input stage is always reachable - no stage is ever gated on having visited the one before it, because visitation is not data and a visitation gate simply rebuilds the wizard the tabs exist to remove. The results stage is enabled when the document is genuinely computable. Two deliberate keeps: the Next button stays on every input stage, retiring only Previous, because a row of eight equal-weight tabs gives a first-time assessor no cue that RULA is scored in order - the tabs serve the returning analyst fixing one posture, the footer walks the newcomer. And the step title stays in the header, carrying the full method wording, which is what pays for the short tab labels. The redundant "Step 4 of 8" counter is gone.
Updates install in the background, and the only way to confirm one had actually landed was to go looking at the About page, which is no signal at all for anyone who does not know to look. The first launch after a version change now shows a single welcome card naming the version you are now running, the version you came from, up to three lines of what changed, and a link to these release notes. It appears once per version and is never shown on a first-ever install, because someone evaluating the product for the first time should not be greeted by a welcome-back card. There is no "do not show again" control, deliberately: the card is already once per version, so suppressing it would switch off the only signal you get.
The tools built this cycle rendered correctly on Classic but broke badly on Charlie and the dark themes: white cards with white text, black text on black cards, white tables with black text. Every symptom traced to one defect. Where a page builds part of its interface in code rather than markup, the themed colour it looked up came back fixed at whatever theme the application started in, and never updated when you switched, so one half of a card came from the correct theme and the other half from the startup theme. The shared helper that exists to prevent this was corrected and the tools that had written their own way around it now go through it, with a rebuild on theme change so imperative content refreshes rather than waiting to be revisited. It is now a standing rule with a test behind it.
Freely clickable stage tabs expose things a one-way wizard hides, and two were found and fixed rather than left for you to find. RULA and REBA could show a previous result after an input changed; both now adopt the recalculation idiom Snook already used. And NIOSH always resumed onto its results page, because the test it used to decide where to land was true after the first navigation, making the remembered step dead code - the tabs mitigate it anyway, but the resume is corrected.
SCTA was reclassified from ErgoSCTA in an earlier release by changing display text, and two surfaces were missed: the first-run splash and the in-app guide both still said ErgoSCTA, months later, to every new user of the tool. A correctly named guide already existed and was wired to nothing. Both are corrected and the orphaned duplicate is retired.
A storage-layer defect meant a schema migration could run, have its output silently discarded by a partial save, and still have the file stamped as migrated - so the next load skipped the migration on the grounds that the file claimed to be current, and it never ran again. It surfaced in the governance fold but was never specific to it: any migration whose output lands in a service you do not hold a lock on hit the same thing. Fixed at the bundle level so migrations converge, rather than only at the stamp.
This release renames tools down to their stored identity and consolidates two governance chains into one, so compatibility was the constraint the work was built around rather than a check at the end. Existing projects open cleanly. Renamed tools carry read-side aliases so a file written under ErgoFRAM, ErgoCWA, ErgoLink, ErgoStrata or ErgoSCTA still loads; nothing is rewritten in place, and a loaded project simply takes the new form on its next normal save. The governance fold runs as a versioned migration that preserves the original state value rather than translating it away, and verifies frozen governance packs without ever re-signing them. A project saved before this release carries no integrity digest and is reported as exactly that - no integrity data available - rather than as a tamper warning. Aliases here exist because data is already in the wild, which is the only reason we keep them.
A small 1.4.1 maintenance update shipped between 1.4 and this release without release notes of its own. Its changes are included here, so this page is the complete record of everything that has changed since version 1.4.0.0.
All nine new tools ship as Preview. They are complete and usable, their methods are implemented faithfully and their calculations are tested, but they are new: their interfaces and outputs may change in response to what practitioners tell us. Three deliberate method positions are worth knowing before you rely on them. SWAT derives its interval scale by rank mapping rather than full conjoint scaling, which is a disclosed simplification. FRAM produces no numeric resonance score, because no canonical calculation for one exists. SAGAT does not run the trial - the simulation freeze happens in your simulator, and the tool builds the query bank beforehand and does the scoring afterwards. Each is stated in the tool and in its Library Guide, not only here.