Northwind Cloud weekly report
Report NWC-R-2026-W40 · Period 28 Sep to 4 Oct 2026, with a trailing 8-week window from 10 Aug 2026
Coverage 6 types of source (issue trackers, vendor forums, Q&A sites, help-center communities, release notes, status pages), 1,904 posts scanned, 412 judged relevant, 187 unique reporters. 162 citations checked; every citation in the released report resolves and was verified. Before release: 5 claims removed, 3 rewritten, 1 downgraded. 0 safety-class topics pending human review.
Known gaps One community forum awaiting written permission. Sources that need a paid license, such as Reddit, are not read.
Counts measure public discussion in the sources read, not incidence or failure rates.
Executive summary
Headline. Sign-in loops on SSO sign-in rose for the second week, and 9 reporters described them this week. Aggregated
Top issues
| ID | Issue | Severity | Priority | Reporters (week / 8 wk) | Trend | Status | Why it matters |
|---|---|---|---|---|---|---|---|
| NWC-ISS-4H8T2C | Sign-in loop after SSO sign-in, rising after certificate rotation | S2 | 74 | 9 / 23 | ↑ Rising | Investigating | Reporters on the Gov tiers describe being unable to reach the console until an admin acts. |
| NWC-ISS-9P2W6M | Scheduled export jobs stall at 99% | S3 | 58 | 4 / 17 | → Stable | Known | Reporters describe re-running exports by hand each morning. |
| NWC-ISS-3J7Q5R | Audit log search returns no results for ranges over 30 days | S3 | 52 | 2 / 12 | → Stable | Fixed in 8.14.2 | Fix shipped two weeks ago; too little volume before the fix to compare. |
Top requests
| ID | Request | Demand | Requesters (8 wk) | Trend | Linked issue |
|---|---|---|---|---|---|
| NWC-FR-6D1K8V | Bulk role assignment from a CSV file | 66 | 31 | ↑ Rising | None |
| NWC-FR-2M5X9B | Scheduled audit log export to an external log store | 54 | 19 | → Stable | NWC-ISS-3J7Q5R |
| NWC-FR-8F3N4T | Dark mode in the admin console | 41 | 22 | → Stable | None |
What users praise (in development)
This section is in development and is not yet in production reports.
| What users like | Reporters (8 wk) | Badge |
|---|---|---|
| Role templates save setup time for new teams | 14 | Aggregated |
| Status page posts arrive quickly during incidents | 9 | Aggregated |
Safety flags. None this week. Aggregated
Fix verification. NWC-ISS-3J7Q5R: Inconclusive (too little volume before the fix to compare). Aggregated
What changed
- NWC-ISS-4H8T2C moved from 5 to 9 reporters this week, after the 8.14.1 release on 22 Sep. Aggregated
- NWC-FR-6D1K8V gained 7 new requesters, 4 of them on the Gov tiers. Aggregated
- NWC-ISS-3J7Q5R had 2 reporters this week, against 3 in the week before 8.14.2 shipped. Aggregated
Deep dive: NWC-ISS-4H8T2C, sign-in loop after SSO sign-in, rising after certificate rotation
Also called SSO redirect loop; login bounce after cert renewal · Severity S2 (data loss, lockout or unavailable), supported by 11 independent reporters · Status Investigating
Priority 74 of 100, by factor
| Factor | Points | In plain language |
|---|---|---|
| Severity | 24.0 | S2: reporters describe losing console access. |
| Reach | 22.7 | 23 unique reporters and 58 mentions in 8 weeks. |
| Velocity | 10.0 | 14 reporters in the last two weeks against 5 in the two before. |
| Workaround value | 6.5 | The workaround with the most reports that it worked needs an admin. |
| Corroboration | 5.0 | Two types of source each have 2 or more reporters. |
| Recency | 6.0 | Most reports are from the last 14 days. |
What would change this: a low-burden workaround that 3 or more reporters say worked would lower Priority by about 3 points.
Symptoms
- 18 reporters describe being returned to the sign-in page immediately after a successful identity-provider sign-in. Reported [E14] [E22]
- 7 reporters describe the loop starting the first time they signed in after the scheduled certificate rotation. Reported [E31]
- 4 reporters describe the loop clearing on its own after several hours. Reported [E40]
Error messages and codes
| Text as reported | Reporters |
|---|---|
ERR_SAML_SIG_INVALID |
9 |
Session could not be established (code 4012) |
6 |
Affected environments
| Tier | Reporters | SSO (SAML) | Smart card | Password | Unknown method |
|---|---|---|---|---|---|
| Commercial | 3 | 3 | 0 | 0 | 0 |
| Gov 1 | 11 | 8 | 2 | 0 | 1 |
| Gov 2 | 6 | 4 | 2 | 0 | 0 |
| Gov 3 | 0 | 0 | 0 | 0 | 0 |
| Unknown tier | 3 | 1 | 0 | 0 | 2 |
| Total | 23 | 16 | 4 | 0 | 3 |
Versions named: 8.14.0 (13 reporters), 8.14.1 (6), not stated (4). Not reported on: the Gov 3 tier; password sign-in. Aggregated
The concentration on SSO sign-in after the rotation date is consistent with the identity-provider metadata not being refreshed on the tenant side; this suggests investigating how cached signing certificates are replaced during rotation. Inferred [E31]
Timeline (first-person reporters per week, 12 weeks)
| Week starting | Reporters | Event |
|---|---|---|
| 13 Jul | 0 | |
| 20 Jul | 0 | |
| 27 Jul | 0 | |
| 3 Aug | 0 | |
| 10 Aug | 0 | |
| 17 Aug | 0 | |
| 24 Aug | 2 | |
| 31 Aug | 2 | Release 8.14.0 (1 Sep) |
| 7 Sep | 3 | Scheduled SSO certificate rotation, Gov tiers (status page, 9 Sep) |
| 14 Sep | 2 | |
| 21 Sep | 5 | Release 8.14.1 (22 Sep) |
| 28 Sep | 9 |
Workarounds
| Workaround | Label | Worked / partial / did not | Threads | Burden | Risk badges |
|---|---|---|---|---|---|
| Ask an organization admin to re-upload the identity-provider metadata | Confirmed (5) | 5 / 1 / 1 | 3 | High | Requires admin |
| Clear console session cookies and sign in again | Confirmed, temporary (3) | 3 / 5 / 1 | 4 | Low | Time burden |
| Switch the tenant to password sign-in until fixed | Mixed | 2 / 0 / 1 | 2 | High | Requires admin, Disables security function |
| Open a support case for a manual metadata refresh | Secondhand | Relayed only | 2 | High | Vendor ticket |
The report does not endorse workarounds. Labels count what users said about their own attempts; they are not our conclusions.
Suggested investigations
- Compare tenants that re-uploaded metadata with those that did not, for the 7 reporters who named the rotation date. Inferred
- Check whether 8.14.1 changed session handling for the Gov tiers, given the rise in the week it shipped. Inferred
Verifier tally
| Check | Items checked | Result |
|---|---|---|
| Citations resolve to stored posts in the window | 162 | 1 claim removed |
| Quotes match the cited post exactly | 38 | 2 quotes removed, 1 claim removed with them |
| Numbers recompute from stored data | 214 | 2 rewritten |
| Error and version strings appear word for word | 19 | 1 claim removed |
| Reported claims supported by their citations | 97 | 1 downgraded to Inferred, 1 removed |
| Every factual sentence cited | 241 | 1 sentence removed |
| No usernames, personal data or full posts | Whole report | Passed |
| Hedged wording for interpretations | 22 | 1 rewritten |
| Human review on safety-class topics | 0 topics | Not applicable |
Totals: 5 claims removed, 3 rewritten, 1 downgraded. The report was released after all checks passed.
Evidence appendix (excerpt)
| ID | Type of source | Author (pseudonym) | Date | Claim type | Verifier status | Link | Quote |
|---|---|---|---|---|---|---|---|
| E14 | Vendor forum | reporter-7Q2 | 29 Sep 2026 | Reported | Verified | https://example.com/forum/t/1042 | Quote omitted in public sample |
| E22 | Issue tracker | reporter-K4M | 1 Oct 2026 | Reported | Verified | https://example.com/issues/318 | Quote omitted in public sample |
| E31 | Q&A site | reporter-3VD | 10 Sep 2026 | Reported | Verified | https://example.com/questions/77 | Quote omitted in public sample |