What's new
Notable changes to Oho — new capabilities, changes to how something behaves, and anything that needs you to do something. Newest first.
This page starts in September 2026
Oho has been changing for longer than this list has existed. Anything that shipped before September 2026 — including the platform upgrade itself — is described in the pages it affects rather than here.
Coming in the next release
These are built and staged for the next release rather than live everywhere today. Where a change needs you to turn something on, the linked page says how.
Compliance and review
- Registry downgrades can wait for a person before they reach your other systems. Move a credential type into Confirm registry downgrades and a registry withdrawing that credential is held for a decision rather than published straight through. An unanswered hold auto-confirms after a window you set (default 72 hours). → Review & Decide
- A WA Working With Children Check the register says is valid no longer shows as expired. The WA register doesn't publish expiry dates, so a stale typed-in date used to override a positive register answer. That date is now cleared and the credential asks for the real one in Review & Decide. → How monitoring works
- Applicants and workers can go back into a submitted check, correct it, and resubmit. Because the amendment can unsettle a verdict already reached, the change goes to Review & Decide rather than silently replacing it. → Review & Decide
- Pausing scanning on a credential that is expired, revoked or superseded reopens the requirement it was covering. A paused problem no longer reads as compliance. → Compliance rules
- Compliance-check evaluation can run as a background job, and synchronous runs are bounded. → Evaluating compliance
- Equivalence sets can be picked directly in a screening package. → Compliance rules
Checks and registers
- ImmiCard is now checked against the Home Affairs VEVO service instead of being taken on trust. → Right to work
- An NDIS Worker Screening clearance held under a different name is flagged for review. → NDIS Worker Screening
- A credential the register can't find no longer stays verified forever, and a renewed Queensland Blue Card shows the problem straight away. → How monitoring works
- A new "USI Transcript" check asks a person to list the nationally recognised training on their USI transcript and saves every line to their qualifications.
Data and imports
- Your import sheet can record where a worker works, not just where they live. Six new Workers columns capture the work address, which is what a state-scoped compliance rule reads. → Spreadsheet template reference
- A date of birth on the Workers sheet no longer overwrites one already in Oho — the difference goes to Review & Decide instead. → Review & Decide
- Emptying a cell and deleting its column now mean different things on the Workers sheet. → Spreadsheet template reference
- iChris syncs continue from where the last successful sync got to, on their own. → Connect iChris
- Workers created or updated via the REST API are linked to their organisation automatically. Workers that already exist are not backfilled. → API Reference: Workers
Access
- Manager users can be restricted to only the workers they manage. → Roles and access
- Recruit / Continuous access can be managed by group membership. → Roles and access
Things to watch for
These change numbers you may be reporting on, or behaviour you may be relying on.
- Workers whose checks haven't come back are now counted as At Risk on the Compliance Overview, not as Compliant. Your At Risk number will go up. → Understand your Compliance Overview
- The organisation notification email is now a list, and it always gets the mail — expect your shared inbox to receive more than before. → Set up notifications
- The first expiry alert now says "expiring soon" — the separate "expiring" stage is retired. → How monitoring works
- A credential status our connectors don't recognise now reads as "Pending" instead of "Active".
- Suspended and failed credentials now appear in the Compliance Overview's attention queue.
- A qualification still being earned no longer counts as a pass.
- An exemption the registry has invalidated no longer excuses a worker from holding the credential it replaced. → Exemptions
- The "Try New User Experience" appearance setting has been removed — everyone is on the new UI.
For developers
API changes are listed here too, but the contract detail lives with the endpoint.
- OAuth2
client_credentialsauthentication is available for machine-to-machine integrations. → Authenticate with OAuth2 - The credentials API's documented shape for
ownerson a read now matches what it has always sent. → API Reference: Credentials - The PID connection test answers with a real status code, and needs settings permission.
- Deleting a credential equivalence set is refused while a screening package still references it. → Evaluating compliance
- Decisions a person records now publish
credential.verified, not justcredential.updated. → Webhook payload reference /openapi/timeline/v1is deprecated and answers410 Goneafter 30 September 2027. → Audit trail