What’s new in
GrantCore.ai — 23 September 2026
One night of releases, all live. Agency administrators: see the
Agency Administrator Guide; applicants: see the Team User
Guide §11–12.
- Notice of Intent reopen — an officer can withdraw
an NoI decision; it returns to pending, the workflow goes back to
NOI_SUBMITTED, the applicant is told (Funder → Application
Intake)
- Funding Inbox — every open call across every
agency, read against the applicant’s profile: why you qualify,
what you are missing (with fix links), what to
confirm; fit score with reasons; save / dismiss / start; new calls
flagged (Applicant → Funding Inbox)
- Capability permissions — 14 capabilities × 8 agency
roles; platform defaults equal the former role lists; agency
grants/revokes per role; Admin immutable; every change audited
(Funder → Agency Settings → Roles & capabilities)
- Organization master — one registry record per
organization (legal identity, BN9, verification, hierarchy, aliases);
applicant profiles auto-link; agency directory with a duplicates queue
and merge-never-delete (Funder → Organizations)
- Tenant router — an agency’s custom domain resolves
to its tenant on every request: registration mode (open / invite /
closed) enforced, applicants enrolled, tenant-first inbox, branded
sign-in (platform)
- Invitation-only calls — visibility public /
invite-only / internal; per-email invitations with notification,
accept-on-apply, revoke; hidden from catalogue, search, matching agent
and uninvited inboxes (Funder → Opportunities → Details)
- Electronic voting in panels — members vote fund /
not fund / defer / abstain with score, comment and conflict-of-interest;
private while open; quorum; chair closes and tallies; outcome becomes
the recommendation (Reviewer portal; Funder → Panels & Decisions
→ Open)
- Organization workspace (institution administrator)
— agency appointment or domain-matched claim; members (admin / signatory
/ research office / viewer); cross-agency applications and awards;
institutional sign-off request → approve/decline; competition-level
submission gate (Applicant → My Organization; application workspace;
Funder → Organizations)
- Communication templates — per-agency, versioned
templates for 8 lifecycle moments with merge fields, conditionals,
EN/FR, preview and platform-default fallback; live for acknowledgement,
NoI outcomes and invitations (Funder → Communication
Templates)
- Multi-site projects — participating organizations
from the registry (lead / co-applicant / collaborating institution /
partner / site / subcontractor) with site, budget share, contact;
sign-off per organization; partner workspaces see the project
(Application workspace → Quick Actions)
- Parallel workflow branches — the engine executes
fork/join (guarded branch spawn, per-branch event routing, join
all/any); designer validates fork/join designs (Workflow engine +
designer)
- Agent ledger coverage — every agent run (authoring
and advisory agents included) is now a ledger entry with its action
class, evidence and approval requirement (Funder → AI Agents /
competitions ledger)
- AI data policy per agency — Protected B (or
“never”) means the agency’s data is processed by the private AI only;
agents fail closed with AI_POLICY_NO_CLOUD rather than using a cloud
provider; classification recorded in the ledger (Funder → Agency
Settings → AI & data policy)
- Seven-language UI for the new applicant pages —
Funding Inbox and My Organization translated (EN/FR/DE/ES/IT/PT/AR, 97
keys, parity audit 100%); the eligibility engine’s reasons, gaps and fix
hints are bilingual EN/FR and follow the UI language; Command Centre
banner points to ready-to-apply calls; team user guide section 11 added
(Applicant portal)
- Applicant consent per tenant — agencies declare
scopes and a privacy notice; when required, applicants consent
(versioned) before applying; renewal on notice change; withdrawal;
directory shows consent state (Agency Settings → Applicant consent;
Funding Inbox)
- Event outbox + agency webhooks — every business
event (submitted, acknowledged, NoI decided, decision recorded, voting
closed, competition transition, sign-off decided, award created) is
recorded in an outbox and pushed to the agency’s subscribed URLs with an
HMAC-SHA256 signature, retries with backoff, dead-letter and replay;
secret shown once, rotatable; audited (Agency Settings → Webhooks
& event outbox)
- Unified rule DSL — one rule language for
eligibility, form conditions and workflow guards (20 operators
incl. has, between, matches); eligibility rules may be typed (catalogue)
or expressions with EN/FR messages and fix links; catalogue, validation,
dry-run (sample profile or a real applicant) and simulation
across the competition’s applicants (who would be blocked, by
which rule) from the competition page; invalid rules refused on save
(Competitions → Eligibility rules)
- Agency API keys / service principals — keys for
ERP, case and warehouse systems to call the funder API: one agency role
per key (never admin), capability allowlist, expiry, per-minute limit,
rotation, revocation; pinned to the issuing agency; no
applicant/auth/billing surface; service accounts cannot log in; every
call and denial audited (Agency Settings → API access)
- Executive plane — one consolidated overview per
agency and for the whole Government of Canada (intake pipeline,
decisions and success rate, agreements and disbursements incl. overdue
schedules and s.34 gaps, service-standard attainment, agent automation,
oversight risk, governance) on the Impact & Results page; department
comparison table in the government scope (Executive — Impact &
Results)
- OpenID Connect federation per agency —
institutional sign-in rebuilt on the installed library (the old code
could not run), authorization code + PKCE + state + nonce, per-agency
provider in Agency Settings (secret masked), login-page buttons,
allowed-domain and verified-email guards, provisioning toggle, agency
membership on sign-in; verified end to end against a mock identity
provider — the platform owner (Agency Settings → Sign-in; login
page)
- Agency Administrator Guide — sign-in (OIDC), roles,
consent, AI policy, rules, webhooks, API keys, executive view; published
at /grants/admin-guide.html and linked from Help
(docs/FUNDER-ADMIN-GUIDE.md)
- App shell in seven languages — navigation, section
headings, portal names, top bar and account menu follow the UI language
(EN/FR/DE/ES/IT/PT/AR) on every page; previously English everywhere
(shell.js (v8))
- Hardening — webhooks refuse
private/loopback/link-local targets and embedded credentials in
production and never follow redirects (SSRF); SSO issuers must be public
https hosts in production; unit tests for the guard (outbox.service,
agency settings)
- Eligibility rule history — every change to a
competition’s rules is versioned with author, time and note; restore as
a new version (nothing deleted); History modal on the competition page
(Competitions → Eligibility rules → History)
- Eligibility explanations in seven languages — the
Funding Inbox’s why-you-qualify / what-you-are-missing texts and
applicant-class descriptions now exist in DE/ES/IT/PT/AR as well as
EN/FR (parity-tested); expression rules accept message_
(Funding Inbox; rules test/simulate)
- Typed integration adapters on the webhook rails —
per-webhook payload templates ({{placeholders}} over the event envelope,
raw values preserved, custom content type) so an ERP payment request or
a case-system ticket arrives in the receiver’s own schema; new payment
events on s.34 certification, s.33 requisition and ERP batch sync
(Agency Settings → Webhooks → Template)
- Consent renewal notices — when an agency changes
its privacy notice or scopes, applicants with stale consent get one
in-app notification (never email) and the change is audited (Agency
Settings → Applicant consent)
- Applicant consents strip + language menu — the
Funding Inbox lists every consent given (agency, date, current / renewal
needed / withdrawn) with Withdraw; a language menu
(EN/FR/DE/ES/IT/PT/AR) now sits in the top bar of every page
(Funding Inbox; app shell)
- Consent events for integrations — consent.granted
and consent.withdrawn flow through the outbox/webhooks so a department’s
privacy register can follow applicant consent (Webhooks
catalogue)
- Executive overview by fiscal year — the FY box on
the Impact & Results page now also drives the executive tiles
(?fiscal_year=2025-2026) for the agency and the government view
(Executive page)
- Incident SLA reminders: daily three times, then
weekly — the ‘SLA breach’ e-mail for an unacknowledged ticket
no longer arrives every day forever ; the ticket still has to be
acknowledged or resolved by a human (incident-sla-worker)
- Workflow guards on the unified grammar — the
designer validates transition guards with the same rule validator
(server + dialog) and shows the operator list (Workflows)
- Executive page in French — the executive and impact
page (headings, tiles, tables, descriptions, buttons) renders in French
when the UI language is French, for Official Languages compliance of the
executive layer; other languages fall back to English on this page
(Executive page)