Tutela — school transport, safeguarded

Release notes

What's new in Tutela

What we've shipped recently, in plain language. Written for the people who use the platform rather than the people who build it.

[1.69.0] - 2026-09-23

Added — see who has read each policy, and export it for an audit

Every policy now has a Who has read it view, alongside the existing "Who reads it". One decides who is obliged; the new one shows what came back.

  • Still to read, grouped by how late — more than a month overdue, more than a week, overdue, and not yet due. Each person shows why they are on the list: their role, their depot, a school they drive for, or their own name.
  • Signed, with the date and what they agreed to. The title and version shown are the ones as they stood when that person signed, not today's, because that is what they read.
  • Withdrawn — people who were asked and then moved out of the group it was assigned to. If they move back, it comes back.

Somebody who has left still appears under Signed, marked as no longer with you. An acknowledgement is a record of something that happened, and it does not stop being true when somebody moves on — that is usually the one you will be asked about.

Each person also has a full record of everything they have ever acknowledged, reached from their qualifications page. It keeps withdrawn policies and older versions, so a document you have since replaced still shows the acknowledgement somebody gave it at the time.

The version history for a policy now shows how many people acknowledged each version, so "show me that this driver accepted the policy as it stood in March" is one screen.

Added — an audit pack you can hand over

Export for an audit produces a PDF for one version: its details, its full approval trail, and everyone who acknowledged that exact version. You can export superseded versions too, and each one shows how many acknowledged it.

There are two buttons, and the difference matters:

  • Download the pack gives the acknowledgements — who, when, and what they agreed to. It does not open anybody's stored signature. This is what an audit usually asks for.
  • Download with signatures also includes the signatures themselves. These are stored encrypted, so this opens all of them at once, and it is recorded against your name.

Both need the same permission. The second is not a lower bar — it is a deliberate choice, so that seeing the register can never quietly become a way of opening every signature in it. The file name and the pack's own cover say which one you have, so the two cannot be confused in a shared folder.

Signing in the console means typing your full name; signing in the driver app means drawing it. The pack labels each, rather than presenting a typed name as though it were a drawn signature.

A pack holds up to 500 acknowledgements. Above that it is refused rather than shortened, so you can never hand over a pack that stopped early without saying so.

Added — outstanding policies on the compliance dashboard

A tile showing how many acknowledgements are still outstanding, and how many are overdue. It is amber rather than red: an unread policy is chased, never enforced, and it does not stop anybody driving.

Fixed — the parent portal's bottom menu now lines up on a phone

Two of the five buttons along the bottom of the parent portal have labels long enough to run onto a second line, and those two sat higher than the other three. The row now lines up whatever the labels say.

Fixed — the example consent form in the demo now has questions on it

In the demonstration system, the example consent form sent to a family opened with nothing to answer — just a title and a Send button. It now carries the questions it should always have had, and the example of a form already returned shows each answer beside the question it answers.

This affects the demonstration data only. Nothing about a real operator's own forms has changed.

[1.68.0] - 2026-09-22

Added — feedback and complaints

Parents, schools and members of the public can now send you feedback, a compliment or a complaint, and you can handle it all in one place.

  • Your own form, ready to go. Every bus company now has a starter feedback form, so parents and schools can reach you straight away. Change the questions to suit you. It includes a new Contact Details question.
  • Parents and schools don't type their details. When they send feedback from the family or school portal, their name, email and phone come from their account and are shown back to them.
  • A public link and QR code for everyone else. Press Share on the feedback page to turn on the public link, copy it, or download a QR code to print for your buses. People using it are asked for their name and an email or phone number. If you want to accept anonymous feedback, make the Contact Details question optional.
  • Everyone gets a reference number straight away, by email as well if they left an address.
  • Handle it properly. Assign each one to someone, add notes, and reply. Replies are emailed, and parents and schools also see them in their portal. Close it with what you found and did. Notes can't be edited or deleted, so the record of how a complaint was handled stays complete. Each one appears on your task list as soon as it arrives, with complaints marked high priority, and moves to whoever you give it to.

Fixed — demo bus stops are now on real streets

In the demonstration environment, some sample bus stops were placed in the river. Every demo stop now sits on a real residential street, and routes no longer cross the water.

Added — assign a policy to a depot, or to a school's drivers

Until now a policy could go to a role, or to one named person. You can now also send it to:

A depot — everyone based at that yard, and anyone moved there later. Good for anything about the place rather than the job: the yard's traffic plan, where the keys live, who to ring after hours.

A school's drivers — everyone currently driving a route for that school, relief drivers included. The list follows your roster, so a driver put on the route next term is asked without anybody remembering, and a driver taken off it stops being chased.

Both work the way role assignments already did: you maintain the rule once instead of maintaining a list forever, and nobody is missed because a hire, a transfer or a route change never reached a spreadsheet. Each picker shows how many people it currently comes to, and that's the same count used when the policy is actually handed out.

Added — you're told who a depot assignment leaves out

A depot assignment skips anybody who has no depot recorded, and the screen now says how many people that is before you save.

This is worth knowing, because cover lists elsewhere in Tutela do the opposite on purpose: a driver with no depot shows up in every depot's list there, so a picker is never empty on the morning somebody rings in sick.

Here the sensible default is the other way round. If assigning to one yard quietly included everybody whose depot was never filled in, you'd believe you had narrowed to that yard and actually have sent it to most of your staff — and once people have been asked, you can't un-ask them. So they're left out, and now you can see it rather than having to work it out.

Changed — people stop being chased for a group they've left

If a policy was assigned by a rule — a role, a depot or a school — and somebody stops being in that group, anything they still owe is withdrawn and the job closes. They stop being chased for a yard they've left. Chase people for things that no longer apply to them and they learn to ignore the chasing, which is the thing worth protecting.

Anything already signed stays exactly where it is. That somebody accepted a policy in 2026 is still true after they move depot, and it stays on their record and in anything you produce for an auditor. Leaving a group never removes evidence.

If they rejoin the group, what was withdrawn comes back with them and a fresh window to read it — so a transfer entered by mistake and corrected the same day costs nothing.

Somebody you assigned individually is never dropped this way. You chose them, so only you un-choose them.

Fixed — the afternoon-absence button on busy stops

On a stop with a lot of children, the driver's button for marking a child off the afternoon bus showed as a small tag instead of a full-size button. It now matches the buttons beside it.

Added — your Policies screen now tells you where every policy stands

The Policies list used to show what you'd written. It now shows what's happened since.

Each policy has two new columns:

Who it is for — the roles and the number of named people it's currently assigned to. If it says Nobody yet, the policy is live and no one has been asked to read it. That's usually a job somebody started and didn't finish, and it was previously invisible.

Acknowledgements — how many people have confirmed they've read the wording that's live right now, how many still owe you a confirmation, and how many are past their due date.

There are two filters above the list. Narrow to policies or procedures, or show only the documents somebody still has to read, or only those past a due date. The filters search everything you have, not just the page you're looking at.

Why it isn't "12 of 15". We show the counts separately on purpose. A fraction's second number changes every time somebody joins or leaves, so a week after a staff change it would look as though confirmations had gone missing when nothing had. Two straight counts can't mislead that way.

One thing worth repeating: publishing a new version of a policy resets the signed count to zero, and that's correct. People agreed to the wording they were actually shown, so the confirmations you already hold stay attached to that wording rather than quietly carrying over to new text nobody has read.

As before, a policy somebody hasn't read yet is chased — it never stops anyone driving.

Fixed — the document store was impossible to find

Your company's own paperwork — accreditation, insurance, licences — has always had a screen. It just had no link to it anywhere, so the only way in was to already know the web address. If you'd concluded the feature didn't exist, that's why.

It's now in the menu, next to Policies. Nothing about the screen itself has changed and nothing stored there was ever lost — it simply couldn't be reached by clicking.

Fixed — deleting a stored document now asks first

Deleting a document from that store used to happen the instant you clicked, with no confirmation and no way back. It now asks you to confirm, and tells you what will be removed before you say yes.

Changed — corrected the guidance on attaching files to a bus

The buses guide said compliance documents could be attached to a bus. That wasn't quite right, and the guide now explains what actually happens: evidence for a bus attaches to that bus's compliance item, so the certificate sits next to the expiry date it proves. There's also a new guide covering the company document store.

Added — send a photo of your card with a renewal

When you send the office a renewed card or certificate from the driver app, you can now attach a photo of it or a PDF. Take the photo with the tablet or phone camera. The office sees it next to the details you sent, so they no longer have to ask you for the card itself.

A card you send in still doesn't count until the office has checked it. The photo helps them check it, but it doesn't replace the check.

Added — outstanding policies now show on your staff compliance screen

Staff qualifications has a new Documents column: the policies and procedures each person has been assigned and hasn't confirmed reading yet. Amber while they're still within their window, red once something is past its date, and it filters with the rest of the screen under Needs attention and Coming up.

Each person's own qualifications page shows the same thing in full, listing what they owe and when it's due.

An unread policy still never stops anybody driving or being rostered. That hasn't changed and isn't going to: a driver held at the depot over paperwork is a run that doesn't happen and children left waiting at a stop. Outstanding documents raise a task for the person and show on these screens, and that's the whole of it. It's kept visibly separate from the "cleared to work with children" answer for the same reason — that question has one meaning and shouldn't start collecting others.

Changed — everywhere that counts outstanding policies now counts the same way

The figure on the compliance screen, the one on a person's own page, and the list the person sees themselves are now all reading one definition rather than three. Three separate counts eventually disagree, and the trouble with that is every one of them looks perfectly reasonable on its own.

Something drops off all of them together when the person reads it, when you withdraw the policy, when you publish a new version, or when they leave. Stopping an assignment is the one thing that deliberately doesn't clear it — stopping means nobody new is asked, and the people already asked still owe it.

Fixed — two ways an old policy task could hang around

Withdrawing a policy left the task on people's lists, and closing it didn't help: it came back the next time the overnight check ran. And publishing a new version left the previous version's task open alongside the new one, so a single policy showed up twice with the same title and doing the live one left the other sitting there.

Both are cleared now, on every screen that lists them, including the driver app.

Added — policies now need approving before they go live

Writing a policy and signing it off are two different jobs, and they're now two different steps. When a draft is ready, send it for approval; someone with approval rights reads it and either approves it or sends it back with a reason. Only an approved policy can be published.

This is the question an audit actually asks. Not "is there a policy" — everyone has one — but "who approved this version, and when". That now has an answer on the policy itself.

While a policy is waiting for approval it can't be edited, so whoever is reading it is reading something that isn't moving underneath them. The person who sent it can withdraw it at any time, which simply makes it a draft again and doesn't record anyone as having refused it.

If it's sent back, the reason is shown to the author on the screen where they fix it. That reason stays in the record even after the policy is eventually approved, so the history shows the rounds it went through rather than only the final outcome.

Approving needs a different permission from writing. Compliance officers and operations managers have it, and an operations manager can approve a policy without being able to write one — which is what makes it a real second opinion.

If you're the only administrator, you can approve your own policy. A rule you can't satisfy would just mean policies never get published. But the record says so: the version is marked as self-approved with no second person, you're told that before you approve rather than after, and it's visible to anyone reviewing your policies later.

Policies published before this change keep their wording and their history exactly as they were. They're shown as published before approvals were recorded, which is simply the truth — marking them approved would have put a name against a decision nobody made.

Changed — writing a new policy takes you straight to the editor

Creating a policy used to drop you on the policy's summary page, where the only thing worth doing was press a button to start writing. Now it takes you straight into the editor with your empty draft open.

Starting a new version of an existing policy already worked this way. Creating one didn't, for no good reason.

The summary page is unchanged and still does everything else — version history, publishing, withdrawing, who reads it, and editing the details — and it's still where you land when you open a policy from the list.

Added — you can now say who has to read a policy

Writing a policy and publishing it told nobody. You could get the wording right, put it live, and it would sit there — there was no way to say who it actually applied to.

There is now. On any policy, Who reads it lets you assign it to a role or to one person.

Assigning to a role is usually what you want: it covers everyone in that role today and anyone who joins it later. Assign a policy to your drivers and the next driver you take on is asked to read it without anybody having to remember.

A few things we were deliberate about:

  • You see who it means before you commit. The role picker shows the number of people each role currently comes to, so you're not finding out afterwards that you sent something to ninety people.
  • People are asked straight away, not overnight. And if it reaches nobody yet, we tell you which harmless reason applies — nothing published yet, or nobody in that role at the moment — rather than saying "done" over a zero.
  • A deadline is counted per person, from the day the policy lands on them. Someone who joins in three months gets the same reading window everyone else got, instead of arriving already overdue.
  • Stopping doesn't excuse anybody. Stop an assignment and nobody new is asked, but people already asked keep their task and their record. A change to your settings shouldn't quietly let a dozen people off a policy they were told to read.
  • You can only remove an assignment that has given out nothing — one you've just mistyped. Once people have been asked, it can be stopped but not removed, so the record of who was asked and why stays intact.

People whose accounts are suspended are left out, because asking somebody who can't sign in to read a policy creates a job nobody can ever finish.

As before, an outstanding policy never stops anyone driving. It raises a task and shows on your compliance views, and that's on purpose.

Deciding who reads a policy is a separate permission from writing one, so the person who maintains your wording and the person who decides who's obliged to read it don't have to be the same person.

Changed — your trading name now leads on work orders and invoices

Your company settings hold two names: the trading name everyone knows you by, and an optional legal (registered) name for when the entity you're registered as isn't the name you trade under.

The trading name has always been what Tutela shows you day to day. But on a work order sent to a repairer, if you'd filled in a registered name it appeared instead of your trading name — so the repairer saw an entity they may never have dealt with, with nothing connecting it to you.

Now both appear, trading name first, on the two documents where the distinction matters: the work order you send to a repairer, and your tax invoice. If you trade under your registered name, or you've left that field blank, you'll see one name as before — never the same name twice.

Nothing else changes. Families, drivers and your own staff still see your trading name only. The two settings fields now explain which is used where, and if you write your own policies there are separate placeholders for the two names.

Added — link risks to reports, depots, drivers, routes and stops

A risk in your risk register can now be linked to the things it's about: a hazard, near miss or incident report, a depot, a driver, a route or a stop. Link from the risk's own page, or from a report's new Linked risks section. Links stay with a risk when you revise it.

The register has a filter bar, so you can find every risk linked to one depot, driver, route or stop, or narrow it by category or residual risk level. From a report, Show in the risk register lists the risks it's linked to.

Unlinking keeps a note of who linked and unlinked it. You only see links to records you're allowed to see.

Added — delete a service record entered by mistake

A service record entered twice, or against the wrong bus, can now be deleted from its own page. You're asked why, and the record comes off the bus's history and servicing schedule along with the odometer reading it recorded. Tutela keeps a note of who deleted it and why.

Added — "Maintenance" service type

Service records and service programmes can now be filed under Maintenance, alongside Service A, B and C, Scheduled, Unscheduled and Repair.

Improved — travelling with a friend: you'll hear back, and you can change your mind

  • You're told the outcome. When the bus company arranges, declines or withdraws a trip you asked for, you get an email, and the trip stays on your Travelling together page with how it stands.
  • The other family is asked by email when you name their child, and they can change their answer until the bus company decides.
  • Either family can withdraw a trip from the portal, up until the child is on the bus.
  • Requests for a day with no bus are turned away straight away, rather than being accepted and never happening. The same goes for a trip you've already asked for, and a day your child is marked absent.

Fixed — trip changes during a run

  • A trip can no longer be withdrawn once the child is on the bus, so nobody can be left on board with nothing on the driver's screen to mark them off.
  • A trip arranged or withdrawn while the bus is out now reaches the driver's screen within about a minute.

Added — Messages between the office and your drivers

The office and your drivers can now message each other inside Tutela. Everything sent is kept, with who sent it and when, so "was the driver told?" has an answer on the screen rather than in somebody's memory of a phone call.

  • In the office, Messages sits next to Tasks. Choose a driver and start writing. You have one conversation with each driver, so everything said stays together.
  • On the bus app, drivers get a Messages screen where they can read what the office sent and reply.
  • Drivers can't read or send messages while they're driving a run. The app stays on the run, and messages wait until it's finished. When a driver is on a run, the office sees that on the conversation, with a reminder to phone if it matters for the road.
  • Messages can't be edited or deleted once sent. If something was wrong, send another message that says so.
  • Only the people in a conversation can read it. Messages are stored encrypted.
  • A number beside Messages shows how many conversations have something new.

Added — import the risk register you already have

If your risk register lives in a spreadsheet, you can now bring it into Tutela instead of typing it in. Download the template from the risk register, or use your own spreadsheet with the same headings. Tutela shows you every risk it will add, with its levels worked out, before anything is saved. If any line has a problem, nothing is imported until it's fixed, and importing the same file twice doesn't add anything the second time.

Added — service history on each bus's page

A bus's page now shows its latest services, with a button to add one for that bus and a link to its full service history. The card that used to be titled "Service record" is now "Status and odometer", which is what it shows.

Added — "Only for this operator" on discount codes

A discount code can now be limited to one operator, so nobody else can use it even if the code is passed on. Codes are still never applied automatically — apply one from the operator's subscription, or give them the code to enter on their Billing page.

Improved — Messages keep up by themselves, and drivers can message the office

  • Conversations update as you go. With a conversation open, new messages appear within a few seconds without reloading, and anything you're halfway through typing stays put. The number beside Messages updates by itself too.
  • Drivers can message the office. A Message the office button in the bus app starts a conversation that anyone in the office can read and answer, so drivers don't need to know who's working today. These appear in the office's Messages list as Office inbox.
  • An email if a message is waiting. If a message sits unread for about fifteen minutes, you'll get one email saying so. For privacy the email never includes the message or who it's from. Drivers aren't emailed while they're driving; it arrives after the run.

Added — Message groups, and messages between drivers

  • Groups. Set up message groups for the whole company, for each depot, or for drivers you choose. Company and depot groups keep themselves up to date as drivers join, leave or change depot. Anyone in the office with Messages can read and take part in any group. Find them under Messages → Groups.
  • Messages between drivers, if you want them. You can let drivers message each other one-to-one. It's off until you turn it on. When it's on, drivers are told their operator can read these conversations, company administrators can review them under Messages → Driver conversations, and every review is recorded on the conversation.

Added — open an inspection, print it, and export inspections for an audit

Click the time of any check on the Inspections screen to open it. You'll see every question the driver was asked and the answer they gave, plus their notes and photos, the defects a failed item raised, the odometer reading, and the driver's signature. Questions appear as they were worded on the day, even if you've edited the checklist since. Your buses' own extra questions are included too.

Download PDF on an inspection gives you a printable copy for your records.

Export for an audit builds one PDF of every inspection for the buses and dates you choose: a contents page first, then each inspection on its own page. Checks that were later replaced are included and marked, because an audit is asking what happened. If your selection is too large for a single file, you're told how many inspections it found, so you can export it in parts.

Added — Make a task from a message

  • Turn a message into a task. In a conversation, choose Make a task under a message. The task form starts with a short line from the message for you to reword. The task links back to the conversation, and only people in that conversation can open it. The message itself isn't copied into the task or its email.

Added — Report a fault that's already been reported

  • No more duplicate faults from the daily check. When a driver answers Fail and the bus already has faults waiting to be fixed, they can pick the one they've found instead of reporting it again. The fault gets a note saying it was seen again, and the inspection shows which fault it was reported against. It never makes a fault less serious: a critical item failed against a minor fault makes that fault critical and takes the bus off the road.

Added — Parents can message their child's driver

  • Off until you turn it on. A company administrator can let parents message the driver of their child's trips under Messages → Groups.
  • For today's trips. From the family portal, a parent can message the driver of a trip their child is on today. They see the driver's first name only. Once the day's trips are done, the conversation closes.
  • Safe for the driver. During a run a parent's message only appears while the bus is stopped at a stop, never while it's moving, and the driver replies after the run. Parents are told this, and told to phone you for anything urgent.
  • The office can read them. Anyone in the office with Messages can read these conversations under Messages → Parent messages. Each time someone opens one it's recorded, and parents can see that in their "Who has looked" report.

Fixed — The driver's screen now keeps up with changes from the office

  • If you add a child to a run, or take one off, while it's under way, the driver's list now updates by itself. It waits until the driver isn't mid-tap.
  • If you mark a child absent during a run, the driver sees a banner naming them.

Changed — Routes can't be reshaped while a bus is driving them

  • While a run is under way you can't change the route's stops, times, directions, turns, road path or direction. The route page tells you, and you can make the change once the run is finished. This stops a change in the office reaching a bus that's out on the road, including taking children off its list.
  • Renaming a route, and adding or removing children, still work at any time.

[1.67.2] - 2026-09-21

Fixed — a checklist rule could change just from opening it

If you opened a checklist question's display rule and the comparison it used wasn't one the editor offers for that kind of question, the editor quietly swapped it for a different one — and saved that over your rule the next time anything on the page changed. You hadn't edited it; opening it was enough.

The worst version of that swap is "only show this when the answer is blank", which can hide a question that has to be answered. The editor now keeps whatever the rule actually says, marks it as not available for that question type, and leaves it alone unless you change it yourself.

We checked every checklist rule currently in use. Two were in the affected state, both on a pre-start check, and in both cases the behaviour on the bus was already what it should be — no check was being skipped.

[1.67.1] - 2026-09-19

Internal improvements only.

[1.67.0] - 2026-09-18

Fixed — a child riding home with a friend didn't appear on the bus at the school

When you arranged for a child to ride a service they're not normally on, the platform worked out where they got on by itself — and on an afternoon trip it got it wrong. It picked the start of the route rather than the school, so the driver had nobody to mark on when the child climbed aboard at the gate. The child only appeared on the card for the stop where they got off, which is where drivers ended up marking them both on and off.

Morning trips were wrong in the same way and further out: the journey was recorded running in the wrong direction, and never touched the school at all.

The platform now finds the school properly and works out the journey from whether it's a morning or an afternoon trip. If a route has no stop marked as a school, it says so and asks you to fix the route, instead of quietly picking the wrong stop.

Arrangements already recorded the old way are being corrected, including the record of where the child actually got on. Nothing is overwritten — the original stays, with the correction recorded alongside it and the reason for it.

Added — you now choose where an ad-hoc traveller gets on and off

Recording one of these arrangements used to take both ends of the journey from the child they were travelling with, with nothing to look at and nothing to change. That's now a second page: it proposes the journey, shows it to you, and lets you move either end before you record it.

So you can finally record the trips that don't follow the usual pattern — getting off at a grandparent's stop, or joining partway along the run.

It also means the suggestion is something you've seen and agreed to, rather than something worked out behind the screen. That's the part that went wrong above.

Fixed — ad-hoc travellers were missing from most of the driver's run sheet

Someone riding a service they're not normally on only showed up on the stop the driver was actually working. Looking ahead down the run, they weren't there — including a passenger the driver had picked up without a set-down stop recorded, who is meant to stay on every remaining stop until they're marked off. They now appear throughout, and at depots and turnarounds too, so there's always somewhere to mark them off.

Their ON and OFF buttons also now follow the trip the same way a child's do: the one you'd expect at that stop leads, and the other is still there but smaller. Before, both were offered equally at every stop, which made it easy to record the wrong one — and a stray tap can't be edited away afterwards.

[1.66.0] - 2026-09-18

Added — the dispatch run page shows anyone travelling who isn't on the roster

When you arrange for a child to ride a bus they don't normally ride, that arrangement now appears on the run itself — under Also on this run, with who they are, where they board, and whether it's been approved.

Until now it only showed on the driver's screen on the day. If you'd arranged something for tomorrow, there was no way to confirm from the office that it had reached the bus, which is exactly when you'd want to check.

Someone the driver picked up at a stop, without anyone approving it beforehand, is marked as such — that's a thing for the office to follow up rather than a normal booking.

They're counted separately from Expected, which stays the run's own roster, so the reconciliation figures are unchanged.

Added — tap the expected count on a route preview to see who they are

On the driver app's route preview, the number of children expected at a stop is now a link. Tapping it lists them by name for that day.

It's names only — no photos, no addresses, no contact details. You'll only see it for a day you're actually on that route, the same rule that decides whether you see the number at all.

Opening the list is recorded, the same as anywhere else a child's record is viewed. The count itself isn't: a number isn't a record of a child, and a name is. The page tells you so when you open it.

The list needs signal. The count works without one, because it's stored on your phone with the rest of the page, but the names are fetched when you ask for them so the look can be recorded properly.

[1.65.0] - 2026-09-17

Fixed — a driver's date of birth can now be recorded

The driver app shows a driver their name and date of birth, and tells them the office maintains both because they have to match their licence and their working with children card. That was true of the name, and not of the date of birth — there was no field for it anywhere, so a driver asking the office was asking for something nobody could do.

It's now on the person's record in the console, under Driver details, for anyone who can manage your team. Drivers still can't change it themselves, which is the point: it has to match the documents that authorise them, not something they've typed.

It's optional, stored encrypted, and used to tell two drivers of the same name apart when you check a licence or a card against the issuing register.

Improved — school closures now take buses off the road for you

When a pupil-free day or closure is recorded for a school, runs already prepared for that day are stood down automatically, and put back automatically if the closure is removed. Runs a driver has already started are never changed; you're told about those instead. Previously you were asked to cancel the runs yourself.

Where more than one bus company serves a school, a closure entered by one company now waits for the school to confirm it before it affects anyone's buses. The school is emailed and can confirm or reject it from its portal. If nobody at the school can sign in, another company serving the school can confirm it.

Added — choose when compliance reminders start, and how often

Settings → Reminder schedules lets you set, for each kind of compliance record, how far ahead of the due date reminders start and how often they repeat.

They aren't all the same job. An annual inspection can usually be booked months early, so a reminder at 90 days is something you can act on. A registration you can't pay until a fortnight before doesn't need one — and a reminder nobody can act on is the reason people stop reading them.

The screen shows exactly which days you'd be reminded on, so you can check a schedule reads the way you meant before saving it. Anything you haven't changed keeps the standard schedule, and there's a way back to it for anything you have.

Two things you can't change. Reminders can't be switched off — you can start them later or space them out, and you'll always get one the day before something is due. And once a record is overdue it's chased every day until it's completed.

Nothing changes until you open the screen: every kind of record keeps the schedule it has today until you choose otherwise.

Added — files and notes on a compliance item

Each compliance item — a registration, an inspection, an insurance policy — now keeps its own paperwork and its own running record.

Attach as many files as the item needs. An inspection produces a certificate and a report; a rectification produces the invoice, the photo and the reissued certificate. Previously there was nowhere to put the second one. Every upload is scanned, stored privately, and only ever downloaded through that page.

Notes are now a thread, not a box. Each entry records who wrote it and when, so the chase history — who rang, what they said, when the booking moved — lives on the item instead of in somebody's inbox.

Notes can't be edited or deleted, on purpose. The worth of "still waiting on the certificate" is that it was written before anybody knew how it turned out. If a note is wrong, add another saying so.

The old single Notes box on the edit form is gone, because it was replaced by whoever edited the item next. Anything already written in it has been kept as the first note in the thread.

Removing an attachment deletes the file, and the record that it was attached — by whom, and when — stays on the item.

Changed — your own qualification types have their own screen, and can be edited

Settings → Your own qualification types is now its own page, rather than sitting at the bottom of the qualification requirements grid. The two are different jobs: one sets what a role must hold, the other sets what exists to be held.

You can now rename a type, or change how long it runs for. Previously neither could be changed once added, so a typo in the name was permanent unless you stopped offering the type and added a replacement.

Two things worth knowing before you rename one:

  • Renaming changes what existing records are called, not just new ones — someone whose record was created months ago will show the new name. That's what you want when correcting a typo. If you're trying to turn it into a different qualification, add a new type and stop offering the old one instead. The screen tells you how many records a type is on before you rename it.
  • Changing the term only affects new records. An expiry date already recorded came off somebody's certificate, and it is never recalculated.

Changed — the qualification requirements grid is easier to read

The grid no longer scrolls sideways on a normal screen. Column headings wrap over two lines instead of forcing each column as wide as the qualification's name, and the spacing is tighter.

On a phone, where the grid is still too wide to fit, the Role column now stays in place while the rest scrolls — so a tick is always attributable to the role beside it.

Fixed — your own qualification types can now actually be required of a role

If you added a qualification type of your own and then required it of a role, the tick box accepted it, the page said it had saved, and the requirement was not kept. Reloading showed it unticked again, which looked like a mis-click.

It means any requirement you set this way was not being enforced. Someone could be rostered without the qualification you believed you were requiring. Built-in qualifications were never affected — only your own types.

This is fixed. Please check any of your own types you meant to require of a role, and tick them again — a requirement that was lost this way did not leave a record behind, so it cannot be restored for you.

Added — a Relief Driver role

You can now give someone a Relief Driver role instead of, or as well as, Driver.

It does exactly what Driver does — same app, same run screen, same buttons. A relief driver is not a restricted driver, and nothing on the bus behaves differently. The one thing that can differ is what you require of them, because qualification requirements are set per role and that was the only way to ask different things of two groups of drivers.

It starts out requiring exactly what Driver requires, so if you don't need the distinction you can ignore it and nothing changes.

Somebody can hold both roles — the regular driver who also covers relief is normal. When they do, they must meet every requirement from both. Giving someone an extra role never takes a requirement away from them.

Relief Driver appears on the requirements grid as its own row, and in the role list when you add or edit a person.

Changed — the PTD is now recorded as three qualifications, not one

A Passenger Transport Driver authorisation isn't a single document. The authorisation, the medical and the police clearance are obtained separately and run out at different times, so the qualification register now carries three entries instead of one: PTD - Authorisation, PTD - Medical and PTD - Police Clearance.

Kept as one record, the register could only ever be right about whichever part lasted longest. A driver whose authorisation runs for another three years, with a medical that lapsed months ago, would have read as fully current — and telling you otherwise is the whole job of the register.

Existing records have been moved across automatically. Anything previously recorded as a Passenger Transport Endorsement is now the authorisation, with its dates, number and attached document unchanged. If a role required it, it still does. Nothing needs re-entering — though you'll want to add the medical and the police clearance as separate records when you next have them to hand.

The medical needs an expiry date, for the same reason a CPR record does: it's a separate record precisely because it runs on its own cycle, and one with no date sits there looking permanent. The police clearance doesn't ask for one — a police certificate doesn't expire on its face, and we'd rather leave the field blank than have you invent a date. If you re-check on a fixed cycle, put that date in and it will be chased like any other.

A police clearance is not a Working With Children Check, and Tutela won't treat it as one. It doesn't satisfy a child-protection requirement and it doesn't clear a driver to carry children — the two screen for different things against different registers.

Added — a billing page for company administrators

Company administrators now have a Billing page showing what the subscription costs and how that figure is worked out: the number of buses charged, the price per bus, and the total. Pricing is per bus per month, and prices exclude GST, which is added on the invoice.

  • Which buses are charged. Every bus in the fleet is charged except a retired one — a bus that is out of service, in the workshop or grounded is still part of the fleet. The page lists the fleet in two columns, charged and not charged, so the figure can be checked at a glance.
  • Invoices can be viewed from the same page.
  • Discount codes can be entered there.
  • Cancelling takes effect at the end of the current billing period.

If an account ever falls behind on payment, the page says plainly what is paused and what is not. Runs are never affected — drivers keep their run screens whatever the state of the account.

Only company administrators can see billing. Drivers, office staff, parents and schools never see it.

Added — see everyone's qualifications in one place, and record regular rechecks

Compliance → Staff qualifications shows every staff member and driver with the qualifications their roles require, and flags anything missing, expired, awaiting verification or running out soon. A requirement with nothing recorded against it now shows up here, where before nothing reminded you about it. The compliance dashboard also counts staff qualifications that need attention.

Recheck periods. You can now set how often each qualification is checked again against the issuing register, for example looking up a Working With Children Check every 90 days. Qualifications that are due or overdue for a recheck are flagged.

Recording a recheck. On a person's qualifications page, Record recheck saves when you checked, how, and the result. The page shows the date it was last checked and when the next check is due, and a Check history lists every check so you can show they are being done regularly. Checks can't be edited or removed. If a recheck finds a qualification is no longer valid, it is archived straight away.

Added — record your vendors' licences, and get reminded before they run out

A vendor's page now has a Licences section for the licences, authorisations and insurance they need for the work they do on your fleet, such as a motor vehicle repairer licence, an authorised inspection station or public liability insurance. Add the expiry date and the certificate, and record when and how you checked the licence was valid.

From 60 days before a licence expires you'll get a task to ask the vendor for the renewal, with more as the date approaches. Add the renewed licence as a new record and the reminders stop. The old one stays on file as the record of what they held before.

The vendor list shows each vendor's licence status, and the compliance dashboard lists vendor licences that have expired or run out in the next 30 days.

When you record a service, compliance item or work order against a vendor whose licence has expired, the vendor is marked in the list and you'll see a warning after saving. The record still saves.

Changed — hours worked and claims waiting for payment are now on one screen

Operations → Hours & claims payable lists everything payroll owes for a period in one place: each driver's hours worked and every approved claim that hasn't been paid yet. Use the tabs to show everything, just hours worked, or just claims — and Download CSV gives you exactly what you're looking at, ready to attach to a pay run as the record of what was paid.

  • Approved extra hours are listed once, as their own line, so nothing is counted twice.
  • A claim approved late for an earlier week still appears, so it isn't missed.
  • You can tick claims and mark them as paid from the same screen. Download the CSV first — paid claims drop off the list.
  • Actual time is now shown in hours (for example 5.5 h) rather than hours and minutes, to match the other figures — including on drivers' own hours screen.
  • The download's columns have changed. If you import it into payroll, check your import still lines up.

Fixed — old and corrected qualifications no longer show as a problem in the driver app

On a driver's qualifications screen, a card that has been renewed now shows as Replaced, and a record the office corrected shows as Archived. Neither raises the "needs attention" warning any more. A card that has expired or been withdrawn with nothing in its place is still flagged as before.

[1.64.0] - 2026-09-16

Changed — "Revoke" is now "Archive" on the qualification register

Taking a qualification off someone's register is you saying this isn't the record I rely on — it was entered by mistake, the wrong document went on it, or the person no longer holds it. It is not the issuing body cancelling their card, which only the issuer can do. The wording said the second, so the button, the confirmation and the label on the record now all say Archive, and the label is a neutral grey rather than a red alert.

Nothing about how it behaves has changed. Archiving still takes effect immediately, still cannot be undone, and if it was the person's only current child-protection check they still stop being cleared the moment you do it.

Archived records are now hidden until you ask for them. When someone has any, Show all appears above the table to bring them back and Show active puts them away again, with a note of how many are hidden. This is only about what the table shows you — the band at the top of the page still takes every record into account, so what it tells you about whether that person is cleared never depends on which view you are in.

Fixed — a lapsed item could still show as current

On the compliance items list and on an item's own page, the current / due soon / overdue label was worked out when the item was last saved, and never worked out again. An item entered a long way ahead therefore went on showing as current right through its due date — and the list sorted on that same label, so a lapsed item could sit near the bottom among the ones that were genuinely fine.

The label is now worked out fresh every time you open the screen, from the due date itself. Nothing needs re-saving and no dates changed: items that had quietly lapsed will simply start showing as overdue, and sort to the top where they belong.

Two things were not affected, and were correct throughout: the compliance dashboard counts, and the reminders and tasks raised as an item approaches its date. Those have always been worked out from the due date, so nothing went unnotified.

Added — see what is about to lapse across the whole fleet

The fleet list now shows two more columns: Rego due and Inspection due. Each carries the date, grey while there is time, amber inside the last month, and red once it has passed.

Until now those dates lived on each bus's own compliance screen, so finding out whether anything was about to lapse meant opening every bus in turn.

Two things worth knowing about how they read:

  • Registration is still the number plate. Rego due is when that registration runs out.
  • A dash means nothing has been recorded yet — it does not mean the bus is in order. A bus you have never entered a registration for stays blank rather than looking reassuring.

The colours are worked out fresh every time you open the list, from the dates themselves, so a bus that lapses overnight is red the next morning without anyone touching it.

Added — record a registration renewal from the bus itself

Registration, insurance and inspection dates are kept as items against each bus. Until now you could see them on a bus but not add one there — recording a renewal meant leaving the vehicle, going to the full compliance list, starting a new item and finding that same bus again in a dropdown.

There is now an Add compliance item button on a bus's overview and on its compliance screen, and the bus you came from is already filled in. Save, and you land back on the bus rather than somewhere else. A bus with nothing recorded yet offers the same thing from the empty table instead of simply saying there is nothing there.

Renewing stays what it always was: open the item and change the due date. Anything the old date had raised for your attention clears itself once the date moves.

Changed — archived qualifications are tucked out of the way

On a team member's qualifications, a record you take off the register is now called archived rather than "revoked". Taking a record off — because it was entered by mistake, corrected to the right type, or no longer applies — was never the same as the issuing body cancelling someone's card, and the old word made it read that way.

Archived records are now hidden until you ask for them. When a person has any, Show all appears above their qualifications and brings them back, and Show active hides them again. Whether the person is cleared to work with children is worked out from every record either way.

[1.63.0] - 2026-09-16

Added — work orders now tell the workshop about the bus

A work order used to carry the fleet number, the registration and the make and model. A repairer ordering a part needs the VIN, and one judging whether a service is due needs to know how far the bus has run since the last one. Both were a phone call to the office.

Every work order — on screen and on the copy your repairer receives — now shows:

  • the VIN
  • the odometer now, with where that reading came from and when
  • the reading at the bus's last service, the date, and how far it has run since

These come from the bus's own record, so they are current rather than whatever was true the day the job was raised. If a reading has never been recorded, the work order says so plainly instead of leaving a gap. The reading you type against a particular job is still there, now labelled Odometer for this job so the two cannot be confused.

If a bus's current reading is lower than the reading at its last service, the work order says so rather than showing a distance. The two figures can't both be right — an odometer may have been replaced, or a reading entered against the wrong bus — and a workshop needs to know that before it decides whether a service is due.

Added — tag a driver onto a work order

The workshop often wants to ask the person who noticed the fault what it sounded like, or to arrange who is dropping the bus off. You can now choose a driver to contact when you raise a work order, or from Edit.

Their name and mobile are printed on the work order the repairer receives — that is the point of it, but it does mean their mobile goes to a business outside your organisation. The field says so before you choose anybody, it starts as Nobody, and a work order with nobody tagged names no driver at all. Only people who hold the driver role are offered.

Added — more faults found after you've sent the work order

A driver often finds a second thing wrong on a bus that is already booked in. That fault belongs on the job you already have, not on a new one.

From the fault itself you can now choose Add this fault to a job already booked in, which puts it on the existing work order instead of starting a second job at the same workshop for the same visit. You can still add faults from the work order, as before.

Once a work order has been sent, anything added afterwards is marked Added after sending, and the work order tells you the copy your repairer is holding does not mention it. Send again emails them the current version with the new faults included, and saves a copy of exactly what went out. The reminder stays until you actually send it again — there is no way to dismiss it, because dismissing it would not change what the workshop is working from.

Only open work orders can take new faults. Adding a fault to a job still never marks that fault fixed, and finishing a job still never puts a grounded bus back on the road.

Added — add extra hours or a reimbursement for someone yourself

Not everything gets claimed in the bus app. A driver rings the depot, you agree an hour of bus-washing on the spot, or an invoice arrives by email for something a member of your team paid for out of their own pocket.

Driver claims now has Add extra hours and Add a reimbursement at the top of the page. Choose who it is for, the day, the hours or the amount, and what it was for — and it goes straight onto the pending-payment list, ready for the next pay run. You can attach a receipt if you have one, and a PDF is fine as well as a photo.

A few things worth knowing before you use it:

  • Adding a claim approves it. There is no second check by anyone else, so you need permission to approve claims in order to add one. The form says so before you save, and the button reads "Add and approve".
  • You cannot add one for yourself, for the same reason you cannot approve your own. Your name is not in the list — ask a colleague, or claim it in the bus app the usual way.
  • You can go as far back as you need. Drivers are limited to the last 90 days and told to talk to the office about anything older, so this is where that gets recorded.
  • It is for anyone on your team, not only drivers. Someone who never gets behind the wheel can still be owed money they spent on your behalf.
  • A claim you add is marked as added by the office wherever it appears — on the claim, in the payroll download, and on the person's own list in the bus app, where it says it was added for them and is already approved. That is how they spot one entered against the wrong name or the wrong day, and it is worth them checking: like every approved claim, it cannot be edited afterwards.

Fixed — on the afternoon run, children who never got on no longer follow the driver home

Reported by an operator. On an afternoon run, a child who was marked neither onto the bus nor away at the school stayed on the driver's screen for the rest of the afternoon — and their street still looked like it had somebody waiting to be dropped off. Drivers were pulling up at empty kerbs to a tile asking them to mark a child off a bus that child had never boarded.

Now, when the bus leaves a stop where children get on, anyone still unmarked is recorded as not on the bus. There is no tick box and no extra question: pressing Departed is the answer. Those children move into the collapsed group at the bottom of the stop, and their own stop reads as finished, so the screen shows the driver the children who are actually there.

There was already a tick box offering to do this. It was not ticked by default, and in practice it was never ticked, so the problem it was built to solve carried on happening.

Until the bus has gone, nothing is decided — a child may still be walking up to it. It is only leaving the stop that settles it, which is why that is the moment it happens.

If somebody turns up after all, tap them on. Their tile keeps a working button in the collapsed group, at every stop for the rest of the run, and the later tap wins.

The Nobody here button is unchanged and still worth using: it says the same thing one tap earlier, while the driver is standing at the stop rather than pulling away from it.

None of this applies at a stop where children get off. "Still waiting" there means a child who is on the bus, and the app will never record one of those as though they were never aboard. The end-of-run sweep of the bus is unchanged and remains required.

Fixed — a one-off traveller is now treated as a passenger everywhere on the run

Someone riding a service they are not normally on was already included in the count a run has to balance before it can be finished. They were missing from several of the controls a driver uses to get there, and in three places that mattered a great deal:

  • In Manual Mode — the single-list view for days the planned route does not match the road — they did not appear at all, so there was no way to mark them on or off while the run still could not be completed without it. They are now in the list with everyone else.
  • "All off" marked every child off the bus and left them on it, having just told the driver the bus was clear. It now marks everybody off. "All on" and "Nobody here" likewise.
  • The check that holds a bus at a stop until everyone there is accounted for did not count them, so a bus could leave a stop where a one-off traveller was still waiting. It does now.

Three smaller things came with it. Their tile now shows whether you have already tapped them, so a reload no longer hides what you did. A tap the office's system refuses is put back and says why, instead of silently staying on screen. And a tap made by mistake can be undone, which previously was not possible for these passengers at all.

If you have been carrying one-off travellers, nothing you recorded was lost — the run's own count always included them. What changes is that the screen now agrees with it.

One privacy fix came with it. When a bus has been stationary for a few minutes the run screen blurs the children's names, so somebody standing at the door can't read them. A one-off traveller's name was not being blurred. It is now — their name is a child's name like any other.

Changed — a one-off traveller is always shown to the driver

The approval screen used to ask whether to show the arrangement to the driver. It no longer does, and the answer is always yes.

The question could not be honoured safely. The traveller is part of the count the run must balance, so a driver who could not see them could not mark them on or off — and the run would then refuse to finish, with nothing on screen to act on. A driver also has to know to let them onto the bus in the first place.

Approvals recorded before this change are unaffected; they were always shown to the driver in practice.

Added — record a one-off traveller the office was told about

When a parent rings to say somebody is riding a different bus, you can now write it down straight away instead of keeping it in your head until the driver gets there.

Ad-hoc travel has a new Record an arrangement button. Choose who is travelling — one of your students, or a visitor you hold no record for — and the child they are travelling with. The service and both stops come from that child's own arrangement, so there is no route to pick: the traveller gets on and off exactly where they do.

It accepts today, which the parent portal deliberately does not. When a family is told to call the office about a same-day trip, this is where that call now lands.

Two things to know:

  • Recording it approves it. There is no second step, and your name goes on the decision. For that reason the button is only available to people who can already decide a request — the same permission, not a new one. Everyone who could see ad-hoc travel before can still see all of it.
  • It asks how consent was obtained, and will not take a blank. Nobody has been asked through the app on these, so what you write is the whole record that somebody agreed. Write what you actually did, for example "rang mother 2:40pm, confirmed". The arrangement is then recorded as agreed by phone rather than through the app, which is the truthful version — it is never recorded as though no permission was needed.

Like every other arrangement, it cannot be edited afterwards. A change is a withdrawal and a new one.

Fixed — Ad-hoc travel is now in the menu

The ad-hoc travel screen had no menu entry. You could only reach it by following the link on a task, so if nothing was waiting for a decision there was no way in — and no sign the screen existed. It is now under People, next to Walking home.

Fixed — requests to add a school are picked up faster

When you ask for a school to be added to the shared register, that request now shows as outstanding work on our side until it is dealt with, rather than depending on a single notification being noticed.

This matters because a school that is not yet on the register will block a passenger list that names it. Nothing changes in how you raise the request.

Added — a minimum hours per shift agreed with one driver

Minimum hours per shift has been a single figure for the whole company. If you have agreed a different minimum with an individual driver, you can now record it against them.

Open the driver under People and you'll find Driver hours on their record. Leave it blank — as it will be for almost everybody — and they use the company minimum, which the box shows you. Fill it in and that driver uses theirs.

Two things worth knowing before you use it:

  • A driver's own figure replaces the company one; it isn't whichever is larger. So if you set 3 hours for someone and later raise the company minimum to 4, that driver stays on 3 and their runs count for less than everybody else's. Their record warns you whenever their figure is below the company one, and clearing the box puts them straight back on the company minimum.
  • A change applies from today onward, exactly like the company setting. Days already worked keep the minimum that was in force at the time, so hours a driver has already been shown never change underneath them — and that holds for clearing the box as well as changing the number.

The company-wide setting is unchanged and still covers everyone who has no figure of their own.

Fixed — two controls on the driver screen were off the edge of a cab tablet

On the tablet sizes fitted in a bus, two things on the run screen had moved off the visible area. Both are fixed.

"I have swept the bus" at the last stop. The end-of-run sweep confirmation — the one a run cannot be completed without — had been pushed below the bottom of the screen, and because that screen does not scroll, there was no way to reach it by scrolling either. A driver finishing a run could find the step they were being asked for simply not there.

To make room, the "unexpected passenger" panel now steps aside at the last stop of a run, and only there. It is unchanged at every other stop. At the final stop everyone is getting off, so it is the one place that panel has nothing to do — and it was competing for space with the sweep check, which is not something we will let anything compete with.

Dismissing a hazard warning. The road-hazard warning that appears as a bus approaches a known hazard sat slightly too low, so its Dismiss button was just off the bottom edge and would not respond when pressed. The warning now sits fully on screen and dismisses normally.

Both were introduced in the previous release and neither could happen on a phone or a desktop — they only appeared at the specific screen size of an in-cab tablet, which is where it matters most. We have added checks at that exact size so neither can return unnoticed.

Changed — Coverage keeps your place, and can fill a whole day at once

Working through a term of cover gaps is now much quicker.

  • Filters apply straight away and are remembered. Changing Look ahead updates the list immediately. The next time you open Coverage it shows the view you last used.
  • Show only what needs filling. A new Show option, Needs filling, hides every run that already has a driver, so a term with a handful of gaps is a short list.
  • You come back to where you were. After assigning a relief driver you return to the coverage list at the day you just covered, with that day marked so you can see the change took.
  • Cover a whole day in one go. When a driver is off for the day and both their morning and afternoon runs need cover, Cover all puts one relief driver on both. It only offers drivers who can take every run. If anything has changed since you opened the page, nothing is saved, so you are never left with half a day covered.
  • If a driver you pick can no longer take a run, the screen now tells you why instead of silently reloading.

Changed — compliance reminders now say who they are about

  • A task about a qualification running out, or one recorded but not yet checked, now names the staff member it concerns — so you can see at a glance whose licence is due without opening each one. Previously, several people coming up for renewal in the same month produced a screen of identical-looking rows.
  • Only staff appear this way, and only against their own qualifications. Tasks never carry a student's name.

Added — you can attach a document to a qualification you already recorded

If you recorded a qualification without the certificate to hand, you can add it later. Open the person's qualifications and use Attach evidence on the record.

Until now the only way to get a document onto an existing record was to revoke the qualification and record it again — which left a revoked entry on a child-protection register for what was really just late paperwork, and anyone reading the register afterwards could not tell the difference.

A document can be added once and cannot be replaced or removed. The register is a record of what was checked and when, so swapping out the supporting document later would undermine the whole point of it. If the wrong file goes on, that is still a revoke and re-record. Nothing else about the qualification changes when you attach a document: the number, the dates and any verification stay exactly as they were.

Added — first aid and CPR are now named separately, and expiry dates fill themselves in

A first aid certificate and its CPR component expire on different cycles — CPR yearly, first aid every three years — so they have always needed to be two records. They now read as Provide First Aid and First Aid - CPR, instead of both showing as "First Aid".

When you choose a type and enter the issue date, the expiry date now fills in automatically: three years for Provide First Aid, one year for CPR. It is a suggestion, not a rule — type over it whenever the certificate says something different.

The child-protection checks deliberately do not fill themselves in, because the term varies by state. That field stays blank and asks.

Worth a look at your own records. Because both dates used to be typed by hand, a CPR certificate recorded under the first aid type would have been given a three-year date — and would show as current for two years after the CPR component actually lapsed. If you see two "First Aid" rows against one person, it is worth checking which is which.

Improved — a renewal now clearly replaces the record it renews

If you record a renewal before the old certificate expires, both records used to show as current, with nothing to say which one you were relying on. This was most confusing on a licence renewal, where the number is unchanged and the two rows looked identical.

The newest record of each type now shows as current and the earlier one as superseded. The older record stays on the register — it is part of the history, and it still counts toward whether someone is cleared. It simply no longer competes with the renewal for your attention.

Added — you can add qualification types of your own

If you track a qualification Tutela does not already list — an in-house induction level, a defensive driving course, a licence upgrade — you can now add it yourself. Go to your compliance settings, under Your own qualification types. Give it a name and, if it expires, how long it runs for. It can then be recorded against a person and required of a role exactly like the built-in ones.

Two things worth knowing:

  • Your own types do not clear anyone for contact with children. Only the built-in child-protection checks do that, whatever you name your own type. This is deliberate and cannot be changed from the settings screen.
  • You stop offering a type rather than deleting it. Records already using it keep their name and keep counting; it just stops appearing when recording something new. You can offer it again at any time.

The built-in types cannot be renamed, hidden or redefined. They mean the same thing for every operator, which is what makes a qualification register worth anything.

Added — fixing a qualification recorded under the wrong type

If you've recorded something under the wrong type — a CPR certificate entered as first aid is the usual one — there's now a Wrong type? button on the record.

Choose what it should have been and Tutela does what you'd otherwise do by hand: the original is revoked with the reason recorded, and a new record is created under the right type carrying the same dates, number and document across. You don't retype anything.

Both records stay on the register. The original isn't edited or removed — it shows as revoked, with "recorded under the wrong type" against it, so anyone reading the register later can see what happened and when. That's deliberate: a qualification record is evidence of what was checked, and quietly rewriting one would make the register worth less.

The new record needs verifying again. Whoever checked the original checked a different qualification, so the replacement starts as awaiting verification until someone confirms it against the issuing register.

You can only correct within the same family — first aid to CPR, a licence to an endorsement, one child-protection check to another. Anything else isn't a correction, it's a different qualification, and should be recorded on its own.

[1.62.1] - 2026-09-14

Fixed — the attendance register no longer warns you about a change that saved perfectly well

The attendance register was showing a red message saying your last change had not been saved, and it was showing it on every visit — whether or not anything had gone wrong. It appeared on the office register, the school register and the parent register alike.

Nothing was actually lost. Every mark ticked while that message was on screen was recorded normally. The message itself was the fault: it is meant to appear only in the one situation where it is true — when your sign-in has ended and a mark really has not been saved — and instead it was on screen from the moment the page opened.

We have fixed it, and it is worth saying why we treated it as urgent rather than cosmetic. That message exists so that on the rare occasion a mark genuinely does not save, nobody walks away believing a child has been marked as not travelling when they have not. A warning that is showing all the time stops being read, and then it is not there on the day it matters. It now appears only when something has actually been refused — and when it does, it still names what did not save and offers you the way back in.

The same underlying fault was hiding in two other places, so those are fixed too: the "show on map" buttons when setting up a route, and the address lookup on a charter request, could each appear in a browser that was unable to use them. Both now appear only when they will work.

[1.62.0] - 2026-09-14

Fixed — the single-run view now keeps itself up to date

When you open one run from the dispatch board, that screen now updates itself while you watch it. It didn't before: it showed you the run as it stood the moment you opened the page, and then stayed that way — while the dispatch board behind it carried on updating. So the two could disagree, and the more detailed screen was the one that was out of date.

That screen is the one you open when a parent rings to ask where the bus is, so this matters. It now moves as the run does: the bus on the map, the road it has driven, the stops changing as the bus reaches and leaves them, the arrival times filling in, and who is on board. The time it last updated is shown above the run.

If it can't reach us, it says so and dims the figures. That is the more important half. A screen that has quietly stopped updating looks exactly like a run where nothing is happening, and there is no way to tell the difference by looking. Now there is: if you see that message, what's on screen is the last thing we heard.

Once a run is over the screen settles, because a finished run has nothing further to report.

Two smaller things were fixed alongside it. A stop reached exactly on its scheduled minute was being tagged as off schedule by nothing; it now correctly shows as on time. And the stop markers on the map keep pace with the table beside them instead of staying as they were when the page opened.

Changed — the faults register filters as you go, and sorts by column

Bus and Status apply the moment you choose them. No button to find afterwards.

The search box now does two things. As you type, it narrows the rows already on screen straight away — the half that matters when somebody is on the phone and you need the fault now. Press Enter and it searches every fault instead, which is what reaches one that isn't on the page you are looking at.

Where that distinction could mislead, the screen says so: if typing finds nothing on a register that runs to more than one page, the message is "Nothing on this page matches what you typed — press Enter to search every fault". "Not on this page" and "not on the register" are very different answers, and only one of them means the fault was never raised.

The three boxes you type into — Search and the two dates — still wait for you to finish. Tabbing between them was reloading the page mid-way through filling the bar in, so they commit when you press Filter or Enter.

Number, Raised, Severity and Status are now clickable headings. Click to sort, click again to reverse. Sorting leaves your filters alone and your filters leave the sort alone, so you can narrow to one bus and then order that bus's faults however suits.

The register now opens on fault number, newest first. If you imported your history that is a more useful order than "most recently raised" — an imported fault carries the date it happened, so sorting by date threads years of old records back through the middle of the list.

Added — withdrawing a fault that was raised in error

Faults get raised by mistake. A thumb catches the wrong item on the pre-start check, a fault gets logged against the wrong bus, two people report the same thing twice.

Until now there was only one way to clear one: mark it fixed. That put a repair on the record that never happened — on the one document a regulator is most likely to read. And where the fault was serious enough to take the bus off the road, marking it fixed was the only way to get that bus back into service. The system was asking you to write something untrue in order to undo its own mistake.

Raised in error, on the fault's own page, now says what actually happened. Give the reason, and the fault comes off the register.

  • If the fault was why a bus was off the road, the bus goes back into service — unless another serious fault is still open on it, in which case it stays off, exactly as it would have if you had genuinely fixed this one.
  • Nothing is deleted. The description, the photo the driver took, the notes, anything attached — all of it stays, along with who withdrew it and why. A record that simply vanished would leave the next person unable to tell a fault that was withdrawn from a fault nobody ever reported, and those are very different things to find in a history.
  • Only open faults, and only the people who can clear a fault. Reporting a problem and deciding a reported problem never happened are different calls, and the second one can put a bus back on the road.
  • Changed your mind? Put it back. Choose It was a real fault and it returns to the register, re-grounding the bus if that is what it does. That undo is deliberately no harder than the withdrawal, because a real fault taken off the register is the more serious of the two mistakes.

Withdrawn faults are under Withdrawn, or All, and on the bus's own history.

Added — asking the driver to isolate the battery, only when it matters

A bus left over a long weekend or a term break with the isolator in comes back to a flat battery, and that is a run that does not leave the depot on the Monday.

You can now set, on each bus, how many days it can sit before its battery should be isolated. Add the new Vehicle isolation question to your fleet checklist once, and each bus is then asked it at the end of its last run of the day — but only when it is genuinely about to sit for longer than the number you set for that bus.

The number lives on the bus rather than on the checklist on purpose. A newer bus on a trickle charger will happily sit for a fortnight; an older one with a draw on it will not survive three days, and one number for the whole fleet would be wrong for half of it.

A few things worth knowing:

  • The count is idle days — the days the bus actually sits still. A Friday run whose bus is back on the road Monday is 2. Make that Monday a public holiday and it is 3. So a bus set to 2 is left alone on an ordinary weekend and asks before a long one.
  • Only the last run of the day asks. If a bus runs morning and afternoon, the driver is asked once, after the afternoon run. If it only runs in the morning, they are asked then.
  • Leave the field blank and the bus is never asked. That is how every bus starts, so nothing changes for your drivers until you set a number.
  • Set it in bulk from the Fleet screen — tick the buses, enter a number, apply.

The driver is told why they are being asked: "This bus is not scheduled to run again for 3 days." A question that turns up once a term reads as a glitch without it.

Added — a checklist answer that is recorded and nothing more

Checklist questions can now be marked Informational. The driver is asked the question as a normal Pass/Fail, the answer goes on the record, and nothing else happens — no fault raised, no workshop job booked, nobody sent to chase it.

This is what to use for the things you want captured but not actioned: "Bus swept for litter", "Keys returned to the office". Until now the only way to get those into the record was to mark them Minor, which put them on the fault list beside the cracked mirrors and made that list longer than anybody would read to the end of.

It is different from Not a check, which removes the question's Pass/Fail buttons entirely. Informational keeps the question and drops only the consequence. The driver's screen says which is which, so nobody hesitates over answering honestly.

Added — charters for excursions and camps

Schools can now book a bus and driver with you for an excursion, a carnival or a camp, and you can cover it from the same place you run everything else.

  • Schools ask from their portal: what the trip is for, how many are going, who to call on the day, and the pickup time for the trip out and, if there is one, the trip home. You're emailed when a request arrives.
  • Accept or decline, with a reason the school can see.
  • Offer each leg to several drivers at once — the first to accept gets it. Drivers who are off that day, or not cleared to drive, are shown but can't be picked, with the reason next to their name.
  • Choose the bus once a driver accepts. The school sees the bus number and the driver's first name when they're confirmed.
  • Both ends of every trip, with addresses. The school gives the place and its street address for the pickup and the drop-off, plus a note about where exactly to pull in — which gate, which car park — and the driver sees it on the day. Where address checking is switched on, the school can check the address and pick the right match, so you get a confirmed location rather than a line of prose.
  • Charters appear on the driver's roster — on Today's runs, in their week and on their month calendar, in their own colour, and tapping one opens the job.
  • On the day, the driver's app walks through it: the pre-start check where the bus needs one, a count of everyone on, a count of everyone off, and a walk through the bus to check nobody is left on board. The job can't be finished without the walk-through, and if the counts don't match, the driver has to say why — and you're told.

Added — work orders

Track the jobs your workshop has on each bus, from the moment something needs fixing to the moment it's done, and send them straight to your repairer.

  • Start a work order from what prompted it: a defect, an item a driver flagged on a pre-start check, a service that's coming due, or from scratch.
  • Send it to your repairer as a PDF by email, with a copy of exactly what was sent kept on the work order. Or download it and send it yourself.
  • Keep everything together: notes, quotes, invoices and photos, and costs entered excluding GST with the GST and total worked out for you.
  • Record the service in one click once the job's done, filled in from the work order.
  • Finishing a work order never puts a grounded bus back on the road by itself. That's still a separate, deliberate step on the defect.

Added — link a bus defect to a safety report

When a bus is involved in an incident and comes out of it needing a repair, the defect and the report can now be linked, so the investigation and the fix are tracked together.

  • Raise the defect straight from the report, with the bus already chosen, or link one that's already on the defect register.
  • See it from both sides: the report lists its defects and whether they're fixed, and each defect lists the reports it's linked to.
  • A reminder when you close: closing a report with a linked defect still open shows which ones, and whether the bus is off the road. You can still close the report.

Added — policy templates

Keep your standard policies as templates and start a new policy from one instead of a blank page.

  • Your own templates: the wording plus the settings a new policy starts with. Save any existing policy as a template in one click.
  • Your details filled in for you: your company name, ABN, address and contact details are dropped into the new policy automatically.
  • Copied, never linked: changing a template later never changes a policy you've already written from it, so what your team agreed to stays exactly as it was.

Added — download a policy as a PDF

Policies and procedures can now be downloaded as a PDF, ready to file, print or send to an auditor.

  • Every published version, including older ones, from the policy's version history. Each PDF shows its reference, version number, publication date and what changed.
  • Drafts too, for the people who write policies. A draft PDF says DRAFT on every page and states that it isn't in force, so it can be circulated for comment without being mistaken for the real thing.
  • Your team can keep a copy of what they agreed to — from My inductions, or in the driver app — and they get the version they signed, even if it has been updated since.

Fixed — a hazard tapped by mistake no longer leaves a report behind

When a driver taps the hazard button on the road, that tap now records only that they saw something — where and when. It becomes a numbered hazard report once somebody says what it was: the driver at the end of the run, or the office.

  • Taking a flag back leaves no report. A driver who tapped by accident and took it back used to leave a numbered report on the register that nobody had filed. Now none is made, and the flag comes off every map straight away — including the dispatch board, where a taken-back flag could previously linger.
  • The office can chase the ones nobody described. Flags a driver hasn't written up are listed at the top of Hazards and incidents, oldest first. You can write one up (ideally after asking the driver) or dismiss it. Each also shows as a task until it's dealt with.
  • Clearer wording for drivers. The screen shown after taking a flag back now says the same thing as the confirmation before it.

Fixed — drivers are asked for their PIN once when they sign in, not twice

On a shared tablet, a driver who tapped their name and entered their PIN could be taken straight to the locked screen and asked for it again — most often first thing in the morning, on a tablet that had locked itself the evening before. Signing in now counts as unlocking, whether with a PIN or a password. The screen still locks by itself after it has been left alone for a few minutes, exactly as before.

Fixed — turn-by-turn now takes you to the next stop, and finds a way back if you leave the route

The directions beside the map could show the wrong turn — on some runs the turn back into the depot for the entire journey — and never mentioned the stop you were heading for.

  • Directions now run from where the bus is to the next stop. The turns up to the stop are listed in order, followed by the stop itself and how far away it is. A stretch with no turns simply shows the stop and counts down the distance.
  • At a stop, the directions show the way out, so you know which way you're pulling out before you leave.
  • If you leave the route or drive past a stop, the app suggests a way back. It gets you back onto the planned route as soon as it can, or back to the stop you missed, and shows the suggestion on the map as a dashed line. It's clearly marked as a suggestion rather than a checked bus route, so use your judgement.
  • With no signal, it shows which way the stop is and how far in a straight line, and says so, rather than giving directions it can't stand behind.

Added — drivers can claim extra hours and reimbursements

Drivers can now claim from the bus app for time spent working outside their runs — cleaning a bus, taking one to a repairer — and for money spent on the company's behalf, with a photo of the receipt.

  • The office approves or declines each claim. A declined claim shows the driver the reason, so they know whether to claim again.
  • Approved claims wait on a pending-payment list with totals, ready to download for payroll. Once payroll has paid them, the office marks them as paid, one at a time or in a batch.
  • Approving and paying are separate permissions, so the person who runs payroll can mark claims as paid without being able to approve them. Nobody can approve or pay their own claim.
  • A driver can change or withdraw a claim until the office has dealt with it. After that it's fixed, so what was approved is exactly what was claimed and what was paid.
  • Receipts are kept privately for seven years, then the photo is removed; the claim stays on record.

Added — hours worked, for drivers and the office

  • Drivers can see the hours they've worked, a week at a time, with a total for each day — every run they completed, when it ran, and what it counts as. It's under the new Hours & claims item in the bus app's menu, which is also where claims now live.
  • A shift runs from the pre-run check to the post-run check, and a short shift counts as your company's minimum hours per shift.
  • Set the minimum under Company settings. It starts at 2 hours. A change applies from that day onward and never alters hours already shown for earlier days.
  • Approved extra-hours claims are added to the day's total.
  • The office gets an hours report — every driver's hours for a date range, a day-by-day view for each driver, and a download for payroll.
  • On smaller landscape tablets, the bus app's menu now sits in two columns so every item fits on screen.

Added — a calendar, with public holidays

  • One calendar for what's happening each day: services, public holidays, drivers' time off, school holidays and pupil-free days. Switch between a week and a month, and filter by driver, school or route.
  • Drivers get it too. Your week in the bus app now has a month view as well. Each day shows public holidays, the driver's own time off and closures at the schools they drive to. Further ahead than runs are published, it shows what the roster says, clearly marked as not yet published. Drivers only ever see their own time off.
  • Public holidays are built in for Western Australia, and you can add your own local days, such as a regional show day.
  • Public holidays never cancel runs. The dispatch board warns you when runs are still scheduled on a public holiday, so you decide.

Added — Manual Mode for runs that don't go to plan

  • Drivers can switch a run to Manual Mode: one list of every child on the run instead of working stop by stop. Each child is marked on, off, or didn't board, wherever the bus is. It's for detours, road closures, stops taken out of order, or a relief driver who doesn't know the route. Drivers can switch back at any time, and nothing already marked is lost.
  • Every mark records the time and, where the device knows it, the location. A mark made at one of the run's stops is recorded at that stop.
  • The same safety checks apply: everyone who got on must be marked off, and the bus must be swept, before the run can finish. In Manual Mode every child on the list must also be marked before the run can finish.
  • The office can see it: a run in Manual Mode is marked on the dispatch board.

Changed — a tidier About me for drivers, and a clearer warning about your quals

About me had boxes for Your Quals and Your tasks on it, and both of those already have their own place in the driver's menu. Two ways to reach the same screen from one page is one more thing to think about, so the boxes have gone. Nothing has been removed from the app — the menu takes you straight there, as it did before.

The box for messaging has gone too. It was the most prominent thing on the page and all it said was that messaging is not switched on yet. When it does arrive it will have its own place in the menu.

The warning about a lapsed qual has moved, not gone. Open Your Quals and the top of the screen now tells you if any of your cards has expired or been withdrawn, and names which one — right above the list, so you are not scrolling to find out. If everything is in order it says nothing at all, which means a message there always means something needs dealing with.

A card you have sent in that the office has not checked yet does not count as needing attention — there is nothing more for you to do with it, and it still shows as Waiting to be checked in the list. Previously the list and the summary could disagree about that.

We also fixed a case where a qual that had been withdrawn could still show as Waiting to be checked, which read as though you only had to sit tight.

Fixed — claiming money you spent is now offered where claiming time already was

Hours & claims in the bus app offered drivers a Claim extra hours button and nothing next to it for money out of pocket. Reimbursements worked perfectly well — the form, the receipt photo and the office's approval list have always handled them — but you had to go into Your claims first to find the button, and a screen that offers one kind of claim and stays silent about the other reads as though the other one doesn't exist.

Claim a reimbursement now sits beside Claim extra hours on the Hours & claims screen, the same size and the same weight. Nothing else changed: the same form, the same receipt photo, the same approval.

If your drivers have been claiming fuel or parking some other way because the app looked like it couldn't take it, this is why, and it is worth telling them.

Changed — find a guardian by name, as you type

The search on the guardians list now finds a parent or carer by any part of their name, first or last and in either order, as well as by part of an email address or a phone number typed with or without spaces. Previously it only matched an email address or phone number typed exactly. The list narrows as you type, and pressing Enter searches every guardian rather than just the page in front of you. The list is now in alphabetical order.

Changed — deciding a driver claim is now one question instead of two boxes

Approving or declining a claim used to mean reading two side-by-side panels — one to approve, one to decline — with the "why it's declined" box sitting open even when you were about to approve.

It is now a single Decision: choose Approve or Decline, and the reason box appears only if you choose Decline.

The button follows your choice and says which way it goes — Approve claim or Decline claim — and it only appears once you have chosen. That is deliberate: an approved claim can't be edited afterwards by anyone, so the button that commits the decision should say what it is about to do rather than leave it to a setting further up the page. Choosing an option on its own changes nothing until you press it.

Nothing else about claims changed: the same figures, the same reason shown to the driver, and you still can't alter an amount — a wrong figure is declined with a note so the driver can send a corrected claim.

Fixed — a change to the attendance register that didn't save now says so

If a parent, a school or your office was signed out while the attendance register was open, a tick could be refused and the box would quietly clear itself with no explanation. It was easy to believe the change had been made when it hadn't.

Now a box that couldn't be saved turns red. If the reason is that you've been signed out, or the page was open too long, a message across the top of the register says your change was not saved, with a button to sign in again or reload. Boxes stop accepting ticks until you do, so nothing else can be lost the same way.

Each tick on the register is also now sent exactly once. Previously a change could be sent a second time when the page was next opened, which could put back a tick you had just cleared.

An expired sign-in page also now explains what happened and offers to try again, instead of showing a bare "Page Expired" error.

Added — we can now check whether a change was attempted and didn't save

When a parent, driver or school contact tries to save a change and it is turned away — for example because they had been signed out — the platform now keeps a short note that the attempt happened: when, on which screen, and why it wasn't accepted. It never keeps what was typed.

So if someone tells us "I did update it", our support team can now see whether they tried and it was refused, rather than having to guess. These notes are removed automatically after six months.

Someone riding a bus they are not normally on

Three things that happen every week now have a proper place in the system, instead of a phone call and somebody's memory.

A parent can ask for a friend to ride home with their child. From the family portal, for a particular afternoon: who is travelling, which service, where they get on and where they get off. It is a REQUEST — the portal says so before you send it and again while it is waiting — and the operator decides.

If the visitor is another family's child, that family is asked too. One parent cannot put another parent's child on a different bus on their own say-so. If the other family does not answer in time, staff can still approve it, but they have to record how they actually got in touch — so what is on file is what really happened.

A visitor who is not one of the operator's students can be brought along, named, and travelling with the child who invited them. Their name and phone number are kept only as long as they are needed and are then removed automatically; the record that the journey happened stays.

A driver can add somebody who turns up at a stop. A name is required — it is what lets the office follow it up — and a phone number if there is one. If the driver does not yet know where the person is getting off, that is fine: they appear at the top of every remaining stop, so they cannot be forgotten, and the driver marks them off wherever they actually leave.

The bus cannot finish a run with somebody aboard nobody can name. That is the point of all of it. Until this, a driver who did the right thing and recorded an extra passenger produced a run that looked perfectly tidy — the person counted for nothing. Now the run stays open until they have been named or marked off, and this one cannot be overridden.

A child riding elsewhere is shown to their usual driver as travelling on another service, never as away. If anything goes wrong, the first question is which bus they are on, and the screen answers it.

The office gets a new Ad-hoc travel screen: what is waiting for a decision, what is on the road today, and everything already agreed. A request that has not been answered shows on the tasks list the same day, and a passenger added on board shows there as urgent.

Where a court order is on file restricting who may collect a child, an arrangement involving that person cannot be made online at all — in either direction. The family is asked to ring the office.

[1.61.0] - 2026-09-10

Added — you're now told when a school changes its bell times or its calendar

Schools can keep their own details and calendar up to date from their portal. Until now none of that reached you: the school did the right thing, saw it saved, and nothing appeared on your side.

A change now lands on your task list, and because a school record is shared, every operator serving that school is told at the same time.

  • A bell time moving gives you a task naming the old time and the new one — "afternoon bell moved 3:00pm to 2:35pm" — with who at the school recorded it. It's a normal-priority task: the change takes effect from now on, and you have until the next run to decide what your service does about it.
  • A day the school is shut gives you a high-priority task, because runs are prepared about a week ahead and a bus and driver are already rostered to that date. Nothing is cancelled for you — cancelling a run nobody asked us to cancel is the one mistake that puts children at a stop with no bus — so the task points you at the dispatch board for that day.
  • A closure being withdrawn raises a task too. If you'd already stood a bus down for that day it won't come back on its own, and that's the direction that's easy to miss.

Closures further out than the runs we've prepared stay quiet, because nothing is rostered yet and there's nothing to put right. If one of those days later comes into range and still needs your attention, it appears then.

A change that doesn't actually change anything raises nothing — a list that reports non-events is one people stop reading.

Added — schools that ring a different bell on some days

Plenty of schools finish early one day a week. Until now a school record held a single morning bell and a single afternoon bell, so a school with a short Wednesday could only be recorded as one or the other — right four days out of five, and wrong on the fifth.

A school can now record the days that are different. On the school's own details page, and on the shared school record, there is a row per weekday: fill in only the times that differ, and leave the rest blank for the usual ones. A school whose Wednesday afternoon finishes early but whose morning is unchanged fills in one box. Blank always means the usual time — never "no bell" — so a partly filled form can never claim a school has no afternoon.

Because school records are shared, entering this once reaches every operator serving that school.

And a route can now run to a shifted timetable on those days. On the route's setup page there is a box per weekday for how many minutes that day's service shifts — use a minus for earlier, so a school finishing twenty-five minutes early is -25. The whole run moves together: every stop, by the same amount, keeping the gaps between them exactly as they are. Any stop with a planned wait keeps that wait.

The two are deliberately separate. The school says when it rings its bell; you decide what your service does about it. Two operators serving the same school can absorb the same early finish differently, and neither can change the other's timetable.

Days already on the board are updated. Runs are prepared about a week ahead, so the day that needs shifting has usually been created before anyone tells you about it. Setting a shift now corrects those upcoming days overnight rather than waiting for the following week. A run that is already under way, or finished, is never re-timed — it is a record of what happened.

Where a route has a shift, its stops-and-timing page says so at the top and gives the time that day's run actually starts, so the timetable underneath is never read as if it applied to every day.

And the two are joined up. If a school records an early finish and one of your routes to that school hasn't been shifted to match, that route's page says so — naming the day, the time the school rings, and a link to the setting. It's a prompt rather than a complaint: if the route already absorbs the difference, the page says that's fine and nothing needs changing. It's raised only on morning routes when the morning bell moves and afternoon routes when the afternoon one does, so it stays quiet where it would only be guessing.

[1.60.0] - 2026-09-09

Fixed — the run review no longer flags a missing signature nobody asked for

The safety-checks table on a finished run marked every check without a signature in amber, and raised a warning counting them — even where your checklist never asked the driver to sign that half of the run. Since a signature is a question you add to your own checklist, and it can be asked before the run, after it, or not at all, that warning was firing on checklists that were set up exactly as intended.

The signature column now has three readings. A signature shown means the driver signed. none, in amber, means your checklist asked for one on that half of the run and did not get it. A dash means it never asked. The warning above the page counts only the first kind, so an amber signature is now always worth looking at.

Fixed — the route map no longer stops working while a route is being drawn

On a route whose road path had not been approved yet, the map beside the route builder could stop responding partway through setting up: reordering a stop, opening the road-path panel or placing a turn would leave the map without the line it was meant to draw and without framing the leg being worked on. It only happened on routes that were still being built, which is exactly when the map is most needed.

Fixed — email to us was going to an address that did not exist

Two of the addresses Tutela used to reach us were never actually set up, so mail sent to them was rejected and quietly thrown away. Both now point at info@tutela.au, which is monitored.

This affected two things:

  • Asking us to add a school to the register. When you submitted a request, the screen told you it had been sent — and it had been recorded correctly, so nothing was lost from your account. What did not happen was the alert telling us to go and look at it, so a request could sit waiting far longer than it should have. If you asked us to add a school and have not heard back, email info@tutela.au and we will pick it up straight away.
  • Questions about the Terms. Our Terms of Service and School Portal Terms each listed a separate address for questions about the terms themselves. That address did not work. Both pages now show info@tutela.au for terms, privacy and data questions alike. If you wrote to us about the terms and received no reply, please send it again.

The wording of the terms has not changed, only the contact address, so nothing needs to be re-accepted.

Fixed — the turn-by-turn directions now sit beside the map however you hold the tablet

Held upright, the directions were dropping into a box underneath the map and pushing the list of children down the screen. They now stand beside the map at every size and in both orientations — the map takes two thirds of the width, the directions take the last third, and the children keep the full width underneath.

Added — the arrival time now sits with the directions

The directions column carries the stop you are driving to, the time you are expected to reach it, and the minutes and distance still to go. Every figure is measured from where the bus actually is and replaced each time the tablet sends its position, so the reading follows the road rather than an average of it. The same figures stay in the bar across the top, worked out once and shown in both places so the two can never disagree.

The turn you are driving comes first in the column, because it is the one that stops being useful a minute later. Held upright there is only room for that turn rather than the queue of the next few behind it; turn the tablet sideways and the queue comes back.

The app still will not re-route you. If the bus leaves the approved path the directions stop advancing rather than inventing a new instruction — the only roads it will send a bus down are the ones the office drew and approved.

Fixed — the driver help guide now pictures the run list as it actually looks

The illustration in the driver's guide showed the run list as a single list with a departure time beside each run and one Open run button underneath. The screen has never looked like that: each run is its own card, carrying the route, whether it is the morning or afternoon run, the date and where the run has got to, with its own Prepare button, the Offline map row and the Preview the route link.

That mattered because the guide's own words underneath described the offline map and the route preview, and the picture above them showed neither — so a driver was reading about controls the illustration said were not there, and looking for a departure time the card does not print. The picture now matches the screen, and the guide says plainly that the order of the list, not a printed time, is what tells you which run is next.

The same section listed six places the menu can take you when there are eight; Safety and Time off were missing.

Fixed — every illustration in the help guides now matches the screen it shows

Having found one, we checked all fifty-one. Four were showing nothing at all: two confirmation dialogs and the policy-writing form had been written in a style the help system did not understand, so what reached the page was a heading, the words "Nothing to show" and a couple of buttons. A column had been silently dropped from two more.

The picture of the driver's child tiles was the most important one. It still showed the old tile — a coloured outline on a white card — which we replaced some time ago after a driver told us the states could not be told apart at a glance at a door. The guide now shows the tiles as they are: filled solid, with the child's year level and the "stayed on" bar.

A number of other pictures had drifted from the screens they illustrate and have been redrawn from them: the dispatch board, the route builder, the attendance grid, the fleet compliance and servicing tables, the checklist schedule, the operator and school registers, the security console, the backup page, the qualification register, the import review, the family portal and the safety report screens.

We also corrected several things the words got wrong. The guides told drivers to tap Finish run; the button says Complete run. They told office staff to look for a dot on the help button, which we removed a while ago on purpose. They described a qualifications screen and an access-log screen that do not exist, and offered two buttons the family portal home does not have. Where a guide quotes what the app says when it refuses to finish a run, it now quotes the app's own words rather than a paraphrase.

Finally, the help system now refuses to publish an illustration whose content never reaches the page — so this particular kind of silence cannot happen again unnoticed.

Added — turn-by-turn directions beside the map

The driver screen now gives directions one turn at a time, in its own column next to the map: the turn coming up, the road it is onto, the note the office recorded for it, and the distance counting down — with the next few turns listed underneath so the driver can see what follows.

It replaces the old Getting here list, which showed every turn for the leg at once and never moved as the bus drove, and the single turn prompt that used to sit in a band across the top of the screen. Both said the same thing in a place the driver was not looking; this says it where the road picture is, and it advances by itself.

Where the office has not yet approved a road path for a route there is nothing to measure the bus against, so the column shows the recorded directions for the leg as a plain list instead — including the written directions, which are still there behind Directions. The map keeps a third of the screen and the directions a sixth; the children's half is unchanged.

Fixed — turns are now given in the order you drive them

On a route with turns recorded on more than one leg, the directions were being handed to the tablet in the wrong order — grouped by their position within each leg rather than by the order the bus meets them. The prompt could then place a turn far from where it actually is, and after the first turn of a run it either said nothing or named the wrong one.

Turns are now sent in driving order. This affected both of the routes currently running.

Fixed — the driver screen's top bar no longer runs items together

On a small tablet held upright, the items along the top of the run screen could sit on top of one another — the schedule chip could cover part of the hazard button, and the run's name could be squeezed until there was nothing of it left to read.

The bar now grows to a second line when there isn't room for one, instead of squashing everything until it collides: the run name and the two controls stay on the first line, and the arrival estimate and the schedule chip take the second. On a landscape cab tablet nothing changes — it stays a single line exactly as before.

Checked by measuring every item on the bar against every other one, at every screen size we support from a small phone to a wide desktop, with the longest wording the bar can carry. Nothing overlaps and nothing runs off the edge at any of them.

Fixed — the arrival estimate now follows where the bus actually is

Drivers reported that the estimate didn't seem to keep up while they were driving — the figures moved, but they weren't a statement about where the bus had got to.

The estimate itself was being worked out correctly; it just wasn't reaching the tablet often enough. It relied on a once-a-minute check that carries a lot with it, and on a country road that check frequently didn't get through — silently, so nothing on screen said the figures had gone stale.

The answer now comes back on the message the bus already sends every twenty seconds or so while it's moving, worked out from the position that message just carried. Three times as often, from the most recent place the bus has been, and with no extra work for the tablet or its battery. Between those the figures keep counting down as before, so the panel is never sitting still.

Fixed — the dispatch board follows the shape of the day

Runs with nothing to flag are now listed in the order they leave, earliest first. Runs that need attention still come first, exactly as before — what has changed is everything underneath them, which used to be in no particular order.

Fixed — today's runs are listed in the order you drive them

If you are rostered on more than one run in a day, the driver app now lists them earliest first, so the run you are about to do is the one at the top of the screen. Before this the order was not guaranteed, and an afternoon run could appear above the morning one.

Your week works the same way, so both screens agree about a given day.

[1.59.0] - 2026-09-07

Added — filters on the defects list, and a number on every fault

The list of faults could only be switched between "open" and "everything", so any narrower question meant reading the whole thing — which, if you've brought fault history in from another system, can be years deep.

There's now a filter bar above the list. Pick a bus, a status, type a search, or set the dates the fault was raised between — in any combination. The dates are inclusive and they're your depot's days, so a fault reported first thing in the morning is inside the day it was reported on.

The list stays filtered while you work. Open a fault, read it, come back, and you're looking at the same list you left — including if you come back later through the menu. A filtered list says so above the table, and when it has nothing in it, it tells you it found nothing matching your filters rather than claiming there are no faults. Clear puts the whole register back.

Added — every fault now has a number you can quote

Faults are numbered, in the same style as incident reports and first aid records — one sequence per year for your operation. The number leads the list and heads the fault's own page, so it's the first thing to hand when a workshop asks which job you're calling about. It's also searchable, so a number off a job card finds the fault.

Faults already on your register have been given numbers too, oldest first, including any history you imported.

Changed — clicking a row on the defects list opens that fault

The row itself now opens the fault, rather than only the small View button at the end of it. The bus is no longer a link on this screen: it used to be, so a click aimed at the row could land on the bus instead of the fault you meant. The bus is still one click away from the fault's own page.

Added — a defect now keeps the whole story of the fault

A defect used to be one sentence when it was reported and one sentence when it was closed. Everything in between — the part is on order, the mechanic had a look and it is the other side, the driver says it has been doing it for a week — lived in somebody's inbox, and the register looked as though nothing had happened.

Every defect now carries:

  • Notes. A running record of what has been done about the fault, with who wrote each one and when. Notes cannot be edited or deleted afterwards, so what the record says today is what it said at the time — a correction is a new note. You can add one to a defect that has already been closed, which is where "this came back three weeks later" belongs.
  • Files. Attach a quote, an invoice, a mechanic's report or a photograph taken in the yard. Every upload is scanned, stored privately, and only ever downloaded through the defect page — it is never a public link. Anyone who can report a fault can attach a file to it; removing one is kept to the people who can resolve a defect, because a file taken off a fault is evidence taken off the record.

Added — say when a fault was actually reported

Faults are often entered after the event, because a driver mentioned it at the depot on the way past. Raising one now asks for a Reported date and time, filled in with the moment you opened the form and yours to change. A fault reported on Friday and entered on Monday is now recorded on the Friday, so the bus history — and anything an audit reads back from it — says what really happened.

The date is read in your own operating timezone, and it will not accept a time in the future.

Changed — a failed checklist item now asks the driver what they saw

When a driver answers Fail on a checklist question that raises a defect, the app now asks for a photo or a short note before the checklist can be submitted. Either one is enough — nobody has to supply both.

Until now that account was optional, which meant the workshop usually received the word "No" and a question title, and had to ring the driver to find out what was actually wrong. The driver is standing next to the fault with a camera in their hand; that is the moment to ask.

Three things this deliberately does not do:

  • Items that only book workshop work are not affected. A low washer bottle books a job rather than reporting a fault, and it is still a single tap.
  • A Pass still costs nothing. Failing an item must never be more work than passing it.
  • It never holds a bus in the depot. If the tablet has no signal, the checklist is accepted as it stands and the missing photo is flagged for the office to follow up. The safety decision has already been made on the answer itself — the bus is grounded, or it is not, whether or not anyone got a photograph.

[1.58.1] - 2026-09-03

Fixed — a driver could not back out of a run they opened by mistake

If a driver opened the wrong run and started it, the app kept them on it. That is deliberate while a bus is moving — the run screen is built for someone responsible for a bus full of children, and nothing should pull them off it. But it left no way back for someone who had simply tapped the wrong line, and the only button that released them was Complete. So a run got marked as finished when it had not happened, and the service it belonged to had nothing left to operate.

Three changes:

Opening a run early asks first. Open a run more than an hour before it is due to leave and the app names the run, says when it is due and how far off that is, and offers Back to my runs or Open it anyway. It is a screen of its own rather than a note on the run, because a note above a big green Start button is one people tap past.

Drivers can leave a run they should not be in. There is now This isn't the run I meant to open beside the Start button, and Exit at the top once a run has started. Either puts the run back to not started so it can be driven properly later. If a pre-start check had already been done, it stops counting for that run and the next driver is asked for a fresh one — a check done at dawn is not a check on a bus setting off in the afternoon. The option disappears once the bus reaches a stop where children are, and it is never offered if anything at all has been recorded for a child.

The office can clear a run that should not have run. The dispatch board now has a Finished today list below it — what finished, who drove it, when, and how many were carried, with runs that carried nobody highlighted. Clear puts one back to not started. It asks for a reason and for your password, so that a console left unlocked at a depot desk cannot be used to rewrite a run under your name, and it is refused outright on any run where a child was marked on or off. Those runs are a record of children, and the way to fix one is to correct that record, not to erase it.

Clearing needs the run-cancelling permission; being able to watch the board does not give it to you.

Fixed — a tablet could appear twice in your device list

A tablet remembers that it is registered in the browser or app you set it up in, not in the tablet itself — so setting one up in a browser window and then opening the installed app created a second entry for the same physical tablet. A website has no way to read a device's identity, so this is a limit of what we can detect rather than something we can silence.

Tutela now tells you when a vehicle already has a registered tablet: on the screen where you choose the vehicle, and again after you approve. It does not stop you, because some buses do run two — but if it is the same tablet registered twice, you can revoke the older entry so the list stays accurate about what can see your students.

The help guide now explains this, and recommends setting a tablet up from the app the driver will actually use.

Fixed — driver names looked greyed out on the device list

Names of the drivers assigned to a shared tablet were displayed in a faded style that made them look switched off. They now read normally.

Fixed — no way to start registering a shared tablet

The sign-in screen now offers Register this tablet at the bottom, under "Setting up a shared tablet for this bus?". Until now the setup screen existed but nothing led to it, so there was no way to reach it from the app on the tablet.

One thing worth knowing when you set one up: register from the app the driver will actually use. A tablet remembers that it is registered only in the place you registered it, so if you register in a browser window and the driver opens the installed app, they will meet a password screen instead of their name.

[1.58.0] - 2026-09-02

The same fault twice on the register can now be merged into one

If you brought your fault history across from another system, some of it probably arrived as more duplicates than you actually had — a comment somebody added to an old record often comes across as a fault in its own right, so one problem shows up as two open faults on one bus.

Merge now sits on each open fault, both on the list and on the fault itself. Pick the one to keep, say why they are the same fault, and the register shows one instead of two.

Nothing is deleted. The record you merge keeps its own page and everything on it, and its wording is shown on the fault you kept — which is usually where you want it, because the follow-up is often the most recent thing anyone knows about the problem.

It is not the same as marking a fault fixed, and it is not recorded that way. Merging says the two write-ups were always one fault; it does not say anyone has dealt with it.

Three things it will not do:

  • It will not merge faults on two different buses. Two buses can have the same thing wrong with them, in the same words, on the same day — that is two faults.
  • It will not touch a fault that has already been dealt with, in either direction.
  • It will never put a bus back on the road. If the fault being merged is the more serious of the two, the one you keep is raised to match it, and a bus that is off the road stays off the road. Bringing a bus back into service is still a separate decision by somebody allowed to make it.

Merging sits with the people who can clear a fault rather than everyone who can report one, since it takes a fault off the open list.

And if you get it wrong, you can undo it — the fault goes straight back on the open register as its own. Both the merge and the undo stay on the record, with the reasons given.

Fixed — drivers being sent to the sign-in screen instead of the PIN pad

If a tablet had been switched off overnight and was opened the next morning, the app sometimes asked the driver to sign in with their email address and password rather than simply asking for their PIN. It could also send the driver a message saying their device may have been copied.

Nothing had been copied. When the app starts up it asks the server for several things at once, and those requests could arrive close enough together to be mistaken for two different people using the same device. The app now recognises its own start-up for what it is.

The protection itself is unchanged: a device really being used by two people at once is still detected, still signed out, and still reported. Only the mistaken case has gone.

Added — shared tablets: tap your name, enter your PIN

A tablet that lives in a bus can now belong to the bus rather than to one driver.

Your office registers it once. On the tablet, choose Register this tablet; it shows a short code, and someone in the office types that code in, gives the tablet a name, chooses its vehicle and ticks the drivers who use it. From then on, anyone on that list signs in by tapping their name and entering their PIN — no email address, no password, on a cold morning in a vehicle.

Drivers rostered to that vehicle today can sign in as well, even if nobody has ticked them, so a last-minute change of driver doesn't need a phone call to the depot. And if your name isn't on the screen at all, signing in with your password is still there on the same screen.

Two things worth knowing:

  • The code is read off the tablet, not sent to it. Nothing is emailed, and the code on its own doesn't let anybody in — so it's safe to read it across a depot. The office should still check that the details on their screen match the tablet in front of them before approving it.
  • Signing out at the end of a shift doesn't un-register the tablet. The next driver gets the name list, not a setup screen.

Too many wrong PINs will stop that one driver using that one tablet for a while. It doesn't lock the tablet for anybody else, and it never takes the bus out of service.

Security — an updated third-party component

We updated a text-formatting component used to render the in-app help pages, closing three issues its maintainers reported. Nothing in Tutela behaved incorrectly and no action is needed on your side; we apply this kind of update as soon as one is available.

[1.57.0] - 2026-08-26

A skipped stop now shows as done on the driver's map

When a driver skipped a stop, its marker on the map stayed the same colour as the stops still to come, and the road past it kept showing as road still to drive. Skipped stops now show as finished — in grey rather than the green used for stops the bus actually called at, so the two stay tellable apart — and the route past them colours as travelled straight away, including when the screen is reopened part-way through a run.

The office's live map already showed skipped stops this way. The two now match.

Filter tabs look like tabs again

The Open / All style filters on several screens — reported faults, risks, corrective actions and safety reports — were showing as plain text instead of a proper set of tabs. They always worked; they just did not look like buttons. They now do.

A bus's open faults now show on its own page

Opening a vehicle from the fleet list used to show its details, its capacity and its service record — but nothing about whether anything was wrong with it. Any reported fault lived on the compliance screen, one click further on, so a bus with an open defect looked exactly like a bus with none.

Its faults now appear on the vehicle page itself. Open ones are shown by default, since that is what you are usually looking for, and a button switches to All when you want the full history. A grounding fault is marked as such, and each row links through to the full record.

The page has also been tightened up so more of it fits on screen without scrolling.

The driver app stays put during an update

When the platform is updated, there is a short moment while the new version starts up. If a driver tapped through to a screen during it, they could land on a bare error page from outside the app — no runs, no children, no buttons — with nothing telling them what had happened.

The driver app now recognises that moment for what it is. The screen they already had open keeps working, and a screen it cannot reach shows the app's own "you're offline" page, which tells them their recorded taps are safe on the device and will send by themselves. Anything a driver had already recorded was never at risk; the problem was the screen, and it is fixed.

Updates themselves are unchanged: a new version is still never applied to a tablet part-way through a run, and a driver is only ever offered it once their run is finished.

A child can be marked absent right up until the bus reaches their stop

Once a run had started, the register refused to mark anybody on it as not travelling — even children the bus was nowhere near yet. A parent ringing at ten past eight about a child not due to be picked up until half past could not be recorded at all, and the message went back to living in somebody's memory.

That was too blunt. The question is not whether the bus has set off; it is whether it has been to that child's stop. So a child further down the route can now be marked, and un-marked, right up until the bus arrives at where they wait.

Once the bus is at the stop, it is too late — the driver has the list in front of them and children at the door, and a change landing at that moment would alter a list somebody is working through. If that happens, the screen says so plainly and tells you to ring the depot, because that child is still expected and somebody needs to know.

Nothing about a child who has already boarded changes. What the driver recorded at the door has always come first, and still does: a child who is on the bus stays on it whatever anyone files afterwards.

Drivers are told when you change something on their run

A change made close to a run had no reliable way of reaching the person driving it. During a run the app could tell a driver that something had changed, but not what — so a roster tweak and a child taken off the bus looked identical, and there was nothing to see at all between runs.

Now there are two places it shows up.

Between runs, a bell appears beside "Today's runs" on the bus app whenever something has changed in the last day, with a count on it. Opening it lists what changed, for which child and which bus. Reading the list is what clears the bell — there is nothing to acknowledge. A change that has since been undone shows as the undoing rather than as both, because what a driver needs is where things stand now.

During a run, a bar appears along the bottom of the run screen naming the child — for example that they are not travelling — with a button to bring the screen up to date and a cross to dismiss it once read. It will not refresh the screen underneath a driver who is part-way through a stop.

Two honest limits, both worth knowing. It needs a signal, and it checks about once a minute while a run is on — so it is quick, but it is not instant. And it is not a replacement for a phone call: if a change really matters and the child's stop is minutes away, ring the depot as well. The screen is a good way to tell a driver something. It is not a guarantee that they have been told.

[1.56.0] - 2026-08-26

The attendance register applies its filters as you set them

Choosing a route on the attendance register used to leave the grid where it was until you found and pressed Filter — and if you did not, you were reading a week of the wrong children with nothing on the screen to say so. Choosing a route now applies it straight away.

The Student search has moved up beside the route filter, so the two controls that narrow the register sit together on one line instead of stacked in two.

The grid itself is tighter. Rows take up less height and the table ends at the bottom of your screen rather than past it, so several more children are in front of you before you scroll, and the day and AM/PM headings stay put as you scroll through the rest.

Drop-down lists no longer open by themselves

Search-as-you-type drop-downs across the platform were arriving with their list already open, covering whatever sat underneath until you clicked somewhere. They now stay closed until you click into the box.

New team members are now invited by email

When you added someone to your team, Tutela generated a password and showed it to you on screen — once — and it was then up to you to get it to them. A phone call, a note on a desk, a message. It worked, but it put a working password for your operation onto whatever you happened to use to pass it on, and there was no record of whether it ever reached them.

Now Tutela emails them instead. Adding a team member sends them an invitation, and they choose their own password from it. There is nothing for you to write down and nothing to read out. Drivers are told plainly that their account is for the driver app, so nobody spends their first morning trying the wrong sign-in page.

The invitation works once and lasts three days. If it does not arrive, there is a Resend invitation button on the team list, and sending a new one stops the old one working.

Once somebody has signed in for the first time, that button becomes Reset password — because from then on the password is theirs, and a reset is what they need rather than a fresh invitation.

Parents and school contacts now have a password

Until now, the family portal and the school transport portal had no password. You entered your email address, we sent you a link, and opening the link signed you in. Nothing to remember — which was the point.

It also meant that every single sign-in depended on an email arriving. A junk filter, a full mailbox, an unsubscribe, or a work address somebody had left behind, and there was no way back in without ringing the bus operator.

So both portals now work the ordinary way. When you are invited you choose a password, and after that you sign in with your email address and that password whenever you like. Nothing else has to reach your inbox again.

The old way is still there, as Email me a sign-in link instead, right under the sign-in button. It is the right choice at twenty to seven in the morning with a sick child and no idea what your password was, and it is how you get in if you were invited but never got round to choosing one. It works exactly as it did before.

And you can now rescue yourself. Forgot your password sends a fresh link to the address we hold, so a lost invitation no longer means a phone call.

A few things that have not changed:

  • The sign-in page still never tells anyone whether an address has an account. A wrong password and an unknown address give exactly the same answer.
  • Sign-in links are still single-use and short-lived.
  • School contacts are still asked to agree to the School Portal Terms before they can see anything, and every student record they open is still recorded against their name.

School contacts will be asked to agree to the portal terms once more

The School Portal Terms have been revised. The clause about not sharing your access named only the sign-in link, because that was the only way in when it was written — it now covers your password as well.

That is a real change to what you are agreeing to, not a tidy-up, so everyone is asked to read and accept it once more at their next sign-in. Nothing else about your access changes, and it is a single screen.

Schools can be set up without going through a bus operator

A school's portal contacts could only ever be created by a bus operator, or by a school administrator who had to have been set up by a bus operator first. That made a school's own staff list depend on a company outside the school.

A school's first contact can now be set up centrally and becomes that school's administrator, who can then add and remove their own colleagues. This changes nothing about what anyone can see: a school contact only ever sees the children covered by a current data-sharing agreement with the operator carrying them, so a contact set up before any agreement exists sees nothing at all.

[1.55.0] - 2026-08-25

More of the run screen, on the tablet in the bus

A driver sent us a photo of a run screen with a lot of empty space on it and the bottom of the stop card cut off. Two things were taking room that had nothing in them.

The stop card now reaches the bottom of the screen. It had been stopping short by about the height of the bar across the top — left over from when there were two bars up there rather than one. Underneath it, the page was also carrying a strip of blank space meant for phones, which a tablet in landscape has no use for. Between them that was a sixth of the screen, and all of it came out of the children's tiles, which are the only part of the card that gives way.

On a run's last stop it also means "I have swept the bus" now sits fully on the screen rather than being clipped by the bottom edge.

The turn directions step aside while you're at a stop. The next-turn banner and the Getting here line are both about driving, and while you're at a door you aren't. They go for as long as you're stopped and come back the moment you tap Departed — the same thing the map already did, for the same reason. Show map is still there if you want the road while you're stopped.

"The bus has moved on" now only appears when we can't do it for you

You could get this message about a stop the app was already about to close by itself — so you'd be told to mark a stop departed a moment before it marked itself. That makes the automation look unreliable, and a message you learn to swipe past is one you'll miss on the day it matters.

Now it appears only when the app genuinely can't close the stop, and it tells you which of the two reasons it is:

  • An earlier stop isn't finished. The app only ever works on the earliest stop you haven't finished with, so while one sits unfinished behind you the one you've just left can't close on its own. The message now scrolls to the earlier stop rather than the one you're at — that's where the tap belongs, and finishing the wrong one wouldn't have unblocked anything.
  • The stop has no location saved. There's no zone around it for the bus to leave, so it can never tick off by itself. It will keep happening on every run until someone in the office sets that stop's location, so it's worth reporting.

If a departure was refused instead — usually because the bus was early — you get that refusal by name, because "mark it departed" wouldn't have worked.

For whoever looks after the tablets

The driver diagnostics screen has a new Screen panel: the screen size in the units the app's layout actually uses, and which of the two run-screen layouts this tablet resolves to. Quote those when reporting anything about spacing. A tablet sold as 1920x1200 usually reports 960x600 to the app, and the two numbers lead to opposite conclusions — the first guess at the fault above was wrong for exactly that reason.

A checklist question that only appears before a long break

You can now set a question on a fleet checklist to appear only when the bus is about to sit unused for several days — and stay off the screen the rest of the time.

The reason we built it is battery isolation. "Battery isolated?" is worth asking when a bus is being parked for a long weekend or the end of term, and it is noise before an ordinary Tuesday. Asking it before every single run is how a check turns into something drivers tap through without reading, so until now the only real options were to ask it always or not to ask it at all.

In a question's Display conditions, the Source list on a fleet checklist now offers Days the bus is unused before its next run, under About this run. Set it to appear when that is more than 2, put the question after the run, and it asks on a long weekend and stays quiet on a normal one.

The number counts the days the bus sits, not the days on the calendar. A Friday afternoon run whose bus is back on the road Monday morning is 2 — Saturday and Sunday. Make that Monday a public holiday and it is 3. A bus running again the next day is 0.

The count comes from your roster and looks past the week of runs that have already been created, so the last day of term answers with the whole break rather than with however far ahead the runs happen to go. A bus with nothing at all scheduled counts as the longest gap there is, so the question is asked rather than skipped.

Two things worth knowing:

  • If a school's calendar has not been filled in, we assume the school is open. That is the same assumption that stops runs being cancelled by mistake, and it means a term break you have not entered yet reads as an ordinary week — so the question will not appear. If you want this over the holidays, put the term dates in.
  • Preview cannot show you this one. Preview has no bus and no run behind it, so the question always appears there. Check it on a real run instead.

Everything else about conditional questions is unchanged: a question the driver never saw is treated as never asked, so it cannot hold up a check, ask for a photo, book a fault or take a bus off the road. And if anything about a condition is unclear, the question is shown rather than hidden.

The arrival time on the driver's run screen stays with you

Drivers told us the arrival time and the distance left had gone from the top of the run screen. They had — not because of the size of the screen, but because the app had nothing it was willing to say. Two situations covered most of a normal run, and both are fixed.

Before you pull away from your first stop. Until now nothing had happened for the app to measure, so the whole strip stayed blank — on the screen a driver opens before setting off, which is the moment they most want it. It now starts from the published time for that first stop and works the rest of the route out from how long the legs usually take. If you open the run already past that time, it shows now rather than a time that has been and gone. From the moment you leave the first stop, everything is measured again.

After you skip a stop. Skipping a stop used to take the reading away for the rest of the run. That caution was there for a good reason — the app will not guess at how long a road takes when the road you are now on is not the one it has times for — but it went much further than it needed to. A skip now costs only the leg it spans; every stop beyond that is estimated as normal. And once the same stop has been skipped on a few runs, the app has measured that drive and the reading comes back on its own.

Where it genuinely does not know, it still shows nothing at all rather than a number that would look right and be wrong.

The on-board count stays on screen on a small tablet

On smaller tablets, a full "held until" message in the run header could push the on-board count off the right-hand edge of the screen. The count is the number you check before finishing a run, so it now keeps its place and the schedule message shortens instead.

Faults are now listed in the Fleet menu

Fleet → Defects takes you to every fault raised against every bus. Until now the list existed but had no menu entry — you could only reach it from a button on the compliance screen, or by knowing the web address.

It's there for anyone allowed to look at faults, dispatchers included. Seeing the list and clearing a fault are separate permissions, and only the second one is restricted.

Bring your fault history with you

If you kept your bus faults somewhere else before Tutela, you can now bring that history across instead of starting from an empty register. Fleet → Defects → Import history.

Export your issues as a CSV and upload it. A Fleetio export works as it comes; other systems need a heading row with each fault's reference, what was wrong, its status, when it was reported, and a VIN or registration to say which bus it belongs to.

Nothing is written until you say so. The upload shows you what it will do first — how many faults are ready, how many are still open, how many were already brought across, and any rows it can't take, each named with its row number in your spreadsheet. The rest still import, so one bad row doesn't hold up the file.

Three things worth knowing:

  • Importing never takes a bus off the road. Faults that are still open arrive as open so you can see them, but grounding a bus stays a decision someone makes in Tutela. What your old system called the fault — "Critical", "High" — is kept in its description, so nothing is lost.
  • Uploading the same file twice is safe. Anything already brought across is left exactly as it is, including anything you have since dealt with here.
  • Times are read as your depot's local time, and if the file was exported by someone in another state the screen says so before you import.

Columns we have nowhere to put — meter readings, work orders, who was watching — are listed back to you rather than dropped quietly.

Clearer wording about what the parent portal shows

The invitation and sign-in emails said parents could "see your child's bus", which reads as watching the bus move. That isn't what the portal does, so the wording now says what it does: which stop your child uses, when the bus is due, and whether they boarded today — along with absences, forms, contacts and the record of who has viewed your child's details.

Nothing about the portal itself has changed. If a live view of the bus is ever offered, it will be something your operator turns on deliberately rather than something that appears.

[1.54.1] - 2026-08-24

Finding a child on your student list

The search box above the student list now matches any part of a name, first or last. Before, it only found a child when you typed their family name in full and spelled it exactly — a first name found nothing at all, and anything short of the whole surname came back as though the child wasn't there.

Now typing a few letters is enough. You can type both names in either order, type a name back the way the list prints it, and ignore capitals, apostrophes and accents — a name with an apostrophe or an accented letter can be typed either way and is still found.

The list also narrows as you type, so you can watch it come down to the child you want without waiting for the page to reload. That part looks only at the children currently on screen; pressing Enter searches your whole register, including anyone on a later page. The line beside the box tells you which of the two you're looking at, so a short list is never mistaken for the full answer. Escape clears the box.

If the search stops narrowing as you type, it still works — press Enter and it searches your whole register as before.

The same fix, everywhere else it was needed

Three other searches had exactly the same problem and are fixed alongside it.

Choosing a child when you record first aid, and naming a child on a safety report, both now match any part of a name. These are screens you open because something has happened to a child, and having to spell a surname perfectly before the system would admit the child existed was the worst possible place for it. Both still need you to type something — neither will list your children for you — and if more children match than the screen can show, it now tells you how many and asks you to narrow it, rather than quietly showing you the first handful.

Searching the fleet by registration also matches any part of a plate now, with or without the dashes and spaces, so three characters glimpsed on the back of a bus is enough to find it.

[1.54.0] - 2026-08-24

The driver's run screen stays where the driver needs it

As a bus moved along its route, the run screen could drift away from the top on its own — arriving at a stop, moving on to the next one, or refreshing in the background. Nothing the driver did caused it, and the further it drifted the more likely the stop's name and its Arrived and Departed buttons had scrolled out of view.

The screen now returns to the top whenever it updates itself, and it does so on both the page and the stop card, which can scroll separately on a larger tablet. The drift was worst at the busiest stops, so the stops where it mattered most are the ones that improve most.

One thing deliberately stays as it was: if a driver has scrolled down to look at a particular child, a background refresh leaves them there. Only the screen moving on its own is corrected — never the driver's own scrolling.

A demonstration environment that looks like a real operation

The sample data everyone sees when trying Tutela has been rebuilt.

Children, families, staff, schools and suppliers now read as people rather than as placeholders. Brothers and sisters share a surname, an address and a stop, and travel with the same parent — so a family looks like a family. Two children happen to share a name, because in a school of that size two children usually do, and it shows how the attendance screens tell them apart.

The names are chosen carefully. First names are ordinary ones; family names are invented and are not names in use. That is deliberate and permanent: the demonstration site is open to anyone, and it shows home addresses and live bus positions, so nobody looking at it can ever be a real child. It stays that way.

The demonstration now shows the whole platform working, not just parts of it

A large amount of the product was simply not represented in the sample data, so screens that work perfectly well appeared blank to anyone looking around. That has been fixed across the board. The demonstration now includes:

  • a driver booking time off, suggesting who should cover each run, and an operator approving one, declining another and leaving a third to decide
  • safety reporting end to end — a hazard still in place, a near miss that was investigated and written up, an injury with first aid given and the parent telephoned, and the follow-up actions that came out of it, one finished and one overdue
  • staff training and policies, with people who have passed, one who did not reach the pass mark, one part-way through and one running late
  • the school year: term dates loaded from the published state calendar, a pupil-free day, an unplanned closure, and children on a fortnightly travel pattern
  • maps and route lines, with recorded journeys to play back
  • the parts that exist because real information arrives imperfect — two records of the same bus stop, drivers reporting that a stop's position is wrong, and a school's spreadsheet part-way through review with rows that could not be matched
  • families using the parent portal: walk-home permission requested, granted and declined, contact details updated and confirmed, and photographs submitted for approval
  • vehicle workshop items, documents, message history, and the record of who has looked at a child's information

Everything was created the way the product itself creates it, so what the demonstration shows is what the platform actually does — not an approximation assembled for display.

Checks so this cannot quietly happen again

Two checks now stand behind it. An automated one confirms that every part of the system has sample data behind it, and points out anything new that does not. And when a release is prepared, the release process now asks whether what is shipping needs the demonstration updated — recording the answer either way, so the decision is deliberate rather than forgotten.

[1.53.0] - 2026-08-24

  • The day headings on the attendance register now stay put while you scroll. On a long route you could end up part-way down the list ticking a column of identical boxes with nothing on screen to say which day, or whether it was the morning or the afternoon. The weekday and the AM/PM labels now stay in view however far down you are, and the list scrolls underneath them. The same applies to the register in the bus app, where the grid runs a fortnight wide on a small screen.
  • You can search the register for a child. Where the list is long, a Student box above it narrows the grid to the children whose name you type. Names match in any order, so you can type a name as you heard it, and a count tells you how much of the list you are looking at. Press Escape to bring everybody back. Marks you have already made are untouched while the list is narrowed — hiding a row changes nothing about it.
  • Drivers can now tell you who they have asked to cover for them. When a driver books time off, they are offered the chance to name who is taking each affected run — and most of the time they already have someone, because drivers sort cover between themselves before they ring in. Until now that conversation stayed between them: you were told the run had no driver and started ringing round for the person they had already spoken to.
  • A different person can take each run. A week off is rarely covered by one person. Each run gets its own suggestion, so one driver can take the Monday and another the Tuesday, and any run nobody was found for is simply left blank.
  • The job that reaches you changes accordingly. Instead of "this run has no driver" you get "approve or decline", and it takes you straight to the decision — who is away, which runs are affected, who they suggested for each, and their note. Approving puts that driver on that run as relief, for that date only; the usual driver comes back automatically afterwards.
  • You decide each run separately. Take the ones that suit you and turn down the ones that do not — approving four and declining one is a normal outcome, not a workaround. Everything is ticked for you by default, since agreeing with the lot is the common case.
  • Each suggestion is re-checked at the moment you approve it, not the moment it was made. Somebody suggested three weeks ago may since have booked their own leave, had a check lapse, or been put on another run that morning. Anything that has gone stale is flagged on screen before you commit, and is skipped rather than quietly producing a roster that looks solved and is not — the rest of your approvals still go through.
  • Declining does not cancel the driver's time off. Their leave was never waiting on you — it took effect the moment they entered it, and they are already off the runs. You are only deciding who drives. Turn a suggestion down and that run goes straight back to needing a driver, and stays on your coverage screen until you cover it. Nothing goes quiet.
  • Drivers only see people who can actually take that run. Somebody already driving, away themselves, or without current tickets for the day is not offered. Where nobody can, the driver is told plainly for that run and that you have it in hand — rather than being shown an empty box that looks like a fault.
  • You can now record which depots a driver works out of. On a person's record, tick as many yards as apply — the driver who covers two towns is exactly who this is for. It is used to put the nearest people at the top of a cover list, and it is a suggestion rather than a restriction: you can always roster somebody from another yard. Leaving every box clear is a proper answer and means "offer this person for any run", which is what the app assumes when nothing is recorded, so nobody is left out of cover for having no depot against their name.

[1.52.0] - 2026-08-21

  • The child picker when marking someone away is now searchable, and tells two children with the same name apart. It used to be a plain list of names, which on a register of several hundred meant scrolling — and where two children genuinely share a name, there was nothing on screen to say which was which. You can now type a name, and where a name belongs to more than one child the year level is shown beside it. It appears only where it is needed, so the ordinary list stays clean.

  • Why that mattered. Picking the wrong child means one child marked away who is in fact travelling, so the driver does not wait for them, and another left expected who is not coming. Names on their own could not always tell you which was which.

  • The separate "Report a student not travelling" page in the school portal has been removed. Everything it did is on the attendance register, which also shows what has already been recorded, who recorded it, and whether you can clear it — none of which the old page could. One change to note: the old page could repeat an absence weekly until a date, and the register cannot. A recurring absence is now entered as days; a child who is never at school on a given weekday belongs in a school roster instead.

  • Demo and training data now uses realistic names. The sample children were drawn from a short list, so the same name came up often enough to look like a fault. A handful of shared names remain on purpose, because that is what a real school looks like.

  • The school portal now opens on the attendance register. A school contact signing in lands straight on the week's register, which is where the work is.

  • The separate "Today's students" page has been removed. It listed the school's children with this morning's and this afternoon's status — the same thing the register shows in its columns for today, alongside the rest of the week. Two screens answering "is this child travelling today" could be caught disagreeing about a child, and had been. Which service a child is on is now the register's route filter, and where more than one bus company serves a school, the company's name sits under each child's name on the grid.

    One difference is worth knowing about when a school asks: the register is built from bus stop assignments, so a child enrolled at the school who has not been given a stop does not appear in the portal at all. The old page listed them as unassigned.

[1.51.0] - 2026-08-21

  • A new "All on" button boards everyone waiting at a stop in one tap. Marking a full kerb on one at a time is not something a driver can do while looking after a bus, and until now only the set-down side had a bulk option. It sits beside Arrived, and it will never touch a child who has already been marked — not one already on, and not one marked absent. Its count drops as children are marked by hand, so the number on the button is always what the tap will actually do.

  • The four stop controls now sit in a fixed two-by-two block and stay put. Arrived and All on on top, the stop's bulk action and Departed underneath. They used to appear and disappear depending on the stop, which meant hunting for them; now they hold the same position all run and simply grey out when there is nothing left for them to do.

  • All on works with no signal, like the controls beside it — saved on the device the instant it is tapped and sent when coverage returns, with the children's rows updating on screen straight away.

  • The office can now see when a run's recorded times don't match what the driver actually did. If the tablet loses signal, the actions it saved are sent when it reconnects. Where one of those is refused, the driver has to enter the stop again — and until now that stop kept the time of the second entry rather than the time the bus was really there, which could be an hour out on a long stretch without coverage. Nothing on the run looked wrong: the numbers balanced, the end-of-run check was recorded, and every automatic check passed.

    The run review page now compares what the driver did on the tablet against what the run recorded, and flags anything the run has no record of. It says plainly when it cannot make the comparison — a tablet that never regained signal sends nothing, and that is not the same as a clean run.

    There is also a nightly check for runs whose stop times contradict the route order, which cannot happen on a road and always means the record was written after the fact.

  • A stop entered again after a failure now keeps the original time. Where the tablet's first attempt is refused, it remembers when the bus was actually at that stop and uses that time when the driver enters it again, instead of the time they pressed the button.

  • When a stop won't let you mark Arrived, the app now tells you why — and takes you to the stop that needs closing. Only one stop can be open at a time, because the bus is one bus. If an earlier stop is still open, Arrived is greyed out on the stop you're at. The message used to say only that the earlier stop was still open and to mark it departed first, which left the most useful part unsaid: a stop set to wait for its timetabled time will not let you leave while children there are still unmarked. So the driver was sent to a button that then refused them, with nothing on screen explaining the difference.

    It now says how many children are still to be marked at that stop, and adds a Go to button that jumps straight back to it. From there it is one tap — either mark the children who are still outstanding, or press Departed and give a reason — and the stop you are actually at becomes usable immediately.

    This matters most at the school on a morning run, where the whole load gets off and the screen that lists everyone on the bus only appears once the school stop is marked arrived. The Go to button is a plain link to the same screen, so it works with no signal.

  • The driver app now tells us when something on a tablet goes wrong, without waiting for someone to report it. Some faults on a device are completely silent: a screen draws correctly, a button looks normal, and tapping it does nothing at all. Until now the only way anyone found out was a driver noticing and calling in — after the run, if at all.

    The app now notices these itself and records them alongside the other diagnostics from that device, so they show up when the run is reviewed. What it records is technical only: which kind of fault, and where in the app it happened. It never records anything about the children on board, and it never delays anything the driver has recorded — sending a diagnostic always waits behind the records that matter.

  • We can now tell which version of the app a tablet is actually running. The driver app never updates itself in the middle of a run, on purpose — a driver takes a new version deliberately, when the bus is stationary. That means two tablets in the same depot can be on different versions for a while, which is fine, but it made some reports hard to place: a device that had not been updated yet and a genuine fault looked the same from the office.

    Each device now records its version when it changes, so that question is answered on the run review instead of by ringing the driver.

  • Internal: better tooling for checking how each screen looks on the tablet sizes and phone sizes drivers and parents actually use, and a fix to a testing fault that could make unrelated checks fail and point at the wrong thing.

  • Importing a route now checks whether a stop already exists before adding it again. Imports match stops on the stop number in the contract, and two contracts can give the same physical place two different numbers — which is how a depot ended up in one operator's list twice, under two names and two street numbers on the same road. Each new stop is now compared against the ones you already have, and anything that looks like a repeat is flagged for you to look at.

  • The warning sits on the stop's own page, on both stops, and says why the two look alike. If they are the same place you can remove the wrong one; if they are genuinely different, mark them as different and no future import will raise the pair again.

  • Nothing is merged automatically. In the case that prompted this, the stop number, the name and the address all differed — so the evidence is circumstantial and the decision stays yours. The check is also deliberately quiet: several stops on one street is normal and is not treated as a repeat on its own.

  • An import now tells you when a stop could not be located from its address. That stop has no arrival zone, so arrival there has to be marked by hand until someone sets its position. Previously this happened without saying so.

  • A stop that no route uses can now be deleted. Until now a stop created by mistake — a duplicate that arrived with an imported timetable, say — could only be renamed. Its page now has a delete panel that tells you where the stop stands: if nothing has ever called there you get a Delete button, and if something has, the panel says what is holding it instead of leaving you guessing.

  • A stop a bus has actually served is never deletable, and the page says why. Runs that called there still hold what happened — when the bus arrived, and who got on and off. That record only makes sense while the stop exists. Taking the stop off the route is the action for that, and it already removes it from every future run straight away.

  • Marking a stop inactive is not the same as removing it, which the guide now says plainly. The tick is a label; it does not take the stop out of the list or out of the picker when you build a route.

[1.50.0] - 2026-08-19

  • The driver app now makes sure it has been given location, and asks for it if not. On some phones and tablets the app never asked for location at all, and there was nothing on screen to say so. A driver in that position drove the whole run without it: stops did not tick themselves off on arrival, the office could not see the bus on their map, no hazard warning could be given, and no position was recorded against the children getting on and off. The run itself worked — every stop was marked by hand — but nobody found out until afterwards.

    Two things have changed. The app now starts location tracking on its own rather than waiting for the map, so the request is made even on a device where the map cannot be drawn at all. And the driver's runs list now checks whether location has actually been allowed: if it has not, a card at the top offers to turn it on, at the depot, before anyone is driving.

    If location has been blocked in the device's settings, the app cannot ask again — so instead it shows the steps for the phone or tablet in the driver's hand, and clears the message by itself once the setting has been changed. It also points out the trap that catches most people: a phone treats an app added to the home screen and the same app in the browser as two separate apps, so allowing location in one does not allow it in the other.

    Where location is already working, nothing appears at all.

[1.49.1] - 2026-08-19

  • The run map now opens zoomed to the run. Opening a run from the dispatch board showed most of the state, with the run's stops a single dot at the edge of the map — you had to zoom in by hand every time before it told you anything.

    The map now opens framed on the run: its road path, its stops, and where the bus actually travelled are all in view. The road path was also missing from that map entirely, for the same underlying reason, and is now drawn.

[1.49.0] - 2026-08-19

  • Inspections now show one line per run. The register listed the before-the-run and after-the-run checks as two separate rows, leaving you to work out that they belonged together. Each run is now a single line showing both checks side by side, with their times and outcomes.

    A run that was checked before but not after now says so plainly, instead of the second check simply being missing from the list.

    You can still see every check individually — there is a switch above the table. Nothing about the records themselves has changed: each check remains its own permanent entry that cannot be edited or deleted.

  • Drivers can now clear a mis-tapped child even with no phone signal. If a driver taps the wrong child, the CLR button on that child's tile takes the record back. Until now that button only worked where there was coverage — so on a run through a patchy area, the only button that responded was the one that marks a child absent. Drivers were using it to undo a tap, which left children recorded as absent when they simply were not on the bus that day.

    CLR now works the same way every other tap does: it is held on the device and sent when signal returns. It also appears straight away after a tap, rather than only after the screen next reloads — which was the moment it was most needed and least available.

    Clearing a record still asks for confirmation, and still says the child is not marked absent — it simply takes the entry back.

  • Checklist questions now show the answer buttons you set up. If you built a question with a set of answers to choose from — multiple choice, a dropdown, tick boxes or a number — the driver was shown an empty box to type into instead, and the answers you wrote never appeared. They now appear as real buttons, sized for someone standing at a bus rather than sitting at a desk.

    This affected the questions you add alongside your safety checks. The Pass/Fail safety checks themselves were never affected and always showed their proper controls.

    One question type — attaching a file — still shows a text box. Letting a driver upload a file from the roadside raises questions about storage and privacy that we want to answer properly before turning it on.

  • Your checklist now appears in the order you built it. Questions were being regrouped on the driver's screen — all the Pass/Fail checks first, then everything else — no matter how you had ordered them. Since operators sequence a checklist to match the way a driver walks around the bus, that could send them around it in the wrong order. The checklist now follows your order exactly, on the driver's screen and in the preview.

  • The driver app now confirms it has the road hazard list. The run screen warns a driver when the bus is approaching a reported hazard. Until now, a driver who saw no warning had no way to tell the difference between a clear road and a warning that was not working — both look exactly the same from the cab.

    The app now records whether the hazard list actually reached the device, so that question can be answered afterwards rather than guessed at. The driver's diagnostics screen also states plainly how many hazards the device is holding, and says so when it is holding none because the list never arrived.

    Nothing changes in how the warning itself behaves.

[1.48.0] - 2026-08-19

  • The estimated arrival now sits at the top of the run screen, and it counts down. It shows three things together — the time the bus is expected at the next stop, the minutes left, and how far along the road is left:

    07:42 ETA · 4 min · 2.6 km

    It stays at the top of the screen, so it doesn't scroll out of sight while a driver works through the children at a busy stop.

    The clock time deliberately holds steady while the bus is running to time — that is what it is for. If the bus keeps the pace the route usually keeps, the arrival time does not change, and a number jumping about would be harder to trust rather than easier. The minutes and the distance are the ones that move. Get held up and the arrival time moves later; make up ground and it moves earlier.

    Previously only the clock time was shown, which meant a driver running to time saw a figure that never moved and reasonably read it as stuck.

    Where the app genuinely cannot work out an arrival — no recent position, the bus not on the road the route usually takes, or a skipped stop with no recorded run between here and there — it now shows nothing rather than a figure that would look right and be wrong.

[1.47.1] - 2026-08-19

  • The driver app now moves through a run with no signal at all. Marking a stop as departed moved the screen on to the next stop only once the app had reached the office. With no coverage that never happened, so the screen stayed on a stop the bus had already left for the rest of the run, with the stop the driver was actually driving to further down the page.

    The screen now moves on the moment the driver taps, whether or not there is signal, and the record still syncs quietly in the background as it always did. If the office refuses the departure — most often because the bus is being held until its published time — the screen goes back to that stop rather than leaving the driver on the wrong one.

    With no signal the next stop shows names rather than photographs until the app is back in coverage. Everything on it works either way.

  • A stop the bus has already left no longer shows the children's photographs. Those faces belong on the stop the driver is working, not on the list of stops behind them.

[1.47.0] - 2026-08-18

  • The driver app's run screen now loads in well under a second. On longer routes it had been taking several seconds every time, and because the screen refreshes itself each time a driver marks a stop as departed, that delay was landing at exactly the wrong moment — the run would appear to sit still after leaving a stop, sometimes for a minute or two, before catching up. It was doing far more work per stop than it needed to. On a full route it now does a fraction of that work.

  • The estimated arrival time now updates as the bus drives. It was worked out from the last stop the bus recorded plus how long that stretch of road usually takes, which meant it could not tell whether the bus was running to time — hold the bus up and the estimate would sit unchanged until it arrived. It is now based on where the bus actually is and how much of the road is left, so it responds while there is still time to act on it.

    A bus running behind now shows a later arrival, and one running ahead shows an earlier one.

  • Skipping a stop no longer leaves a misleading arrival time. When a driver marked a stop as not visited, the remaining estimates were still being worked out as though the bus were driving to it and back — which on a stop well off the main road put the estimate out by more than twenty minutes. Where the bus can be located on the road ahead, the estimate is now based on that. Where it cannot, no time is shown at all rather than a figure that looks right and is not.

  • On Android tablets, the child's name and their on-board marker are visible again on the run screen. In landscape on those tablets the photo was taking more room than its tile allowed, so it pushed the name and the ON/OFF marker out of view — leaving the driver a cropped photo and nothing else to go on. Both are back, and the tile now looks and behaves the same as it does on an iPad, sized to the screen.

    Please have a driver check the boarding screen on your own tablets after this update.

  • The driver app now uses the full screen on Android tablets, the way it always has on iPads. On the tablets many operators mount in their buses it was falling back to the phone layout — the logo and the menu taking the top two thirds of the screen, with the run list pushed off the bottom before the driver could see it.

    Landscape tablets now get the side menu, so the run list starts at the top of the screen where it belongs. Phones and tablets held in portrait are unchanged.

    On shorter screens the logo is a little smaller, so every menu item — including Refresh — fits without scrolling.

  • A route can now say which depot it runs out of, and drivers see the buses parked there. When a driver's bus fails its morning check and they pick another one, the list is the buses based at that route's depot rather than the whole fleet. On a large fleet that's the difference between scrolling for the right bus and seeing the few that are actually in front of them.

    Leave the depot blank and nothing changes — the driver sees every available bus, as before. You don't have to go and set it on every route for this to be safe. If a route has no depot, Tutela uses wherever the bus being replaced is based, so it usually does the right thing before you've set anything at all. A bus with no depot recorded is always offered, so a blank field on a bus never takes it off a driver's list.

    It narrows the list, it doesn't enforce anything. A driver who has genuinely walked to the next yard can still take a bus from there. What a bus may not do is still decided by its status and its faults.

  • Questions that only appear when they're needed now actually work on the bus. You could already set a question to show only when another one is answered a particular way — and the setting saved, and the driver was asked it anyway, every run. That's fixed: a conditional question now stays out of the driver's way until its trigger is answered.

    A question the driver was never shown is treated as never asked, all the way through. It can't hold up a check for being unanswered, it can't ask for a photo, and it can't book a fault or take a bus off the road. If a driver answers a follow-up and then changes their mind about the question above it, the follow-up clears itself.

    One deliberate safeguard: if anything at all is unclear about a condition — including one pointing at a question you've since deleted — the question is shown rather than hidden. Being asked something that didn't apply costs a tap. Not being asked something that did is a check nobody did.

  • The checklist preview is now a working form you can fill in. It shows what the driver sees, with real controls, so you can answer your way through a checklist and watch it behave — including whether a conditional question appears when you meant it to. Until now it listed the questions with the fields switched off, so there was no way to try a form short of putting it on a bus and driving.

    Nothing you enter in the preview is saved. There's no fault raised, no reading recorded, and no bus affected — it's a rehearsal.

    The summary of what the run asks, with each question's severity and how often it's asked, is still there above it. Both come from the same place, so they can't tell you different things.

  • You now get a once-a-day summary of your outstanding tasks, with anything urgent listed first and called out separately. One email, not one per task — and none at all on a day when you have nothing outstanding.

  • Cover alerts only interrupt when a bus is genuinely at risk. A driver booking time off for next term is something to plan around, so it waits in your daily summary. A run still without a driver within a week is escalated and emailed on its own. If you have already assigned a relief driver, the alert is never sent — covering the gap closes it for you, with nothing to dismiss.

  • Spare buses now have a status of their own: "Out of service". It means a bus that is perfectly fine but not in daily service — the one sitting in the yard ready to cover. Until now the only place to put it was Grounded, which is meant for a bus with a fault.

    A spare can still be driven, and that is the point. It appears in the roster's bus list and in the driver's bus picker, marked (spare), so a driver whose bus fails its morning check can take it and go without ringing the depot.

    Grounded now means a fault, and only a fault. That makes the grounded count on your dashboard worth reading again — it is the buses with something wrong with them, not the ones you have parked up. It also avoids an awkward corner: putting a bus back on the road follows fixing the fault, so a serviceable bus marked grounded was one you could not clear the normal way.

    If you are importing your fleet from a spreadsheet, phrases like "Out of service", "OOS", "Off road", "Suspended", "Inactive" and "Spare" all come in as Out of service now. Nothing in a spreadsheet can mark a bus as grounded any more — a fault is something someone finds on a bus, so those lines are handed back to you with their line number and you decide.

[1.46.0] — 2026-08-18

  • You can now book a relief driver straight from the coverage screen. Where a run has no driver — because the usual one has told you they are unavailable, or nobody is rostered — a Cover button opens a short screen listing the drivers who could actually take it, and you pick one.

    Only drivers who can genuinely do it are offered: cleared to carry children that day, not someone who has booked the day off, and not already driving another run at the same time. If nobody qualifies, the screen says so and explains why rather than showing an empty list.

    Cover applies to that day only — the route's usual driver returns automatically afterwards, with nothing to undo. If the run already exists the driver sees it on their app straight away; for a date further ahead, the run is created with the relief driver already on it.

  • A child marked as not at school now stands out on the run page. On the live run view, that state used to render as plain grey text, which looked the same as a child nobody had scanned yet — two opposite meanings with the same weight. It now carries its own colour, so at a glance you can tell the children the school roster says are not in today from the ones still waiting on an answer.

[1.45.1] — 2026-08-18

  • Near misses and incidents no longer appear on drivers' maps, and have their own screen in the driver app. Only hazards — conditions on a road, like a collapsed kerb or a blind exit — are pinned on the map for other drivers. A near miss or an incident is an account of something that happened to a person, so it now goes to the office to be looked into rather than to every tablet in the fleet. If a near miss shows a stretch of road is genuinely dangerous, the office raises a hazard for it, which is the record that warns everyone. In the driver app, tapping Near misses & incidents now opens its own list instead of the hazards one, and it shows only reports that driver filed or is named on — nothing they are unconnected to. A driver still sees everything they reported themselves, whatever kind it was.

  • You can now book a morning or afternoon off across several days at once. If you can drive one run but not the other — a show week, a course, a standing commitment — set the first and last day and choose Morning run only or Afternoon run only. It now applies to every one of those days, instead of having to be entered a day at a time or declared as a full day you did not need to take off.

    When you save it, the app tells you in plain words which way round it was taken — for example that you are off every afternoon run between those dates and still expected on every morning one — and that sentence stays on the declaration so you can check it later.

    A validation message that appeared twice on this screen now appears once.

  • Opening a finished run now shows you what actually happened. The stops list gives you the time each stop was due, the time the bus arrived and the time it departed, side by side, with the difference marked where it ran early or late. The map shows the route the bus was meant to take, every stop on it in order, and the track of where it actually went — so you can see at a glance where a run deviated. Previously a finished run showed an empty map and a list that said a stop was departed without saying when.

    While a run is in progress the bus still shows on the map as it always has. That marker is the only thing that disappears once a run ends, because it is the only part that stops being true.

    Early is shown as plainly as late, and neither is marked as good — at a pickup, a bus that beats the timetable can leave a child at the kerb.

[1.45.0] — 2026-08-18

  • A driver's day off now actually takes them off the run, and tells you urgently. When a driver enters time off for a day whose runs have already been set up, those runs come off them straight away and an urgent task is raised naming the runs that need cover — so it reaches you without anyone having to open a screen. The run also disappears from that driver's own schedule, so nobody is left thinking they are still expected. Withdrawing the time off puts them back on and closes the request; rostering a relief driver closes it too, with nothing to tidy up. A run that is already under way is never changed, and neither is a completed one — a bus with children on board is never re-rostered underneath its driver.

  • A new Coverage screen shows which runs have nobody to drive them, weeks ahead. Found under Operations, it looks forward across the next fortnight, month or term and lists every scheduled run with who is rostered and whether they can actually take it. Where a run has nobody, it says which of three things is wrong — no driver rostered at all, a rostered driver who has told you they are away, or a rostered driver whose working with children check is not current — because each needs something different from you. The last of those is the one that otherwise looks fine everywhere until the driver is stopped at the depot. Days when a route's school is closed are left out, so holidays do not fill the screen with gaps that are not gaps. It works well beyond the point where runs have actually been created, which is what makes it useful for arranging relief cover while there is still time.

  • Drivers can now tell the office about days they will not be available. A new Time off screen in the driver app lets a driver enter a day, or a stretch of days, they cannot drive — all day, or just the morning or afternoon run — along with an optional note. It goes through the moment they save it; there is nothing to approve and no phone call to remember. A driver can see everything they have entered, including days that have already been, and take one back if they can work after all. Taking one back asks them to confirm, because that is the direction that can leave a run short. This is the first part of a larger piece of work on seeing coverage gaps early enough to arrange a relief driver.

  • A new Inspections screen shows every completed bus check. Under Fleet → Inspections you can now see the pre-start and post-run checks your drivers have completed, opening on today by default and filterable by date, bus, driver, whether the check was before or after the run, and whether it passed. Each row links through to the bus and to the run it belongs to. Previously the only way to see a completed check was to open one bus and scroll its compliance page, which showed its last fifteen and could not answer whether a particular day's runs had been checked at all.

    Nothing on this screen can be edited or deleted, deliberately: a check is the record that someone walked around a vehicle before it carried anybody, and a record that can be changed afterwards is not a record. Where a driver has re-run a check after a fault was put right, both are kept and the earlier one is marked as replaced, so you can see what happened rather than wondering why a bus appears twice.

  • The driver app no longer waits on the network when a driver taps something. Arriving at a stop, departing one, and marking a child on the attendance grid are now always recorded on the device first and sent in the background. Previously the app would try to reach the office directly whenever the phone reported a connection — and a phone reports a connection on one bar in a tunnel, so on patchy coverage the app could sit for many seconds before falling back to saving it locally. Taps are now instant everywhere, and worst on nothing.

  • A stop no longer jumps forward and then back again. This was the same problem seen from the driver's seat: the screen moved the stop on straight away, then undid it when the slow request eventually gave up. With the wait gone, the flicker goes with it.

  • Screens that check with the office now give up gracefully instead of hanging. Checking a route, refreshing a run, and syncing the week's roster each have a time limit. If the office cannot be reached they say so promptly and carry on with what is already on the device, rather than leaving a driver watching a control that never answers.

  • Locking the app after a period of inactivity is now immediate. It previously waited to hear back from the office before showing the unlock screen, which in an area with no signal meant a long pause on a screen that had already decided to lock.

  • Two taps in the same second are both sent. When a driver tapped two children together, the app could start sending the first and quietly set the second aside, with nothing to pick it up again — so a boarding could sit unsent until the driver reloaded the screen, which is not something anyone should be doing while driving. The app now always checks again before it finishes sending, so nothing is left behind.

  • Anything still waiting to send now retries on its own. Until now the app only tried to send when a driver did something, when the phone announced it was back online, or when the run screen was opened. If something was missed in between, it waited. The app now sweeps up anything outstanding by itself, trying again less often the longer it keeps failing so it doesn't drain the battery, and immediately when the phone comes back into coverage. Nothing on a run should ever depend on a driver noticing, and nothing should ever need the screen reloaded at the wheel.

  • Attendance marks made without signal now actually send. Marking a child as not travelling from the fortnight view while out of range would tell the driver it would send when back in range — and then never send it, leaving the office planning around a child whose absence never arrived. These are now delivered as soon as there is a connection, and always after anything recorded about a run in progress.

[1.44.1] — 2026-08-18

  • The hazard warning on the driver map is easier to read. It is now solid rather than see-through, and the map's own buttons move out from behind it while a warning is showing, so the distance and the Dismiss button are never obscured.

  • The last stop of a run lays out properly. When the end-of-run steps appear alongside the stop, the stop's buttons no longer overlap them. Nothing on that screen can now be covered by something else.

  • The expected arrival time keeps up when a bus is delayed. Previously it was worked out when the stop was left and then stayed put, so a bus held up on the road went on showing a time it had already missed. It now moves with the clock once a bus is running behind, and the delay carries through to every stop still ahead. The driver's screen also refreshes the time while travelling rather than only when a stop is reached.

  • The saved signature shows on the end-of-run check. Drivers who have saved a signature saw a broken picture where it should have been. The check itself always recorded correctly; only the preview was affected.

  • The driver Safety screen counts hazards and incidents separately. Near misses and incidents now have their own card with their own count, because they are handled differently — a hazard is something to fix or accept, while a near miss or an incident is something to look into. Nothing new is visible to a driver who could not see it before.

  • The end-of-run steps now wait for the depot. On a route that returns to a depot, the sweep and the finish controls appear beside the stop only once the bus is parked there. They used to appear at the last stop children get off at as well, which is a bus that is neither empty nor finished with. On a route that ends at a kerb, nothing changes — that stop is still where the run is closed. The steps remain reachable at the foot of the run screen at any time, so a driver who has to finish early is never held up.

  • "Standing condition" now applies to hazards only. It marks something nobody is going to remove, so that drivers keep being warned about it without it sitting on the outstanding work list forever. A near miss is an event rather than a condition, and belongs on the path where somebody asks what happened.

[1.44.0] — 2026-08-17

  • Drivers now see when the bus is expected at each stop still ahead. Each upcoming stop on the driver's screen shows a predicted arrival time and whether that is on time, early or late against the published time. The prediction is built from how long the same bus has actually taken between those stops on previous runs, so it reflects the route as it is really driven rather than a generic estimate. It disappears once the bus arrives, because at that point the recorded arrival is the better answer.

    Where there is not yet enough history for part of a route, no time is shown for the stops beyond it. We would rather show nothing than a figure we cannot stand behind.

  • You can set how long the bus stands at each stop. Alongside the existing hold setting, each stop on a route now takes a "stops here for" time, which feeds the predicted arrivals above. Left blank, we assume a minute at an ordinary stop and seven at a school. Setting it to zero is respected for a stop the bus passes without waiting.

  • Fixed: the school details page overstated what changing a bell time does. It said that changing a bell time changed what services are timed against. It does not — a service's timings are held against the route itself, and updating a bell time records the new time without moving any service. That claim has been removed. The page still explains that every operator serving the school sees these details and that a change reaches all of them at once, both of which hold. Making a bell time change reach services properly is work we have now scheduled.

  • Fixed: the school details page pointed name corrections at the wrong people. A school's name and official code are held centrally, because every operator's passenger list finds the school by name. The page invited schools to raise a correction with their bus operator, who has no way to make one. That wording has been removed.

  • New policies now suggest a review date a year out. When you write a policy or procedure, the "review it by" date arrives already set to twelve months ahead, rather than blank. It is still yours to change: move it if the policy needs looking at sooner, or clear it entirely if it does not need a scheduled review — and it stays cleared. Publishing a new version starts the twelve months again, on the reasoning that rewriting a policy is reviewing it.

  • Fixed: a stray piece of code showed in the browser tab. The policies and procedures list displayed an ampersand as raw characters in the browser tab title. Display only, now corrected.

[1.43.0] - 2026-08-17

  • Fixed: on newer tablets, the driver's stop buttons could sit under the home bar. On a tablet with a rounded, buttonless screen, the controls at the foot of the driver's stop card — Arrived, Departed, Nobody here — could be drawn partly beneath the thin bar at the very bottom of the display. That strip belongs to the device, which takes the first tap for itself, so a driver at a stop could press the button and see nothing happen. Those controls now keep clear of it. On tablets without one, nothing has moved.

  • Changed: the driver's run screen now decides its layout by how the tablet is held. Turn the tablet landscape and the map sits beside the children; hold it upright and the map moves to a band across the top, giving the children the full width. Previously that choice was made on the tablet's width alone, so two tablets held the same way could show two different screens — a large tablet held upright got the side-by-side layout meant for landscape, while a smaller one turned sideways did not. Drivers moving between tablets now get the same screen for the same grip, whatever the device.

  • Improved: the driver screen is now checked automatically across far more tablets. Our automated checks now cover Android tablet sizes and smaller 7-inch tablets alongside the iPad sizes already covered, each in both portrait and landscape, and on the browser engine iPads themselves use. Every size passes.

  • Fixed: a run review no longer raises the same alarm twice. Reviewing a run could show two separate critical findings that were really about the same children — once as children with no record of any kind, and again as children still waiting when the bus left. The second is now raised only in the case that genuinely warrants it: leaving a stop ahead of its allocated time without everyone aboard.

    Ordinary departures still show the number of children outstanding against each stop, where it belongs. That count was never meant to stand on its own — leaving a stop with children outstanding usually just means nobody was there — and treating it as an alarm put a critical warning on runs where nothing had gone wrong, which made the finding that does matter easier to miss.

  • Improved: a checklist can now be read at a glance. Each question in the builder shows its three safety settings on its own row — what a failure means, how often it's asked, and whether it belongs before or after the run — instead of only inside the panel you open one question at a time.

    It was the difference you most needed to see that was hardest to spot: a question that can take a bus off the road and one that is only there for information look identical in the list. Now they don't. Hover a badge for the longer wording, and for a weekly question, the days it appears on.

    Every question shows all three, including the ordinary ones, so a blank row never has to be interpreted. The row updates as you change a setting, so the list and the panel can't disagree.

  • Fixed: questions the driver app asks now open over the top of everything. One of them — the question asking why a bus is leaving a stop ahead of its timetabled time — could open underneath the map, so the wording and some of the answers were cut off down one side while the button to carry on stayed in plain view. That was the wrong half to be readable.

    The underlying cause applied to every dialog in the driver app and in the office console, not only that one, so all of them were changed rather than the one that was reported.

  • Fixed: the contact button no longer covers the children below it. On the stop screen, the wide Contact bar sat over the row of cards underneath — covering their names, and putting its own button on top of theirs, so a tap meant for one child could land on a control belonging to another.

    It is now a round button in the top corner of the child's card, matching the absent button opposite it, and the numbers open over the top of the screen instead of pushing the cards about. Nothing about who is listed has changed: parents first, who may collect still marked, still there with no signal, and still behind a tap so a cab screen isn't showing every family's phone numbers all run.

[1.42.0] — 2026-08-17

  • New: set a servicing schedule once and apply it across the fleet. "An A service every 10,000 km or 6 months, whichever comes first" is now something you write down once and put as many buses on as you like, instead of a next-due date somebody has to remember to type onto every service record.

    This closes three gaps that were easy to miss because none of them produced a warning. A newly added bus had no schedule at all until its first service. If one workshop invoice never got entered, the chain simply stopped and nothing was ever due for that bus again. And the interval had to be re-entered correctly, from memory, every time.

    Each bus now shows when it is next due — by date and by odometer, whichever arrives first — on the schedule's own page and on the bus's compliance page, and you get a task ahead of time that closes by itself once the service is recorded. A bus that is on no schedule says so plainly, because "nothing is watching this" and "nothing is due" are very different things.

    Two rules worth knowing. If your mechanic wrote a next-due date or reading onto the service record itself, that still wins — they had the vehicle in front of them, and the page tells you when it is happening. And where a reading is missing or unconfirmed, the platform says what it cannot work out rather than guessing, because a warning built on a number nobody has confirmed is worse than no warning.

    A schedule can be retired but not deleted, so what your fleet was maintained to stays on the record. Individual buses can be taken off one at a time, and their service history is untouched.

  • New: keep a list of the businesses you buy work from. Workshops, inspection stations, tyre fitters, parts suppliers, insurers. Record one once and every service and inspection can say who did the work, instead of repeating a name somebody typed — so you can finally ask what you have spent with a workshop, or who last signed off a bus.

    Names are one row whatever the capitals, so "Boddington Auto" and "boddington auto" stop being two different businesses. Anyone who can record servicing can add a business; it does not need an owner, because the person entering Friday's inspection is the person who knows who did it.

    A business is never deleted — you retire it, and it stops being offered on new work while every record that already names it stays exactly as it was. On an inspection that name is the record of who certified the bus was roadworthy, and it stays available on that record's own form even after the business is retired, so correcting a cost can never quietly drop it.

    Opening a business shows everything attributed to them and what has been recorded against them — stated as a floor, with a count of the jobs that have no cost recorded, rather than a single figure that would read as the whole story.

  • New: match up the supplier names you typed before. Everything recorded before you had the list carries a typed name and no business attached. A screen now lists those names, says how many records carry each one, and lets you point them at the right business in one go — or create it from the name itself.

    Nothing is matched for you, on purpose. Guessing that two similar names are the same business would sometimes be wrong, and a wrong guess would credit a statutory inspection to a business that never did it while making the record look more certain than it was. The name you typed is never deleted either; matching adds who that was, it does not replace what was written at the time.

  • Changed: importing a fleet now shows you your spreadsheet before anything is written. Uploading takes you to a review screen showing your whole file — every column and every row — with a box at the top of each column saying where that column is going. Columns that aren't being imported are greyed out, each row is marked as one you'll be adding or one that will update a bus you already have, and nothing is saved until you press Import. When you do, the same table fills in: green where the vehicle imported, amber where it imported but one of its fields couldn't be read, red where the row couldn't be imported at all — with the reason beside the row it belongs to, and the reasons grouped above so you can see the shape of the problem at a glance.

  • Fixed: one unreadable field no longer costs you the whole vehicle. If an optional field held something we couldn't read — an unfamiliar fuel type, or a depot you hadn't set up yet — the entire bus was refused. Now the bus imports and that one field is left empty for you to fill in, with the cell marked so you can see exactly which one. Only the fleet number, registration and status can stop a row. This could previously refuse an entire file: if an import of yours came back with nothing imported, it's worth trying again.

  • Fixed: an import that achieved nothing said so in green. When no vehicles could be imported, the result was still shown as a success message with a tick. It now reads as the warning it is.

  • Fixed: the family contact list confirmed things twice. Adding or removing a contact showed the same confirmation message twice over. Harmless to look at, but a parent using a screen reader heard it announced twice, one announcement cutting across the other. It now appears once.

  • New: drivers can see each child's year level on the run screen. It shows beside the child's surname on their tile — so a driver can tell at a glance which children may be let off on their own, and can separate two children with similar names at a busy stop.

    It appears wherever you've recorded a year level on the child's record, exactly as you typed it. Children without one simply show nothing there. Nothing else on the tile moved or shrank — the photograph is the same size it was.

  • New help: signing in. The in-app help now covers how drivers sign in and set or change their PIN, and how parents and school contacts get into their portals. Both portals are passwordless — people enter their email address and we send them a link — so there is no password for you to reset, and the guides explain what to check when somebody says they can't get in.

    With these written, every screen in Tutela is now covered by a guide.

  • New: write your own policies and procedures. Under Operations → Policies you can now write a policy, format it properly — headings, bold, bullet points, links — and publish it for your team to read and agree to. Pasting from Word is fine: the formatting it brings along is stripped and your words are kept.

    Each one gets its own reference, so you have something to quote when somebody asks which policy you mean.

    Publishing a new version asks everyone to read it again, including people who agreed to the previous one — that's the point of publishing rather than quietly editing. You're asked to say what changed, in a sentence, and that sentence is what your team is told.

    A published policy can't be edited. People agreed to a specific wording, and if they signed it, their signature belongs to that wording — changing the words underneath would leave their signature attached to something they never read. To change a policy you write a new version, and the old one stays exactly as it was, alongside the record of who agreed to it. Opening a policy shows you every version, when each was published, by whom, and what changed.

    Withdrawing a policy stops it being given to anybody new. Nothing is deleted, and everyone who already agreed to it keeps that record.

    Training with questions and a pass mark is a different kind of document and isn't part of this yet.

  • Fixed: policies and inductions now read the same on every screen. The same document could appear formatted in one place and as plain, run-together text in another, depending on whether you opened it in the office or a driver opened it on their phone. Headings, bullet points and emphasis now show the same way wherever the document is read — which matters most on a policy where a bulleted list of things to check could otherwise look like a numbered list of steps to follow in order.

[1.41.0] — 2026-08-15

  • New: a stop can now have its own departure time, so a school wait isn't counted as running late. Most stops leave as soon as the bus is done, but a school doesn't — you arrive for a set time and wait while the children come out. Until now there was only one time per stop, so a bus that arrived at 3:00 and left at 3:15 exactly as planned was recorded as fifteen minutes behind schedule, every day.

    Editing a stop's timing now offers a second box, Departs (if it waits). Leave it blank for an ordinary stop. Where you fill it in, the wait stops counting as lateness, Hold if early holds the bus until the departure time rather than releasing it on arrival, and a bus that arrives late still leaves at the scheduled time so the run can catch up.

  • New: a court order now reaches the driver. Where you've recorded that a named person must not be given a child, the driver's stop screen says so plainly — the person's name, the child, and to call the office if they turn up. Until now that record reached the office and the family portal but never the one person who would actually hand the child over.

    It names the person on purpose. A warning that says only "there's a restriction" leaves a driver guessing at a door, which is the position the order exists to take them out of.

    Only a restriction you've matched to somebody on file appears there. If the order names a person you hold no record for, it stays a warning for your staff and is marked as such on the child's record. We won't put a name in front of a driver on the strength of two typed names looking alike — matching the wrong person means refusing a child's own parent, and matching nobody means a driver who thinks a check ran when it didn't. If you want an order acted on at the bus, link it to the person's record.

  • New: parents can keep their own contact list up to date. A parent opens their child's page and can add the people we'd ring if we can't reach them — a grandparent, a neighbour, a family friend — change a number that's moved, or take somebody off the list. No phone call to the office.

    Only a parent marked as a primary guardian of that child gets this, and nobody they add can sign in. Everyone on the list is a contact: a name and a number. A carer a parent allows to collect their child is still a contact — being allowed to take a child off a bus has never been the same thing as holding an account, and now the software says so rather than relying on somebody choosing the right button.

    There's a "this list is still right" button that records the date a family last checked. "It's up to the family to keep it current" with nothing prompting is how you end up with the list you already have, and an out-of-date emergency contact is only ever discovered in the one situation where it had to be right.

    Your office sees every change on the child's record — who added or removed whom, and when. Nothing needs approving; nothing happens out of sight either.

  • New: court-ordered release restrictions now do something. You could always see a warning that one existed. There was no way to record one, and nothing acted on it.

    You can now record a restriction against a person on the child's record, and lift it later. Where the person is someone you already hold details for, the child disappears from that person's view of the family portal entirely, and their permission to collect that child is withdrawn as you save. A parent maintaining the contact list cannot give it back.

    Where the order names somebody you have no record for, it's recorded as a warning for your staff and says so on the row — we've nothing to match it to, and we won't guess. Lifting a restriction keeps the record of it, with the date and who lifted it.

  • Changed: an emergency contact can no longer be given a portal account. Only a parent holds a login. If you try, the screen now explains why and points you at the tick that decides it. On a child's record, "primary guardian" and "emergency contact" are alternatives rather than two boxes.

    Related: somebody listed as an emergency contact on a child no longer sees that child in the portal, even if they hold an account through a child of their own.

  • Fixed: a form with a terms and conditions question can now be submitted. If you added a "Terms & conditions" question to one of your forms, nobody could send that form back — ticking the box was refused, and so was leaving it alone, so there was no way through at all. The message named the box the person had just ticked, which made it look like they had done something wrong. Ticking it now works, and the agreement is recorded against the response.

    If a form of yours has been getting no replies, this is worth checking: people may have tried and been unable to finish. Making the question optional is now also meaningful — before, it made no difference.

  • Fixed: a file attached to a form is now saved. If one of your forms asked for a document — a letter, a certificate, a photo of a form — the person filling it in could choose the file and send it, and everything looked like it had worked: the form submitted and the confirmation appeared. The file itself was not kept, and the question showed as blank when you opened the response. Nobody was told, so a missing document looked like the sender's oversight rather than ours. Files are now stored and appear against the response as expected.

    Anything sent before this was not kept and cannot be recovered — if you are waiting on a document somebody told you they had sent, it is worth asking them again. Files are stored privately, are not reachable from the web, and are kept across updates.

  • Added: a driver can now record a stop as not visited even after the app has marked it arrived by itself. The app watches the bus's position and closes a stop on its own when it looks like the bus has been there — which it sometimes gets wrong, because a bus driving past on the next street looks much the same. Until now that left the driver with a stop marked as visited and no way to correct it. They can now record it as not visited, and the automatic arrival is withdrawn and noted against the stop so you can see it happened.

    This applies only to arrivals the app decided on its own. A stop the driver marked as arrived themselves still cannot be recorded as missed — ask the depot to correct it — and neither can a stop where anybody has already been marked onto the bus.

  • Fixed: the driver app now recovers on its own when it gets out of step with the office. If a stop changed while the app was showing an older picture of the run, the app could keep trying to complete that stop over and over for the rest of the run, and had no way to correct itself. It now takes the office's answer whenever it is told, and moves on.

  • Fixed: tapping "skip" twice on a stop no longer takes the driver off the run screen. If the button was pressed twice — easily done when the first press gives no immediate sign that anything happened — the stop was recorded correctly the first time and the second press was treated as a mistake, replacing the run screen with an error page in the middle of a run. Pressing it again now simply confirms what was already recorded, and anything the app genuinely cannot do is explained on the run screen itself instead of taking the driver away from it. The same applies to putting a stop back on the run.

    The record was never affected: stops recorded as not visited were saved correctly throughout, along with the reason and who recorded them.

  • New: click a run on the dispatch board to watch it. The board tells you about every run at once; there was no way to look at just one. Clicking a run now opens a live view of it — the bus on a map on the left, and who is on board on the right, with the stops and how the run is tracking against them.

    It's for the moment a parent rings asking where the bus is, or an alert fires and you want to see what's actually happening — without ringing the driver, who is driving. The screen is read-only and refreshes itself; nothing is recorded or decided from it.

    Because it names children, it needs the permission to see a student as well as the one to use the dispatch board. Anyone already doing dispatch has both. Opening it is recorded against your name, as every view of a child's record is.

  • New: drivers can see who to ring about a child. An emergency contact was a phone number the office held and the driver couldn't reach — which is the wrong way round, since the driver is the one standing next to the child.

    A ☎ Contacts button on the child's tile now shows the people to call, with the number as a tap-to-dial link. It says how each person is related to the child, and whether they're allowed to collect them from the bus — a different question from whether you can ring them, and the one that matters at a door.

    It stays behind the button rather than sitting on screen all run, it works with no signal, and it covers only the children on the run in hand — clearing from the device when the run finishes, the same way the photographs do.

  • Fixed: a fleet file with two columns of the same name could not be imported. If your export carried two columns with an identical heading — some fleet systems produce this — the import correctly refused to guess which one to use, then asked you to set one of them aside. Doing so did not help: both columns shared a single setting, so whatever you chose applied to both and the same question came back. There was no way through it.

    You can now choose each column separately, and the import runs. Refusing to guess between two columns is deliberate and has not changed — a wrong guess would put one fact in another fact's place on every row — but you can now answer the question it asks. Related: a file containing a blank column heading no longer shifts the columns after it out of line.

  • Fixed: the run review told you a completed checklist was missing. If a driver finished the after-the-run half of their checklist, the review of that run could still say it had never been done — while, a line further down, correctly counting it among the run's checks. The checklist was always safely recorded; only the review's summary was wrong, and it is now reading the same records as the rest of the page.

  • Fixed: an odometer reading a driver entered showed as "not recorded". The reading goes in with the checklist, and the review was looking somewhere else for it. It now shows what the driver actually entered. Where only one reading exists — the before-the-run checklist does not ask for one — the review says so plainly instead of implying nothing was captured. Where there are two, you get the distance.

  • Fixed: a run that had not happened yet could be described as clean. Runs are prepared several days ahead, and opening one of those showed the same reassuring summary as a run that had operated without incident. A run that has not started now says so, and says clearly that this is not the same thing as a clean run. Runs that have not begun are also no longer listed on the review page at all — it is a record of what happened, and they have not happened.

  • Changed: the run list is ordered with the most recent run first, including within a single day, so an afternoon run now sits above that morning's. Two small display fixes on the same screen: a run's duration no longer shows eleven decimal places, and its status reads as a word rather than as it is stored.

[1.40.0] — 2026-08-14

  • Fixed: at a stop with three children, the last one no longer sits below the fold. The panel asking whether the bus called at a stop took up about a third of the stop screen on every approach, pushing the children's photographs down — so at a busy kerb a driver had to scroll to see the last face while boarding. It now folds down to a single line you can open when you need it, and opens by itself in the one case that is not a question: when every child at the stop has already been marked away.

  • Fixed: the driver app said the bus was running late when it was running early. The reading at the top of the run screen measures against the stop the bus is up to. If a driver recorded a stop as not visited, the app kept measuring against that stop for the rest of the run — so the longer the run went on, the later it claimed to be. On one afternoon run it read an hour late while the bus reached the depot ahead of schedule.

    It now moves on to the next stop that is still open, the same one the card below it shows. The two always name the same place. The office's board was never affected — it had the run right the whole time, so nobody was dispatched on the wrong picture.

  • Fixed: Arrived and Departed now respond the moment you tap them. They used to wait for the office to confirm before anything on the screen changed, which meant the two buttons drivers press most felt slowest on a weak signal — and fastest with no signal at all, because that path never waited. Both now respond immediately and confirm a moment later. While a tap is still on its way, the stop shows the same "saved on this device, not yet confirmed" wording it always has, and if the office refuses the action the button goes back the way it was.

  • Fixed: at the depot, Finish run was pushed to the bottom of the screen. Once the bus was marked arrived, the Arrived button kept its full size and pushed the end-of-run steps nearly off an upright tablet. It now shrinks to a small ticked button once you've used it, the way the sweep and Finish run steps already did. A completion gate a parked driver has to hunt for is how a bus sweep ends up done at the roadside.

  • Fixed: the "did the bus call here?" panel no longer appears at a stop you've arrived at. At a school stop it sat above the children's photographs and the driver could not see a row of faces without turning the tablet sideways. It now disappears once the stop is marked arrived — where the question has no honest answer anyway — and the tiles move up into the space.

  • Fixed: the Safety page now says how many open hazards you have. The Hazards card showed a count only while something still needed describing. Once a driver had written up what they saw — which is exactly what we ask them to do — the card went back to showing nothing at all, so a hazard they had reported themselves looked as though it had never been recorded. It now says how many are open in as many words, whether or not any of them still needs an account, and it says that alongside any note about checks it could not run rather than instead of it.

    The hazards screen itself was always right and always listed the report. It was the card in front of it that had gone quiet.

  • New: drivers can send in any qualification their role requires, not just a working-with-children card. The screen where a driver sends a renewal used to offer three child-protection cards and nothing else, which was no help if what the operator needed was a first aid certificate or a passenger endorsement — the office had to take those over the phone and type them in. The list now matches whatever your operator has set as required for the role, so it differs between operators.

    The same screen now shows, at the top, anything the role requires that the driver does not currently hold, each with the reason — nothing recorded, expired on a date, or waiting to be checked. That is the same list the office's rostering screen uses, so the two cannot disagree about why somebody is held back.

    Not every qualification needs a number or an expiry date, and the form no longer insists on both. A certificate often has no number and an induction does not expire; leaving those blank is now correct, rather than something to invent a value for.

    Nothing a driver sends in counts until the office has checked it — unchanged, and more important now that more kinds of record can be sent this way. A driver held out of the app by a lapsed card is still held out until the office confirms the new one.

  • Fixed: the bus app no longer says the bus has moved on while it's still parked. At the start of a run drivers were being told "the bus has moved on, but this stop is still open" before the bus had moved at all. The app was working that out from the bus being near the next stop, which at a depot is true from the moment the engine starts. It now waits until the bus has actually driven away from where it stopped. This matters more than the wrong words: that message is the only warning a driver gets when a stop is quietly holding up every stop behind it, and one that cried wolf every morning is one they'd have learned to swipe away.

  • New: a school can keep its own details up to date. Schools now have a School details screen in their portal covering their bell times, address, suburb and office contacts. Until now, correcting a bell time meant the school telling you, you telling us, and us making the change — three steps for something the school could type in ten seconds, and each step was somewhere it could stop.

    Only the school's nominated administrator can change anything; everyone else at the school can look. Every change records who made it and when, and the screen shows it.

    Two things worth knowing. Bell times are what your services are timed against, and the school's record is shared by every operator serving it — so if a school moves a bell time, your run times need a look. And a school still can't change its own name or official code: those are how every enrolment list finds the school, so a school correcting its name to the version on its letterhead would stop those lists matching, for you and for everyone else driving there. Name changes still come through us.

  • Fixed: the data-sharing agreement form no longer lists schools you don't serve. The school dropdown was showing every school on the system, so you could pick one and then be told on save that it wasn't valid — and it meant a screen was showing you schools that are nothing to do with you. It now offers the schools on your own list, and tells you where to add one if that list is empty. Agreements you already hold are unaffected, and editing an old one still shows its own school even if you've since stopped serving it.

  • Fixed: a school contact can no longer be added to an agreement that has ended. If an agreement had expired or been revoked, adding a contact to it still created the account and emailed them a sign-in link — and they would then sign in to an empty portal with nothing explaining why. They were never able to see anything they shouldn't; access has always been worked out from agreements that are currently in force. Adding a contact now says the agreement has ended and what to do about it. Removing a contact is unchanged and still works either way, which is the important half.

  • New: CPR is now recorded as its own qualification. It's usually done alongside a first aid certificate, but the two run out at different times — CPR yearly, first aid every three years — so keeping them as one record meant one expiry date that could only be right about one of them. Somebody whose first aid ran for another two years could have a CPR component that lapsed months ago and still read as current. CPR now has its own entry and its own expiry, must carry an expiry date, and can be recorded on its own for anyone who's done the standalone course.

  • Changed: long dropdowns can be typed into. Picking a school, a bus, a driver, a guardian or a stop from a list of any real length used to mean scrolling. Those lists now filter as you type, and they're sorted alphabetically. The school picker on the stop form also had its search box and its dropdown rendering side by side as though they were two separate fields — that's now one control.

  • Fixed: importing your fleet no longer picks the wrong depot for a bus. If your spreadsheet had two columns that could both be read as the depot — say a "Base" column and a "Group" column — the import quietly used whichever came last, and buses ended up filed against the wrong one. It now uses the column actually named for the job, and if two columns genuinely mean the same thing it stops and asks you which to use rather than guessing. The same check found a fleet export carrying two different columns both headed "Year", each saying something different.

  • Fixed: a bus's status is read whatever way you've written it. "Active", "ACTIVE" and "active" are now the same thing, along with the usual ways other fleet systems phrase it. Anything we genuinely don't recognise is still refused with the line number, rather than guessed at — we will never put a bus on the road because of a word we had to interpret.

  • Fixed: an old spreadsheet can no longer wind a bus's odometer backwards. Importing a file exported weeks ago — or the same file twice — used to overwrite the current reading with the older, lower one, quietly. A reading lower than the one already held is now recorded and flagged for you to look at, but it does not become the bus's figure. Imported readings also join the bus's reading history and are labelled as having come from an import, so you can tell at a glance where a number came from.

  • Changed: you now confirm what your columns mean before a fleet import runs. Previously an import went ahead as long as it could find the two columns it absolutely needed, and told you afterwards about everything it had dropped. A real fleet export can carry well over a hundred columns, so that was a long list arriving too late to do anything about. You now see your own column headings with your own values beside them, and say what each one is, before anything is written — which also means columns we can store no longer get missed just because your spreadsheet spells them differently. A file downloaded from our own template still imports in one step.

  • Improved: when a driver's app tells them something, we now keep a record of it. Until now the platform recorded what was saved — a child boarding, a stop arrived at — but nothing recorded what the app told the driver at the time. If those two ever disagree, that gap is the whole story, and it was invisible: a wrong message could sit on a screen for a full run and leave no trace behind it. The driver's device now keeps a short, device-side note of things like an action it could not send, a button it had to refuse because the depot has no signal, or a moment it could not get a position — and sends them on once everything more important has gone. Only codes and identifiers ever leave the device, never the wording a driver saw, because that wording sometimes includes a child's name.

  • Improved: a run's report now shows which device the driver was using. Where a run was driven from more than one device — a tablet that failed and a phone that finished the job — the report says so, because the times on the two come from two different clocks and are easy to misread as a delay.

  • New: asking us to add a school is now a conversation rather than a form you post into a void. Previously you filled in a name, got a message saying we'd let you know, and then heard nothing — there was no way to see what had happened, and if we couldn't add the school, the reason went nowhere. You now get an email either way, and the answer is listed on the same screen you asked from. Where we found the school already on the system under a different spelling, we tell you which spelling we're using, because that's the one your passenger lists need to match.

  • New: we check for a school that's already there before you ask for it. Search by name and suburb from the request screen and you'll see close matches labelled with how sure we are — adding one of those takes a moment, where a request takes as long as it takes us. If you send a request for a school that's already on the system with the same name in the same suburb, we stop and show you it first. You can still go ahead if it really is a different school.

    Why it's worth the extra step: a school is held once and shared by every operator serving it, so a second copy means two sets of term dates and bell times, and the buses that get created depend on which copy has the right ones.

    We ask for the suburb because school names repeat a great deal — there are many "St Mary's Primary" — and the suburb is what tells two of them apart. We also ask for the school office's email address, which we keep against the school so it's there when you're ready to give their office access to their own portal. Adding a school does not create a login for them; that still needs a data-sharing agreement, and it's still your decision.

[1.39.0] — 2026-08-14

  • New: a school contact is emailed when they're given access. Until now, adding a school contact created the account and told them nothing — somebody had to ring them with the address and explain how to sign in.

    They now get a message naming the school and who added them, a link to the portal, and the two things people always ask: that there is no password — they enter their email address and a sign-in link is sent — and that every time they open a student's record it is recorded against their name. It links to the portal terms so they can read them before being asked to agree.

    The email is a link to the sign-in page, not a way in on its own. Sign-in links are still sent one at a time, work once, and last 15 minutes.

  • Fixed: the access label on the school portal's "Who has access" page no longer spills over its background. On narrower windows the wording wrapped onto a second line while its coloured badge stayed one line tall, leaving text sitting outside it. The labels now stay on one line and the table scrolls sideways if it needs to.

  • New: load your state's term dates instead of typing them. Term dates are the same for every government school in a state, so entering them school by school was the same four ranges over and over — and every retype was a chance to fumble a date.

    On a school's calendar, pick the state and year and press Show these dates. You'll see the four terms and, beside each one, exactly what pressing Add would do: Will be added, Already set, or Skipped where it overlaps a term you already have — and the term it clashes with is named.

    Nothing is saved until you press Add, and nothing is ever overwritten. These dates decide whether a bus is created for a day, and a term ending a day early would mean no bus on a day children are at school — with nothing to notice it, because nobody watches for a run that doesn't exist. So you see what will happen before it happens, and a school's own dates always win over the state's.

    These are the dates for government schools. Catholic and independent schools usually set their own, and some regional schools differ from the metropolitan calendar, so check them against what the school told you.

    Development days aren't included, and can't be — each school sets its own, so there's no statewide list to load. Those still go in as closures, which is the half only the school can tell you.

    Schools can do this from their own portal too, on the same Term dates screen where they already add and remove terms by hand.

    If a date is close but not identical, it says so. Where a term you already have overlaps the state's by only a day or two, you'll see how far out it is — "yours ends 1 day later" — rather than just being told there's a clash. That's the case where the difference is usually a typo rather than a decision, and getting a term's last day wrong means no bus on a day children are at school. Your dates are still kept; it just shows you the difference so you can check which is right.

  • New: a school stop can say which school it's for. Stops could be marked as a school stop, but nothing recorded which school — the connection lived in the stop's name and in whoever set it up remembering. That's fine on the day and unreliable a year later, and it meant "show me every stop serving this school" had no answer.

    Tick School stop when adding or editing a stop and a Which school picker now appears, with a search box for narrowing a long list. Only schools you serve are offered.

    A school can have as many stops as you actually use — larger schools run separate set-down and pick-up bays, and nothing limits you to one. You can also leave it blank and set it later; until you do, the stop's page says the school isn't linked yet rather than showing a dash, so a stop nobody has got to is tellable from one where you meant no school.

    Editing a school's address never moves a stop. A stop's position is often nudged to the actual bus bay rather than the school's postal address, and that position is what decides when the driver is told they've arrived — so correcting a typo somewhere else leaves it exactly where you put it.

  • Fixed: a question the checklist treats as optional no longer stops you submitting. Drivers finishing a run could answer every question that was actually due and still be unable to submit, because an optional question further up the form was quietly holding the whole thing back — with nothing on screen to say which one, or why.

    Only questions that are genuinely due now hold up a submission, and those are the ones already marked on the screen. The same fix applies to the pre-start check before a run.

  • New: a school can see who at their school can sign in. School contacts have always had their own individual sign-ins — there is no shared school login, and every time someone opens a child's record it is recorded against that person by name. What a school could not do was see the list.

    Their portal now has a Who has access page: everyone at the school who can sign in, which bus operator added each account, when it was last used, and whether it still works. Contacts who have been removed stay on the list marked as removed, so a school can confirm a removal actually happened.

    It is a list to read, not to change — adding and removing is still done by the bus operator, and the page says who to ring. The reason it is worth having anyway: the school is the only one who knows the day a staff member leaves, and until now they had no way to see that the person still had access.

    Nothing about any child appears on this page.

  • New: a school can be given charge of its own staff access. One contact at a school can now be made its administrator. They can add and remove colleagues at their own school themselves, without ringing anyone — which matters because the school is the only one who knows the day a staff member arrives or leaves.

    Only we can appoint an administrator; a bus operator can't, and neither can the school. Anyone an administrator adds can see that school's students across every operator serving it, so letting one operator hand that out would mean one operator deciding who sees another's students. An administrator also can't appoint a second one.

    A school deciding who is not a school deciding what. Everything a school contact can see is still governed by the agreement each operator holds with that school, field by field. Nothing here lets a school widen its own access — only choose which of its staff use the access it already has. Operators keep the final say: everyone who can read their students appears on their own list, and they can end anyone's access from there.

    Accounts a school creates belong to the school rather than to any bus operator, and are shown that way on both sides. Schools without an administrator work exactly as before.

  • Fixed: an operator could not see, or end, the access of a school contact somebody else set up. Where a school is served by more than one bus operator, its contacts are shared between them — one person, one sign-in, reading each operator's own children under each operator's own agreement.

    The operator's own screen did not show it that way. It listed only the contacts that operator had added, so an operator could be told "nobody at this school has access" while somebody did — and if that person left the school, the operator whose students they could see had no way to stop them. The only option was to end the whole agreement, which would have cut off every other contact at that school.

    The list now shows everyone at the school who can read your students, says which operator set each one up, and shows when each last signed in. You can end anyone's access from there. Because these sign-ins are shared between operators, doing so stops that person signing in at all — the confirmation says so before you go ahead.

    Adding someone who already has access now tells you so, instead of refusing with an unhelpful message about the email address being in use.

  • New: the run screen warns a driver when the bus reaches a reported hazard. Open hazards — a washed-out verge, a collapsed kerb, a blind exit — have been marked on the driver's map for some time. A mark on a map only helps the driver who happens to be looking at it, and a driver is driving.

    Now, as the bus comes near one, a message appears across the bottom of the map saying what the hazard is, in the words of whoever reported it, with the distance counting down. It clears itself once the bus is past, and there is a large Dismiss button for a driver who has read it and wants the map back. Dismissing it keeps it down while the bus is still beside that hazard — and brings it back on the next trip past, because the afternoon run deserves the same warning as the morning one.

    A warning about a different hazard still appears even if the last one was dismissed.

    It works with no signal. The hazards a driver's device is carrying are the ones synced in advance, which matters because the roads worth reporting are often the roads without coverage.

  • Improved: a hazard now looks the same everywhere it appears. The same reported hazard was drawn one way on the route preview a driver reads before setting off, another way on the map they drive by, and another again on the office's screens — and the colours used for how serious it is did not entirely agree either. It is now one marker and one set of colours across every map, so a hazard read in one place is recognisable in the next.

    On the run map that also means the marker can be tapped to read the full note, which it could not before.

  • Fixed: the check at the end of a run now shows the right control for every question. A checklist can ask for more than a pass or a fail — a sign-off, an odometer reading, a fuel quantity — and on the after-the-run check those questions were not being offered the proper control. They now appear as themselves, on both the before-the-run and after-the-run checks, so a signature is signed and a reading is a number.

    Drivers who have saved a signature on their own About me screen sign with a single tick; anyone who hasn't can sign in the box. The driver guide now describes what the after-the-run check can ask for, and says that a pass/fail appearing where a signature or a reading belongs means the checklist needs correcting.

[1.38.0] — 2026-08-13

  • Fixed: an empty "on the roads you drive" no longer implies the road is clear. The driver app checks open hazards against the routes you are rostered to. When it found none it said so — but it said the same thing when it could not run the check at all, which happens if you are not rostered to a route in the next fortnight, or if the routes you are on have no approved path recorded.

    So a hazard could sit on a road you were about to drive while the screen told you there was nothing near it. It now says which of the three is true, in a highlighted box rather than grey text, and says plainly that the last two are not an all-clear. The second one asks you to tell the depot, because it is something only the office can put right.

    The Hazards card on the Safety page carries the same wording, so you see it before you open the screen — it previously read "Nothing recorded yet", which sounds like the company has nothing on file.

  • Drivers can now do their training on their phone. It is in the driver app under Safety → Inductions — the same training, the same record, no need to get to a computer.

    Until now training could be assigned to a driver and there was no way for them to complete it. It showed as outstanding against their name and counted against the company, and nothing they could do would clear it. If your compliance figures have been showing training as overdue for drivers who never had a way to finish it, that is why.

    Two deliberate choices worth knowing about:

    • Outstanding training does not stop anyone driving. It is not a licence or a medical. It shows as overdue and that is all it does — a paperwork gap should not cancel a school run.
    • A driver who has been stood down can still get to it. Being off the road is exactly when there is time to read something.

    Training that asks for a signature has it drawn there and then rather than reusing the one kept for pre-start checks — an induction is signed once, and a signature given deliberately for the document in front of you is better evidence at an audit. Sending a completed induction needs a connection: nothing is kept on the phone, and if the send fails the answers stay on screen to try again. That is on purpose, because the answers are marked and dated when the company receives them.

  • Drivers can now say whether it was a hazard, a near miss or an incident. The button on the run screen is unchanged — still one tap, still works with no signal, still asks nothing while you are driving. The question comes at the end of the run, when the bus is stopped and you know what you actually saw.

    It matters because it changes who sees it. A hazard and a near miss are facts about a road, so the next driver down it is shown them. An incident is an account of something that happened to a person, so it goes to the office and to nobody else's bus. You still see your own on your hazards screen. The office decides how serious it is and can reclassify — you are only asked what you saw.

    For a near miss or an incident, two more things get asked: what you did at the time — the part nobody remembers a week later — and whether anyone was hurt. Ticking that tells the office straight away rather than the next morning, and the report cannot be signed off until somebody has looked into it.

  • Fixed: when a driver's report was serious enough to alert the office immediately, the alert was not being sent. It reached nobody, and nothing on any screen indicated it had not — the report simply waited for the overnight sweep like any other. Alerts raised from a driver's device now reach the people who can act on them.

  • Fixed: the app no longer closes a stop by itself when it thinks the bus drove past. It worked out whether the bus had gone by from where the bus was along the road — and at a stop whose pin sits in the wrong place, that reads as driving past while the driver is at the kerb with the door open. On one morning run it closed four stops and the bus had genuinely served two of them: one closed a second after it opened, while children were still being boarded, and the record then said nobody had been picked up there.

    The app still notices and still says so — a line on the stop, no pop-up, nothing waiting on the driver while the bus is moving. What it does not do any more is decide. The driver closes the stop, either by tapping Arrived if the bus did call, or with a new Skip button if it did not.

  • Drivers can now record a stop the bus drove past. Until now the only way to leave a stop out was where every child at it had already been marked away. That is not what happens on a run: the kerb is empty, the bus is behind time, and there is no reason to pull over — but children were still expected there, so no button was offered.

    The stop now asks the plain question — did the bus call here? — and offers Skip if it did not. Skipping records that those children were not picked up, which is the same thing the record would say if the driver had pulled in, found nobody and driven on. Nothing is hidden: the count the office sees is worked out when the bus leaves, whatever the driver tapped. And it is always reversible — Put this stop back brings the stop and every child's buttons back, for the child who turns out to be standing there after all.

    A stop where somebody is still on the bus can never be skipped. Those children are in seats, and a bus going past a stop where somebody has to get off is the one thing this platform exists to catch. The button is not offered there at all.

  • The "not on the afternoon bus" control is now a round button in the corner of the child's tile, reading PM ABS, matching the ABS and CLR buttons already on the tile. It used to be a bar across the bottom, which took a row of space on every tile of every morning run — and that space came out of the photographs, which are the thing a driver is actually reading at a door. Marking still asks for confirmation, undoing is still a single tap, and the button says PM so it cannot be mistaken for this stop's absence.

  • Fixed: Bases now appear in the Settings menu. Importing a fleet stops if it meets a base it does not recognise and tells you to add it under Settings → Bases — but that menu item was missing, so there was nowhere to go. The screen existed and worked; it had simply never been linked. It is there now, for anyone who can change company settings.

  • Fixed: a report no longer stays on "Actions pending" after its last action is done. Raising a corrective action moved the report to that status and nothing ever moved it back, so it stayed there indefinitely — counted as outstanding on your register, kept raising a task, and for a hazard kept warning drivers about something already dealt with. Completing the last open action now returns it to Triaged, ready for you to sign off.

    Completing one of several actions changes nothing, and a report you have already resolved or closed is left exactly as it is. Marking the last action done never resolves the report for you — deciding the hazard itself is gone stays your call, because that is what stops drivers being warned about it.

    Reports already stuck in this state before the fix stay stuck until they are put right; they can be corrected in bulk on request.

You can now invite parents to the family portal

The family portal — where a parent sees their child's stop and times, tells you when their child won't be travelling, fills in forms and checks who has looked at their child's record — can now be opened up to the families you choose.

On a parent or carer's record there is a new Family portal access panel. Press Invite to portal and they get an email explaining that you have set up access for them, with a button to get started. There is no password for them to choose or forget: whenever they want to sign in, they enter their email address and we send them a link.

The panel always says where things stand — not invited, invited but not signed in yet, or active with the date they last signed in. If an invitation goes astray you can send a new link, which replaces the old one.

You can also withdraw access at any time. That signs the parent out everywhere, stops any link they were sent from working, and closes the portal to them straight away. Their record and its history stay exactly as they were, and you can invite them again later if things change.

Inviting and withdrawing is a separate permission from editing a parent's contact details, so you can decide who in your team makes that call. It is available to company administrators, operations managers and office staff by default.

A parent needs an email address on their record before they can be invited — the panel will tell you if one is missing.

  • Fixed: stops that sit back from the road are no longer treated as though they were on it. Some pick-ups are on a property set back from the highway, reached up a driveway. The app worked out where such a stop sat along the road and got a confident answer that was simply not where the stop is — so as the bus drove along the road past that point, the app believed it had already been to the stop and left. In fact the bus was about to turn in.

    On one morning that closed the stop as a drive-past forty seconds before two children got on. The stop's location was right and its detection area was right; the arithmetic in between was not. A stop away from the road is now left to its detection circle alone, which is what that circle is for.

  • The register now knows when a school is shut. Pupil-free days, staff development days and term breaks are greyed out on the attendance register and in the driver app, with the reason written at the top of the column. Before this they looked like ordinary school days: you could tick a child off for a day no bus was running, and nothing on the screen said otherwise.

    The dates come from the school's own calendar, so they are the same for every operator who serves that school, and they are corrected in one place. A school that has not entered a calendar is unaffected — nothing is greyed, and a missing calendar is never read as "the school is closed".

    One deliberate exception: if a bus is already scheduled for that day, the day stays markable even when the column says the school is closed. Buses are scheduled about a week ahead, so a closure added at short notice can land on a day whose run already exists — and greying out a bus that is still going would be far worse than a column that reads oddly. When you see that combination, the run needs cancelling.

Parents can now send you a photo of their child

Photographs are the hardest thing to collect and the first thing to go out of date. Parents can now send one in from the family portal — they already have it on their phone.

Nothing goes on a driver's list until you approve it. A photo a parent sends waits in a new Photos from families queue, reached from your Students screen whenever something is waiting. You see the photo, the child and who sent it, and you either approve it — at which point it becomes that child's photo — or decline it with a short reason the family can read. Declining without a reason just means the same photo comes back, so the reason is required.

Photos sent this way get exactly the same handling as ones you upload yourself: they are checked for malware, stripped of any hidden location information the camera recorded, resized, and kept private. A declined photo is deleted.

Parents see what they sent and whether it is still waiting, and can take it back before you have looked at it. If a parent sends a second photo before you review the first, the newer one replaces it, so you are never asked about the same child twice.

If your agreements don't allow you to accept photographs from families, this can be switched off for your company.

A week-at-a-glance register for parents

Parents used to mark a child as not travelling one child and one day at a time. A parent with three children away on Thursday and Friday filled in the form four times.

Not travelling is now the same week-at-a-glance register your office uses, showing that parent's own children. They cross the mornings and afternoons their children are not catching the bus, and it appears on the driver's run sheet the same way it always has. They can move between weeks, and once a run has gone the cell shows what the driver actually recorded instead of a box to tick.

For a holiday or a repeat — "away all next fortnight", "every Tuesday until the end of term" — there is a link through to the longer form, which records the whole period in one go. That form is unchanged.

Nothing about the cut-off has changed: once a run has started, that day is fixed and the parent is asked to phone you.

The family portal now fits the screen it's on

Parents use whatever device they have. The portal was built for a phone and stayed phone-shaped on everything else — on a laptop it appeared as a narrow strip down the middle of the window with the menu pinned to the bottom of the screen.

It now adapts: the same portal, laid out for a phone, a tablet or a computer, with the menu moving into the header on larger screens. Nothing was added or taken away, and it behaves identically on a phone.

Parents see their children as cards, with photos

My children now shows a card for each child with their photo, their year, the stop and time the bus collects them for each trip, and what has happened today.

The Not travelling button on each child has gone — that is done on the Attendance page, which covers the whole family and the whole week in one place and is always one tap away. Not travelling in the menu is now called Attendance, because that page also shows what the driver recorded on the days that have already run, not only the days a parent is marking ahead.

The "who has looked" page is much shorter

When someone opens a child's record and works through it, that was recorded as a separate line for each part they looked at — several lines with the same name and the same minute on them. A busy afternoon filled the page, and it was hard to see who had actually looked at anything.

It now shows one line per visit: who it was, what parts of the record they saw, and when. Where a visit covered more than one view, the number of views is shown, so nothing is lost — just no longer repeated. Two different people are always two separate lines, and someone coming back later is a separate visit.

Because each line covers more, the page also reaches further back than it used to.

A fix on the attendance register

The register saves each mark as it is made, and has done since it was introduced — but the old Save register button stayed on screen next to a note saying marks save themselves, which was understandably confusing. The button now disappears as intended. This affects the office and school registers too.

A tidier family home screen

The two small text links under the children list have gone. Both destinations are on the menu bar on every page, so they were a second, differently-worded way to reach somewhere already one tap away.

[1.37.0] — 2026-08-13

  • A checklist can now ask which bus the driver is in — and move the run onto it. Add a Which bus question and the driver sees the bus rostered for the run, ready selected. If they've taken a different one because theirs is off the road, they pick it, and the run follows.

    That last part is why this is worth having, and why asking for the registration as a text question was never the same thing. A typed rego tells whoever reads the check afterwards. It doesn't tell the system — so the pre-start was recorded against the rostered bus, a serious fault took the wrong bus off the road, the odometer landed on a vehicle that hadn't moved, and the office screen showed a bus that wasn't the one on the road.

    Drivers can only choose an available bus — nothing grounded, in for maintenance or retired. If the rostered bus has been grounded since the roster was built it isn't offered either, and the driver has to choose one; the run couldn't have started on it anyway. The choice is checked again when the check is submitted, because a bus can be grounded by a failed check the same morning, after the list on that phone was saved.

    If you've given a particular bus its own extra questions and a driver switches to it part-way through a check, the run moves onto that bus and the driver is asked to run the check again. That's deliberate: the questions they'd just answered belonged to the other bus, and accepting them would record a check that never asked the ones you added because that vehicle needs them.

    Nothing changes on your existing checklists until you change them. If you're already asking for the registration as text, add the new field and remove the old one when you're ready — answers already recorded stay exactly where they are.

  • The fleet import now asks what your columns are instead of refusing the file. If your spreadsheet's headings don't match, you get a screen listing each of your columns with the first few values underneath, and you say what each one is. No renaming, and anything you leave alone is skipped. Your file is held while you answer, so you don't have to pick it again.

  • Hazards are no longer asked to be investigated. An investigation asks why something happened, and a hazard hasn't happened — it's something spotted before it hurt anyone. The findings section no longer appears on one, and a serious hazard can be closed on its summary instead of waiting for an investigation it never needed. Near misses are still investigated: those are the ones worth learning from.

  • "All off" is quicker, records where the bus was, and keeps an honest count. Marking a whole load off at a stop used to wait for the screen to reload before the driver could get on. It now takes effect the moment it's tapped and sends in the background, the same way individual taps already did.

    It also records where the bus was standing when it was used. Individual taps have carried that for a while; the bulk one didn't when the driver had signal, so most set-downs had no location against them. That's the record you'd want if a drop-off is ever queried.

    And the number on the button now counts down as the driver marks children off by hand, so it always shows how many the button would actually act on. Nobody was ever marked off twice — the count on screen was simply behind.

  • Drivers can say who wasn't there, on the way out of a stop. A child expected at school who never got on — nobody rang, nobody marked them — had no record either way, so their tile stayed in front of the driver at every stop for the rest of the run, and their stop kept asking to be driven to even with nobody left to drop.

    Now, leaving a stop where children are still unmarked, the driver is asked whether they were there. It's a tick box and it isn't ticked for them: if they say nothing, those children stay on screen exactly as before. That's deliberate — an unanswered question about a child belongs in front of the person driving, not quietly resolved by the system. Once they answer, those children move into the collapsed group and stop crowding the screen.

    This is only ever offered where children are getting on. Where they're getting off, "still waiting" means a child who is on the bus, and the platform will not let that be recorded as though they were never aboard.

  • A stop where the bus called and nobody came can now be skipped. The "no children expected here" option already appeared once everyone at a stop was marked away, but it didn't count children the driver had recorded as not being there — which is the best-evidenced of the lot, because the bus went and looked.

  • Children's tiles are far easier to read at a glance. On the bus is now solid green and absent is solid orange, rather than the faint tints they were. A child who has been set down goes plain, so a finished stop no longer looks green — green now means "still on the bus" and nothing else. Absent tiles are no longer faded either: that's a fact worth seeing, not one to play down.

  • A safety report is now a set of sections instead of one long page. What was reported, corrective actions, what was found, who was involved, first aid, and triage — picked from a list down the left. Each has its own address, so you can link straight to one or open two reports in separate tabs. The list only shows the sections a particular report actually has.

  • Flagged a hazard by accident? You can take it back now. The warning triangle on the run screen is one tap, sized to be pressed without looking — so catching it by mistake is easy, and always was. Next to Add what you saw there is now Not a real one.

    Three reasons to pick from, all taps and no typing: tapped by accident, already reported, it is gone now. They are counted across the depot, which is how a handful of accidental taps every week becomes something an operator can see and fix rather than something drivers quietly put up with.

    Taking one back stops it showing to other drivers, stops it appearing on the maps, and stops the app asking you to describe it. It is not deleted — the office can still see that a flag was made and taken back, and why. That is deliberate: an entry that simply vanished would leave nobody able to tell "somebody took it back" from "nobody ever flagged anything".

    Only your own flags, and only before you have described one. Once you have written what you saw it is a real report and the office owns it — ask them to close it if it turns out there was nothing there.

[1.36.0] — 2026-08-12

  • Where the bus was is now saved with every boarding. Marking a child on or off records the position at the moment of the tap, and that position was being lost on its way to the office. It arrives now. It is what answers "did the driver mark this early, or did the stop register late" from the record instead of from memory.

  • Driving past an empty stop no longer holds up the rest of the run. If the kerb is empty and you carry on, the app closes the stop for you and records that the bus passed it rather than served it — with nobody marked as picked up. It used to keep the stop open whenever children were expected there, which was almost every stop, and one open stop stops every stop after it from marking itself. Drivers were finishing runs by hand. You are told what was recorded and can correct it when you are stopped, and the office still sees how many children were not picked up.

    Setting-down stops are different and unchanged: while anybody is still on board for a stop, the app will not close it.

  • Approving a driver's stop position now shows you a map. Where the stop is now, its geofence, what each driver recorded and how accurate that reading was, with the distance drawn between them. The screen used to give you two sets of coordinates, which is not something anyone can judge a move from. The stop's own page also tells you when readings are waiting, so the prompt is not the only way back to the decision.

  • Hazards appear on the route preview. Drivers could already see them while driving; now they are on the screen you read before setting off, which is when there is still something you can do about knowing.

  • Fixed: a hazard reported from the bus showed "No location recorded" on the office screen, directly above the position it had recorded.

  • You can now record first aid. What was wrong, what was done, what happened next, and who treated them — for a child, for one of your own people, or for anybody else by name. Reachable from the Safety menu, and from an incident report so the treatment sits with the account of what happened.

    Reading first aid is a separate permission from the rest of the safety module. Someone who can open your hazard and incident register does not thereby get to read what was wrong with a child, and you grant the two independently. Opening the register, or any one record, asks you to confirm your password if you have not done so recently, and every time a child's record is opened it is written to their access log.

    The list itself shows only that a treatment happened and how it ended. What was wrong and what was done are one click further in, so a screen left open on a desk does not put every child's injury on display.

    There is no edit and no delete, here more firmly than anywhere else in Tutela. A correction writes a new record naming the one it corrects, and both stay. A record that could be quietly revised after a bad outcome would be worth less than no record at all.

  • Recording that a guardian was told. Tutela does not contact anybody automatically — what the record holds is your evidence that the conversation happened: when, who made it, and how. It can be recorded once and not changed afterwards, because when a parent was told is the detail that matters if the timing is ever questioned. The register's first tab lists every treatment involving a child where nobody has been recorded as telling a guardian yet, alongside anything that needed an ambulance, a hospital or a doctor.

  • A report can now say who was involved. Who was hurt, who saw it, who gave first aid — staff and drivers from a list, students by searching, anybody else by name. Until now a report could record that something happened and not who it happened to, which is where an investigation starts.

    Seeing that a student was involved is not seeing which student. Everyone who can read the report sees the involvement and whether the person was hurt; the child's name needs permission to view student records, which is granted separately. If you see "Student" where you expected a name, that is the intended behaviour — and every time a name is shown, it goes into that child's access record against whoever looked.

    Getting it wrong has two fixes and neither deletes anything. If someone's involvement was wrong, add them again correctly and the earlier entry is marked as corrected. If the wrong person was named entirely, withdraw the entry and say why — it stays on the file, marked withdrawn, with your name and your reason. That is deliberate: if a child was named on an incident and then unnamed, that is precisely what somebody reviewing the mistake needs to read, and an entry that simply vanished would leave them unable to tell "removed" from "never named".

    Withdrawing also takes back what naming gave. A driver who could read a hazard because they were named on it can no longer read it once the entry is withdrawn.

  • Fixed: searching for a child when recording first aid put their family name in the page address, where it could be copied into logs and browser history outside the record of who has looked at what. The search no longer does that.

  • A report can now record what was found. What somebody looked into, the root cause if they reached one, and what contributed. Until now a report could say what happened and what was decided, and had nowhere to say why anyone believed that was the right decision.

    Recording findings and reading them are different permissions. Anyone who can read the report can read what was found — findings only the investigator can see are findings nobody acts on.

    Contributing factors are tick boxes rather than free text, and that is the point of them. They are counted across the whole register, which is how a pattern nobody noticed becomes visible: three incidents in a term all ticking the same box is a problem with the timetable, and no amount of reading the write-ups one at a time would tell you that. Typed as free text, the same answer written three ways adds up to nothing — so the nearest box that gets counted beats a perfect sentence that does not.

    More than one write-up is normal, and none of them overwrite the others. If findings change, mark yours as a revision; the earlier one stays on the file marked as revised. The question after something goes wrong is rarely "what do you think now" — it is "what did you think then, and when did that change".

  • A serious report will not close until somebody has recorded what they found. High and critical reports only, and the screen tells you before you start writing the closure summary rather than after.

    The closure summary cannot stand in for this. Closing a file and investigating one are deliberately different permissions, and if the person who decides a file is finished can also be the only person who ever wrote anything about why, that separation is not doing anything. Lower-severity reports close as before — and if a report genuinely is not high severity, changing that in triage is a decision you are entitled to make and one that is recorded on the report where anyone can see it.

  • Serious reports now email the people who can act on them, straight away. When a report is recorded as high or critical — or when your triage raises it to one of those — everyone who can triage safety is told within moments. Not everyone who can read the register: an alert sent to people who cannot act on it is one everybody assumes somebody else is handling.

    The email deliberately contains almost nothing. The report number, how serious it is, what kind of report and when it happened, with a link. Not what happened, not where, and not who was involved. Email is the least controlled place anything can end up — forwarded without thinking, and the one copy that never appears in the record of who has read what. The email is there so you know to look now; the file is where you look.

    A driver's hazard will not set this off. Drivers do not set severity — everything they flag arrives at medium on purpose, so a low branch cannot page the depot at six in the morning. Your triage is what makes a report serious.

  • Outstanding safety work now appears on your task list overnight. Every open report — unassigned ones as a task for the team, assigned ones for the person who owns them, which is also how they find out they were given it. And a child treated with first aid whose guardian has not been recorded as told, assigned to whoever wrote the record.

    That last task names the record number and nothing about the child. Far more people can see a task list than can open the first aid register, and the register's gate would not be worth much if the task in front of it gave the answer away.

    Standing conditions never become tasks. They have been assessed and the answer was that they are permanent, so there is no outstanding work — and a task you can never clear is how a list stops being read.

  • Children already accounted for move out of the driver's way. Anyone marked away — by you, or by the driver at the kerb — now sits in the same tucked-away group as children the school roster says are not in today, instead of staying in the middle of the list. On an afternoon run that also stops a child being offered for drop-off at their own stop when they never got on at the school. They are still one tap away, and a child nobody has accounted for stays in front of the driver where they belong.

    The group is now called Not Expected/Onboard.

  • Fixed: the driver app showed some confirmations twice — once in a banner that clears itself and once in a copy that never went away.

[1.35.0] — 2026-08-12

  • Preview a checklist as a particular run would ask it. Pick a day and a morning or afternoon run, and the preview now shows the questions that run would actually put in front of a driver — before the run and after it, listed separately — instead of every question on the form regardless of when it is scheduled. It's the quickest way to check a change to a schedule before a driver meets it.

  • Safety checks no longer lose their setting when a checklist is saved. On a checklist that includes built-in questions such as the odometer reading, saving the form could move a question's safety setting onto the wrong question — and a question left without one stopped being a check at all. On the driver's screen it appeared as a plain box with no Pass/Fail buttons, so it could not raise a fault or take a bus off the road. Fixed. If you have edited a checklist recently, it is worth opening it and checking that each question still shows the setting you expect.

  • Hazards reported from the bus now actually save. Reporting a hazard had never once worked: the driver's app sent it, the system turned it away, and the app treated that as a refusal and discarded it. Nothing was stored and nobody was told. Fixed, along with the screen where drivers write up what they saw.

  • A hazard is now recorded at the time the driver saw it, rather than the time it reached the office. Those are the same moment when the bus has signal — but a hazard flagged somewhere without coverage is held on the phone until the bus reaches a signal, which can be much later, and could previously even record it against the wrong day.

  • Children can only be marked on or off at the stop the bus has actually reached. Every stop on the run screen offered the same buttons, including stops still ahead — so a driver glancing at the wrong card could mark children off before the bus got there. The record balanced either way, which is what made it hard to notice. Those buttons are now held back until the stop is marked as arrived, and the screen says so and says which single tap releases them. Correcting or undoing something already recorded is unaffected, and so is marking a child absent.

  • The finish-run panel no longer overlaps the stop it sits beside. At the last stop of a run, the panel could squeeze the stop details until the stop name, the arrival button and the departure button printed on top of one another. The panel now keeps its size and the page scrolls if there isn't room, so every control stays readable and separate.

  • The green confirmation message now clears itself. It used to stay on screen for the rest of the run, taking up room the driver needed for the stop controls.

  • Finishing a run is now a step-by-step sequence. Back at the depot the driver is asked one thing at a time — confirm the bus has been swept, then the end-of-run checks, then a note about anything hazardous they flagged on the road, then finish the run. Each step appears as the one before it is done, and completed steps stay ticked on screen. Writing up a road hazard is still optional and never blocks finishing; anything left is asked for again on the driver's run list.

  • A Safety section in the driver app. Drivers now have Safety in the app menu, and it leads to their hazards: the ones they reported — including the ones they've already described, which used to disappear the moment they were written up — the ones somebody else's report names them in, and the ones already known about on the roads they're rostered to over the next fortnight. Being named in a safety report and not being able to read it isn't something anyone should find out about later.

    It is not the office's whole register. Every hazard on that screen is either the driver's, about the driver, or on the driver's road.

  • Drivers can report a hazard without being on a run. A broken gate in the depot yard, a collapsed kerb by the bays. It records the position where they're standing and takes them straight to the form, since they're not driving. It's also available to a driver who has been stood down — a lapsed check stops someone driving, it shouldn't stop them reporting what they've seen, or writing up something they flagged before the lapse.

    The one-tap warning triangle on the run screen still works with no signal; this one needs a connection, because a driver standing at a depot can tap it again and a report that looked like it worked would be worse.

  • The checklist schedule table now saves as you go. Each row saves itself a moment after you change it and tells you where it's up to, the same way the question builder does — so a schedule you edited and navigated away from is no longer lost. Only the row you edited is sent, so a colleague working on a different question at the same time isn't overwritten. The Save schedule button is still there for when you've changed several rows at once.

  • The weekly columns follow the cadence you pick. Set a question to weekly and its day boxes and deadline appear beside it; set it back and they go again. Switching a question to weekly without picking any days gives it the usual days for that cadence rather than none — a weekly question that appears on no day at all would never be asked — and the row updates to show you which.

[1.34.0] — 2026-08-11

  • Hazards now appear on the dispatch map. The live map already showed where the buses were; it now shows the open hazards across the whole business alongside them, so the people watching the fleet can see what is on the road in front of it.

    You'll see a hazard the moment a driver flags it, not at the end of their run. A driver reports a hazard with one tap while driving and writes up what it was when they get back. Until now nobody in the office knew anything until that write-up arrived. A hazard that hasn't been described yet now shows as an outlined marker, so you can tell at a glance that a driver has seen something and the details are still to come. It fills in once they describe it, and disappears once it's resolved.

    An outlined marker says simply "Hazard flagged" — that's all anyone knows at that point. Once the driver submits their report, the marker fills in and gives you the report number and how serious it is, with the written account on the report itself.

[1.33.0] — 2026-08-11

  • The driver app now says when it is about to mark a stop for you. A short line appears on the stop while the app can see the bus arriving or pulling away — and no line appears when it can't, which is the useful part: it tells the driver straight away whether to wait or just tap the button, instead of waiting to find out.

  • Driving past a stop no longer holds up the rest of the run. When the bus goes by a stop without stopping — nobody waiting, running behind — the app now recognises it and closes that stop by itself, so the stops after it keep marking themselves as before. It is recorded as what it was: the bus passed the stop, not that it served it. If any child is still expected at that stop the app will not close it; instead it tells the driver on the stop itself, and leaves the decision to them.

  • Every checklist question can now be given its own timing. Questions that are not safety checks — an odometer reading, a note, a signature — can now be set to appear before or after the run, and on whatever rhythm you choose, in the same way a safety check can. Previously those settings were only available once a question was marked as a check, so a reading you only wanted at the end of the run could not be asked there. Existing checklists are unchanged.

  • The driver app marks stops for itself more often. It now works out that the bus has reached or left a stop from where it is along the road it is driving, as well as from how close it is to the stop. That means fewer stops the driver has to mark by hand, it copes with a stop set slightly off the kerb, and leaving a stop is recognised as soon as the bus is clearly on its way rather than after a fixed wait. Marking a stop by hand works exactly as before, and the checks that stop a bus being recorded at the wrong stop are unchanged.

  • Hazards reported from the bus are saved again. A fault meant a hazard flagged by a driver on the road was not being stored, so it never reached the office and the driver was never asked to describe it at the end of the run. Fixed. The same fault was stopping the driver app refreshing the copy of the day's information it keeps for working out of mobile range; that is working again too.

  • One way to each screen in the driver app. Some screens still showed their own Today, Attendance and Your week buttons alongside the menu that already offers them. Those extra buttons are gone — the menu on the left is now the single place to move between screens.

  • A checklist question can now ask for a photo or a note. Set it per answer — most usefully on a fail, so a tyre check answered "no" comes with a picture of the tyre or a sentence about it instead of just the word. Either one satisfies it; drivers are never asked for both. Whatever they send appears on the fault itself, where whoever has to fix it will see it. With no signal the check still goes through — a missing photo never stops a bus leaving the depot — and the fault records that nobody has been asked yet. Photos are held privately and are only visible to people who can already see the fault.

  • Checklist questions can be reordered again. Dragging a question by its handle in the checklist builder never actually moved it — the handle was there and did nothing. Dragging now works, including for built-in questions like the odometer reading, which previously could not be moved at all. Useful if you read the odometer after the run rather than before it: it can now sit at the bottom of the checklist.

  • Finishing a run is now one button at a time. At the depot the driver app shows only the next step — Arrived, then "I have swept the bus", then Finish run — with each completed step collapsing to a single ticked line. Drivers had been scrolling to find the last two controls of a run.

  • The Departed button no longer scrolls off the screen. On a tablet held upright at a stop with a lot of children, Departed could end up below the bottom of the screen, and the list of children could overlap it. It now stays pinned to the bottom with the children scrolling underneath, so the control that closes a stop is always where the driver expects it — and a tap can no longer land on a child's tile by mistake.

  • Saved driver signatures now survive an update. A signature saved in the driver app could be lost when the platform was updated, leaving a blank space where it should have been. Signatures are now stored durably. If a driver's saved signature is missing, the app now says so plainly and asks them to draw it again, instead of showing an empty box — checks already signed keep their own copy and are unaffected.

  • More of the run screen given to the run. The bar across the top of the driver's run screen used to be two rows with a gap between them. The run name, the hazard button and the on-board count now sit on the same single bar as the speed and the schedule indicator, handing the space back to the map and the children's names.

  • The map now stays at quiet stops. It used to disappear at every stop. It now moves aside only when there are more children than fit on screen beside it, which on most stops there aren't — so the road stays in view when it isn't in the way. The app works this out by measuring the screen rather than counting children, and re-checks if the tablet is turned round. One button above the list still overrules it, and now does so in both directions: it will hide the map at a quiet stop as readily as it brings it back at a busy one.

[1.32.2] — 2026-08-11

  • "Your cards" is now "Your Quals" in the driver app menu — the word drivers actually use.

[1.32.1] — 2026-08-10

  • You're asked what a hazard was at the end of the run, not just afterwards. The close-out section now has a box for each hazard you flagged, so you can say what you saw while it's fresh. It holds nothing up — leave them empty and finish the run normally; your runs list will ask again.
  • The hazard button is now at the top of the run screen and stays there. It had been sitting under the stop you were working, which meant it disappeared between stops — and between stops is where you meet a hazard. It's a warning triangle beside the on-board count now, on screen for the whole run. One tap still records the spot and the time and asks nothing else.
  • The sweep and Finish run controls come to you at the depot. Mark the depot arrived and they move up beside it instead of staying at the bottom of a long page. They're still at the foot as well, so nothing is ever out of reach.
  • A child marked off just before leaving a stop no longer reappears as still on board. If you marked someone off and departed a second later, they could show as carried over at the next stop — so the sensible thing to do was mark them off again, and the record ended up saying they got off in two places. The app now remembers what it has just sent for a moment, so the screen can't overwrite what you have only recently done.
  • The form builder now saves as you work, and warns you before you leave. Changes used to be kept only when you pressed Save form, and nothing on screen told you anything was still unsaved — so refreshing the page or closing the tab first lost that work without warning. Three things have changed. Your changes now save automatically a moment after you stop editing. The builder shows where it is up to beside the field count — "Unsaved changes", then "Saving…", then "Saved" — so the state of your work is visible rather than assumed. And if anything still hasn't reached us when you leave the page, your browser checks with you first.
  • Building a form can no longer publish it by accident. Automatic saving covers the questions on the form only. Its name, whether it's switched on, and whether families can see it are still applied only when you press Save form, so a form part-way through being built never goes out.
  • Your safety settings survive every automatic save. Severity, how often a question is asked, and whether it belongs before or after the run are all carried through exactly as you set them. If a question carrying those settings is deleted, you're told which one the next time you save — so a safety check can never quietly stop being asked.

[1.32.0] — 2026-08-10

Added

  • Drivers can flag a hazard from the bus with one tap. A button on the run screen records where the bus is and the time — nothing else, because the driver is driving. It works with no signal, which matters: the roads worth flagging are usually the roads without coverage.
  • The driver is asked what it was once the run is finished. The position and time are already saved; this is just the account. Nothing waits on it — a driver can finish their shift with hazards still undescribed, and anything left shows on your register so you can chase it.
  • Open hazards appear on every driver's map. A fact one driver learned on one run is worth nothing to the driver who meets it tomorrow unless it travels. Hazards sitting close together are grouped with a count, and they work offline. A hazard marked resolved stops warning drivers straight away.
  • Only hazards and near misses reach a driver's screen — never incidents. A hazard is a fact about a road. An incident is something that happened to somebody, and where it happened stays in the office.
  • The hazard and incident register is now a screen you can open. Safety reporting has a home: raise a hazard, a near miss or an incident, see what's still outstanding, and work it through to a close.
  • Hazards and near misses have their own view. A register of what was caught before anyone was hurt reads differently from a list of what already happened, and it's the one an accreditation audit tends to ask for.
  • "Resolved" and "closed" are two different things. Resolved means the hazard itself is dealt with; closed means the write-up is finished. Marking something resolved takes it off the outstanding list straight away, without waiting for the paperwork.
  • Closing a report always asks what happened — including when nothing did. If the answer is that nothing was done about it, that's a legitimate call, and it's the one most worth having written down.
  • You can now record what's being done about a report. Follow-up work can be raised against a hazard or incident, given an owner and a due date, and it turns up on the same outstanding-work list as anything raised from a risk review.
  • Reports now say what actually happened. Every report records what happened and what was done at the time, alongside where and when. A record with a place and a time and no account of the event isn't a record of anything.
  • Hazards can be put on a map. Drop a pin where it is, or search for an address and drop it there — "Albany Highway" doesn't say which end of a forty-kilometre road. The register also shows every located hazard on one map.
  • Hazards close together are grouped, with a count. A depot usually collects a few, and at that zoom the markers land on top of each other so three read as one. They're now shown as a single marker carrying the number, which opens out when you click it.
  • A report can be corrected after it's filed. What was reported can be edited until the file is closed — the account, the type, the date, the place. Severity, status and assignment stay separate, so an edit can't quietly close a file, and once closed nothing can be changed.
  • A new "standing condition" status for hazards nobody can remove. Kangaroos at dusk, an unlit stretch, a crossing that floods every winter. These keep warning drivers indefinitely, but stop counting as outstanding work — so they no longer sit on the to-do list forever looking like something nobody has assessed.
  • Follow-up work can be assigned to drivers, not just office staff. Checking a mirror or re-walking a turn belongs to the person who drives the road.
  • Safety now appears in the menu. The register, the follow-up work list and the risk register were previously reachable only if you already knew the address.

Fixed

  • The driver app now locks itself when it's left alone. It always locked after a few minutes of no use, but the lock only appeared when somebody next pressed something — so a phone put down on a seat kept its last screen showing until it was picked up. It now takes itself to the PIN screen on its own.
  • A phone in use isn't interrupted. The lock watches for the driver actually using the device, so reading a screen keeps it open. And it still doesn't lock during a run, which is unchanged.
  • The app now marks stops arrived for you far more often. It could already do it, but the few seconds it waited only began once the bus had come to a stop — so at a quick stop, where the child is at the kerb and you're away again in seconds, the driver always tapped Arrived first. The wait now starts as you enter the stop's zone, so on most stops it's already marked by the time you're ready to pull out. A drive-past still never counts, and you can still mark any stop by hand at any time.
  • Leaving a stop no longer reloads the driver screen. It used to reload the whole page to bring the next stop up, and every reload made the phone start hunting for a GPS position from scratch — which took up to a minute, during which the app couldn't mark a stop arrived for you and the office couldn't see where the bus was. Only the stop panel changes now. Nothing you've tapped is lost, and anything waiting to send stays waiting.
  • The map no longer clears a turnaround before you've driven it. Where a run goes up a road, turns around and comes back down, the two directions are the same strip of road and no GPS can tell them apart — so the map could mark the detour as already done while the bus was still driving out to it. It now works from how long you've been driving as well, and won't credit you with distance you couldn't have covered in the time.
  • The next turn is now called out one at a time. Where the office has recorded the turns for a route and approved its road path, the manoeuvre you're coming to appears above the map with the road name and how far off it is, and clears itself once you're past. The full list is still there for the leg you're on. This is not satnav: it won't re-route you and it won't speak — it shows the directions the office has already recorded, in the order you meet them, instead of as a list to read while driving.
  • Clearing a mis-tapped child is now labelled. Tiles sit close together and a mis-tap usually lands on the child next to the one you meant. The control that clears it was an unlabelled cross, and a driver who wanted it reasonably concluded there wasn't one — and marked the child absent instead, which says something quite different and means nobody waits for them at their stop. It now reads CLR, in the opposite corner to ABS.

Fleet checklists

  • A checklist item can now book workshop work instead of raising a fault. Until now a driver answering "no" to any check raised a defect, so "the washer bottle is low" and "the tyres are not OK" landed in the same list. There is now a third option: mark a question as Maintenance and a "no" books the job against that bus without recording a fault and without taking the vehicle out of service. The run starts as normal. Critical and Minor behave exactly as before.

    The driver's screen says which is which, so nobody hesitates over a Fail because they are not sure whether it will strand their run.

    Booked work appears on your tasks board — straight away if it has passed its due date, and after a month if it is still sitting there undated.

  • The odometer is now a question you control. It used to be fixed to the bottom of every pre-start screen whether or not you wanted it. It is now a field you can move, rename, mark as required, or leave off a checklist that has no odometer to read. Every existing checklist has had one added automatically, in the same place it always appeared, so nothing changes for your drivers unless you change it. It still updates the vehicle's recorded distance exactly as before.

  • You can now record fuel and AdBlue on a checklist. Add a litres field and the amount is recorded against the bus alongside the odometer reading taken at the same moment, which is what makes fuel economy and running cost per kilometre possible. Leaving it blank and entering zero are treated as different answers — "I checked and added none" is worth recording, and it will not be mistaken for a bus nobody asked.

  • Drivers can save a signature once, instead of drawing it before every run. A driver sets their signature on their About me screen — a screen they can only reach when they are not on a run, so it can be drawn properly rather than with a fingertip at the bus. Add a signature question to your checklist and they simply confirm it each time.

    A driver who has not saved one, or a relief driver, draws on the screen as before, and that signature belongs to that check only.

    Each check records how it was signed — drawn at the time, or the saved signature applied — so a later review can tell the two apart.

    Removing or replacing a saved signature never changes checks already signed. What a completed check shows is what it showed on the day.

    Signatures are held privately, are never public or cached, and a driver can only ever see their own.

  • Checklist scheduling moved onto the question itself. How severe a failure is, how often a question is asked, whether it belongs before or after the run, and which days a weekly question appears on are all now set in the properties panel on the right when you select a question — instead of on a separate screen behind a button. The full schedule is still available as a single table for comparing everything at a glance, now as a read-only overview.

  • The school portal has a menu down the side. A school contact's screens used to hang off buttons on one page, so navigating away meant losing the way back. Every screen now carries the same list: today's students, the attendance register, reporting a student not travelling, and term dates.

  • Today's students now says which bus each child is on. The morning service is listed first, then the afternoon — whatever they happen to be called.

  • Schools get the attendance register. The same week-at-a-glance register your office uses, holding only that school's children, and covering every operator that school has an agreement with rather than just one. They can filter it by route, move between weeks, cross a morning or afternoon a child isn't travelling, and mark a child away for a range of days.

  • A parent's absence stays the parent's. Where a family has already said their child isn't travelling, the school can see it and can't clear it — only the family or your office can. Marks the school made itself, it can clear.

  • Once a run has started, the school is told plainly it can't be changed. The driver already has the manifest at that point, so the screen refuses and asks them to phone you rather than accepting a mark that would never reach the bus.

Fixed

  • A school's Today's students now shows children marked as not travelling. It only ever showed what the driver had recorded, so a child the school had marked away read as though nothing had been noted — while the attendance register showed the mark correctly. The two screens now agree. Where a child was marked away and travelled anyway, the driver's record still wins: they were on the bus.

  • The driver app now has a menu. The Tutela logo has moved to the left of the screen and become a menu: Today's runs, Your week, Attendance and About me, on every screen, with the one you're on highlighted. They used to be spread across three places on the runs list — two small buttons beside the heading, a wide button further down, and nothing at all on the other screens. Refresh sits underneath it.

  • The run screen still has no menu, on purpose. Once a run starts, the whole screen belongs to your stops, your children and the map. That is unchanged.

  • Your cards and your tasks now have their own screens. Both used to be sections part-way down About me, so checking why you were locked out meant scrolling past your own phone number to get to it. They're in the menu in their own right now. About me still tells you where things stand and says Needs attention when a card isn't current — nothing has gone quiet, the detail is just one tap away instead of further down the same page.

[1.31.0] — 2026-08-10

Changed

  • An out-of-date qualification now stops the driving, not the whole app. Previously a driver whose working with children check lapsed was locked out of the driver app entirely — including the screen that would have let them send in the renewal. Now they keep the app and lose only the runs: they can still see their week, the attendance grid and their own details, and can send the renewed card straight to the office themselves.
  • They are told why, before they tap. The runs list explains what has lapsed and points at where to send the renewal, rather than refusing at the moment they try to start.
  • What has not changed is who may drive. An out-of-date driver still cannot open or start a run, board a child or see a child's photograph, and sending in a renewal does not restore any of that — it counts only once the office has checked it against the register.
  • Expiry warnings now arrive every day of the final week. The reminder ladder ran at 90, 60, 30, 14, 7 and 1 days, which left the last week — the one that decides whether somebody can work on Monday — with two warnings and five silent days in between. It now steps every day from seven, and the office is escalated in step, so neither side can be the one who did not know.
  • Those warnings are counted on the depot's calendar. They were being worked out from the server's date, which is a day behind the depot's for the first part of every morning. That has been corrected — which matters far more now the final week is counted day by day.

Added

  • One fleet checklist instead of three. There used to be a separate pre-start checklist, post-run checklist and end-of-week checklist to build and keep in step. Now there is one. Each question carries its own rhythm — every run, daily, weekly, monthly, quarterly or yearly — and says whether it belongs before the run or after it, so one checklist does all of it and drivers are shown only what is actually due.

  • Extra questions for particular buses. Some vehicles need more than the rest: a wheelchair hoist, an older bus you are keeping an eye on. You can now build a second checklist and choose which vehicles it applies to, so those questions are asked on those buses instead of being pushed at every driver in the fleet. Several buses can share one, so "the three with hoists" is maintained once rather than three times.

    These questions are always added to your company checklist, never instead of it. A bus with extra questions is still asked everything every other bus is asked. There is no way to configure a vehicle that gets fewer checks than the rest of the fleet.

  • Weekly questions can name their days, and a day they must be done by. Pick the days a weekly check appears — Monday and Thursday, say — so it is not sitting on the screen being scrolled past five mornings running. You can also set the day it must be done by: from that day, if the week's answer is still outstanding, the question is shown whatever days you picked and the checklist cannot be sent without it. The driver is told which question by name rather than just being refused.

    A check that missed a whole week is outstanding straight away rather than waiting for its day to come round again. A question you added this week is not held against anyone until its deadline arrives.

  • The buses with no safety check are now named. If no fleet checklist has been built, buses can start a run unchecked. That is deliberate — nobody setting up should be locked out of their own fleet — but it used to be silent, and a bus with no check looked exactly like one that had passed. The checklist screen now lists the vehicles affected and keeps saying so until a checklist exists.

Fixed

  • Checklists built on the pre-start checklist screen were not enforcing severity. Items saved there were being recorded as informational whichever severity was chosen, so a failure could not raise a defect or take a bus off the road, and re-opening the screen showed every item as informational. Severity now applies as set. If you built your checklist on that screen, check the severity of each item is what you intended.

  • Editing the checklist no longer resets how often each question is asked. Saving on the checklist builder was putting every weekly, monthly and after-the-run question back to "every run, before the run" — so drivers were quietly asked more, with nothing reporting a change. Questions now keep their schedule when the checklist is edited.

  • Buses now record what you actually keep about them. Class, base, transmission, fuel, engine number, GVM, registration state, contracted daily km, bus life expiry and allocated students — all optional, all editable on the bus's own screen, and all importable.

    Allocated students is an allocation, not a load. It can be more than the seating capacity and that's correct — not every allocated student travels on every run. Tutela won't stop you entering it, and nothing treats it as a capacity limit.

    Bus life expiry is marked on the bus's page once the date has passed.

  • Bases — the towns your fleet works out of. Set them up under Settings → Bases, then choose one on each bus. It's a managed list rather than a typed box on purpose: typed, "Boddington" and "boddington" would become two different bases and any grouping built on them would quietly be wrong.

    A base is retired rather than deleted, so a bus that already uses one keeps it and nothing loses its history. Importing a base that doesn't exist is refused for that line and names it, rather than creating it from a typo.

  • The importer understands the headings your existing system uses — Class, Rego, Seats, Group and Depot are all read correctly, so you usually don't have to rename anything.

Fixed

  • An import could clear cameras and GPS on every bus. A file that didn't mention those columns — an odometer refresh, say — was treating them as "no" rather than "not mentioned", and quietly clearing them fleet-wide while reporting success. A column your file doesn't include is now left completely alone.
  • Dates written the Australian way are read correctly. 03/04/2019 is 3 April, not 4 March. Previously it was accepted as the wrong day without complaint.
  • Numbers with commas are accepted. 184,000 is what a spreadsheet writes for an odometer; it used to be refused.
  • Columns Tutela can't store are now named. They're still skipped, but the screen tells you exactly which ones, instead of reporting a clean import while quietly dropping them.

Added

  • Drivers get an "About me" screen. It holds their own details, the cards that let them drive, and anything allocated to them — reached from the bottom of their runs list when they are not on a run.

  • Drivers keep their own contact details up to date. Phone, home address and emergency contact are theirs to change, and the office sees the change straight away. That removes a phone call and, with it, the chance of a number being mis-heard or typed in wrong.

  • Drivers can send in a renewed card without ringing up. They enter the card and its new expiry and it goes to the office to be checked against the register. It counts for nothing until that check is done — the screen says so plainly, so nobody sets off assuming they are covered.

  • Everyone can see where their cards stand. Current, waiting to be checked, or out of date. Expired cards stay on the list rather than vanishing, because an expired card is the reason somebody is locked out.

  • Name and date of birth stay with the office. They have to match what is printed on a licence and a working with children card, so the screen shows them and points to the office for changes.

  • The driver app now stays on the run while a run is under way. Once a driver starts a run, the app keeps them on it — the other screens are out of the way until the run is finished. Everything they need for the run itself is unaffected, and anything saved on the device with no signal still sends as normal. Finishing the run gives the rest of the app back.

  • You can import your fleet from a spreadsheet. Import fleet on the Fleet screen takes a CSV, so setting up no longer means typing every bus into a form one at a time. Start with the downloadable template — it has the right headings and an example row.

    Only fleet number, registration and status are required; make, model, year, seats, seatbelts, wheelchair positions, cameras, GPS, odometer and dates can all be left blank and filled in later.

    Every line is read on its own. The buses that are complete go in, and any line that can't be imported is listed afterwards with its line number and the reason. Correct those lines and upload the same file again — one bad row never holds back the rest.

    A bus already in your fleet is updated rather than added again. It's found by its VIN first, and by registration only when your file gives no VIN — a VIN belongs to the vehicle for life, whereas plates get changed and reissued. So when a bus gets new plates, change that one column and import again; it stays the same vehicle, with its history intact.

    An update writes only the columns your file fills in. A blank column is left alone, never cleared, so a file carrying just fleet numbers and plates can't wipe the details of every bus you have.

    A bus's status is never changed by an import. Grounding and ungrounding are separate permissions held by particular people, and a spreadsheet must not be able to put a grounded bus back on the road.

    If a line's VIN and registration point at two different buses, that line is refused and named — only you can say which is right.

    Registration, insurance and inspection dates are not imported here — they decide whether a bus may run, and are recorded on each vehicle's compliance screen.

Fixed

  • Turns read from a contract are now placed just before the junction, not on it. A turn sitting exactly on an intersection could send the road path past the intersection and back again, because the point was as close to the road being turned onto as to the one the bus arrives on. Placing it a few metres back up the approach removes the ambiguity.

    This was behind the wrong-looking paths reported on real routes: a leg driving several roads its directions never mention, roads covered twice, and in one case nearly seven kilometres of driving between two stops two hundred metres apart.

    Turns you place by hand are never moved — where you drop one is where it stays.

Added

  • Drivers can record a stop they didn't drive to because nobody was expected. If every child at a stop has been marked away, the run screen says so and offers a way to note that the stop wasn't visited. It keeps a record — who decided and when — so a stop that was checked and deliberately left out is no longer indistinguishable from one that was missed.

  • That record can always be undone. If somebody turns up at a stop after all, the driver puts it back on the run and boards them exactly as normal. The app never treats an advised absence as the final word, and it never tells a driver a stop may be left out — the decision is the driver's, and we'd always encourage a word with the office first.

  • The dispatch board keeps counting properly. A run with a stop recorded as not visited shows its progress accurately instead of appearing to stall.

  • Drivers can see how many children to expect at each stop when they preview a route. The preview now shows a number against every stop that children ride from, for the day you're previewing — the children assigned to it, less anyone whose family, school or office has told us they're away, and anyone whose timetable means they aren't travelling that day.

  • A stop with nobody expected is called out. If every child at a stop is away on that day, the preview says so plainly instead of leaving you to work it out from a list. Stops that never carry children — depots and turnarounds — are left alone, so the message only appears where it means something.

  • Previews still show numbers only, never a child. No names, no photographs and nothing that identifies anybody appears on a preview; those stay on the run itself, on the day. The numbers reflect what we'd been told when the page loaded, and the preview will tell you if it's since gone out of date.

  • The road path is now built one leg at a time. The Road path tab shows the leg you're working on, with a strip above it for every leg on the route — click any of them to jump straight there, or step through with Previous and Next.

  • The map shows the leg you're on as the subject and dulls the rest. The other legs are still drawn, so you can see how this one joins them, but they're no longer competing for your attention.

    This is what makes a wrong path findable. If part of a route follows a road the bus doesn't take, page through the legs — the moment the bad line lights up, that's the leg, and its turns are on the card in front of you. Previously the whole route was one line and nothing on the screen said which leg owned any part of it.

  • The leg strip shows where the work is, so you don't have to go looking: an amber dot for a leg with a turn nobody has placed, a red one for a leg with no road path.

  • Press the ⌕ button on any stop or turn and the map flies to it and rings it for a few seconds. A dozen turn markers look identical on the map; this is how a row tells you which one it means.

  • The map now holds its position while you work. Dropping or moving a turn used to zoom the map back out to the whole route, so placing several turns around one junction meant finding that junction again every time. It now stays exactly where you left it, at the zoom you were using. Moving to a different leg re-frames the map on that leg.

[1.30.0] — 2026-08-09

Fixed

  • Legs of a route now follow the road automatically. Whenever you change something that affects how a bus gets between two stops — moving a stop, adding or dragging a turn, reordering them, re-reading the directions from the contract — that leg is put back on the road straight away. You no longer have to press anything to make it happen.

  • A leg with no road path is now unmistakable on the map. Where a leg has no road path, the map joins its two stops with a dashed grey line instead of drawing it like a road. That dashed line is a placeholder: it shows the stops are connected and in what order, not a way a bus can drive.

    This is the important fix. Previously those stretches were drawn in the same colour and weight as a real road, so a straight line across open country looked like a long country road — on your map and on the driver's. Drivers now see the same dashes, described the same way, and their guide tells them plainly not to follow one.

    The wording under the map changed to match. It used to say the remaining legs were "not drawn yet", which was never true — they were drawn, just as though they were roads.

  • A leg only asks for you when the road service could not answer. If there is genuinely no road between two points, or the service was unreachable, that leg offers a button to try again and says why it is there. Every other leg looks after itself.

  • Removing a stop now removes the turns on the legs either side of it. Those turns used to stay on the map after the stop had gone, looking exactly like turns the route still required — and because the leg they belonged to no longer existed, there was no way to delete them. Any left over from before have been cleared.

  • Re-reading the directions from a contract no longer loses turns you had placed. If you had dragged a turn onto the right junction and then re-read that leg's directions, the turn came back with no position and had to be placed again. Where you put a turn is now kept, and takes precedence over an automatic guess.

Added

  • Road path is now two columns, with the map alongside. The leg cards are on the left and the map on the right, and the map stays in place while you scroll the legs. Placing a turn means pressing a button on a leg and then clicking the junction on the map, and those two were previously a long scroll apart on a route with a dozen legs.
  • Working a leg no longer sends you back to the top of the page. Every action on the Road path tab now returns you to the leg you were working on, with its card still open.
  • You can correct a turn without removing it. A small pencil control on each turn changes what the bus does there and the contract's wording for it, leaving the turn exactly where it is on the map. Fixing a typo used to mean deleting the turn and adding it again, which threw away its position — the slowest part of the job.
  • A stop's page now shows it on a map. Opening a stop used to give you its latitude and longitude as numbers, which told you very little — the only way to see where the stop actually was meant opening the edit screen. The map is now on the stop's own page, with the pin and the circle around it.
  • You can see the arrival circle, not just its size in metres. Every stop has a circle around it that the bus has to come inside for the system to notice it has arrived. That circle is now drawn on the map at its real size against the surrounding streets, so you can tell at a glance whether it comfortably covers the place buses actually pull in — which is much harder to judge from a number alone.
  • The map on this page is view-only. You cannot drag the pin or move the stop from here. Changing where a stop sits is still done on the edit screen, on purpose: the pin decides whether a bus is recorded as having arrived, so it should not be possible to nudge it while you are only looking.
  • A stop with no location saved says so plainly. Rather than showing a map pointing at nowhere, the page tells you the stop has no coordinates yet and that arrival cannot be detected there — and offers a link to add them, if you have permission to edit stops.

Note that the street map behind the pin is our own, and is currently fairly coarse when you zoom right in. Improving that detail is separate work already on our list.

[1.29.0] — 2026-08-08

Fixed — the Refresh button now sits under the logo in the driver app

On Today's runs and Your week, Refresh was rendering off to the right of the Tutela logo rather than beneath it — most noticeably on a tablet in landscape, where it ended up in the far corner of the screen, well away from the run list a driver is reading.

It now sits directly under the logo on phones and tablets alike. Refresh is what a driver reaches for when they think the screen might be out of date, so it needs to be where they look for it.

Added — drivers can look at a route before they drive it

Preview the route now appears under every run on Today's runs and on Your week, including days ahead. It opens the route on a map: the road it follows, the stops in order, and the time each one is due.

It is for learning a route you have not driven, or one you are covering for someone else, and it can be opened the night before. Nothing on it starts a run and nothing on it records anything — there is no Arrived, no Departed and no marking children on or off. No children are listed on a preview at all; their names appear on the run itself, on the day.

The screen has its own Prepare offline map, so the streets for a route you are about to learn can be stored without waiting for it to become a run.

Added — the app tells a driver when the route on the device is not the current one

The driver app keeps pages on the phone so they still open with no signal. That is what makes it work in a blackspot, and it means a screen can be showing something the office has since changed — a stop moved, a time changed, or the road path re-approved. Until now nothing said so, and a route looked at last term would open again looking perfectly normal.

The route preview now checks itself against the office each time it opens, and says which it is: this is the current route, this is not the current route, or — with no signal — that it could not be checked, along with when it was last confirmed current.

When it finds a change it says so before changing anything on screen; Get the latest route loads the current one on the next tap. A screen that swapped one road for another while a driver was reading it would be the exact problem this check exists to catch.

Changed — the road path now has its own tab on a route

Building a route and checking the path it drives were sharing one crowded screen, in two narrow columns. The form for adding a turn was squeezed so hard its labels ran onto three lines and its text box shrank to about a centimetre wide, the table of legs cut off its own Status and Actions columns, and placing a turn meant pressing a button on the left of the screen and then clicking a map on the right.

Stops & timing now does one job: the stops, their times and their order, with the map beside them. The map stays put as you scroll, so it is still there when you reach the bottom of a long route.

Road path is a new tab with the full width of the screen. The map sits across the top, the approval panel is under it, and then there is one card per leg carrying everything about that leg together — what the contract says, the turns on it, whether its path is current, and the tool for drawing it by hand.

Legs stay closed unless one needs you: a turn not yet on the map, or a path that is missing or out of date. So the legs that are open are the ones with something to do.

Nothing has been removed, and every control works as it did. Adding a stop, and tracing the road as you add it, are both still on Stops & timing where they belong.

Changed — the map keeps half the screen while you are driving

The map used to shrink on the way to a stop, based on how many children were waiting there — down to a narrow strip for a busy one. That meant the map was at its smallest while you were still driving to the stop, which is exactly when you want it.

It now keeps half the screen the whole way. When you arrive, the map steps aside completely and the passenger list takes the full width — which is the point at which you actually need the room.

The passenger tiles themselves are unchanged: a busy stop still switches to the wider rows that keep names readable.

[1.28.0] — 2026-08-08

Added — an overnight check that looks for things that do not add up

Tutela now runs a nightly review of the day's operating data, looking for records that disagree with each other — a planned run expecting a different number of children than are actually assigned to it, two stops close enough together that the bus cannot tell them apart, a bus reported as swept well before it finished its route.

It reports; it never changes anything. Travel records are kept in a way that never overwrites what was recorded at the time, and an overnight job quietly correcting them would remove the very evidence that something needed attention. Anything it finds is raised for a person to look at and decide on.

The three things it looks at were each chosen because they had genuinely happened and nothing had reported them. More will be added the same way.

Fixed — the run now continues to the depot, and that is where you sweep the bus

Once the last child stop was worked, the driver screen had nothing further to show — even with a long drive back to the depot still ahead. The only way to close the run was to sweep the bus and finish it there at the kerb, sometimes half an hour before the bus was actually parked.

The sweep is the check that catches a child left on board. It belongs at the end, with the bus stopped and empty.

The depot is now part of the run on the driver's screen. After the last child stop, it appears as the next place to go, with an Arrived button. Mark the bus arrived when you are parked, and the sweep and finishing the run happen there.

Each end of the run now offers only the button that makes sense for it. You do not arrive at the depot you start from, so that stop offers Departed — tap it when you pull out. You do not depart the depot you finish at, so that one offers Arrived. The starting depot is also recorded automatically when you begin the run, so the time the bus set off is kept properly.

If you need to finish a run early, everything still works exactly as before. Nothing is locked behind reaching the depot.

Fixed — assigning a child to a stop now updates how many are expected on runs already planned

Runs are prepared ahead of time. If children were assigned to a route's stops after those runs had been prepared, the runs kept the number they were created with — which, on a route set up in the usual order, was none.

Everything the driver sees was correct: the right children appeared on the right stops, and the check that a bus is not left with a child aboard was never affected. What was wrong was the run's own idea of how many children to expect, which is what the office uses to tell whether everybody who should have travelled did.

Assignments now feed through to any run that has not started yet, in both directions — adding a child raises the number, removing one lowers it. Runs already under way or finished are left exactly as they are, because those are a record of what happened rather than a plan of what should.

Fixed — a stop no longer marks itself arrived while the bus is still at the last one

Where two stops are close together — opposite sides of a road, or a little further along the same street — each can sit inside the other's arrival zone. When that happened, the moment a driver marked the first stop departed, the app could decide the bus had also arrived at the second and then left it, all without the bus moving an inch.

The effect was that the second stop opened and closed by itself while the driver was still working the first. A child getting off at that second stop could then be recorded against the stop after it, so the record showed them staying on the bus longer than they did.

The app now checks that the bus has genuinely left the previous stop before marking the next one arrived by itself. If it cannot tell the two apart — which happens when the stops are closer together than the position reading is precise — it does not guess. It leaves the stop for the driver to mark, and the Arrived button works as it always has.

Marking a stop arrived by hand is unaffected in every case. The driver is at the door and can see where the bus is, so nothing overrules them.

One affected record from a recent afternoon run has been corrected. The child's alighting now shows against their own stop. Nothing was deleted to do it — the original entry is still there with the correction recorded alongside it, which is how this platform handles every change to a travel record.

Added — put a turn on the map by clicking it

When Tutela reads the turns out of a contract, some of them come back marked Not on the map yet. That is normal, and it is usually the important ones: a turn exists because the contract goes a way the map would not have chosen, so the turns that matter most are the ones the app cannot place by itself.

Until now the only way to place one was to type in a latitude and a longitude, which is not something anybody should need to know.

Now each of those turns has a Place on the map button. Press it, and a band appears across the top of the map naming the turn you are placing. Click the junction the contract means, and that is where the turn goes — it saves straight away.

To back out without placing anything, press Cancel on the band, press Escape, or press the button a second time.

A turn that is already on the map now has Move on the map in the same place, which works the same way. You can still drag it, and you can still type the position in by hand if you would rather.

[1.27.1] — 2026-08-07

Fixed — the import review screen no longer asks you to decide on rows that aren't children

Passenger lists often end with a line the source system adds for itself — the date and time the file was exported. That line was being treated as a child with an unreadable name, so it appeared in the review list as a row needing your attention, when there was nothing you could usefully decide about it.

It also meant an import you had actually finished never showed as finished, because that row was still waiting for an answer it could never be given.

Rows like this are now set aside automatically. They're still listed, marked Not imported with the reason, and still counted — so the number of rows matches your spreadsheet and you're never left wondering where a line went. They just don't ask you for a decision.

Only rows that clearly aren't children are set aside, and the test is deliberately strict: the name must contain no letters at all and the row must carry no student details — no year, no stop, no address, no school, no parent. A child whose name is simply written oddly still comes to you for review, exactly as before. Leaving one extra row on the list costs you a moment; setting a real child aside would not be acceptable.

Fixed — the import review screen no longer jumps back to the top after every decision

Accepting or declining a row reloaded the whole page, which put you back at the top of the table. On a long import that meant scrolling down, finding your place, deciding one row, and being sent to the top again for the next one.

Rows now update where they are. The page doesn't move, so you can work straight down the list.

This matters for more than patience: accepting a row writes it to the child's record immediately, and losing your place after every decision is exactly how the wrong row gets accepted.

Two things deliberately still reload, because the whole page genuinely changes: finishing the last outstanding row, and coming back to a screen you left open long enough for your session to need refreshing.

If a decision can't be recorded, the reason now appears on that row rather than in a message at the top you've already scrolled past — and the buttons stay usable so you can try again. A row is only ever shown as decided once the platform has actually recorded it.

The screen works exactly as before if your browser has JavaScript turned off.

Fixed — parents' names from a passenger list no longer lose their surname

Passenger lists write a child's name as Surname, Firstname, but write parents and emergency contacts as plain names with no comma. Tutela was reading both the same way, so a contact's whole name ended up in the first-name field with the surname left empty — and because lists show a contact as "surname, first name", those people appeared with a comma and nothing in front of it.

Tutela now recognises that a name with no comma can't be split reliably. It doesn't guess: splitting on the last space is right for most names and wrong for plenty of real ones, and getting it wrong quietly is worse than not doing it. Instead the name is kept whole and the row is flagged on the review screen so you can put the surname in yourself.

It doesn't block the import. A child isn't held up because a contact's surname couldn't be told apart from their first name. Names already imported this way stay as they are until someone edits them — but they now display sensibly rather than starting with a stray comma.

Fixed — re-importing a passenger list no longer creates duplicate contacts

An emergency contact listed with no mobile number and no email address had nothing Tutela could recognise them by, so every time the same file was imported they were added again as a new person. The child's contact list stayed correct, which is why this wasn't obvious — the duplicates built up quietly in the contacts list behind it.

Tutela now also matches a contact by name against the people that child already has, so re-importing the same file recognises them instead of adding them again. Capitalisation and extra spaces no longer make someone look like a different person either.

The match is deliberately limited to that child's own contacts rather than everyone on your books. Two different people can share a name, and on a platform that records who may be near a child, merging two people is a worse mistake than listing one twice.

Fixed — "Finish run" no longer appears while you are still driving to your last stop

The run-completion section — the sweep confirmation, the Complete button, and the warning about children who have not been marked off — used to move up beside your passenger list as soon as you left the second-to-last stop. So for the whole final leg you were being told children were unaccounted for, while those children were correctly still on the bus on their way to the stop where they get off.

It now waits until you have actually arrived at the last stop children are picked up from or set down at, or until every stop is done.

The warning itself has been reworded to match where you are. While the run is still going it now says how many children are on board, which is what that number means mid-run. It only describes children as unaccounted for once you are genuinely finishing — because a warning that appears on every single run is one drivers learn to scroll past, and then the run where it matters looks exactly like all the others.

Nothing about when a run is allowed to finish has changed. The same checks block completion, in the same way, at the same points. The completion controls are also still on the page for the whole run, lower down, so a driver who has to end a run early can always reach them.

Fixed — the map now gets out of the way while you are at a stop

At a stop you are standing still, looking at the children in front of you, not navigating. The map used to keep a share of the screen anyway — how big a share depended on how many children were at the stop, which is not really the point. At a quiet stop it could still be taking well over half the screen while you worked through the list.

Now the map steps aside completely the moment you arrive at a stop, and the passenger list takes the full width. When you depart and start driving again, the map comes straight back. On a phone, where the map used to sit above the list and push it down, it does the same thing.

If you do want the map while stopped — you have pulled up short of the marked stop, or you want to see what is coming — there is a Show map button above the list. It stays available the whole time you are at that stop, and the map returns to hidden at the next one.

Automatic arrival and departure keep working exactly as before while the map is hidden. They never depended on the map being on screen.

Fixed — a button no longer looks pressed when the platform refused what you tapped

If something you tapped was refused — an arrival recorded out of order, a change the platform would not accept — the screen still showed it as done. The control looked pressed, could not be pressed again, and nothing had actually been recorded. On a departure that meant the manual button, which is meant to be the way out when the automatic one fails, was the thing that had been taken away.

Four things are fixed:

  • Anything the platform refuses is now put back, and you are told what happened, in a line of text on the stop itself. No pop-ups.
  • It is put back to what the platform actually holds, not to a guess. Previously the screen assumed the step before had worked, so if that had also been refused the card could end up claiming the bus was standing at a stop it had never reached.
  • An automatic arrival that gets refused now says so. It used to fail completely silently, which meant automatic arrivals could stop working for the rest of a run with nothing on screen to tell you. The manual Arrived button was live the whole time — you just had no reason to know you needed it.
  • "Saved on this device" and "confirmed by the office" no longer look the same. A stop waiting to reach the office now says so and its control is marked, so a slow connection and a refusal are no longer indistinguishable.

Fixed — "Prepare offline map" no longer blames your signal for problems that aren't signal

Preparing a route for offline use reported the same message whenever anything went wrong: try again where there is signal. That was misleading in most cases — if the platform answered at all, your signal was fine, and the message sent drivers looking for coverage they already had.

The most common cause turned out to be the idle screen lock. If you sit on your list of runs for a few minutes without touching anything, the app locks itself — that's deliberate, and it's what stops a tablet left in a bus being readable by whoever picks it up. But the page stayed looking normal, so the first sign of it was this button failing with a message about signal.

Now the app takes you straight to the PIN screen instead. Enter your PIN and tap Prepare again.

The other cases say what they actually are too: that you have been signed out and need to sign in again, that the run is not assigned to this device, or that something went wrong at our end and nothing is wrong with your tablet. Signal is only mentioned when the request genuinely could not reach us.

Where the platform cannot classify the problem, the message now includes a short error code — please read it out to the office, as it is what lets us find the cause.

[1.27.0] — 2026-08-07

Fixed — the on-board count now stays on screen while you scroll

The number of children currently on the bus used to scroll out of view along with everything else — which is worst at a busy stop, where scrolling the list of children is exactly what a driver is doing.

It now stays pinned at the top of the run screen, along with the route name, however far the page scrolls. It's the number checked at the end of the run, and a mismatch is far easier to sort out at the stop where it happened than back at the depot.

Added — drivers can tell the office where a stop actually is

A stop pin in the wrong place is a real cost: the app can't recognise the bus has arrived, so the driver marks it by hand and the arrival time is whenever they remembered rather than when they got there. Until now the only people who could correct a pin were in the office, working from a map — and the people who actually know are at the kerb.

Drivers now have a Set stop location here button on the stop they're working. One tap records where the bus is and sends it to the office.

It doesn't change anything. The office receives it as a task, sees it against the current position, and decides. Nothing moves unless they approve it — so a driver can send one whenever a pin looks wrong without worrying about the consequences.

Readings build up rather than replacing each other, which makes them far more useful. Where several drivers have recorded the same stop, the office sees how closely they agree and can accept the consensus of all of them instead of any single reading.

Before approving, the office is told two things that are easy to miss: which other routes share that stop — because moving it moves it for all of them — and how many drawn road paths will need approving again afterwards.

The button only offers itself when the location reading is good enough to be worth recording, and says so when it isn't.

Fixed — the driver app now notices when the phone stops giving it GPS

Phones and tablets sometimes quietly stop supplying new location readings — no error, the readings simply stop arriving. When that happened, the map's dot sat still and the speed froze with nothing to say the reading had gone stale, and the only way back was to reload the page. Automatic arrival at stops stopped working for as long as it lasted.

The app now spots it and says so, showing "GPS not updating — use Arrived" and blanking the speed rather than displaying a number that had stopped being true. Marking stops by hand works exactly as normal throughout. It also restarts location tracking by itself, so it typically recovers within a minute without the driver doing anything.

The office side is fixed too, and this was the part nobody could see. The app used to keep sending the last known position on its normal schedule, so a bus that had stopped reporting looked on the dispatch board like a bus reporting normally from somewhere it had already left. It now sends nothing while the reading is stale — a gap on the board is the honest signal that a bus has stopped reporting, and it's something the office can act on.

This affects all devices equally; nothing in it is specific to one make of phone or tablet.

Fixed — finishing a run now works with no signal

Depots are often the worst place for signal on the whole route, and finishing a run is the one thing drivers had to do there. Confirming the bus sweep, answering the post-run checklist and marking a whole load off at a school all needed a connection — with none, the tap appeared to do nothing and nothing was recorded.

All of these are now saved on the device the instant they are tapped, and sent as soon as there is signal. The driver sees the confirmation straight away.

Completing a run still waits for a connection, on purpose. The check that nobody was left on board is run by the office against the full picture, and until everything the driver recorded has arrived, that picture is incomplete. The app now says so plainly instead of leaving the button live and losing the tap.

Fixed — marking children off at a school, with no signal

"All off" at the school and "Nobody here" at a stop both had the same problem: with no connection the tap was lost, for every child it covered. These are the controls that exist precisely because marking thirty children one at a time is not something a driver can do while supervising them, so losing them at a rural stop was losing the only workable option.

Both now save to the device immediately and send when signal returns. Each child still gets their own individual record, exactly as before.

Fixed — signing out now clears the device even with no signal

Signing out is what erases a run's cached pages, rosters and children's photographs from a device. That clean-up used to need a connection, so a driver handing a shared tablet back in a yard with no signal left all of it behind.

The device is now cleared the moment Sign out is tapped, before anything touches the network — the part that protects children cannot depend on signal. If the office cannot be reached, the driver is told two things plainly: this device has been cleared and is safe to hand over, and the session itself will end once there is a connection, so they know to sign out again when there is.

Fixed — the driver app no longer locks mid-run

The screen lock exists so a tablet left in an empty bus is not showing a list of children. During a run it was doing the opposite of its job: a driver working in a signal blackspot could come back to a locked screen and be unable to unlock it, because checking the code needs a connection.

A run in progress no longer locks. A bus mid-route has its driver on it, which is the question the lock exists to answer. The moment a run is finished the normal lock comes straight back, which is when a tablet actually gets left behind. Screens left untouched during a run still blur the children's names, as they always have.

Fixed — recorded actions could be lost when a device came back online

If a device had been out of signal long enough for its screen to lock, everything the driver had recorded while offline — arrivals, departures, pre-start checks — could be discarded the moment the connection returned, silently. Boarding taps were unaffected.

Anything the driver records is now held on the device until the office has genuinely accepted it. A locked screen delays sending; it can no longer discard anything.

Fixed — the driver app stopped making pointless requests with no signal

While out of signal, the app kept trying to report its position every twenty to sixty seconds even though the attempts could not succeed. Nothing was lost and nothing showed on screen, but it woke a device that is already running GPS, a map and the offline system for hours at a time. It now waits quietly until there is a connection, and resumes on its own.

Added — the contract's turns now enter themselves

When a route is imported from a contract, the contract already lists the turns for each leg — "depart depot, right into Mill Road, left into Riverbank Drive, left into the highway". Until now the office had to read that and enter each turn by hand, giving a map position for every one. On a route with a turn between nearly every stop, that meant it mostly didn't get done — and a route's approved path could quietly stop matching what the contract asked for.

The Road path panel now shows the contract's own words for each leg, with a button to read the turns straight out of them. There's one for a single leg and one for the whole route.

It tells you what it found, and it separates the three outcomes, because they need different things from you:

  • Placed on the map — done, and drawn with its arrow.
  • Still to place — the turn was read but the app couldn't work out where it is. Normal, and usually the turns that matter most: a turn is in a contract precisely because the route isn't the obvious one, so the ones the app can place are the ones that were never in doubt. It shows the contract's wording so you can tell which turn it means.
  • Couldn't be read — wording the app didn't recognise, kept exactly as written so you can see it. Worth telling us about; it usually means a form of words we haven't taught it yet.

Reading again is safe. It replaces what was read from the contract before and leaves anything you added or moved yourself completely alone — so a corrected import just gets read again.

Nothing here approves a route. The turns feed the suggested path, and a person still approves it, exactly as before.

Fixed — the Road path panel was cut off at the right on longer routes

On routes with long stop names, the leg status and part of the manoeuvre form were clipped at the edge of the panel rather than scrolling. Both columns on the route page now hold their width properly.

Changed — you approve a route once, and legs snap to the roads by themselves

Approving the road path leg by leg has gone. Legs now follow the roads automatically, the turns come out of the contract, and you check the finished route and approve it once — which is what most offices were doing anyway before handing a route to a driver.

An edit in the office no longer changes the road under a bus that's out driving. This is the part worth knowing. There are now two versions of a route's road path: the one you're working on, and the one drivers have. Moving a stop or adding a turn changes yours and leaves theirs exactly as it was. The page tells you when the two differ — "Drivers are seeing an older version of this route" — and approving releases what you've built.

Previously an edit reached a driver the moment you made it, which was survivable when approval was per leg and cost one segment of their map. Approving a whole route at once would have taken the entire road line off every bus on it, in the middle of an afternoon, because somebody was planning next term.

You can still withdraw a route from drivers. Their map falls back to straight lines between the stops, and nothing you've built is lost.

Changed — approving tells you what's still outstanding, and lets you proceed anyway

Before you approve, the route lists what still needs you: turns not yet on the map, wording the app couldn't read, stops with no location, legs with no road path. Each is listed separately because each needs something different done about it.

You can approve regardless — you're the one checking it. Some turns will never place themselves; "turn around at the end of the close" names a place rather than a road. What was outstanding at the moment you approved is recorded with your approval, so it's on the record rather than guessed at later.

Added — turns are placed by dragging them on the map

Adding a turn no longer asks for a latitude and a longitude. Choose what the bus does, optionally type the contract's own wording, and add it — it appears on the map halfway along the leg, and you drag it onto the junction the contract means. It saves where you drop it.

They've also moved to sit with the stops, under the leg's own directions, which is what you're reading from when you decide a turn is needed. If you can't use a mouse, each turn still has a small control for setting its position by hand.

Added — the contract's turns are read in as part of importing it

Importing a contract now reads its turns automatically, so on most routes there's nothing to press. The button to read them again is still there for a leg whose directions you've corrected.

Fixed — signing out with no signal no longer leaves you signed in

Signing out clears the run, roster and photographs from a device straight away, connection or not. But the session itself needs a connection to close — so on a shared depot phone, the next person could have found themselves opening the app as the previous driver once signal returned.

The app now refuses itself in that state: it says the device has been signed out, and finishes the job properly the moment there's signal. If you sign out with no signal, hand the phone over with confidence — it's clear, and it will not open as you.

Changed — a school's roster pattern is now the school's, shared across operators

A roster pattern — "Kindy, two week cycle" — describes a school's own timetable, so it now belongs to the school rather than to each bus operator separately.

Before this, a school served by two operators needed the same pattern set up twice, and nothing kept the two copies in step. If the school moved its Kindy day, whichever operator was told had it right and the other did not. It is the same problem the shared term calendar solved: one school, one set of facts.

When you create or edit a pattern you now choose which school's timetable it is. Only schools you serve are offered.

Nothing about the days your children travel has changed. Existing patterns keep working exactly as they did. Where we could tell which school a pattern belonged to — from the children already on it — we have filled that in for you. Where a pattern covered children at more than one school, or had no children on it yet, we have left the school blank rather than guessing, because guessing would put a real child on the wrong days. Those show as needing a school chosen, and until then they behave as before.

[1.26.0] — 2026-08-06

Added — drivers can now read the route's directions in the cab

The directions for a route — the turns the contract requires, and the contract's own wording where the office has entered it — now appear on the driver app, above the stop being driven to, under Getting here.

Closed it's a single line showing the turns as short labels, which is what can be taken in at a glance. Tapping it opens the full directions to be read while stopped.

Until now those directions existed only on the office side, so following the route depended on the driver already knowing it. That's the gap this closes: a relief driver, or anyone covering a route for the first time, can now read what the route actually requires at the moment they need it.

It describes the leg into the stop shown, not out of it. A leg nobody has described shows nothing at all rather than an empty panel, so a blank means it hasn't been entered yet.

This is not turn-by-turn navigation — it doesn't track your position, re-route you or speak. It's the route's own directions, put where they can be read. It also works with no signal, including on a run the driver has never opened.

Added — record the turns a contract requires, and have the route follow them

Where a contract says the bus must turn at a particular intersection, or U-turn at the end of a road, you can now record that on the route as a manoeuvre — click the point on the map, choose what happens there, and add a note in the contract's own wording.

When you ask for a suggested path, it's now routed through those points instead of the mapping service taking its own view. That's the difference between a route that resembles the contract and one that follows it: the mapping service plans for a car, not a 12-metre bus with a route it isn't allowed to vary.

Manoeuvres show on the route map as violet squares, separate from the round stop markers, so a route can be checked against the contract at a glance.

Nothing about approval has changed. A suggested path is still a draft, and somebody still has to look at it and approve it — a manoeuvre makes the suggestion better, it doesn't make it correct. If you change a manoeuvre on a leg that was already approved, that leg goes back to needing approval and says so, because the path was approved on the basis of driving a different way.

Added — store a route's map on the phone before you drive it

Drivers can now tap Prepare offline map against a run to download that route's streets onto the device while there's still signal — at the depot, before setting off. The map then draws the whole way round, including through areas with no coverage.

Until now the map only worked offline for parts of a route the driver happened to have looked at earlier while online, and nothing told them which parts those were. A driver opening the app for the first time somewhere without coverage had no map at all.

It says what it's actually doing rather than leaving anyone to guess. It reports progress while downloading, tells you plainly when a route's path hasn't been drawn and approved in the office yet, and says so if a download didn't finish rather than reporting success. If the office changes a route's path afterwards, the app notices and asks for it to be prepared again — the changed section being exactly the part a driver is least likely to know.

Preparing is optional and never automatic: it uses data, so it happens when the driver asks for it. Without it the map behaves as it always has.

Added — the driver's map now shows progress, zooms to the next stop and faces the way you're going

Three changes to the map on the driver app, all aimed at the same thing: less time looking down.

You can see how far you've come. The part of the route already driven is drawn in grey and set back; the part still to come stays bold and blue. Where a route goes out along a road and comes back down the same road, the part still to come is always drawn on top, so it's never hidden behind where you've been.

The map zooms itself. Instead of one fixed zoom that was too far out for stops on the same street and too close for a long country leg, the map now frames your bus and the stop you're heading for, tightening as you get close so the kerb and the surrounding streets are easy to read on approach.

The map turns with you. It now rotates so the direction you're travelling points up the screen, rather than leaving you to translate a north-up map in your head. It holds still while you're stopped, so it won't spin at a kerb.

All three step aside the moment you move the map yourself. A new compass button switches back to north-up whenever you want it, and the recentre button puts everything back to following you.

Fixed — the driver's map now follows the road, like the office's does

When a route's path has been drawn and approved in the office, the driver's map now shows that same path — the roads the bus actually travels — instead of straight lines drawn from one stop to the next. Drivers and office staff looking at the same route now see the same shape.

Routes whose path has not been approved yet keep showing straight lines between the stops, exactly as before. The map is also framed to keep the whole path in view when a route loops or detours well away from its stops.

Added — a one-tap way to say nobody was at a stop

Until now, if nobody came out to a stop, a driver's only options were to mark every child there as away one at a time — not something anyone can do while looking after a bus — or to drive on and record nothing. Drive on won, understandably, and the day's record could not tell the difference between "nobody was there" and "the bus left without them".

There is now a Nobody here button on the stop, showing how many children it covers, so one tap records all of them at once. It is completely optional: nobody is required to use it, nothing blocks a driver who does not, and no warning is shown for leaving a stop without it. Children not being at a stop is a normal morning.

It records them as not on the bus, which is kept separate from "not travelling". "Not travelling" means somebody let you know in advance or at the stop. "Not on the bus" means they simply were not there and nobody said why. Families and schools see the same wording, so the two questions — "we told you" and "she was waiting there" — can still be told apart afterwards.

Changed — a bus is no longer held at a stop once everyone is on board

Stops are held until their timetabled time so a child walking out at the published minute is not left behind. That hold used to apply even when every child at the stop was already on the bus or already accounted for — protecting nobody, and spending time the rest of the route needs. On one morning that was around nine minutes across three stops, and the bus reached the school late.

The hold now lifts as soon as everybody at that stop is accounted for. Leaving then is an ordinary departure: no reason is asked for and nothing is recorded against the driver or the run. While anyone at the stop still has not been marked, the hold applies exactly as before, and the message now says how many children that is instead of a general warning.

Fixed — leaving a stop early no longer stalls the rest of the run

If a bus pulled away from a held stop without the driver marking it departed, the app used to leave that stop open — and because only one stop can be open at a time, every later stop was then blocked from registering an arrival. The rest of the run stopped working, and the only clue was a message on a screen the driver should not be reading while moving.

The departure is now recorded so the run carries on, and the driver is told on the stop that it has been recorded. Because the timetabled hold was still in force, it is also raised for the office to review.

Added — early departures now reach the office

When a bus leaves a stop ahead of its timetabled time and children there have not been marked on board or accounted for, that now creates a task for the office to look at and close. It shows the route, the stop, how early the bus was and how many children were affected, and it links to the attendance register for that day. Whether the driver gave a reason at the time or the departure was picked up automatically is recorded and distinguished.

Leaving a stop the bus was free to leave does not create one — this is only for departures ahead of the timetabled time with children still unaccounted for. Live runs in this situation are also flagged on the dispatch board, while there is still time to call the driver.

Tasks carry only counts, times and the stop — never a child's name.

Fixed — the reason for leaving a stop early can now actually be given

On stops the app marked as reached automatically, tapping Departed during a hold could be refused for want of a reason while no screen offered anywhere to enter one. The confirmation now appears wherever the hold applies, however the stop was reached. The list of reasons has also been updated: an option that no longer applies has been removed, and two that come up in practice — waiting as long as was safe, and running behind — added.

Fixed — a driver's screen is no longer covered by the schedule banner

The Early / On time / Late banner sits at the top of the run screen and was overlapping the route name and the on board count — the number that tells a driver whether anyone is still on the bus. The screen now makes room for it. The banner also shows the current speed in a circle beside the status, and shows a dash rather than zero when there is no GPS fix yet, so a stationary bus and a GPS that is not reporting cannot be mistaken for each other.

Fixed — part-time school days can now be set up

Children who are only at school on some days can be given a school-day pattern, including a two-week cycle, so they are not expected on the days they are not there. The screens for this existed but nothing linked to them, so the Days at school picker appeared to offer Monday to Friday and nothing else. There is now a School rosters entry under People, and the child's own form points to it.

Fixed — "not on the bus" is easier to spot on the attendance register

The mark for a child nobody accounted for was an outline with no fill, which was easy to skim past on the one entry that raises a question rather than answering it. It now has a filled amber background, matching the equivalent mark it shares its meaning with. The symbols still differ in shape as well as colour, so the register can be read without relying on colour at all.

[1.25.1] — 2026-08-05

Fixed — stop numbers on the map now match the stop list

Two markers on a route map could show the same number, because the map numbered stops one way and the stop list another. Markers now use the number from Stops & Timing, with D for the depot and S for the school, on both the office map and the bus app.

Fixed — the bus app now follows the run instead of sticking on the first stop

On a route that starts at a depot, the app stayed on that first stop for the whole run. Drivers had to scroll past every stop to reach the one they were actually at, and automatic arrival never fired at any stop, so every arrival had to be tapped by hand.

The app now skips over stops there is nothing to do at, so it moves along the run as each stop is worked and automatic arrival and departure work again.

Fixed — children could not be marked off at some end-of-route stops

Where a stop was recorded as the end point of a route but children were also set down there, the bus app offered no way to mark them off. The run then could not be finished, because it correctly refuses to close while anyone is still shown as on board.

Those stops now offer the usual controls whenever children are assigned to them. The setting that caused it can also now be seen and changed on the stop's own screen, where before it could only be set when a route was first brought in.

Changed — one clear setting for making a bus wait at a stop

There were two settings for the same idea. The one an operator could see did nothing, while a hidden one — switched on for every stop by default — was what actually held the bus. That is why buses waited at stops nobody had asked them to wait at.

There is now a single Hold if early tick box on each stop in a route, off unless you turn it on, and it is the setting the bus app obeys. Anything you had already marked as a timing point carries over unchanged.

Drivers who need to leave a held stop before its time can now do so from the app, giving a short reason that is recorded against the run. Previously the app told them to do this and gave them nowhere to do it.

Changed — tidier relationships on imported contacts

Contact relationships arrived from the source file however they happened to be typed — "MOTHER", "Mother" and "mother" were three different entries. They are now grouped as Parent, Grandparent, Other Relative or Other. Anything unusual is kept as written rather than forced into a category, so wordings like "Legal Guardian" are not lost.

Changed — a shorter key to the attendance marks, and a clearer one for "not on the bus"

The key under the attendance grid listed six marks. Two of them were not pulling their weight: one described a child who is away using the same symbol and the same meaning as "absent", and another could never actually appear on the grid at all. Both are gone, so the key now explains the four marks you will actually meet. Where an absence came from is still shown when you hover over the mark itself.

The mark for not on the bus has changed from a dash to an exclamation mark. It means the trip ran and nobody recorded this child either way — the only mark on the grid that asks a question rather than answering one — and as a dash it read like an empty box and was the easiest thing on the screen to look straight past.

The office register and the bus app now show the same four marks, described the same way.

Added — school rosters, for children who aren't at school five days a week

Some children aren't in every day. Kindy and pre-primary groups often run two or three days, and some run a fortnightly cycle — two days one week, three the next. Until now that meant marking the same children away every week, all year.

You can now record it once. Set up a roster — the days those children are at school, either the same every week or across a two-week cycle — give it a name, and put children on it. Everyone else stays as Monday to Friday, so most children need nothing done at all.

A roster is not an absence, and that is the point. A rostered day off shows the same ✕ you already use in the book, but nothing is recorded against the child, so it never reaches their attendance record. A child who is simply never there on a Monday no longer builds up a year of absences and end up reading as one of your most frequently away children. Illness and one-off changes still belong in the attendance register, exactly as before.

If a child comes in on a day they normally do not, tick the + in that cell. They are expected for that one day, the bus will wait for them, and nothing about their pattern changes. If a parent then rings to say they are ill after all, mark the absence as normal — that wins, because it is the more recent thing somebody told you.

On the bus app, children who are not at school today fold into a "Not at school today" line at the stop instead of filling the driver's list. They are still one tap away, each with a working board button — so if plans change and a child turns up, the driver boards them as normal. What actually happens always beats what was planned.

Fixed — removing a stop from a route now works on routes that have been running

Taking a stop off a route failed with a server error whenever a bus had already called at that stop and picked children up there — which is most stops on most established routes. The removal never went through, so nothing was lost, but there was no way to complete it and no explanation on screen.

It works now, and the way it works has changed for the better.

A stop that no bus has been to yet — one you added by mistake this morning — is simply removed, as before.

A stop that has been served is retired instead. It comes off the route and off every run that hasn't started yet, immediately, exactly as you'd expect. What it doesn't do is reach backwards: the runs that already called there keep it, along with the time the bus arrived and the record of who got on and off. That history is what a complaint or an incident is answered with, so an ordinary edit to next week's route can no longer change what last Tuesday says.

The confirmation message now tells you which of the two happened, so a stop still showing on an earlier run sheet reads as the record it is, rather than as the removal not having worked.

[1.25.0] — 2026-08-05

Fixed — accepting a suggested change on an imported list now applies it

Accepting a row on the import review screen looked like it had done nothing: the row still read as undecided and the child's record was unchanged. The decision was being saved, but the change itself only happened when a separate button further up the page was pressed, and nothing said so.

Accepting now makes the change straight away, and says what it did — whether the child was added, their record updated, or there was nothing left to change. Accepting several rows at once behaves the same way. Rows that are blocked still cannot be accepted.

Changed — clearer wording on the attendance register

The register had two entries meaning much the same thing, one of which could never actually appear. There is now a single, plainer description for a trip where no boarding was recorded. Drivers can also reach the attendance page directly from their week view.

Fixed — student and parent lists are now in alphabetical order

Several lists of names were appearing in no particular order — most visibly the "Someone not travelling?" roster on the bus app, and also the parent portal, the school absence form and the parent picker in the office console.

All of them now read alphabetically by surname, then first name — including the office student list, where the order now holds across pages rather than only within one. Nothing was ever missing from these lists and nothing was recorded incorrectly; they were simply harder to scan than they should have been.

Fixed — drivers can clear a tap made by mistake

If a driver marked the wrong child as on the bus, the only way to undo it was to mark that child as not travelling. That cleared the tap, but it also told the system a child who was actually catching the bus would not be — and if the driver did not then mark them on again, nobody would be waiting for them at their stop.

There is now a separate control for exactly this. It removes the tap and says nothing about whether the child is travelling, so they simply go back to not yet marked. It asks for confirmation first, and the original entry is kept in the record with a note that it was withdrawn, so the office can see a correction was made rather than wondering why a child was marked away.

[1.24.0] — 2026-08-05

Added — drivers get the attendance book on the bus app

The bus app has a new Attendance screen, beside Today and Your week. It is the paper book: the children on your routes down the side, the days across the top, a morning and an afternoon under each.

This week shows what actually happened — who was on the bus, who was marked away, and where nobody recorded anything either way. A fortnight ahead is yours to mark, so a parent saying "she's not on the bus all next week" is a handful of taps instead of a trip through ten screens.

It works with no signal. Ticks made at a depot with no coverage wait on the phone and send themselves when you are back in range. A tick that is waiting says so, and one that could not be saved turns red and puts itself back — so the screen never shows a tick nobody recorded.

A run that has already gone cannot be changed. If a mark is sent late and the bus has already run, the app says so plainly and asks you to ring the depot, because that child is still expected and somebody needs to know.

You only ever see the children on the routes you are rostered to.

Most absences should still come from parents and schools, who have their own screens for it. This is for the ones you are told at the kerb.

Added — accept or decline import rows on the review screen

The review screen now has a decision on every row: Accept or Decline, and a separate pair for the stop where the file disagrees with the one you already have.

There's also a button to accept everything the current filter is showing, and it tells you how many rows that is before you press it. Nothing is written until you apply.

Added — stops can be marked morning, afternoon, or both

Each stop now says which runs it's used on. New stops are set to both, because that's the usual case.

When you build a route, only the stops used on that kind of run are offered — so a morning-only stop can't end up on an afternoon route by accident. Changing the setting never removes a stop from a route you've already set up; it only governs what you can add from here.

Changed — the afternoon assignment is now made for you

Put a child on a morning stop and they're put on the afternoon run at the same stop automatically. You're left with only the children where that can't be done — where the stop isn't used in the afternoon, or the afternoon route doesn't call there. In those cases nothing is created and the message tells you which it was, so you're never left believing the afternoon is covered when it isn't.

An afternoon stop you set yourself is never changed. A child returned somewhere different stays exactly as you arranged it, and you're told it was left alone. That also applies if you later move their morning stop — the morning moves, the afternoon doesn't.

Children already on the system have had this filled in, so the only ones left to place by hand are the genuine exceptions.

Added — accept or decline import changes one row at a time

Importing a passenger list used to be all or nothing: you either committed every row or none of them. Faced with a file where a handful of rows need a second look, that meant doing nothing — so correct files sat unimported and the records stayed wrong.

You can now decide row by row, and come back to a part-finished import later. The stop is decided separately from the rest of the row, because the usual answer is to take the address and year level from the file and keep the stop you already have.

Declining is recorded as a decision rather than left blank, so a row you have already refused isn't put back in front of you next time the same file is loaded.

Added — a Refresh button on the driver app

The app keeps pages so they still work without signal, which means a screen can quietly be showing something older than what the office has changed. There's now a Refresh button under the logo, so a driver can ask for the current picture without hunting for the browser's own reload.

On the run screen itself it isn't needed — that screen already tells you when it has gone out of date.

Changed — you can now fix a missing stop from the child's own record

The Transport section warns when a child rides in the morning but has no afternoon stop — meaning they won't appear on that run's list and the driver won't know to collect them. It then told you to go and sort it out on the route, which is the wrong place to send someone who has just been shown a problem.

Where the return route calls at the same place, the warning now offers to assign it in one step. Where it doesn't, you're told plainly that nothing was created rather than being left thinking the afternoon is covered.

The change reaches today's run straight away, so the driver's list is right for the afternoon rather than tomorrow. Anyone who can only view a child's record still sees a read-only panel.

Fixed — a child who stays on past their stop no longer disappears from the driver's screen

On the afternoon run, each stop lists the children due to get off there. If a child didn't get off at their own stop — asleep, or they didn't hear their name — they dropped off the screen entirely for the rest of the run. There was then no way at all for the driver to tell us anything about that child: not that they were still on the bus, not where they eventually got off.

The end-of-run check would correctly refuse to let the run finish, because as far as the record was concerned a child was unaccounted for. But the driver had no way to resolve it other than overriding the check — on a run where they knew perfectly well where the child was. A check that can only be got past by overriding it is a check people learn to override.

Now they stay on the screen at every stop after their own, until they're marked off. They're shown in red, at the top of the list, with the stop they should have got off at. That's meant to be hard to miss: the one thing that must not happen is a child being let off in the wrong street because their name appeared at the stop the bus happens to be at.

"All off" leaves them out, and says so underneath. If they're taken back to their own stop, they're marked off there. If they do get off where the bus is, the driver taps them individually — so the record shows where they actually got off, which is the whole point of keeping it.

The morning run was never affected: the school stop already lists everyone on board.

[1.23.0] — 2026-08-05

Changed — finishing a run is now where you are, not at the bottom of the page

The sweep confirmation and the Complete Run button sat below every remaining stop, so on a phone they were several screens down and drivers were not finding them. A run that can't be closed stays open, and the board goes on showing a bus still out.

At the last stop they now appear alongside the children you have just worked through, so closing out is part of finishing rather than a hunt. Earlier in the run they stay at the foot, where they don't compete with the stop in hand.

Fixed — being early at the last stop no longer stops you finishing a run

Arriving ahead of schedule holds the bus, so a child who comes out at the published time doesn't miss it. At the final stop, where everyone is already off, that protects nobody — and it was stopping drivers closing the run. It no longer applies there.

Added — the driver screen now notices when it's out of date

The run screen was drawn once when opened and never refreshed itself, so a change made afterwards — a child added to a stop, an absence marked in the office — stayed invisible. On one run that meant two children never appeared on the driver's list at their own stop.

It now checks periodically and refreshes. It won't refresh out from under you: if anything you've done is still waiting to send, or you're working a stop, or you've just touched the screen, it offers a button instead of reloading. With no signal it does nothing and says nothing.

Changed — the first stop of a run no longer shows an Arrived button

You start there, so there's nothing to arrive at — the run begins when you depart it.

Fixed — correcting a child from on-board to absent now works

If a driver tapped a child on by mistake and immediately corrected it to absent, the child stayed counted as being on the bus. Nothing could clear it — the end-of-run "all off" didn't touch them, and there was no getting-off to record for a child who was never on. The run couldn't be finished and reported children unaccounted for.

The count now follows the last thing the driver actually said about each child. The original entry is kept and marked as corrected, because these records are never edited or deleted.

Fixed — automatic arrival at stops now works in practice

On a real run the app recorded no automatic arrivals at all, and the driver marked all thirteen stops by hand — despite good GPS throughout.

The check was too brittle: a single imprecise reading threw away the whole wait and started again, which at a small stop zone happens constantly. It now tolerates an uncertain reading instead of discarding progress, and takes the GPS's own margin of error into account.

Fixed — the screen no longer locks while you're driving

The privacy blur, which hides the child list when a bus is parked and unattended, was deciding a moving bus was stationary if location updates paused for half a minute. It now waits considerably longer before treating a bus as stopped.

Fixed — the days you tick when rostering a driver are the days that apply

The day picker on the roster and the rest of the platform disagreed about which day was which, so every day was stored one out — a driver rostered Monday to Friday was recorded as Tuesday to Saturday. Monday's runs were left with no driver at all.

Both now read the same definition. Existing rosters have been corrected.

Changed — the absence register is now an Attendance register

The screen where the office marks children as not travelling now also shows who was actually on the bus. It is called Attendance, and it sits under People. If you have the old address bookmarked it still works and will bring you here.

Nothing about marking an absence has changed. You still get a week at a time, a morning and an afternoon box for each child, and each tick still saves as you make it.

What is new is the other half of the week. Once a trip has run, its box is replaced by what the driver recorded at the door, so a week of a route reads at a glance instead of having to be assembled one child's record at a time. Every mark has its own shape as well as its own colour and says what it means when you hover over it, and there is a key underneath the grid.

Two of those marks are worth knowing about:

  • Still marked on board. The child got on and was never marked off. On a trip that has finished, this is the one to check straight away.
  • Nothing recorded. The bus ran and nobody marked this child either way. This is not the same as absent — nobody said where they were, so it is a question to ask, not an answer. Until now there was no way to see the difference from the office at all.

A trip that has already run cannot be edited from this screen, and that is on purpose. What the driver recorded at the kerb is the record; a screen that could quietly overwrite it would be worth less than the paper book it replaced. A genuine mistake is corrected on the trip itself, which keeps both the original and the correction.

Fixed — the app follows the run order before marking a stop arrived by itself

On a route that goes out along a road, turns, and comes back down the same road, there are stops on both sides. They sit only metres apart, so GPS alone cannot tell one from the other — which side you are collecting from depends entirely on which way you are travelling.

The app now only ever marks the next stop on the run as arrived by itself. The stop on the far side of the road is not a candidate until you have worked your way round to it, so it cannot be picked up on the outbound leg and cannot be confused with its neighbour opposite.

A driver can still mark any stop arrived by hand, in any order. Buses genuinely do serve stops out of order — a road closure, a diversion, a stop you have to come back to — and the driver is there and can see. What changed is only what the app is allowed to decide on its own.

Added — a child's stops now appear on their own record

Until now you could only see where a child is collected by going to the route. Their record now has a Transport section: the stops they're assigned to, morning and afternoon, with the route and the days it applies. It's the answer to the question a parent actually asks on the phone.

It's read-only — assignments are still made on the route, because having two places to create the same thing is how the two end up disagreeing.

Added — you're now told when a child has a morning stop and no afternoon one

This one is worth reading.

Morning and afternoon are separate routes with separate stops. A child assigned to one and not the other does not appear on the other driver's list at all — they're simply not expected, and nothing anywhere said so. The first to find out was the driver at the school gate, or nobody.

That's now visible in two places: a warning on the child's own record, and a marker against the child in the route's list. A child who catches no bus at all isn't flagged — they're not missing anything.

When you assign a child you can also tick "also assign the same stop on the return route", which creates the return assignment there and then. It's off by default and deliberately so: a child collected from home is often dropped somewhere else entirely, and we won't assume an afternoon arrangement nobody confirmed. If the return route doesn't call at that stop, nothing is created and you're told — so you never come away believing the afternoon is covered when it isn't.

Schools are now shared, and a school sees all its children in one place

A school is often served by more than one bus operator. Until now each operator kept their own separate copy of every school they worked with, and nothing connected them — so a school dealing with two operators existed twice, with two sets of term dates, and neither operator could see the other's.

Schools are now held once for everyone.

For your office. Your schools screen is now the list of schools you serve. You choose them from a shared register rather than typing them in, and you keep your own reference and notes against each one — private to your team. No other operator can see which schools you serve.

You can no longer edit a school's name, address or bell times, and that is on purpose: you would be changing them for every other operator serving that school, including re-timing their runs. Those details are maintained centrally. If a school you serve isn't in the register, use Request a school — we'll add it, and you don't need to do anything else. The form shows you close matches first, because most of the time it's already there under a slightly different name.

Removing a school takes it off your list only. Your students and routes are untouched — a child hasn't stopped attending their school because you've stopped driving there.

Term dates now belong to the school. If another operator also serves that school, you're both looking at the same calendar, and so is the school. This closes a real gap: a school telling one operator about a pupil-free day used to leave the other one running a bus to a locked gate. Every term date and closure records who entered it, so a date that turns out to be wrong can be traced and asked about.

For schools. A school contact now signs in once and sees every one of their children in a single list, whichever bus company carries them, with each row saying who that operator is. Each operator's own data-sharing agreement still decides what that school can see about their children, exactly as before — so two children on the same page can show different detail, because two operators agreed to different things. A school with an agreement covering one operator sees nothing about children carried by another, and an agreement that lapses stops that operator's children appearing with no action from anyone.

Importing a passenger list. The school named in a file is now matched against the shared register. A school we can't identify with confidence stops that row for review rather than quietly creating a near-duplicate — with one shared register, a duplicate is one everybody would see.

A row held for review now shows everything it's waiting to change

On the passenger list review screen, a row marked Needs review used to show only the reason it was held. If that same row was also changing something else — a year level, a medical note, an address — you couldn't see it.

Now you see both: the reason it's held, and everything else it's waiting to apply, clearly marked as not yet applied. This is the screen that tells you what an import will do to a child's record before it does it, so it should tell you all of it.

A child on a different stop no longer stops the whole import

If the passenger list names a different stop from the one a child is assigned to, that row used to need review — and because nothing can be applied while any row needs review, a handful of them held up the entire file.

That was the wrong call for how these lists actually work. Your runs call at more stops than the authority's approved list, and a stop only becomes matchable once they add it and give it a number, so the two lists will disagree on some children as a matter of course. Waiting for that to resolve meant waiting indefinitely.

Now the import goes ahead. The child's stop is still never changed — that hasn't moved, and won't: you may have moved that child deliberately for a reason the authority's export doesn't know about. What you get instead is a count on the review screen, and a task once you apply, so the disagreement doesn't quietly disappear. Nothing changed on the platform for those children, so that task is the only record that the two lists differ.

Work through them when it suits: check each child is on the stop you intend, and chase the authority for a stop number where one is missing.

A stop we don't have doesn't stop the import either — but read the task it raises

Same change, seen from the other side: if the list names a stop code that doesn't exist on your platform, the import now goes ahead rather than stopping.

This one has a consequence worth understanding. That child is created with no pickup for that direction. They'll be on your student list and on no driver's manifest, and their record will look completely normal — a child with no stop looks the same as a child who doesn't catch a bus. The same thing happens when the stop exists but isn't on a route running that way.

So applying now raises a high priority task telling you how many pickups couldn't be set up. Nothing else on any screen will tell you. Until you create the stop — or add an existing one to a route — and assign the child from their record, those children have no transport arranged.

The summary counts are now buttons

Rows in file, To create, To update and Need review are clickable. Choose one and the table below shows just those rows, with a Show all rows link to go back. On a long contract, finding the handful that need attention no longer means scrolling past the hundreds that don't.

[1.22.0] — 2026-08-04

Added — import your passenger list instead of retyping it

Your transport authority issues a passenger list for each contract — every child on the service, with their address, school, stops and contacts. You can now upload that spreadsheet rather than typing it in.

Uploading does not import. It reads the file, works out what would change, and waits. You then see every row and, for a child already on the system, the actual old and new values side by side — not "3 fields differ". Applying is a separate button on a separate screen, because the worst thing an import like this can do is decide two different children are the same child.

Where a row can't be resolved with confidence, it is held rather than guessed, and nothing at all can be applied until it's dealt with — not even the rows that are fine. Applying the easy rows first is how a small problem becomes an invisible one. Each held row says exactly why: an unknown stop, two children the file can't tell apart, or a name it can't read.

A few things it deliberately will not do:

  • It never moves a child's stop. If the file disagrees with a stop you've set, it flags it and changes nothing. You may have moved that child last week for a reason the export doesn't know about.
  • It never gives anyone permission to collect a child. The list says who a child's contacts are; it doesn't say who may take them off a bus, and those aren't the same question. You grant that yourself, per person.
  • It emails nobody. Creating a parent record sends nothing at all. A parent gets a sign-in link when they ask for one.
  • It never deactivates a child missing from the file. That might mean they've left, or it might mean a partial export. Instead your administrators get a task to check — with a count, not a list of names.

Whether a child needs a harness, a booster or a wheelchair space now comes across from the file too, so it can be counted for a run rather than read as prose.

Fixed — the Departed button can no longer be covered by a child's tile

At a stop with a lot of children, the tiles could run past the space they had and overlap the Departed button underneath them. That was worse than it looked: where they overlapped, a tap aimed at Departed was taken by the child's tile instead, and marked that child on or off the bus.

Boarding records can't be edited — a mistake can only be corrected by a new entry — and marking a child off who is still aboard is exactly what the end-of-run check exists to catch. So this is fixed at the root: the list of children now scrolls within its own space, and Arrived and Departed stay where they are, whatever the list does.

Changed — children's names are readable at a busy stop

Drivers told us that when a lot of children are on the bus, the tiles shrank until the names couldn't be read. The app was fitting everyone on screen at any cost, and the cost was the one thing that screen is for.

That trade is now the other way round. Names are bigger, the tiles are wide enough to show a full first and last name without cutting either off, and the map gives up more of the screen while you're working a stop — you're stopped and looking at children, not navigating. Where everyone no longer fits, the list scrolls, and you may see one tile cut off at the bottom. Nobody is missing and nobody is left out of the count.

The tap targets have not been made smaller to achieve any of this — they're slightly larger than before.

Changed — the driver app now uses the whole of a tablet screen

On a tablet in landscape, the driver app put everything in a narrow column down the middle with the logo above it, leaving most of the screen doing nothing — and pushing the first thing you need further down.

The logo now sits in the top right, out of the way and larger, and your runs start at the top left. On a phone nothing changes: the layout there was already right for the space.

Added — see tomorrow's runs on the dispatch board

The dispatch board only ever showed today. You can now step forward or back a day, so you can check tomorrow is covered while there is still time to do something about it.

A board showing any day other than today is clearly marked as not live: it does not refresh by itself, and it does not show vehicle positions. A live-looking board that isn't live would be worse than no board at all, so the difference is stated on screen rather than left to be inferred.

Fixed — the platform admin menu no longer wraps, and works on a tablet

The menu across the top of the platform administration area had grown past the space available and folded onto a second row. On smaller screens it disappeared altogether with nothing to replace it, which left that whole area unreachable from a tablet.

Both are fixed: the links sit on one row on a desktop, and collapse into a menu button on anything narrower.

Fixed — a driver rostered onto a route now sees it in their app

If you rostered a driver onto a route after the day's runs had already been generated, the driver's app showed them nothing — while the dispatch board showed the run with nobody assigned. Neither screen said anything was wrong.

Runs are now kept in step with the roster: rostering a driver, changing one, or removing one all reach the runs that have not started yet.

Runs already under way are never touched. Once a driver has begun a run, the record of who is operating it stays exactly as it is — that record is tied to the children on board, and it is not something to rewrite behind the scenes.

[1.21.1] — 2026-08-04

Fixed — qualifications can be recorded again

Adding a qualification to a staff member or driver was blocked. On types that are not issued by a state scheme — First Aid, a medical certificate, an induction — the form still showed a Jurisdiction field, then refused to save because that field is not allowed for those types. There was no way to clear it, so the qualification could not be added at all.

The form now shows only the fields the chosen qualification type actually has, and updates as you change the type.

Fixed — a driver could not be rostered onto a route

Two separate faults, both now corrected.

The driver list was empty. The dropdown for choosing a driver was looking for the wrong thing, so at many operators it offered nobody and the route could not be rostered.

Requirements were being enforced that the operator had never set. The system was insisting on a driver licence record and a medical certificate for every operator, regardless of what that operator had configured as its own requirements. A driver holding everything their company actually asked for was still refused.

Your requirements are now the only ones that apply. If you require a driver licence, it is checked and must be valid for the whole rostered period. The same for a medical certificate, a working-with-children check, or anything else on your list. If you have not asked for something, it is no longer demanded.

To be clear about what has not changed: whatever you do require is still enforced strictly, and a driver who does not hold it is still refused. A grounded vehicle is still refused. Those checks were never the problem — the problem was being blocked by requirements that were not yours.

[1.21.0] — 2026-08-04

Improved — the console no longer scrolls when everything already fits

Every page in the operator console showed a scrollbar and scrolled a little, even when the content did not come close to filling the window. It was a layout fault rather than anything to do with your data, and it looked worst on the emptiest screens. Fixed.

Improved — a shorter, better-balanced footer on the public site

The footer on our public pages was about three times taller than it needed to be, with most of it empty. The link groups now sit side by side.

Changed — the help button no longer shows a dot

A small dot sat on the help icon whenever a guide covered the screen you were on. It looked like an unread notification, and because it was always there it could never be cleared. Help is always available, so it does not need to announce itself. That style of indicator is being kept for notifications, where a count that goes down as you deal with things is the whole point. The help button and its menu work exactly as before.

Changed — our trading name reads consistently across the legal documents

The Privacy Policy, Terms of Service and School Portal Terms now all read Zeus ICT Services Pty Ltd t/a Tutela AU. No terms changed — only the name they are signed under, which had drifted between documents.

Behind the scenes — groundwork for text messaging

We have built the foundation for sending SMS, so that in future we can reach drivers and families where they actually are — a text about this afternoon's bus is read; an email often is not.

Nothing is being sent yet. The capability ships switched off, with a separate second switch that has to be turned on before a single message can leave. That is deliberate: a text cannot be unsent, and the people on the other end are parents and drivers.

Two rules are built in rather than left to good intentions. A child's name can never appear in a text message — the system refuses to send one that contains it, because a text is readable on a lock screen by anyone holding the phone and is kept by the phone network. And messages are strictly limited in volume, so no automated process can ever flood a family with them.

[1.20.0] — 2026-08-04

Fixed — the "who is travelling" screen now really does open without a signal

Drivers were told this screen worked with no connection. On the road it did not — it showed the "you're offline" message instead. The fault was that the offline version of the screen was listening for the wrong web address, so it never recognised the screen it was meant to stand in for. It now opens correctly, and the driver sees who is expected on the run.

We have also added a check that compares every offline screen against the real address it belongs to, so this particular kind of mistake cannot reach a bus again.

Improved — a driver's next run opens with no signal, even if they have never seen it

The driver app now keeps a copy of the coming week's runs on the device, and builds the screen from that copy when there is no connection. Previously a screen only worked offline if the driver happened to have opened it while in coverage, which meant the first run on a new device, or the first stop out of range, could be a dead end.

The run screen shown this way is clearly marked as a plan, not the live run screen. It lists the stops in order and the children expected, and it deliberately carries no buttons for marking children on or off. A screen that looks like it is recording boardings while doing nothing of the kind is worse than one that plainly says it cannot — so it says it, at the top, before anything else.

Improved — starting a run out of coverage is now tested end to end

Completing a pre-start check and starting a run with no signal already worked: the check is saved on the device and sent when the connection returns. What we did not have was a test that actually switched the network off and walked a driver through it. We do now, including the case that matters most — a bus that fails a major pre-start item is still recorded, and still does not start, because a vehicle taken out of service is something your whole depot needs to know about and a device with no signal cannot tell them.

Improved — the help guides now show you the screen

Every guide has been rewritten in plain language, for the people actually using Tutela rather than the people who built it. Where a guide describes a screen, it now shows you a picture of that screen — what the buttons say, what the labels mean, and what a warning looks like when it appears.

Some guides have clearer names as a result. "Making sure everyone is off the bus" and "Keeping qualifications current" are the same guides you had before, saying the same things in fewer words. Any links or bookmarks you already have still work.

The illustrations are drawn by Tutela rather than being photographs, so they follow whichever colour theme you're using and always match the current design. Every one is labelled as an example, and the names in them are made up — no real child ever appears in a guide.

Added — help guides, built into the platform

There is now a Help section inside Tutela, written for the people using it rather than for us.

It knows which screen you are on. The question-mark control in the header carries a dot whenever a guide covers the page you are looking at, and opening it lists those guides. That is the fastest route from "this screen is refusing me" to the explanation.

It starts where the platform says no. The first guides written are the ones that explain a refusal: why a run will not complete, why a driver cannot be rostered, why a vehicle cannot be assigned, why acceptance of the Terms is being asked for. Each of those refusals is deliberate, and each is baffling without an explanation — so the explanation is now a page away instead of a phone call.

There is a guide for each part of the job. Everyday work — runs, absences, students, guardians, routes and stops, vehicles, hazards and inductions. Administration — the qualification register and its daily checks, your team and their permissions, forms and checklists, the risk register, company settings, integrations and data-sharing agreements. And a compliance section written for the person who has to answer a regulator, a school or a parent about what Tutela records, how long it keeps it, and who has looked at a child's information.

You see the guides written for you. Everyday guides are open to everybody with an account. The administration and compliance guides are shown to the people who hold those responsibilities.

Search across all of it from the Help index, with the matching passage shown so you can tell which guide is the one you want before opening it.

You can reach Help from the header on any console screen.

Improved — the driver app now prepares your week in advance

Driver screens used to work without a signal only if you had opened them earlier while connected. The app now downloads your rostered runs and the children on them ahead of time, whenever it has a connection — so a screen you have never opened still works in a blackspot.

Your device holds names only. Photographs are never downloaded ahead of a run, and everything downloaded is erased when you finish a run or sign out.

Added — an About page

There is now an About page explaining what our name means. Tutela is Latin for guardianship — the duty of care owed to someone who cannot yet protect themselves. The page sets out the two things the platform exists to prevent: a child left on a bus, and a child's information reaching someone who should not have it. You'll find it in the footer.

Improved — the Privacy Policy and Terms are now reachable from everywhere

Previously these were linked only from our public website. They are now linked from the sign-in screens and from inside the parent portal, the school portal and the operator console, so you can read them at any point without going looking.

The school portal also links the School Portal Terms, which is a separate document from the operator's Terms of Service.

Changed — internal

Improvements to our own build and testing process. No change to the platform.

[1.19.1] — 2026-08-03

Fixed — the platform now works to your local time, not the server's

Everywhere the platform asked "what is today", it was answering with the server's date rather than your depot's. Perth is eight hours ahead, so from midnight until 8am local — which is the whole morning school run — the answer was yesterday. Further east it was worse, running to 10am.

That is what was behind a driver opening the app before their morning run and being told they had none rostered. It also affected:

  • the dispatch board, which showed the previous day's runs right through the morning peak;
  • a parent or school marking a child as not travelling "today", which could be recorded against a day whose bus had already left;
  • the overnight job that creates each day's runs, which was working from a date that had already passed at the depot and so published six days ahead instead of seven;
  • reminders about expiring accreditations, licences and services, judged against a date up to ten hours stale;
  • every time shown on screen — when a defect was raised, when a run's sweep check was confirmed, when a walk-home request was decided — which were displayed in the server's time rather than yours.

While fixing it we found a related fault in how each stop's scheduled time was stored. It meant a bus arriving on time was recorded as arriving many hours early, which in turn could hold a driver at a stop waiting for a departure time that had already passed. Stop times, arrival records and the "running behind" indicator on the dispatch board are all now correct, and existing records have been corrected in place.

While tracing this we also found that the overnight job which publishes each day's runs was failing every night for a reason unrelated to time, and never actually creating them. That is fixed too.

Your operating timezone was already set against your company and has not changed — the platform simply now uses it everywhere.

[1.19.0] — 2026-08-02

Changed — the driver app's logo is now readable on a tablet

The logo was the same small size on every device, so on a depot tablet it sat in a lot of empty space and the wording underneath it could not be read. It now scales up on larger screens.

The run screen is unchanged — it carries no logo at all, deliberately, so nothing competes with the stop a driver is working.

Added — The driver app now shows its version, and updates wait for a safe moment

Three improvements to how the driver app keeps itself up to date.

You can now see which version a device is running. The driver app shows its version quietly at the bottom of the sign-in screen and the runs list. When a driver says a new feature isn't showing, that number answers the question straight away — whether the device is behind, or something else is going on. It is deliberately kept off the run screen: while a driver is working a stop, nothing should compete for their attention.

A new version no longer arrives in the middle of a run. Previously an update could take effect on a screen a driver was actively using. It now waits until the run is finished, and the driver chooses when to take it. Nothing a driver has already recorded is affected either way — it stays saved on the device and syncs as normal.

The app checks for updates on its own. It looks for a new version when a driver picks the device back up, and periodically through the day, so a device left on one screen for a whole shift no longer falls behind. When an update is ready and no run is in progress, an Update now button appears. It shows up only when there is genuinely something to install, rather than sitting there permanently — a button that is always present invites tapping when the real problem is mobile coverage, which updating will not fix.

These checks are silent when there is no signal. Losing coverage on a bus is normal and expected, and it is never reported to the driver as a fault.

Changed — Every part of the driver app must now prove it works without signal

The driver app is built to keep working when a bus has no mobile coverage — that is the normal condition on a school run, not an unusual one. Our release checks already confirmed that each screen loads and behaves correctly. They did not confirm that anyone had ever tested it with the signal switched off.

They do now. Before a release can go out, every part of the driver app has to have been exercised with no connection at all. Anything new that has not been is flagged and has to be either tested or signed off deliberately — it cannot pass quietly.

We found two things while putting this in place, both of which had passed every other check: two screens a driver could not open without coverage if they had not opened them earlier while connected, and marking a child as not travelling, which needed a connection to work at all. Both are being addressed.

Added — Drivers can mark a child as not travelling with no mobile coverage

The first of those two is now done.

A parent usually tells a driver at the depot or at the kerb — often exactly where the signal is worst. Until now, recording it needed a working connection, so at the moment it was most likely to be needed it did not work at all, and the message stayed in the driver's head until they got back to the office.

Now the driver taps it and it is saved on the device straight away, then sent by itself as soon as there is coverage. The screen says which of the two has happened, so a driver can always tell whether something is still waiting to send. Putting a child back on the run works the same way.

If it cannot be applied, the driver is told. A run that has already set off cannot be changed — the manifest the driver is working from is fixed. So if a mark was made without coverage and the run departs before it can be sent, the app says plainly that it was not saved and that the child is still expected, rather than leaving the driver believing it went through. That direction matters: a child wrongly marked as not travelling is a child nobody waits for.

The confirmation step before marking someone is unchanged.

[1.18.0] — 2026-08-02

Fixed — "Add Tutela to your home screen" now matches the browser you are using

The instructions for adding the driver app to a phone's home screen were written for Safari, and were shown to every browser on an iPhone or iPad. On Chrome for iOS the Share button is not where those steps said it was, so drivers were sent looking in the wrong place.

Each browser now gets its own steps — Safari, Chrome, Firefox and Edge on iPhone and iPad, and Firefox on Android.

Firefox on Android previously saw nothing at all. That browser does not offer the one-tap install other browsers do, and the app had no way of telling — so it stayed quiet and those drivers were never told the app could be added to their home screen. It now shows them how.

That matters more than convenience: phones clear stored data for a website that has not been added to the home screen, and the driver app keeps unsent boarding records and the offline run details in exactly that storage.

Where a one-tap install is available it is still offered, unchanged. On browsers that cannot install the app at all, nothing is shown rather than instructions that would not work.

Fixed — recording and checking a qualification now matches how the schemes actually work

Three problems on the qualifications screen, all with the same root: the form asked for details that some kinds of qualification simply do not have, so the quickest way through was to make something up.

Only the fields that apply. Recording a medical certificate, a first aid certificate or an induction previously required a card number and an Australian state, neither of which those things have. The form now shows only what the chosen kind of qualification actually carries, and the labels and guidance change with it — a card number for a Working With Children Check, a licence number for a licence, and nothing where there is nothing to give.

You can now see the number you need to do the check. The screen asked you to verify a check against the issuing register while hiding the card number that check requires — so the number had to come off the physical card or from asking the person again. The list now shows it with all but the last four characters hidden, which is enough to match it against a card in your hand. The full number is one click away for staff who are permitted to see it, and every time it is shown we record who looked and when. Short numbers are hidden completely, because showing the end of a short number gives it away.

A reference is no longer expected where none is issued. In Western Australia a Working With Children Check simply confirms on screen that a card is valid today — there is no reference number to write down. The field asked for one with nothing to say it was optional, so it looked compulsory. It is now clearly optional, and in WA it says to leave it blank.

And the date the register was checked is now recorded — separately from the date the result was entered here. Usually the same day, but if you run your checks on a Friday and enter them on Monday, the record shows when the register was actually consulted. Verified qualifications now display that date, so anyone reviewing the register can see what the result rests on.

The issue date of a qualification is now shown in the list as well; it was being collected and never displayed.

You can now attach the document itself. A photo of the card, or the certificate a training provider issued, can be uploaded when you record a qualification — up to 8 MB, as a PDF or an image. Files are checked for malware before they are accepted, and are stored privately rather than anywhere that can be linked to publicly. Only staff who are permitted to see the card number can download the document, since a photo of a card shows the number anyway, and each download is recorded.

Added — drivers can see the week ahead, and record a child who is not travelling

The driver app only ever showed today. A driver wanting to know whether they were on a particular run on Thursday, or what time Monday started, had to ring the depot.

Your week now lists the runs a driver is rostered on for the days ahead — day, route, time and bus. Today stays the opening screen; the week is somewhere a driver goes deliberately. Only today's runs can be opened to drive: a run later in the week can be read but not started, so nothing can be recorded against the wrong day. Anything beyond the published roster says so plainly rather than looking like an empty week.

Parents often tell the driver directly that a child is not travelling — a message on a personal phone that the platform never saw. A driver can now record that against a specific run, so the office and the run's own list know about it too, instead of it living in one person's memory until the morning.

Two things about how that works are deliberate:

  • Marking a child as not travelling asks you to confirm; putting them back does not. If a child is wrongly marked, nobody waits for them at their stop — so the risky direction takes a second, deliberate tap and the safe one is immediate.
  • The week view shows no children at all, and the list for a run shows names only, never photographs, and only when a driver opens that specific run. A driver's phone should not end up holding a week of children's details for journeys that have not happened.

Absences recorded this way are marked as having come from the driver, so your office can see which ones came from a phone call nobody else heard.

Changed — the absence register saves each tick as you make it

Marking children not travelling meant ticking boxes and then pressing Save register, which reloaded the page. Marking four children in a row meant four page loads, or keeping every tick in your head until the end — slower than the paper book it replaced.

Each tick now saves on its own, with no reload, so you can work down a list while a parent is on the phone. The Save button has gone, because it is no longer needed.

Every tick tells you what happened to it. A box that is saving, saved, or could not be saved all look different. If a tick cannot be saved — a dropped connection, or a run that has already departed — the box goes back to how it was and turns red or amber with an explanation. It will never show a tick against a child that was not actually recorded.

If your browser cannot run the page's scripts for any reason, the old Save button appears instead and works exactly as before.

Fixed — the access report no longer says nobody has looked at your child's record

When there was nothing to show, the page said "No one has viewed your child's record yet." That was more than the page could actually know, and on a transparency report that matters: a blank page is not the same as proof that nobody looked.

It now says we have no record of anyone opening the record recently, and notes that a view can take a few minutes to appear. The wording at the top has also been corrected: the page shows views by staff at your bus operator, which is what it has always covered.

If you have more than one child, each is now listed whether or not anyone has opened their record. Previously a child nobody had looked at simply did not appear, which was easy to mistake for something being wrong.

Added — the family portal now has navigation on every page

Until now the only way around the family portal was from the home screen. Once you opened a form, a child's page or the access report, there was no way onwards except your browser's back button — and nothing told you what else was there. Two of the four sections were small links at the bottom of the home page that most people never found.

There is now a bar along the bottom of every page with the four things you can do: My children, Not travelling, Forms, and Who has looked. It sits at the bottom because that is where your thumb reaches when you are holding a phone in one hand.

"Not travelling" can now be opened directly. Previously you had to start from a particular child. If you have one child it goes straight to the form; if you have more, it asks which one first.

Added — a vehicle's odometer now keeps itself up to date, and distance-based services come due

A vehicle's odometer only ever showed the figure typed in when the vehicle was added, even though drivers enter a reading on most pre-start checks and the office enters one on every service. A bus could have been driven for two years and still show its starting number.

Readings entered anywhere — a pre-start check, the start or end of a run, a service, a compliance record — are now kept as a history against the vehicle. The record shows the current reading and where it came from, so you can see at a glance whether it is from this week's pre-start or from the day the bus was added.

Services due at a distance now actually come due. You could already record "next service at 240,000 km"; nothing was watching it. Now, once the vehicle passes that reading, it appears on your task list.

Two things worth knowing about how it treats a doubtful number:

  • A reading is never rejected. If it does not look right — lower than the last one, or a bigger jump than the days since would allow — it is still saved, and marked for you to look at. A driver should never be unable to start their run because a number was mistyped.
  • A queried reading does not count. It will not become the vehicle's current figure and it will not trigger a service, so one mistyped number cannot mark your fleet overdue. It stays visible on the vehicle's record so somebody can correct it.

Existing vehicles have been brought up to date from readings already recorded. Nothing was overwritten with a lower number — a vehicle's figure only ever moves forward.

Fixed — the site described the school portal as read-only, which it is not

The "Who it's for" section of the public site told schools their portal was a read-only view. That has not been true for some time: a school office can say when a student is not travelling, withdraw something their own school recorded, and set their term dates and pupil-free days so buses are not scheduled through the holidays.

The description now says what a school can actually do. What a school can see is unchanged, and is still set by the data-sharing agreement with the transport operator.

Nothing about the portal itself changed — only the description of it. The terms a school accepts when signing in were already accurate, and it was the public page that had fallen behind them.

[1.17.0] — 2026-08-02

Changed — Tutela has a new logo

The platform wears its new identity: a bus on a shield against a city skyline, with the Tutela name and the words School transport, safeguarded beneath it. It replaces the plain shield the platform launched with.

You will see it in the header of every screen, on the sign-in pages, and in the footer of the public site. Headers are a little taller than they were, because the new logo stands taller than the old one and shrinking it far enough to keep the old height would have left the name too small to read.

The browser tab icon and the icon you get when you add Tutela to a phone or tablet home screen have been updated to match. Those use the badge on its own — at the size of a tab icon, a name and a strapline are too small to make out, so the picture does the work.

If you use the driver app on a phone or tablet, it now appears on the home screen as Tutela rather than Drive, with the new icon. You may need to remove and re-add it to see the change, depending on your device.

The logo comes in a light and a dark version, and the platform picks the right one for whichever theme you are using — so the strapline stays readable in dark mode instead of disappearing into the background.

Two pages that never showed who they belonged to now do: the form a parent opens from a link without signing in, and the page for signing on a phone. Both were plain white before, which is not reassuring on a page asking about a child. The logo there is not a link, so it cannot pull anyone away from a half-finished form.

The driver app shows the logo on its sign-in and its runs list, but deliberately not on the screen used while a run is under way — nothing decorative belongs on the screen a driver reads at the wheel.

Changed — buttons that used to look like plain text now look like buttons

Actions at the top of a page — and in the right-hand column of most lists — had no outline until you hovered over them, so they read as ordinary text and were easy to miss entirely. On the Compliance page that meant three ways of getting to related screens sat there looking like a heading.

They now have a visible edge before you touch them. Actions that delete or remove something keep their own distinct look, so they cannot be mistaken for an ordinary one.

A few places were left as they were on purpose: the top navigation bar, controls that sit inside a panel next to the thing they change, and everything on the driver app, which is designed to be read at a glance from a driver's seat and follows its own rules.

Added — you can jump to a page, and choose how many rows to see

Long lists only offered Previous and Next, with no indication of how many pages there were. Reaching anything deep in a list meant clicking Next over and over.

Every list now shows numbered pages you can jump straight to, tells you which rows you are looking at out of the total, and lets you choose how many rows to show at once — 25, 50, 100 or 200. The page you are currently on is shown but is not a link, because you are already there.

Changing the number of rows takes you back to the first page, so you cannot end up past the end of the list looking at an empty screen. Your choice stays with you as you page through, and alongside any search or filter you have applied.

Fixed — you can now open a completed form from the list that says it was completed

On the parent forms screen, a form marked Answered could not be opened. Nothing on the row led anywhere, so reading what a parent had actually written meant going to a different screen and finding the submission by name and date.

The row now links straight through to the answers. For a walk-home permission that matters, because those answers are what you read before deciding whether a child may leave their stop unaccompanied.

Reading a parent's answers still requires the same permission it always did — being able to see that a form came back is not the same as being allowed to read it, so the link only appears for staff whose access already covers that. A form still waiting has nothing to open, and a withdrawn form keeps its link if an answer was already given.

Fixed — a vehicle's seatbelt type now reads properly

The vehicle record displayed the seatbelt type in its stored form rather than in plain words. It now reads the same way it does in the edit screen.

Vehicle and student statuses are handled the same way now, so they read consistently wherever they appear.

Fixed — demonstration data no longer shows duplicate depots and school stops

In demonstration data, each service was given its own copy of the depot and the school gate, so the stop list showed the same depot several times — and the copies were placed at slightly different points on the map. Every service now shares the one depot and the one school gate, which is also how real services work.

This affects demonstration data only. No real stop, route or run was involved.

[1.16.0] — 2026-08-02

Fixed — an approved walk-home permission no longer disappears from your screen

If a permission was approved to start on a future date, it vanished from the walk-home screen as soon as it was saved, because that screen only ever showed what applied on the day. Operators reasonably took that to mean the approval had failed. The same problem also meant a permission dated to start later could not be withdrawn until it began.

The screen now lists every approved permission and says which it is: in place now, starting on a date, or ended. Any of them can be withdrawn except one that has already ended, and a permission that has not started yet is still never shown to a driver.

Fixed — both parents can now see and end a walk-home permission

A permission to walk home from the stop used to be visible only to the parent who submitted the form. The child's other parent or carer saw nothing on their own portal — and could well have found out by turning up to meet a child who was not there.

Every parent or carer listed for a child now sees any walk-home permission for that child, is told who arranged it, and can withdraw it themselves without ringing the operator. Which parent withdrew it is recorded, so the operator can see who made the change. Nothing else about who can see whose children has altered: you still see only your own.

Added — the child's record now shows what has been happening

Opening a child's record showed their details, their school and their contacts, but nothing about what had actually happened — you had to know which other screen to go to. It now also shows, all on the one page:

  • any walk-home permission, including one waiting for a decision or starting on a future date;
  • forms sent about that child and whether they have come back;
  • days in the last fortnight they were not travelling.

It is a summary, not a second control panel. Approving, declining and withdrawing still happen on the screens that own those decisions, and each section only appears for staff whose access already covers it — reading a child's record does not give anyone access to what a parent wrote on a form.

Added — a submitted parent form now appears on the operator's task list

When a parent asked for their child to be allowed to walk home, the request appeared on the walk-home screen and nowhere else, so it was only noticed if someone thought to look. Until the request is decided the child is still met at the stop, so a request that sat unseen meant the family believed something was arranged when it was not.

A request now raises a task the moment it is submitted, and approving, declining or withdrawing it closes that task. What the parent wrote is not copied onto the task — the task names the child and links to the request, and the answers stay where they were submitted.

Added — parents can now find and complete forms without waiting to be sent one

Until now, a form only reached a parent if the transport operator sent it to them specifically. If nothing had been sent, the Forms page in the family portal simply said there was nothing to complete.

An operator can now mark a form as available to parents. Those forms appear under Available to complete, and a parent can start one whenever they need to — choosing which of their children it is about.

The walk-home permission is the obvious one: a parent who decides their child may walk home from the stop can now say so directly, instead of ringing to ask for the form.

Two things are unchanged, deliberately:

  • A walk-home permission is still a request, not a decision. Completing the form asks the transport operator; it does not authorise anything on its own, and no driver is told until the operator agrees. That was already true and remains true whoever starts the form.
  • What you fill in is recorded exactly the same way as a form you were sent — the same child, the same parent, the same date. It makes no difference to the record who began it.

Where the form itself begins by asking which children it is about — the walk-home permission does — the portal no longer also asks first. It was asking the same question twice, which invited a parent to name one child at the start and tick a different one in the form.

You will only ever see your own children in the list, and only the forms your operator has chosen to make available.

Added — schools can tell us their term dates and pupil-free days

Buses no longer need to be scheduled through the school holidays. A school can record its term dates and any pupil-free days or closures, and no bus is scheduled for a day the school is shut. The transport operator can see and change the same calendar, and can enter it on the school's behalf if that is easier.

Leaving it blank is completely safe. Until term dates are recorded, buses run to their normal timetable exactly as they do now. Nothing stops because this was added.

Two things worth knowing about how it behaves:

  • A bus is only held back for a day that falls between two terms you have recorded. If your calendar only goes up to the end of this term, buses keep running after it — we treat a calendar that has run out as missing information, not as the school having closed.
  • A pupil-free day you record stops the bus for that day even if it sits inside a term.

Please keep the calendar accurate. A wrong date means children with no bus, which is a great deal worse than a bus with no children.

Important — schools: your portal terms have changed again

Because you can now record term dates as well as absences, the terms have been updated to describe both, and everyone with school portal access will be asked to accept them once more. Our apologies for asking twice in quick succession — the first update covered absences only, and this one arrived immediately behind it.

Fixed — the school portal listed information it was not actually showing

The roster page displayed a list of the information your agreement covers, including things like home addresses and guardian contacts, while the page itself only ever showed names, year levels and today's boarding status.

Nothing was ever disclosed that should not have been — if anything, less was shown than the agreement allowed. But the list gave the wrong impression of what you were being given, so it now describes exactly what is on the page and nothing more. Your agreement itself is unchanged.

Fixed — the absence form no longer asks you to work out which date boxes to use

Recording an absence used to show a "specific day" box and a "first day / last day" pair at the same time, with a note explaining which ones applied to your choice. The form now simply shows the boxes that apply.

Fixed — checklist items could not be opened for editing

Opening any item on a safety checklist showed a blank panel instead of its settings. The item and its settings were never lost — only the editing screen failed to draw. Fixed, and a check added so it cannot happen again unnoticed.

[1.15.0] — 2026-08-01

Important — schools: your portal terms have changed, and you will be asked to accept them again

The school portal used to be read-only. It now lets you tell us when one of your students is not travelling, and the terms you accepted did not describe that. They do now.

Because this changes what you are agreeing to — not just how it is worded — everyone with school portal access will be asked to read and accept the updated terms once before continuing. It takes a moment and only happens once.

The short version of what changed: you can record that a student is not travelling, it is recorded against your name and your school, and it changes what the driver sees on the bus. You can withdraw something your school recorded, but you cannot change or withdraw what a parent has recorded — if a parent's information looks wrong, speak to the transport operator.

Fixed — the contact address on our privacy and terms pages did not work

The address published on the privacy page and on both sets of terms was not a real mailbox, so anything sent to it bounced — including privacy enquiries and requests to correct information. Every reference now points to a working address.

If you wrote to us about privacy and never heard back, that is why. Please do send it again.

Added — schools can now tell us a student is not travelling

A school can record that one of its students will not be on the bus — for one run, a whole day, or a range of days. Until now only a parent or your office could do that. The case this is for is the one nobody could cover before: a child leaves at lunchtime. The school office knows straight away, the parent may not, and there was no way to tell us before the afternoon run set off. The driver waited at the stop for a child who was never coming, and the end-of-run count showed a difference that was never real. "Left early" is recorded as an afternoon-only absence, so the morning trip the child actually travelled on is untouched.

Every absence a school records is attributed to that school and to the person who entered it, and is visible to you. A school can only see and act on students enrolled with them, and only while a current data-sharing agreement is in place. A school can withdraw an absence its own staff recorded. It cannot change or remove one recorded by a parent or by your office — a parent's word about their own child stays theirs.

If a run has already been handed to the driver, it is too late for the change to take effect, and the school is told so on screen and asked to phone you rather than being left to assume it worked.

Added — one checklist that knows what is due today

Checklists no longer have to be split into a daily one, a weekly one and whatever else. Each question now carries its own rhythm, so a single checklist can hold everything a bus needs:

  • every run
  • daily, in the morning or in the afternoon
  • weekly, at the start of the week or towards the end of it
  • monthly, quarterly or annually

The driver is only asked what is actually outstanding. Everything due every run appears every time; a weekly item appears once that week and then steps aside. If a week goes by without it being answered, it comes straight back rather than being skipped — an unanswered check stays outstanding until somebody does it.

Anything on a longer rhythm is tracked per bus, not per driver. A check done on Monday is done for that bus, so a relief driver later in the week is not asked it again — and a bus that has not had it done still gets asked, whoever is driving.

Added — checks can be asked after the run as well as before

Each question can now be marked as belonging before the run or after it. Anything marked for after the run appears at the end, alongside the walk-through of the bus, and the run cannot be finished until it has been worked through. Reporting a fault does not trap the driver: the fault is recorded and the bus taken out of service as it always was, and the run can still be finished.

Added — a screen for setting all of this

There is now a place to set, for every question on a checklist: how serious a failure is, how often it is asked, and whether it belongs before or after the run. How serious a failure is could not previously be set at all without our help.

Existing checklists are unchanged and keep working exactly as they do today. Every question on them is treated as "before every run", which is what they already were.

Changed — the run screen fits every child at a stop on screen at once

At a stop with more than a few children, the driver had to scroll the list to find someone. The map now gives up space as the number of children grows, so the whole stop is visible without scrolling. At a very busy stop the layout switches to a tighter list — the photographs get smaller, but every child stays on screen and the buttons stay large enough to hit reliably. Nothing is ever shrunk below a comfortable tap size to make it fit.

[1.14.0] — 2026-07-31

Fixed — the driver app now works properly with no signal

Drivers can complete a full run with no mobile coverage. Three things were stopping that, and all three are fixed.

  • Marking the bus arrived or departed took the driver to the "you're offline" screen and the arrival was not saved. Both now save on the device and send themselves when signal returns, and the driver stays on the run screen.
  • The pre-start check could not be completed without coverage, so a run could not be started at all — even though a bus usually leaves the depot before it leaves coverage. It can now be completed and the run started with no signal.
  • On some older or restricted devices the arrival and departure buttons quietly stopped working because the map could not load. The two no longer depend on each other: if the map is unavailable, everything else still works.

Everything a driver taps — children on and off, arrivals, departures, the pre-start check — is now saved on the device the moment they tap it, and sent in the order it happened once there is a connection. A banner shows how many actions are still waiting to send, so nothing finishes a run unnoticed.

The run screen no longer forgets what the driver has done. If the app reloaded — a screen locked and woken, a tab restored — it could come back showing a stop the driver had already marked, because it was showing the last version it had received from us. It now reapplies everything saved on the device, so the screen matches what the driver actually did.

A run can't be finished while anything is still waiting to send. The end-of-run check for a child left on board is worked out by us, from what has reached us — so finishing early would run that check against an incomplete picture, and it could pass when it should not. The Complete button now waits until everything has arrived, tells the driver how many actions are outstanding, and unlocks itself. This is the one place the app deliberately asks the driver to wait, and it is the check we are least willing to let run on partial information.

One thing deliberately still needs coverage. If a pre-start check fails on a major item, the bus is taken out of service — and that has to reach your office, because no other driver should take that bus out either. The check is saved on the device so nothing is lost, but the run will not start and the driver is told to contact you directly.

Fixed — pages showing student and guardian names could return an error

On some systems, any console page that displayed a student's or guardian's name returned an error instead of loading. Student and driver screens were affected in the same way.

No information was lost or exposed, and nothing needed to be re-entered. The records themselves were correct throughout — the fault was in a supporting part of the system that records who has viewed protected details, and it stopped the page rather than showing anything it should not have. Protected details are deliberately built to stop rather than to guess, and that is what happened here.

We have also added an automatic check that catches this class of problem before a release goes out.

Added — suggested road paths when building a route

When you draw the path a bus takes between two stops, we can now propose one that follows the roads, so you correct a suggestion instead of tracing every corner by hand. On a rural leg that is the difference between a few clicks and dozens. A suggestion is only ever a proposal. It is never treated as approved, it is never used for anything on its own, and it only becomes the route's path when a person looks at it and approves it — exactly as a hand-drawn path always has. Road data does not know that a bus is not a car, so the person approving is still the one who decides. This is our own service, running on our own infrastructure. No part of a route, and no stop location, is sent to any outside mapping provider.

Added — add a stop anywhere in a route, not just at the end

You can now choose where a new stop goes when you add it — before any existing stop, or at the end. Previously every new stop landed at the end of the route and had to be moved up one position at a time, which was slow on a long route and most awkward exactly when it was needed most: a child joining part-way through the year. Only the two legs either side of the new stop need their path re-approved. Every other leg keeps the approval it already had, and the route correctly shows as not fully approved until those two are done.

Fixed — a mistyped setting no longer looks like a switched-off feature

If a setting for the road-path service was entered incorrectly, the system quietly behaved as though the feature had never been turned on — the same message either way. It now reports the problem clearly instead of leaving you to guess.

[1.13.0] — 2026-07-30

Added — an absence register, so your office can record who is not travelling

Parents could tell you a child was not travelling through the family portal. Your own office could not — so a phone call to the depot had nowhere to go except a note beside the phone.

There is now an absence register in the console: students down the side, days across the top, with a morning and an afternoon box for each day. It is laid out like the book most operators keep by the phone, and it works the same way.

  • Tick the boxes, then save. Mark several children while the parent is still on the line rather than one at a time.
  • Unticking withdraws an absence rather than erasing it, so the register keeps its history and you can always see what was recorded and by whom.
  • "Away for a range of days" marks a child off for a whole week or a holiday in one go, and the whole run of days can be withdrawn together.
  • Filter by route so you are looking at one bus rather than every child you carry.
  • Days that have already run cannot be changed. Once a bus has set off, the list the driver saw is fixed, and the register says so plainly rather than appearing to accept a change that would not reach anyone.

Absences recorded here reach the driver exactly as parent-recorded ones do: the child shows on the run as not expected, so the driver is not waiting at a stop for someone who was never coming — and the end-of-run check that every child is accounted for stays correct.

Changed — hiding student names on an idle bus now needs the driver's PIN to undo

When a bus has been stopped and the screen untouched for a few minutes, the driver app blurs the list of student names. It is there for the case where the driver has stepped off the bus and the screen is still lit on the dash, where anyone reaching the cab could read who is on board and where they are collected from.

Until now a single tap cleared it, which meant it deterred a passing glance and nothing more — the person it is meant to protect against could tap it too. Clearing it now asks for the driver's PIN, which they already have and already use.

  • It cannot appear while the bus is at a stop. If a stop is open, the names stay visible; if a stop is opened while the names are hidden, they come straight back. A driver is never asked for a PIN while children are getting on or off.
  • Touching the screen still keeps the names visible, so a driver working normally never sees this at all.
  • Names are shown as usual for the whole of a normal run. This only applies to a bus that has been sitting still, untouched.

Added — the driver app can now be added to the home screen

The driver app has always been installable, but nothing ever offered it, so most drivers were running it as a browser tab.

The run list now offers to add it to the home screen. Installed, it opens full screen with no browser bar taking up room, and there is no address bar or tab strip to catch with a stray thumb mid-run.

  • On Android and desktop it installs with one tap.
  • On iPhone and iPad, Apple does not allow an app to install itself, so short instructions are shown instead.
  • It appears once on the run list, never on a run in progress, and can be dismissed.

Added — every sign-in screen on the demonstration site can now be entered directly

Tutela has four sign-in screens — office staff, drivers, families and schools. On our public demonstration site only the office one offered buttons that take you straight in as an example user, so the other three could only be reached by starting somewhere else first. The family and school screens were the awkward ones: both normally sign you in by emailing a link, and the example accounts have no real inbox to receive it.

All four screens now offer the same one-tap entry, each showing only the example users that belong to it, and sized for the screen it sits on.

This applies to the demonstration site only. Real accounts always sign in the normal way, and nothing about how they do so has changed.

Fixed — records that cannot be read are now reported, never shown as scrambled text

Student names, dates of birth and notes are stored encrypted. If the platform is ever unable to unscramble one of those values, it used to show the scrambled text in place of the real one — so a driver could be looking at a run sheet where a child's name was a line of meaningless characters, next to the buttons for marking that child on and off the bus.

  • The platform now refuses to display a value it could not read. It reports an error instead, which is visible immediately and can be acted on, rather than producing a page that looks filled in but is not.
  • The same applies to a date of birth, which previously came back looking simply blank — indistinguishable from one that had never been entered.
  • A new check on our monitoring reports whether stored records can still be read. It runs continuously, so this kind of problem is picked up centrally rather than by a driver noticing something odd at the start of a run.

Nothing about how your data is stored or protected has changed. This is about what happens in the rare case something goes wrong with reading it: the platform now says so plainly instead of carrying on.

Fixed — the dispatch screen now keeps itself up to date

The dispatch screen showed your operating day as it stood the moment you opened it, and never moved again. Buses drove, children boarded, runs fell behind — and the screen kept showing the figures from whenever the tab was opened. Nothing on it said the numbers were old, so there was no reason to reload.

It now refreshes itself every few seconds:

  • Bus positions on the map move, without the map jumping or re-centring while you are looking at it.
  • On-board counts, progress through the run, status and exception flags all update.
  • An "Updated" time sits at the top of the board, so you can always see how current the figures are.
  • If the connection drops, the board dims and tells you it could not refresh, rather than quietly continuing to show out-of-date figures as though they were live.
  • Refreshing pauses while the tab is in the background and catches up the instant you come back.

One thing stays put on purpose: the band at the top listing runs that need attention. It contains a form you may be part-way through filling in, so it is not replaced underneath you. If a new run needs attention while you are looking at the board, you will get a clear prompt to reload.

The screen still shows only movements and counts — never a child's details — which is unchanged.

Fixed — children can now be marked off at school, and the run screen shows faces

The important part first. Children are listed against the stop they are collected from, which meant the school stop showed nobody — even though that is where everyone gets off in the morning. Drivers had no way to mark children off the bus there, so every morning run finished with the whole load still showing as on board, and the only way to complete it was to override the check that says nobody has been left behind.

That check is one of the two things this platform exists for, and a check that has to be overridden every single day stops being a check. It is fixed:

  • The school stop now lists everyone currently on the bus, taken from what was actually recorded rather than from who is assigned where — so a child who got on somewhere unexpected still appears.
  • One "All off" button empties the bus, because marking thirty children off one at a time while they file past is not something a driver can do properly. Each child is still recorded individually, so the record can always say where a particular child got off.
  • Morning runs can now be completed normally, and the override goes back to being what it was meant to be: rare, and worth looking at when it happens.

Changed — the driver run screen now shows each child's photo

The run screen has been rebuilt around the stop the driver is at, with the route map alongside it rather than scrolled off the top.

  • One tile per child, showing their photo. Tapping the tile marks that child on or off. Recognising a face is quicker and safer than reading a surname off a list at quarter past seven, and it matters most for a relief driver who does not know the run.
  • Each tile says what tapping it will do, because the same tap means "on" in the morning and "off" in the afternoon.
  • A separate corner button marks a child absent. It looks small but has a full-size touch area, so it cannot be hit by accident.
  • Where a child has no photo on file, the tile shows their initials and name instead — a normal state, not a broken image.
  • Photos are stored on the device only for the length of the run and cleared when the run finishes or the driver signs out.

Changed — the run screen only offers the actions that make sense at each stop

Every stop used to offer "on", "off" and "absent" as three equal buttons, and two of the three were wrong at any given stop. Morning runs pick children up at their stop and set them down at school; afternoon runs do the reverse.

The expected action now leads at each stop. The others are still available but stepped back, so a genuine exception — a child getting off part-way through an afternoon run — can still be recorded. Nothing has been removed, because a real event that cannot be recorded is a gap in the record.

Midday and charter runs keep all three actions, since those do not follow a fixed pick-up or set-down pattern.

Added — platform support can now see what you see, on the record

When you report a problem with the driver app, the family portal or the school portal, our support team previously had no way to look at those screens. They could read your data from the administration side, but they could not see the page you were describing — so working out why a button was missing or a page looked empty meant guessing at it from the other end.

Support can now open a read-only view of one of those portals as a specific person sees it. It is deliberately fenced:

  • Only our platform team can start one, and only after re-entering their password.
  • They must write down why, before it opens. That reason is recorded against their name.
  • The view cannot change anything. Nothing can be submitted, recorded or edited — not an absence, not a boarding record, not a setting.
  • It ends by itself after a short time, and a bright banner sits across the top of every screen for as long as it is open, so nobody can forget whose account they are looking at.
  • Starting it and ending it are both written to our audit trail.

We would rather tell you this exists than have it be a surprise. If you would prefer support to ask you before doing this, tell us and we will make that your operator's standing instruction.

Changed — medical and behavioural notes now ask you to confirm your password

Opening a student's record still works exactly as before. The medical and behavioural notes on that record are now hidden behind a short confirmation: if you have not entered your password recently, you will see a button asking you to confirm it before those notes appear. Everything else on the page is unaffected.

This is aimed at the console that gets left open — a shared office machine, or a laptop that walks away from a desk. Your morning login is not much protection for the most sensitive thing on the page, several hours later.

Two smaller points that follow from it:

  • If you do not have permission to view medical notes, nothing changes: you are told you do not have permission, rather than being offered a confirmation that would not help.
  • Our record of who viewed a child's medical notes now only counts the times they were actually shown on screen. Previously it counted anyone who could have seen them, which overstated what had been disclosed.

Fixed — a run ended without every child accounted for now stays in front of your dispatchers

Before a run can be completed, every child who boarded must be marked off the bus. A driver who cannot do that can still finish the run, but only by recording a reason — and that is meant to be the point at which the office takes over.

It was not. A run finished that way dropped off the dispatch board straight away, and nothing on any screen said it had happened. The moment your team most needed to look at a run was the moment it disappeared.

  • It stays on the board. A run completed with a child unaccounted for now sits in a highlighted band above everything else, showing how many children were unaccounted for, the counts on and off the bus, and who finished the run and when.
  • It does not go away by itself. Not on a page refresh, not at the end of the day, and not when tomorrow's runs start. It stays until someone deals with it.
  • Someone has to say what they found. Clearing it means choosing what was established — the child was located and is safe, the bus was physically checked and empty, or the count itself was wrong — and that choice is recorded against the run with the name of the person who made it and the time they made it.
  • Not the person who finished the run. Whoever used the override cannot be the one who signs it off. Someone else has to confirm where the child is.
  • A new permission controls who can sign one off, separate from the ability to correct a boarding record. Company administrators, operations managers and dispatchers hold it by default. Existing accounts get it automatically.

The reason the driver typed is shown only to people who are already allowed to see who was on the bus.

Fixed — the driver app now works properly without a connection

Losing signal used to drop drivers onto the browser's own "you're not connected" error page — outside the app altogether, with no run, no student list and no way back until connectivity returned. Submitting the daily pre-start check without a connection did the same thing.

  • Drivers stay inside the app. Any screen that cannot be reached without a connection now shows a Tutela offline page with a way back to the run, instead of a browser error.
  • The screens a driver is about to need are downloaded in advance, while there is still signal, so moving between the run list and the run works with no connection.
  • Submitting the pre-start check without a connection now tells the driver it did not go through. It is deliberately not saved for later: the pre-start is a safety check, and a run must never be able to start on one the office has not received.
  • Marking children on and off is unchanged and still works offline — those taps have always been saved on the device and sent automatically once you are back online.

A privacy improvement came with it. Run screens that had been viewed were being kept on the device indefinitely, and those pages list the children on the run. They are now stored separately and cleared automatically when the run is completed, and again whenever the driver sign-in screen appears — so a shared depot tablet does not keep a list of children from the last driver's run.

Added — stops now close themselves when the bus drives away

The driver app already marked a stop as arrived automatically when the bus pulled up. It now marks it as departed automatically when the bus leaves, so a driver no longer has to remember a tap at every stop while children are settling.

  • A stop closes once the bus is clearly away from it and has stayed away. It needs to be properly clear of the stop, not just over the edge, so a wandering GPS reading cannot close a stop while children are still boarding.
  • If the bus is being held at a stop until its timetabled time, it is never closed automatically. Leaving early needs a reason from the driver, and the app will not supply one on their behalf — it asks instead.
  • If a stop cannot close itself and the bus has already moved on, the driver is now told, and taken to the stop that needs closing.

This also fixes a quiet problem behind it. A stop left open used to stop the automatic arrival detection for the whole rest of the run, with nothing on screen to say so — so one missed tap early on meant the driver was marking every later stop by hand without knowing why.

The manual Arrived and Departed buttons are unchanged and always available. The automatic detection removes the need to use them on a normal run; it does not replace them.

Fixed — a bus can no longer be recorded as arrived at two stops at once

A run is one bus, so it can only be at one stop at a time. Until now the driver app would let a second stop be marked as arrived while an earlier one had never been marked as departed, which left the run's record showing the bus in two places and made the arrival and departure times unreliable.

  • Only one stop on a run can be open at a time. While the bus is at a stop, the Arrived button on the other stops is unavailable and says which stop needs to be marked departed first — so the driver sees the reason rather than tapping a button that does nothing.
  • A stop that has already been arrived at or departed can no longer be arrived at again, so the original arrival time and location are never overwritten.
  • A stop can no longer be marked departed unless the bus was recorded as arriving there first.
  • The manual Arrived and Departed buttons remain available exactly as before. They are the fallback for when the automatic detection does not fire, and they now return the driver to the run screen with a clear message instead of a page of technical text if something is refused.

Stops can still be served out of order. Diversions and road closures happen, and it is better to record an unusual run accurately than to refuse to record it at all.

Added — administrators can now send a team member a password reset link

If one of your drivers or office staff is locked out, an administrator at your organisation can now send them a link to set a new password, straight from your team list. Until now the only way round it was to suspend the account and create the person again under a different email address — which left you with two records for one person and split their training and run history across both.

A few things worth knowing about how it works:

  • A link is sent to the address on file. No password is ever shown or set by the administrator. That means nobody else ever knows the person's password, and anything done with that account can be traced back to the person it belongs to. The confirmation you see says the link was sent, without displaying the email address — team lists are often open on a shared screen.
  • Their current password keeps working until they use the link and choose a new one, so sending one by mistake locks nobody out.
  • Each new link cancels the previous one, and links expire shortly after they are sent.
  • The email tells the person that an administrator started the reset, so an unexpected one reads as something to ask about rather than something to ignore.
  • The link takes drivers to the driver app and office staff to the console, so nobody lands on the wrong sign-in screen after setting their password.

Administrators cannot use this on their own account — there is a change-password screen for that, and it asks for your current password first. Suspended accounts need reactivating rather than resetting, and you will be told so.

This sits alongside the "forgot password" link people can already use themselves. Both paths exist on purpose: someone locked out early in the morning may not be able to reach an administrator either.

[1.12.0] — 2026-07-29

Fixed — stop times can now be corrected without removing the stop

A stop's time could only be set when the stop was first added to a route. After that the only way to change it was to remove the stop and add it back — and removing a stop also removes every student assigned to it, which was not mentioned anywhere on screen. Correcting a departure by five minutes could quietly take children off that stop, and there was nothing to warn you it had happened.

Each row on Stops & timing now has an Edit control. Change the time, mark or unmark it as a timing point, save. Students, stop order and the approved road path are all left exactly as they were. Leave the time blank to clear it if you do not know it yet.

This matters most straight after duplicating a route. When you duplicate an AM route into a PM one and give it a start time, every stop's time is worked out from that start — the run out from the depot, the wait at the school, the run home are all estimates. They were always meant to be refined against what the bus really does, and now they can be.

Added — trace the road a bus actually drives, by clicking along it

When you build a route by hand, you can now draw the path between stops on the map: click along the street from one stop to the next, drag a point to nudge it, click a point to remove it. Do it as you add each stop, and the route arrives finished rather than needing a second pass over it afterwards.

You can also draw or correct any leg later from the Road path panel — including on routes that came in from a contract schedule, which previously could not be adjusted at all.

The two ends of each leg are always the stops themselves, so a path can never be left starting somewhere the bus does not. If a drawn path does not join the two stops it is supposed to, we refuse it and tell you, rather than quietly saving a line that goes the wrong way.

Approving a plain straight line between two stops is still perfectly reasonable where there is no road detail worth capturing — but the button now says that is what it is doing, so a straight line is never mistaken later for a road you checked.

Added — written directions between stops can now be edited

The turn-by-turn notes for getting from one stop to the next ("turn left at the silo, cross the grid") can now be written and corrected on any route. Previously they could only arrive with an imported timetable, which meant a mistake in them could be read but never fixed, and a route you built yourself could not have them at all.

Fixed — the road path list showed an arrow with no stop names

On the Road path panel, every leg displayed as a bare arrow with the stops missing either side of it, so each row looked identical and there was no way to tell which leg you were about to approve. The stop names are back.

Added — you can now reset your own password

Both the office console and the driver app now have a "Forgotten your password?" link on the sign-in screen. Enter your email address and we'll send you a link to choose a new one. The link works once and expires shortly after it is sent, so if you leave it too long, just ask for another.

For drivers this is the one that matters. Until now, a forgotten password before a morning run meant ringing the depot and hoping someone was there — and there was no quick way for them to help either. You can now sort it out from the bus, and the driver app's sign-in screen still points you at your operator, because if you need to drive right now that is usually the faster call.

Two small things worth knowing. We give the same answer whether or not the address you type has an account — that is deliberate, so nobody can use the form to work out who works for you. And choosing a new password signs you out of any other phones or tablets that had remembered you, because if you are resetting it, you may not be the only person who knew the old one.

Changed — drivers are now asked to replace a password that was set up for them

When you create a driver or staff account, the system generates a one-off password for you to pass on. Everyone is now required to replace that password the first time they use it, and on the driver app there is now a screen for doing so — big buttons, readable in the sun, and it asks for nothing but the old password and the new one.

Previously this was only asked for on the office console, and only as a prompt after signing in, so a password that had been handed over could stay in use indefinitely. That matters because a password you passed to someone else is one two people know, and a driver's account opens a list of the children on their bus. Sign-out stays available throughout, so nobody gets stuck on the screen if they need to ring the office first.

Changed — who can see and maintain your school list

The school list now has its own permissions, rather than coming along with permission to see students.

Two things change for you. Your office staff and operations managers can now add and edit schools without being given access to your company settings — previously the only people who could keep a school's bell times or transport contact up to date were those who could also edit your company record, so in practice it fell to an administrator.

And the school list is no longer visible to drivers, parents or school contacts. It used to be readable by anyone who could see a student, which is nearly everyone, because seeing students is what makes a run list work. Your school list is the list of every school you work with — it is yours, and a contact from one of those schools should not be looking at the others.

Nobody in your office loses anything: administrators, operations managers, office staff and dispatchers all keep access, and the permissions are applied to your existing accounts automatically when this update lands. Drivers and parents never had a reason to open the school list, and nothing on their screens used it.

Deleting a school is still restricted to administrators, and still not available from the school pages — a school is referenced by the students who attend it and the routes that serve it, so removing one is not a single-button decision.

[1.11.0] — 2026-07-29

Changed — the main menu now follows the order you set things up in

The menus across the top now read left to right in the order you actually build an operation: Fleet, then Operations, then People. Your buses exist before there is a route to drive, and a route exists before you can put a student on a stop along it — so working left to right means you never open a screen that asks for something you have not created yet.

Two things moved while we were there. Forms and Team are now under Operations rather than Settings: sending a form or adding a team member is something you do week to week, and Settings is for the choices you make once. Schools has moved into People, alongside students and guardians — you reach a school through the people at it.

Nothing changed about who can see what. If a menu item was available to you before, it still is, in its new home.

Changed — address lookup keeps working when the mapping service is unavailable

Looking up a stop address used to depend on a single mapping service. If that service was unreachable or its access had lapsed, every lookup failed — and the message you were shown said no match was found and suggested checking the spelling. The address was usually spelled perfectly; nothing you typed could have worked.

Two changes. The failure is now told apart from a genuine "no such address", so you are no longer sent to re-check spelling for a problem at our end. And when the usual service cannot answer, lookup falls back automatically to open map data rather than giving up.

Worth knowing about the fallback, because it matters most for rural addresses: the open map data has good house-number coverage in metropolitan areas but frequently knows only the street in smaller towns. When that happens the result is labelled "Street match only — no house number in the map data" and places the pin on the street rather than the property. Drag the pin to the exact spot and the stop is set correctly — pin placement has always been a complete way to set a stop. The fallback keeps you working through an outage; it is not a like-for-like replacement.

Fixed — creating a stop without changing the arrival zone failed

Adding a new stop and leaving the arrival-zone distance untouched returned an error instead of saving. The field now starts at the standard distance and saving without touching it works. Editing an existing stop was never affected.

The arrival zone is the distance within which the bus is recognised as having arrived, so a stop without one means the driver marks every arrival by hand. It now fills in with the standard distance rather than being left unset.

Fixed — warning banners looked like ordinary page text

Status banners — the terms notice among them — were drawing their background tint so faintly in the light theme that they read as a plain strip of page with a thin coloured edge. A notice you are meant to act on looked like a notice you could scroll past. Banners now carry a visible tint in both light and dark themes.

Added — forms for parents, and permission for a child to walk home

Parents can now be sent forms to complete in their own portal, and the first of these lets a parent ask for their child to walk home from the bus stop instead of being met by an adult.

Asking is not the same as being approved. When a parent sends the request, it goes to the bus operator to review — nothing changes until they approve it, and the portal says so clearly while the request is waiting. Parents can see at any time which permissions are in place for their children, and can withdraw one themselves without having to ring the office.

When an operator approves a request they also choose, separately, whether it is shown to the driver on their screen or kept as an office record. Approving something and putting it in front of a driver are two different decisions.

Every approval, refusal and withdrawal is kept as a permanent record rather than overwriting what came before, so it is always possible to see who gave permission, when, and whether it had been withdrawn by a particular day.

A walk-home form is set up for you. Rather than starting from a blank page, the form arrives already asking the basics — which children it is for, which days, whether they walk with anyone, when it starts and ends, and a confirmation that the parent understands it does not begin until it is approved. It is your form: reword it, add questions, remove the ones you do not need. Once you have started editing it, it is left alone — nothing is ever added back or reset behind you.

A new question type for parent forms: "Student(s)". Drop it into any parent form and each parent sees a tick list of their own children to choose from. You never type the names, and no parent is ever shown another family's child. It fills itself in differently for every family who receives the form.

Operators can also build their own parent forms and send them to whichever families they choose.

Fixed — maps showed a blank background instead of streets

Every map on the platform — setting a stop's location, the live dispatch view and the driver's run screen — drew the pin, the geofence circle and the zoom controls over a plain background, with no streets underneath.

Each device keeps a copy of the map so it still works when the bus goes out of mobile coverage. That stored copy was being filed under the wrong label, so the device kept handing back the same small fragment of map data for every part of the map and none of it could be drawn.

Maps now draw correctly. The stored copy is replaced automatically the next time you open the platform, so there is nothing you need to do — and the driver screen gets its offline map back, which had been storing nothing usable.

[1.10.1] — 2026-07-29

Fixed

  • The stop picker now shows stop names. When adding a stop to a route, the list showed each stop's internal reference on the first line with the actual name in small grey text underneath — so you had to read the second line to find the stop you wanted. It now shows the name, with the stop number alongside it where the two differ.

[1.10.0] — 2026-07-29

Fixed

  • Staying signed in on a device now actually works. Drivers and parents who chose to stay signed in were still being asked to sign in again on every visit. The setting was being saved; the app simply was not consulting it. It is now.

Added

  • Drivers now set a PIN, and the screen locks when it has been left alone. The PIN is what lets drivers skip the code-generator step that office staff use — a code prompt in a cold bus at first light is how a run starts without a student list. It also means a tablet left in a vehicle stops showing anyone who picks it up who is on board and where they are collected.

    The lock will not interrupt a run. It follows what the bus is doing rather than a stopwatch: while a run is under way and the vehicle is reporting in, the screen stays open no matter how long the gap between stops. It locks when the device has genuinely been put away or left behind. If it does lock, nothing is lost — the run keeps going underneath, and one PIN entry picks up where the driver left off.

    Drivers can change their PIN at any time from their run list. Doing so signs out any other device they were signed in on, but not the one in their hand.

  • Student names fade out when the bus has been parked and untouched. A bus waiting in a school yard with the driver walking a child to the door leaves the screen on and the student list readable to anyone who leans in. So after a few minutes stopped with nobody touching the screen, the student names blur behind a single tap.

    It is a tap, not the PIN, and it is deliberately not a lock: nothing should ever come between a driver and the boarding buttons. Touching the screen at any point keeps it clear, so it will not appear while a driver is working through a stop — and the stop names stay readable throughout, so a glance still tells the driver where they are.

  • Register an operator tablet without handing out a password. Where the depot supplies the tablets rather than drivers using their own phones, an administrator can now create a one-time link, open it on the tablet, and have it registered to a named driver. Nobody types a password on shared hardware.

    The link registers the device and nothing more: the driver still enters their PIN to sign in, so a link that goes astray reaches a lock screen rather than anyone's information. It works once, expires within the hour, and can only be shown to you at the moment you create it.

  • Tell your devices apart. The device list previously showed the technical identifier a phone or tablet reports about itself, which made one device very hard to tell from the next. You can now rename any of them to something you would actually recognise, and operator-supplied tablets are labelled as such alongside the administrator who registered them — so "which of these is ours, and which is a personal phone?" is answerable at a glance.

Changed

  • The live map keeps up better on closely spaced stops. Buses now report their position more often while moving and less often while stopped. On runs where stops are close together the map could previously show a bus still approaching a stop it had already served. Position records are still kept for 24 hours only and are still never shown to families or schools.

[1.9.0] — 2026-07-28

Changed

  • One person can now hold more than one role — including driving. A small operator's manager often wears several hats, and one of those hats is sometimes the driver's seat. Until now each person could be given only a single role, and choosing Driver replaced their office access entirely: they could drive, or they could use the office console, but not both. Now you tick every role someone holds and their access is the combination. Someone who manages the office and drives the Friday run signs in once, with one set of credentials, and reaches both the office console and the bus app.

    The two remain separate places on purpose. Signing in on a bus tablet gets you the bus app and nothing else, so a tablet left in a vehicle can never become a way into the office console — even when the person it belongs to works in that office. Whether someone can drive is now decided by whether you have given them the driver role, so the bus app stays closed to office staff who do not drive.

    Two things follow from this that are worth knowing. Editing a person no longer quietly drops the other roles they hold — previously, changing something small like a phone number reset them to a single role. And a manager who also drives can now keep their bus tablet signed in the same way any other driver can, instead of typing a password at the start of every shift.

  • The sign-in button is now four clearly-named portals. The site offered a single "Sign in", but operators, drivers, families and schools each have their own sign-in page. Anyone arriving at the wrong one was simply told their details did not match — which reads as a broken password rather than a wrong door. The front page now names each portal and says who it is for, and they are listed in the footer of every page.

Fixed

  • The Driver option on demonstration sites now opens the bus app. On demonstration and trial environments, choosing the driver sign-in shortcut returned to the driver sign-in page instead of opening the app. It now opens the driver's run list as intended. Live operator accounts were never affected.
  • Street maps now appear behind your stops and routes. Maps were showing the pin, the geofence circle and the zoom controls over a plain background with no streets. Placing and dragging a pin always worked, but with nothing to place it against it was hard to tell whether you had the right spot. The street map now loads. As before, it is served entirely from Tutela's own servers — we never contact an outside mapping service, because that would reveal where you are looking, and on this platform that is where a child lives.
  • Where the street map has not been set up for an environment, the stop editor now says so instead of simply showing an empty map.

[1.8.0] — 2026-07-28

Security and privacy

  • Automated protection against scanning and abuse is now active. The platform records and acts on automated probing, and shares what it sees with our monitoring service so an address that misbehaves against one of our platforms is recognised across all of them. There is a permanent override list so trusted addresses can never be turned away.

  • Security records are kept for a defined period and then removed. Each kind of record has a retention period matched to how long it stays useful, so nothing is held indefinitely. Two exceptions are deliberate: records of who accessed a child's information are retained in full, and a standing block is never removed by age alone. Alerts that nobody has reviewed are also never removed automatically — an unreviewed alert is outstanding, not stale.

  • Incident, first aid and induction records are now encrypted at rest. The sensitive parts of a safety record — who was involved, what happened to them, what first aid was given, and where — are now stored encrypted, the same protection already applied to student and family details. A signature captured when someone acknowledges a policy is encrypted the same way.

    Encryption is applied to the detail, not to the summary information an operator needs to run reports: severity, category, dates, outcomes and reference numbers remain directly searchable, so registers, filtering and audit reporting work exactly as before.

    This was completed before the feature became available to any customer, so there is no change to existing records and nothing for operators to do.

Fixed

  • Drivers can now sign in. The driver app has its own sign-in page, built for the conditions it is used in — large fields and a large button, no code to fetch from another device, and an option to stay signed in on a bus tablet. Previously there was no way for a driver to sign in at all.

  • Signing out no longer gets you stuck. A driver whose clearance had lapsed could not sign out of a device that was still holding their session.

  • Signed-out users land on the right sign-in page. Drivers, parents and school contacts were all being sent to the staff sign-in page, which their account cannot use, with nothing explaining why.

  • Maps failed to load their background. A fault in the offline caching stopped map imagery loading at all, online as well as off.

Added

  • See at a glance which stops still need a location. The stops list now shows whether each stop has a GPS position recorded. A stop without one has no arrival circle, so arrivals there can't be detected automatically and the driver has to mark each one by hand — worth spotting after importing a schedule, where a few addresses usually don't resolve.

  • Edit a stop straight from the list, rather than opening it first.

  • A clearer public site. The website now sets out how this work is usually done — a scheduling spreadsheet, a separate maintenance system, a paper book in the cab, an incident form emailed to the office, phone calls both ways — against having it in one place. None of it is work that is new to an operator; what changes is where it lives, and whether you can prove months later that it happened.

    It also shows four example screens from an ordinary operating day: the morning board, a fault found on a pre-start check taking a bus off the road, driver clearances approaching expiry, and a parent marking a child as not travelling.

    Every one of them shows something the platform genuinely does today. Nothing on the page depicts a feature that doesn't exist yet, and no child, driver or parent is named anywhere on it.

[1.7.0] — 2026-07-28

Added

  • Build a route by hand. Until now a route could only be created by importing a contract schedule or duplicating one that already existed — so a new service, or anything outside a contract, had no starting point. You can now create a route from scratch, edit it, add and remove its stops, and change their order.

  • Find a stop's location from its address. Adding or editing a stop no longer means hunting down latitude and longitude somewhere else and typing them in. Type the address, press Look up, and choose from the matches — the coordinates fill in and a pin drops on the map beside the form.

    Where a match is only approximate — a locality rather than a building — it now says so, because a stop placed on the centre of a suburb can leave its arrival circle in the wrong place.

  • Place the pin exactly where the bus stops. The map lets you drag the pin, or click anywhere to move it, and the coordinates follow. This matters more than it sounds: the bus bay is often not the building the address points at. If you move the pin somewhere with a different nearest address, the platform offers that address rather than applying it — a description like "bus bay opposite the general store" is more use to a driver than a tidied postal address, and only you know which you meant.

  • See the arrival circle before you save. The geofence radius is drawn on the map as you change it, so you can tell at a glance whether it covers the stop and nothing it shouldn't.

    Address look-up needs to be switched on for your installation. Where it isn't, the Look up button simply isn't shown and the map still works — placing the pin by hand sets a stop just as completely.

Fixed

  • Notices now look like what they are. Warnings and errors were being shown in a tint so faint it was close to the page background, so a warning and a confirmation looked much the same at a glance. They now carry their full colour and a matching icon — which matters most on the daily monitor, where the thing being flagged is a problem on a run that is currently out.

  • The same message is no longer shown twice. A notice could appear once beneath the top bar and again under the page heading, in two different styles, reading as two separate messages. There is now one place notices appear.

    This also fixes notices going missing: some pages showed confirmations but silently dropped warnings, so a warning could be raised and never seen.

[1.6.0] — 2026-07-28

Added

  • Approved route paths. Route maps have always joined stops with straight lines, which can make a route look drivable when it is not. You can now record the actual road path a bus takes, leg by leg, and approve it — the path is something your team signs off, never something the system decides on its own.
    • Each leg of a route shows its own status: approved, draft, or no path yet.
    • Where a routing service is available you can ask for a suggested path, check it, and approve it. Where one is not, you can still approve paths yourself.
    • Approvals are kept when you withdraw one, so nothing you have done is lost.
    • If a stop moves, any path approved against its old position is flagged as needing re-approval rather than quietly continuing to look correct.
    • The map draws only approved paths, tells you how many legs are approved, and says plainly when it is showing straight lines instead.
    • Being able to drag a suggested path onto a different road comes in a later update.

[1.5.0] — 2026-07-27

Fixed

  • Only your own administrators can accept your Terms of Service. Support staff helping you set up can now work alongside you without being asked to agree to the terms on your behalf — accepting stays with the people at your organisation who are authorised to do it. They will see a reminder that it is still outstanding, and nothing is blocked for anyone in the meantime.

Added

  • Safety. A new area for the safety side of running an operation.

    • Hazards and incidents. Report a hazard, a near miss, an injury or damage from one place. Drivers can report a hazard too — they are the ones who see the road. Each report can carry who was involved, an investigation, and the actions taken because of it.
    • First aid. Record treatment given: what happened, what was done, and what happened next. Kept separate from the rest of the safety area, and only visible to the people you choose, because it is health information.
    • Risk register. Score a risk before and after your controls, record which controls you rely on, name an owner and set a review date. Reviewing a risk keeps the earlier version rather than overwriting it, so you can always show what the register said at any point in the past.
    • Inductions and policies. Write an induction with pages and questions, or a policy that is simply read and agreed to. Assign it to a role — everyone in that role now and in future picks it up automatically — or to named people. People confirm and sign, and the signature is tied to the exact version they read. Publish a new version and everyone is asked again, with a note of what changed.
    • Outstanding safety work and inductions appear in your task list. Nothing here ever stops a driver starting a run.
  • Reminders for tasks. Tasks with a due date are now chased automatically — ahead of the date, on the day, and again if they slip. Reminders follow the task if you reassign it, and stop as soon as it is done.

  • Forms can now be filled in. Until now you could build a form but nothing could open it. Every question type you can add in the form editor now renders properly, on a phone as well as a computer, in both light and dark.

  • Preview. See exactly what someone filling in your form will see, before you make it live. Nothing you type in a preview is saved.

  • Signatures. A signature question now gives people somewhere to sign, with Clear and Undo. On a computer they can also choose "Sign on your phone": scan the code shown, sign with a finger, and the signature appears back on the computer automatically. The code works once and expires after a few minutes.

  • Share a form with people who have no login. Onboarding forms can be opened by a link — useful for parents enrolling a child, who should not need an account. Only forms meant for this can ever be shared that way, and only while you have them switched on; turn a form off and its link stops working immediately.

  • Answers are encrypted. Everything submitted through a form is now encrypted before it is stored, the same as the other personal details on the platform. Because of that, the responses list shows who submitted and when; open a response to read the answers themselves.

Fixed

  • File upload questions keep their limits when a form is saved. The file size and file type restrictions on an upload question were being lost the first time the form was saved, so the question went on accepting files it should have turned away. Re-open any form with an upload question and check its limits are what you expect.
  • Forms hold onto their settings correctly when saved. Opening a form and saving it now leaves everything exactly as it was, including the questions the platform supplies itself — which are also clearly marked in the form editor and protected from being copied or removed by mistake.

[1.4.2] — 2026-07-27

Fixed

  • Internal fixes to the platform administration tools. No change to anything you use day to day.

[1.4.1] — 2026-07-27

Fixed

  • Internal fixes to the platform administration tools. No change to anything you use day to day.

[1.4.0] — 2026-07-27

Fixed

  • Tasks now clear themselves as soon as the problem is fixed. Previously a task raised automatically — a bus grounded by an open defect, a credential coming up for renewal — stayed on the list until the following morning's check, even after the underlying issue had been dealt with. An urgent task saying a bus was off the road when it was already back in service is worse than no task at all, because it teaches people to skim past the urgent ones. Resolving the defect, renewing the credential or renewing the compliance record now clears the task straight away, and the overnight check stays in place as a safety net for anything it misses.

  • The top menu no longer wraps onto a second line on wide screens while leaving a gap beside it.

[1.3.0] — 2026-07-27

Fixed

  • The version shown at the bottom of every page was out of date. It had been reporting an older release than the one actually running, which matters more than it sounds: that number is how you check whether a fix you have been waiting on has reached you. It is now read directly from these release notes, so the version in the footer and the release described on this page can no longer disagree.

[1.2.0] — 2026-07-27

Added

  • Automatic, encrypted database backups. Your data is now backed up automatically on a schedule, to storage that is separate from the platform's own — held in a different place, reachable with different credentials, so a problem affecting one cannot reach the other. Every archive is encrypted, and the system will refuse to write one at all rather than write it unencrypted. Backups are verified as they are made, and a restore is rehearsed weekly, because a backup nobody has ever restored is an assumption rather than a plan.

  • Security monitoring across our platforms. Tutela now shares security signals with the monitoring service that watches our other systems, so an address seen attacking one platform can be turned away from this one before it arrives. Only technical details are shared — addresses, times and outcomes. No student, guardian or staff information of any kind leaves the platform, and the monitoring service is never consulted while a page is loading, so it can never slow you down or stand between you and your data.

  • School staff now accept portal terms before they can see a student. Until now, a school contact you gave portal access to could open a student's travel record having agreed to nothing with us — the data-sharing agreement you record against the school was the only thing standing behind it. School contacts are now asked to accept a short set of School Portal Terms the first time they open the portal, and cannot see anything until they do.

    It is a separate document from your own Terms of Service, deliberately. Your terms are a commercial agreement between you and us; a school is not our customer and has no business being bound by them. What school staff accept instead is a plain-language undertaking about the children's information they are shown: that they will look only for a genuine school purpose, keep what they see confidential, not copy it out or share their sign-in link, and report anything that looks wrong. It tells them plainly that every record they open is logged against their name, and that guardians can ask to see who has viewed their child's record.

    Each person accepts for themselves rather than one person accepting for the school, because the undertaking is about what that individual does with what they see. Accepting costs the school nothing and commits it to nothing.

    Nothing changes for parents or drivers. Neither is asked to accept anything — both are covered by your acceptance of your own terms. Drivers in particular will never be shown a terms screen: a driver held at a dialog at the start of a morning run is a run that does not leave, and no amount of paperwork is worth that.

    You can read the School Portal Terms from the footer of our website before offering portal access to a school, and a school can read them without an account.

[1.1.0] — 2026-07-26

Added

  • Tasks — one place for everything that needs attention. A new Tasks screen collects both the jobs your team writes down and the things the platform notices for you. Every morning it checks for qualifications and vehicle compliance coming up for renewal, credentials recorded but never verified, and defects sitting open, and raises a task for each — so an expiry is something you are told about rather than something you discover on the morning of a run. Tasks are assigned to a person or to the whole business; a shared task is visible to every administrator, and whoever completes it completes it for everybody. Each one links straight to the record it is about, so acting on it is one click rather than a search. Tasks that fix themselves — a renewed qualification, a resolved defect — close on their own, so the list stays worth reading.

  • Terms of Service and Privacy Policy are now published. Both are readable by anyone, without an account — a school deciding whether to share an enrolment list, or a parent told their child's route runs on Tutela, shouldn't have to ask permission to find out how the information is handled. The privacy policy sets out exactly what is held, who can see it, where it is stored, and how long it is kept.

  • Your administrator accepts the terms once, for the business. Tutela asks the operator to accept, not every individual. Your drivers, office staff, parents and school contacts are never asked to agree to anything and are never held up by it — a driver about to start a morning run will never meet a terms screen. If the terms change, an administrator is asked to accept the new version; everyone else keeps working, and simply sees a note that an administrator needs to act.

  • Set the qualifications each role needs. A new settings page lets you say what your drivers and staff must hold — and, just as importantly, shows you that list when an assignment is refused. Previously rostering could be blocked with no screen anywhere explaining which qualification was missing.

  • Tutela now suits operators who don't run school services. Tell us what kind of services you run and we'll suggest a sensible starting set of requirements. If you carry no unaccompanied children, you're no longer asked for a working-with-children check. Licence and medical checks still apply either way.

  • Refusals now explain themselves. When a driver can't be rostered, the message names the qualification and the reason — missing, not yet verified, revoked, or expiring before the end of the assignment — instead of simply refusing.

  • Filter the fleet by status. The vehicle list can now be narrowed to active, in maintenance, grounded or retired, with a count on each. The dashboard's "Grounded" figure links straight to the grounded list.

Changed

  • The route page is easier to work with. Its sections are now tabs — stops and map, students, roster — instead of one long page. Adding a driver or a student no longer throws you back to the top: you stay where you were working.

  • "Clearances" are now "Qualifications". The same screen, a clearer name: it has always held driver licences, medical certificates and first aid alongside working-with-children checks, and calling the whole thing a clearance suggested it was only about the latter. Nothing you have recorded has changed.

Fixed

  • The Tutela logo now appears everywhere it should. A few screens — choosing a company, the parent portal, and the sign-in pages — were still showing the name as plain text instead of the logo.

[1.0.0] — 2026-07-26

The first release of Tutela.

Added

  • You can see which version you're on. Every page footer now shows the running version and links straight to these notes, so it's easy to tell whether a change you've read about has reached you yet.
  • A proper way to get in touch. "Request access" now opens a short form on the site instead of trying to open your email program — which simply did nothing if you use webmail. Tell us about your operation and it reaches our team directly, so nothing gets lost. Sending it doesn't create an account: we set each operator up individually, and we'll reply by email.

Changed

  • Tutela now looks like Tutela. The platform has adopted its full visual identity — the shield-and-bus logo, the navy and cream palette, and a new heading typeface. You'll see it across the site, the console and your browser tab. Everything is served from Tutela's own servers, as always: no outside fonts, no outside trackers.
  • Easier to read, in both light and dark. Every colour pairing in the interface has been checked against the accessibility standard for text contrast, in both the light and dark themes, and adjusted where it fell short. Status colours were also checked to make sure they can be told apart at a glance — an "expiring soon" badge should never be mistakable for anything else. Form fields now have a clearer outline.

Fixed

  • Only your own people appear in your lists. A driver dropdown on one of the compliance screens was showing people from outside your organisation. It now shows only your own active drivers.
  • Suspended drivers no longer appear when rostering. Someone whose access has been suspended can't be picked for a route or a compliance record, so you can't accidentally roster a driver who won't be able to sign in.
  • Clearer labels. Roles, statuses and clearance states in the Team list now read in normal sentence case, and expiry warnings say "Expires in 14 days" rather than "expires in 14d".
  • "Are you sure?" now actually asks. Several actions that cannot be undone — suspending a team member, unlinking a guardian from a student, removing a student from a stop, revoking an access token or a trusted device, ending a data-sharing agreement — were going ahead on the first click without showing the confirmation step they were meant to. Every one of them now stops and asks first, and the prompt tells you exactly what will happen before you commit to it.
  • Staff see their full console again. Some staff accounts were shown only the dashboard and were blocked from the rest of the console; team members now see every area and action their role allows.
  • Tidier menus. The console menus now open one at a time and close when you click away or press Escape.
  • Searchable timezone. Choosing a timezone is now a quick type-ahead instead of a very long list to scroll.
  • Link a student to their school. You can now set a student's school right on the student form.
  • Maps now load reliably. A recent library update had left the route and driver maps blank; they now show the map and stops correctly again.
  • No more double-assigning a student to a route. When adding a student to a stop, the list no longer shows students who are already on that route.

Changed

  • A tidier menu. The console menu is now organised into clear groups (People, Operations, Fleet, Schools, Settings), so it's quicker to find what you need.

Added

  • A public front page. The website now opens with a proper introduction to Tutela — what it does, how it keeps children safe, how it protects their information, and how a bus operator gets in touch to come on board — instead of the technical placeholder that used to sit there. It works on phones and in both light and dark themes.

  • Release notes you can read. These notes now have a page of their own on the website, so you can see what's changed without signing in.

  • Clearer about what we do and don't track. Our front page now says plainly that Tutela tracks buses, not children. While a run is on, we record where the bus is so your operator can answer your call, and we record that a child got on and got off at their stop so nobody is left behind. We do not keep a location history of a child, and the bus's own trail is discarded within a day. The wording we had previously was vaguer than that, and we'd rather be exact.

  • Record and verify a driver's working-with-children clearance. There is now a screen for each team member where you can record their clearance — type, state or territory, card number, and expiry — then mark it verified once someone has checked it against the issuing register. Recording is deliberately not the same as verifying: a clearance does not count until it has been checked. Your team list now shows each driver's clearance at a glance, including one that is due to expire, so nobody is quietly blocked from driving on the morning of a run.

  • Add and manage your team. Company admins can now create and manage their own staff and driver accounts — set each person's role, and suspend or reactivate access. New accounts get a one-time temporary password to share, which the person changes when they first sign in.

  • See which devices are signed in. A new screen shows every device currently trusted to stay signed in to your children's information, so an admin can review and revoke access at any time.

  • Manage your company's details. Company admins can now update their operation's name, contact details, address, and timezone. Setting the correct timezone matters — every time shown across the platform is displayed in it.

  • The driver map now works with no signal. The map for a run is stored on the device when it's loaded, so it keeps working in areas with no mobile coverage — the driver still sees the route and their position on the bus.

  • Another layer of protection around your data. We've added a further safeguard at the database itself, so each operator's records stay walled off from every other's — defence in depth beneath the checks already in place.

  • A portal for schools. Schools you work with can be given their own secure, read-only view of which of their students are on which service today and whether each has boarded or been dropped off — nothing more. Access is governed by a formal data-sharing agreement you control: you choose exactly what each school can see, and access ends automatically when the agreement lapses.

  • An integration API. Connect your other systems — school roll syncing, rostering, reporting — using secure, per-integration access keys that you can scope to just what each one needs, set to expire, and revoke at any time.

  • Outbound notifications to your own systems. Subscribe your systems to receive a secure, signed message when key events happen, so your tools can stay in step with what's happening on the road.

  • A portal for parents and carers. Sign in with a link sent to your email — no password to remember — and see your children in one place: their stop, their pick-up and drop-off times, and where they are today ("On the bus 7:44am"). Your phone stays remembered, so next time you go straight in.

  • Tell the driver your child isn't travelling, in a few taps. Choose today, tomorrow, a date, or a range of days; morning, afternoon, or both; and apply it to brothers and sisters at the same time. The driver sees it on their run sheet, so nobody waits at the stop for a child who's staying home — and you get a clear confirmation. If a run has already started, we tell you plainly rather than pretend the change went through.

  • See who has looked at your child's information. Every parent can view a simple report of who in the company has seen their child's record, and when.

  • Daily bus safety checks that keep an unsafe bus off the road. Operators can build their own pre-start checklist for drivers to complete before a run. If a driver marks a serious item as faulty, the bus is automatically taken out of service and a fault is logged for the workshop — and a run cannot begin until the check has been completed and passed. A bus stays out of service until every open serious fault has been signed off with a note. On the bus, the check is a simple Pass/Fail screen with large buttons, built for a driver at the wheel.

  • A compliance home that tells you the truth at a glance. One dashboard shows how many records are overdue, how many fall due in the next 30 days, and how many buses are currently out of service — with the details a click away.

  • Keep every compliance record in one place. Track registrations, inspections, insurance, accreditation and driver licences with their due dates, and log each bus's service and maintenance history. Records are colour-flagged as current, due soon or overdue.

  • Automatic expiry reminders. As any record approaches its due date — and again once it has passed — your compliance staff are reminded by email, so nothing lapses unnoticed.

  • Report and clear vehicle faults. Staff and drivers can report a fault against a bus; a serious fault takes the bus off the road immediately, and only a compliance officer can sign it off to return the bus to service.

  • The operator console has arrived. Bus operators can now sign in and manage their students, guardians, buses, stops and schools in one place, with fast search on each. The console works across desktop, tablet and phone, and looks right in both light and dark themes. Sensitive details like a child's medical notes or home address are shown only to staff whose role allows it.

  • Import a route from a spreadsheet. Upload your route workbook and the morning and afternoon services are read in and set side by side, with the stops and timings laid out and a comparison to check before the route goes live. A map view of each route is being built alongside it.

  • Student photos and document storage. Add a photo to a student's record, and keep your compliance documents in one place. Uploaded files are scanned for viruses, and student photos are shown only to staff whose role allows it.

  • Build your afternoon run from the morning one. Duplicate a route to create its return service in a single step — the stops reverse and the times carry across, ready to adjust.

  • Assign students to stops and roster your drivers and buses. Set who rides from which stop, and put a driver and vehicle on a route — with a safety check that stops an assignment when a driver's clearance has lapsed or a bus is out of service. Link guardians to students, with sensitive custody details visible only to staff whose role allows it.

  • The driver app. Drivers can start their run and mark each child on, off, or absent — and it keeps working with no signal, saving every action and syncing when the bus is back in range. A run can't be finished until every child who boarded has been marked off and the driver has confirmed a walk-through of the bus. If anything doesn't add up, the office is alerted straight away.

  • Live dispatch view. The office can see the day's runs at a glance — who's on board, progress along the route, and anything that needs attention first.